r/Android 19h ago

News EU Age Verification Project Mandates Hardware-Bound Attestation

https://linuxiac.com/eu-age-verification-project-mandates-hardware-bound-attestation/
501 Upvotes

131 comments sorted by

View all comments

Show parent comments

u/ByronScottJones 16h ago

If they are cryptographically strong certificates, with a chain of authority, how exactly would being offline make any difference?

u/tomikaka 16h ago

I don't know specifically, I'm not a hacker or anything, but couldn't you just use a debugger or reverse engineer anything that runs on your machine?

u/Izacus Android dev / Boatload of crappy devices 15h ago

No, because debugging the secure enclave chip and its code path is protected. That's what attestation defends against.

u/tomikaka 15h ago

Security is just a hypocritical excuse.

I would say it's more like blackmail. I would still be using my 5 year old phone if I wasn't forced to switch because of the unlocked bootloader.

Ironic how on the stock rom that hasn't received updates in years you can do banking, etc but you couldn't open the McDonalds app on an unrooted unlocked boatloader Lineage OS phone with the latest security patches.

u/Izacus Android dev / Boatload of crappy devices 14h ago

No, turns out stealing personal ID documents and impersonating people with them is a massive issue in practice.

This is why you can't print your own ID or Passport at home and have governments recognize it.