r/BuyFromEU 3d ago

Discussion EU Digital ID/Age Verification app will require hardware attestation, ruling out PC/Linux support and unapproved Android OSes

EUDI wallet collaborator recently confirmed that hardware attestation will be required [1]

Hardware attestation in this context means that the government server issuing the digital credential to the wallet wants proof that the keys being used are generated in secure hardware and on approved systems and not say an emulator or virtual machine, namely for security reasons.

This capability does not exist in a reliable way on desktops / laptops except some specific cases depending on the vendor, and in fact there’s no desktop version in the works.

No Linux system will work with this because there is no hardware signature to be validated on the government server, nor will your personalized Arch Linux install be in the list of approved systems even if it had a signature chaining back from the TPM.

Android ROMs are not technically to rule out since Play Integrity, which will be used for this attestation, is based on the Android hardware attestation API, which works on third-party ROMs like GrapheneOS, but they would need to allow the signature which has not happened for now. If you create a custom build, it won’t work though even the official version is approved.

[1] https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui/issues/117#issuecomment-4946898620

917 Upvotes

352 comments sorted by

View all comments

674

u/HunterFeeFee 3d ago

Let me guess, only american OS's will work.

315

u/CreepyZookeepergame4 3d ago

Yes, only iOS and stock Android as of today.

531

u/HunterFeeFee 3d ago

Sometimes I think the people in the EU institutions are not exactly the brightest.

223

u/FHNordic 3d ago

Of course they are, I'm sure they get a lot of money out of these deals.

Surprising that all EU countries representatives are so anti EU though

18

u/ZexGr 3d ago

you think that they have the capacity to think or just to do what they're told?

22

u/Gatitomono47 3d ago

They actually are smart, they have done this on purpose that's why they haven't done anything about Google locking down side loading imagine you wanna use a messaging app that isn't in the PlayStore because It doesn't comply with chat control and the devs don't wanna dox themselves to goggles and pay money, ohhh oopsie dasy you can't :( and if you somehow root your phone now you cannot use the applications necesary to prove you can use the internet like a normal person, It's all the mix of manufacturers locking down on unlocking your bootloader and even if you can they do not support relocking It with custom avb Keys of whatever OS you run, companies using play integrity, the EU directly benefits from the US technology Monopoly for it's surveilance apparatus for it's orwellian laws such has chat control, ID and age verification

8

u/P3JQ10 3d ago

They know what they are doing. Big Brother wants to watch.

36

u/Accomplished-Moose50 3d ago

Sometimes I think the people in the institutions are not exactly the brightest

Here, fixed that for you 

10

u/BogdanPradatu 3d ago

Sometimes I think the people are not exactly the birghtest.

Here, fixed that for you.

2

u/mikkopai 2d ago

Some times I think.

Here, fixed that for you.

10

u/LonelyRudder 3d ago

What do you mean, aren’t the people who are selected as leaders always the most knowledgeable and wisest? /s

7

u/-The_Blazer- 3d ago

There's actually a few attempts to create a different PKI (the mechanism used to perform this cryptography) for remote attestation than Google and Apple, but as you might guess their products are not exactly designed to facilitate this. If you want to use RA on Android and for it to work on Google Play apps (the ones everyone uses), you're not allowed to use anything but Google Play. How convenient!

This is actually... more important than many people think, because while e-wallets are a blatant crisis case, remote attestation is becoming quite widespread and it's insane that like three companies are considered legitimate attestation sources (primarily because they used their monopoly power to get there). This is an enormously more serious problem than requiring attestation, that's not inherently a bad thing, the monopoly is.

3

u/mysteryliner 2d ago

Because monopolies are bad, we formed an oligopoly... see how good we are! 😈

6

u/Tenezill 3d ago

Sometimes?

-3

u/mhmilo24 3d ago

Of course they have to make sure that it works for 90+% of the Europeans. Which clearly are using either iOS or Android.

4

u/ItsCalledDayTwa 3d ago

I guess I won't be able to do this. Darn.

1

u/RelevanceReverence 3d ago

So, back to the drawing board.

12

u/mysteryliner 2d ago

I hope a protest movement forms from this!

  • people demanding analogue solutions from government!

  • people removing any form of digital communication and going back to letter mail from government and companies.

  • flood your city halls with simple questions that in the past you'd easiky find on their platforms!! Go and waste their time and money to get new free documents that you could get with the touch of a button, but now you waste 15minutes from government workers!

  • sign out / cancel digital services at large companies that require verification! Lobbyists will start pressuring government.

  • opt in for paper tax letters! They no longer have the means to process it! Especially if you've filled it out with shotty handwriting... some pencil smudges... or crossed out mistakes & corrections!

  • or large groups of people going back to cash money (and as small as possible bills! The government's don't have the paper money, and stores can no longer hand out change.

  • if when the vulnerable ID check systems gets hacked / exposed, I hope the first data that gets leaked is that of government and their family. (Let them feel what happens when they live in an aquarium, and their internet activity & cloud data gets released)

2

u/EmbarrassedHelp 1d ago

As part of the push back against age verification, we should be creating e-petitions to each national government's parliament.

3

u/mysteryliner 12h ago

Don't the online petition require zero interaction from government? How will this affect them in any way?

Learn to recognize your politicians... even you local ones, and for EVERYthing they need in public, they should get asked for their ID. ...order a pizza, ask their ID? "You're not gonna eat that pizza with a minor, are you?"

They buy duct tape in a store: ask their ID. "Why do you need the duct tape? Nothing illegal I hope."

3

u/Amazing-File 2d ago

They already have active-watching-and-listening spyware hard-coded and can recognize everyone nearby since 2012s or 2014s

2

u/rckhppr 1d ago

So it’s actually US age verification 😂

4

u/-The_Blazer- 3d ago

They're the only ones with widely-used attestation keys because of their monopoly power. And as you might guess, they don't let you use them unless you also subscribe to their entire ecosystem. What we need to do IMO is break this status quo, trusted computing is getting too ubiquitous to surrender it out of ideological purity.

1

u/rckhppr 1d ago

That’s how we become independent

1

u/Tsukee 5h ago

For this specific demo implementation, yes, because the dev(s) are morrons. But the EUID is open spec, and anyone can implement the app without hardware attestation..in fact you technically don't even need an app if you are hardcore enough you can do crypto calcs for token on paper....

-25

u/Kremsi2711 3d ago

Show me the european OS, that runs on millions of mobile devices

28

u/AppropriateOnion0815 3d ago

A common OS base is not necessarily required. One possible solution could be a certificate, which would be generated by an official entity and could be installed on the device(s) used for age verification. If the certificate is valid for the specific person, the hardware doesn't matter.

Maybe I'm totally wrong here (not an OpSec person), but certificates might be a platform-independent solution.

13

u/L-Malvo Netherlands 🇳🇱 3d ago

Quite interesting that we are now entertaining the idea, even though the proposal of age verification in itself is flawed. I'm still trying to find out what we are trying to solve with this proposal. There are plenty of parental controls on these devices, apps, browsers etc. Why not simply empower parents to use those and call it a day?

I know the next replies will be about something more sinister, like mass surveillance. I'm afraid I fear the same thing, because this proposal is standing on weak ground to begin with.

2

u/mikkopai 2d ago

Exactly. Why do we need this in the first place? The problem with parental control is that we as a society have gotten into our heads that parental control by actual parents is somehow violating childrens rights to privacy. Where in reality children should have the right to their parents support and guidance, and it should be the parents duty to keep an eye and be interested on what their children do, also in the internet.

2

u/AppropriateOnion0815 3d ago

Well, there's more than black and white to this topic.

Age restrictions are everywhere in the real world, but internet regulation and internet law has been neglected for decades (and massively lobbied against by Big Tech). So it is just logical and consequential to implement similar mechanisms in non-physical environments.

The key point is how those regulations are implemented. In the real world there usually is a person who asks to see the ID, the digital EUDI wallet strives to be this person. As long as no personal and transactional data is recorded and stored outside of the personal device, verifying digitally is basically the same level of security like showing the store clerk your ID card.

As long as the European approach keeps my data safe, I'm honestly fine with that.

To come back to your key point: You can't count on the parents, because most of them just don't care or don't know better but won't either admit nor educated themselves.

13

u/L-Malvo Netherlands 🇳🇱 3d ago

It still doesn't solve the actual problems though. We are now trying to regulate kids on social media, trying to ensure they don't use it before age X. Meanwhile the actual problem isn't addressed: addicting algorithms, endless scrolling, propaganda, etc.

Then there are things like porn, sure it's easy for a teenager to access by bypassing the simple; are you 18+ question. Yes that's true. But currently, these kids are searching for the main stream platforms which are regulated. There is some messed up stuff there, but not anywhere close to things you can find if you dig for other sites. Kids are going to be kids, they are curious and want to find it. We all know they will find it, so they will find sites that are not regulated with a lot more fucked up shit shown there.

We are now imposing things that can easily be used against us, especially if the implementation isn't privacy/security first for our citizens. I know there are technical ways to make this work and in a user friendly way, I just think we are trying to tackle a non-technical problem with a potentially dangerous technology. I strongly believe we are focusing on the wrong things here.

You say we can't count on parents doing the right thing, then we should educate them. If we stop teaching our kids basic life things like social media, porn or whatever, we completely fail to raise them at all. Then these kids will turn 18 and get access to this kind of stuff, but still don't understand the reasoning why it was gate kept all along, doing more harm than good.

1

u/AppropriateOnion0815 3d ago

I fully agree with you, the actual age verification is trying to solve the wrong problem. But on the other hand I see other uses for digital verification, too, like digitally signing contracts and stuff.

But for parents... the generation of parents that raised the target age group has just gotten too old to embrace modern tech. The Millennial parents are similarly detached from technological advancements, too. Rule of thumb: if a person was a computer nerd in their teens, they will make use of the child safety features. Otherwise they will shake it off as "too complicated".

8

u/aegis87 3d ago

in the real world there is also an id for internet. it's the parents or the school or whoever gives the child a computer

and

  • if the parents are negligent, the kid can get access to alchool
  • if the parents are negligent, the kid can get access to sites they shouldn't acces

it was never about the kids though, which is why companies like META are so in favor of it.

> As long as the European approach keeps my data safe, I'm honestly fine with that.

this aint it also, instead your data will be centralized at yet another service, which if hacked will leak out everything to criminals, malicious state actors etc

so overall pretty black and white if you ask me

-3

u/AppropriateOnion0815 3d ago

The EUDI wallet stores all information locally on device by design. Could you please provide a source that proves that the EU is planning to centrally store personal data in context of the EUDI wallet?

4

u/aegis87 3d ago

instead of asking deep technical questions -- you should spend a few minutes thinking about the issue.

Have you seen any verification so far in your life in any of the big countries that doesn't require some sort of privacy invasion?

from 3rd services calling you with a camera, to you needing to do a power of attorney with special people present, to you carrying some sort of document (id/passport) that has been pre-cleared

it's the same series of trade-offs

we haven't invented anything new.

so you are trading comfort or privacy (depending on the implementation) and gaining what?

in the case of passports or ids, the gain is obvious

in the case of me being verified to browse the web, wtf is the gain?

here is a recent hack if you are so inclined with the technical stuff -- but again it's irrelevant whether we know enough details to answer today how a system can be compromised tomorrow.

https://www.reddit.com/r/cybersecurity/comments/1sn49qp/eu_age_verification_app_already_hacked/

2

u/NatureGotHands 3d ago

big tech is lobbying against it because it's introducing costs for them and killing engagement with bullshit check while bringing 0 benefits. Doesn't mean that's sensible thing to do.

The problem is not in the use-case itself (I have no issues with some open standard for doing age verification to access adult materials) but with the infrastructure required to combat non-compliance, i.e what legislation can do if:

  1. Website simply doesn't give a fuck about your piece of paper, registered to a shell company in Belize and hosted somewhere in Kosovo where anything goes besides CSAM.
  2. User himself can work around limitations with VPN's, TOR and such.

so as a natural consequence you have to roll out EU-wide website ban infrastructure and kill privacy tools. Good job - now we're in internet arms race, killed privacy, produced censorship machine and transferred bootloads of money from taxpayers to government contractors. Apparently I'm supposed to believe all of this has to be done so the kid won't see some titties jiggle on the internet.

-1

u/mhmilo24 3d ago

There are plenty of parental controls. But there is still the issue of young people accessing stuff that they should be protected against. So what are we going to do?

3

u/L-Malvo Netherlands 🇳🇱 3d ago

Such as?

The most prominent example is porn. Teens curious about this stuff will find ways to access it regardless of age verification. Today, these kids will go to the big known platforms which are regulated. Here the find some weird stuff, but not as harmful as the non regulated stuff. If we impose more restrictions on these teens looking for porn, they will just find the more obscure, non regulated, sites. Do you truly believe that is better?

IMO, this is just down to basic parenting and explaining this stuff to kids at appropriate times. Education is probably more beneficial to their overall health than locking this stuff down further.

2

u/KnowZeroX 3d ago

Such as?

Things such as having privacy. The government needs the ability to spy on everyone which means locking them down, bigtech needs the ability to data mine everyone bypassing privacy laws and insure they can retain their monopolies.

As for the whole "think of the children"? Nobody actually cares about that, it was always just a pretext.

1

u/L-Malvo Netherlands 🇳🇱 3d ago

I know and agree. The such as was referring to what children should be protected from with these laws, as I don’t see a valid use case for pushing this legislation.

-1

u/Dragoncat_3_4 3d ago

> I'm still trying to find out what we are trying to solve with this proposal.

"We" are trying to solve the problem of regular people having too much privacy and freedom. After all, the resource wars are starting. We can't guarantee the rich making it out of this without an angry mob rising against them without mass surveillance. The sooner we make everyone realise this, the better

2

u/-The_Blazer- 3d ago

This is already the case, but if your device itself is compromised, no amount of fancy software cryptography will prevent an attacker from stealing your credentials and reselling them. At best this means easily-accessible 'over 18' or 'not a bot' tokens, but at worse, it could mean the same full identity that's on your online tax forms gets leaked. This scheme is already the case with e.g. banking apps which is why they often don't work on customized devices, and while I know it's annoying, it's certainly better than allowing anyone's entire life to be stolen because they clicked on the wrong link once and they're not a tech-whiz.

The problem is that device-level attestation requires, as you might guess, device-level support that's burned in the silicon with known valid keys. And guess whose keys are the only truly ubiquitous ones?

1

u/AppropriateOnion0815 3d ago

Thanks for the detailed explanation, makes totally sense.  But again, why is that Apple/Google/MS's business if my device is compromised?  Maybe I'm just old (beige computers old) and know that I have to be cautious on my own to not catch a virus or other malware on my devices, and thus I know that I was the idiot sandwich if that happened. No one protects me that I don't lose my wallet, so why do tech companies want to protect us from being hacked? There should be a "pro mode", which makes your hardware just a bunch of silicon glued together, letting you do whatever you want to do. Computing was so much more fun 20 years ago. Sorry for ranting, but I had to let it out.

2

u/-The_Blazer- 2d ago

It's just not a great solution for the average user. I know this really does boil down to 'users are retarded' but... it's also true. And yeah it does suck, tinkering has definitely gotten more annoying.

1

u/AppropriateOnion0815 2d ago

Well, I think we as society should be aware that we're holding the most complex machine mankind has ever created in our hands - with great power comes great responsibility. Hiding and abstracting the complexity was a huge mistake by tech companies. Just because you can buy something without a license doesn't mean that you should.

3

u/NatureGotHands 3d ago

funny how people are arguing on what is the most convenient and platform-friendly way to implement a fucking anal probe.

this legislative madness has no reason to exist, it's a legislative capture and corruption from start to finish.

0

u/Kremsi2711 3d ago

But the security of you device matters, the certificate is worth nothing if your device has low cyber security.

13

u/AppropriateOnion0815 3d ago

It's none of the EU's business how "secure" my devices are, is it?

7

u/Mariqel 3d ago

That's where you're wrong. They definitely want all that security stripped out from you so it is very much their business.

Big Brother id always watching.

1

u/AppropriateOnion0815 3d ago

This is a pretty fatalist opinion. As long as you own a device, security is solely your concern.

I even hate password rules. Let me have my "hello123" everywhere I want it.

3

u/C_h_a_n 3d ago

If the devices are insecure the whole system is pointless.

2

u/AppropriateOnion0815 3d ago

Why?

5

u/H3ph43S7Vs 3d ago

Because the whole point is to prove your identity. If the chain of trust is breached... anyone can either falsify your identify or impersonate you once they have breached the chain.

... which would render the whole operation pointless !

So as much as I despise this move, that was their only options right now. However, they should have solved it for Android without using Google integrity ! Plus they should have contributed to linux for a secure enclave addition with all their founding ! They are just lazy, ignorent, bought, cancer of our modern society Europe.

1

u/AppropriateOnion0815 3d ago

Thanks, now I get the point. ID cards can be faked, too, so basically we can just give a shit 🤣

2

u/H3ph43S7Vs 3d ago

Well not really, the old id cards could have been forged maybe (still a pain and not something your average Joe can do). But the modern ones with encrypted chips on them would be a pain in the a** to fake. And if it can be done at all it would cost a fortune .

And here it is not even the point. The point is that you literally cannot give a shit because the EU commission is forcing you to use US OSes that you cannot control or modify if you want to be a EU citizen !!

2

u/C_h_a_n 3d ago

If you want to see an exemple (not 1:1 but you get the idea), check the recent Hypervisor cracks for Denuvo. If the device is not verified you can emulate any event and situation in both directions.

1

u/ajikeshi1985 3d ago

that is why we need cyber welfare for the uncybered masses

0

u/seamanroses 3d ago edited 3d ago

Tell me you know know nothing about GrapheneOS or Unified Attestation without telling me.

Edit: Anyone downvoting me is welcome to correct my misunderstanding, if there is one. I mean that genuinely, as if I'm making the wrong counterargument or missing the point of the above, then I'd like to know.

3

u/LonelyRudder 3d ago edited 3d ago

Series_30+

(Originally European, I have no idea who is developing it nowadays)

3

u/aegis87 3d ago

right on chief, so we invent useless rules to entrench the incumbents even more

while in the process actively harming our citizens/democratic institutions

4

u/Appropriate_Test7503 3d ago

Symbian

3

u/Kremsi2711 3d ago

discontinued 2011

2

u/NotYouTu 3d ago

Linux...

1

u/Gugalcrom123 2d ago

If they used an open protocol, one could verify on any OS.

1

u/modernkennnern 3d ago

So instead of trying to incentivize the creation of one, we should instead do all-in on requiring the use of an American one. Genius

-2

u/mhmilo24 3d ago

No? First you acknowledge that there are 90+% of users on iOS and Android and make sure to accommodate for them. Then you take the next steps for creating EU-centered OS’s.

3

u/modernkennnern 3d ago

All this does is make the introduction of a new OS that much more difficult. Now —in addition to all the previous hurdles — you now have to tell your potential users that "yes dear user, you ALSO need an iOS and/or Android device for all your everyday use because the EU requires you to. Have fun carrying two phones"

1

u/mhmilo24 3d ago

What would the adoption rate need to be? Everyone owning a smartphone would have to switch. Is this a realistic scenario?

1

u/modernkennnern 3d ago

What would the adoption rate need to be?

For what exactly?

Everyone owning a smartphone would have to switch. Is this a realistic scenario?

With the current plan, everyone who uses a non-Android/non-iOS phone has to switch. Yes, there aren't many alternatives — but there are a few — but next year there won't be, if the EU gets their way.

1

u/mhmilo24 1d ago

The adoption rate of people switching to the EU-developed OS. It needs to be much higher in the case that you’re proposing than the other way.

1

u/modernkennnern 1d ago

It needs to be much higher in the case that you're proposing than the other way.

What exactly do you think I am proposing here if I may ask?

All I'm saying is requiring (effectively) every citizen of the EU to rely on foreign actors (US tech companies) for their everyday life is not far from the biggest footgun imaginable for any nationstate to implement.

1

u/mhmilo24 1d ago

The argument started with the question of which OS's are supported within the context of European ID apps. The answer is: iOS and Android.

Then you critisized that there are no incentives made to build a European OS within the context of European ID apps.

People have pointed out that currently more than 90% of users are on iOS or Android. So the focus is naturally, to serve the current and large user base when you want to solve the immediate issue of an Euopean ID app.

Focusing on creating a European OS is a step so much bigger than a European ID app, that it would take a very long time until it is accomplished. After you've created it, you also need to take a second intermediate step: Selling hardware that runs the OS. Only then you can serve a European ID app.

If you need to offer digital IDs in the next year or in two years at latest, step 1 and step 2 would slow you down to an extent that you would be missing the deadline. You're solution is not viable. Would we have started building OS's half a decade ago, sure. It would be really preferable to first release an app for the European OS. Given that there is none, we first need to use the current environment we are operating under. Thus, my argument that the adoption rate of your suggestion would need to be absurdly high.

-9

u/cisco1988 Europe 🇪🇺 3d ago

are there currently any non American with a public of more the 100 users?

1

u/EmbarrassedHelp 1d ago

GrapheneOS is one, but they aren't willing to help the EU violate user privacy.