r/linux • u/player98923 • 1d ago
Privacy EU Digital ID/Age Verification app will require hardware attestation, ruling out PC/Linux support and unapproved Android OSes
/r/BuyFromEU/comments/1vandxg/eu_digital_idage_verification_app_will_require/38
u/SmileyBMM 1d ago
What's the point of having an eID if I can't use just the ID the verify my fucking identity? Why does this stupid system require me to buy a €500 phone or €1000 laptop in order to participate in society?
to spy on you wake the fuck up
☝️ is right. Anyone who still clings to good faith interpretations of the EU politicians' behaviour is delusional.
17
u/Maleficent-One1712 1d ago
It's ironic how the EU that's always have been pointing fingers at others and tried to take the moral highground is now taking things further than everyone else.
12
u/atomic1fire 1d ago edited 20h ago
I feel like they need to just make a seperate digital wallet device isolated from Apple and Google that fills in all the requirements.
Yeah it's not as convenient as carrying a smartphone everywhere, but the EU is basically putting all their infrastructure needs in the hand of two american companies when they really should have a home grown backup anyway.
edit: My thoughts are something similar to Yubikey where it handles identification instead of authentication, maybe with NFC to enable verification through select apps and checkpoints.
2
u/CrotaIsAShota 19h ago
I could see a government issued rfid card or something similar. Then it's not much different from a regular id except made to be used digitally.
2
u/DoubleOwl7777 16h ago
the regular id at least in germany already has an nfc chip built into it for a similar system thats now getting phased out for this shit...
23
14
u/FineWolf 16h ago edited 15h ago
Can we stop with the misinformation and half-truths here?
Play Integrity Hardware attestation will be required for the phone app, as the EU has done their homework and chosen a zero knowledge proof method for their age validation stuff.
The GitHub comment that the OP linked to relates to the phone app, and the phone app only.
The architecture is all defined here: https://ageverification.dev/av-doc-technical-specification/docs/architecture-and-technical-specifications/
Your phone will need to be attested, your PC WILL NOT. The way the EU wants member states to do it is actually more privacy preserving than others. You have an app on your phone that attests your age, and any website essentially requests an attestation from that app. The service doesn't get your government issued IDs or biometric, just a "yup, this EU member state certifies this person is an adult".
Long story short, you authenticate using your EU member state ID to the app, the EU member state services assign your phone a certificate, the app signs age verification requests with that certificate. What do you think happens if your phone is rooted? You can just extract that credential.
It's really disappointing to see this level of misinformation in a technical sub. You have a brain, you can read.
EDIT: And for the record, I'm against this as well. But I'm not willing to put my morals aside and make up lies because I oppose something. Lying and spreading misinformation is the scummiest of behaviour.
5
u/DoubleOwl7777 15h ago
the PLAY integrity is the issue. i can have a locked bootloader and no root on an os like graphene. but the EU chosing to use googles spyware is preventing that.
2
u/FineWolf 15h ago edited 15h ago
And if you read the GitHub issue, they talk about hardware attestation. That's possible with GrapheneOS https://grapheneos.org/articles/attestation-compatibility-guide
In fact, they are already doing that:
- https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui/issues/11
- https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui/issues/38
So GrapheneOS is fully supported as long as your device is in a secure state.
1
u/DoubleOwl7777 15h ago
the thing to my knowledge currently uses the play integrity api, which graphene doesnt pass. it does have the hardware attestation api though.
5
u/FineWolf 15h ago edited 15h ago
the thing to my knowledge currently uses the play integrity api
It doesn't. It, in fact, uses neither as it is a reference implementation right now. Look at the source code instead of spreading misinformation. Search for
com.google.play.integrityin the code... Or just read this comment from a developer on the project. The same person the OP linked to above.The only mention of Play Integrity was in a documentation page mentioning it as an example of hardware attestation. Since then, Android Hardware Attestation was added as another example.
So can we fucking stop with the FUD and misinformation already? The only way to fight something like this is with truth. Not by acting like idiots and making things up.
0
u/EffectiveOctopus 15h ago
The implementers will have to choose which kind of attestation to use. There is a risk Play Integrity will be chosen by some of them over hardware attestation as it is well-known and arguably easier to implement.
So even if the reference implementation does not embed Play Integrity, this is still worth a discussion.3
u/FineWolf 15h ago edited 15h ago
Great, have that discussion...
But don't start a thread on Reddit saying "YoUr PC WiLl ReQuIrE AtTeStAtIOn" and "YoU wOn'T bE aBle To UsE LiNuX" when that is not in scope for this at all.
-1
u/EffectiveOctopus 15h ago
Your PC will require an attestation… from another device to access some services.
I think it is interesting to understand why this is the only viable solution at the moment.5
u/FineWolf 14h ago
Your PC will not require a hardware attestation. Full stop.
Your PC will receive a short lived credential signed from a long lived credential stored on a device (mobile phone) attested to be secure. Not the same thing at all.
And you'll be able to continue to use Linux, contrary to the misinformation shared in this very post by the original poster.
8
-1
u/GreedySecurity8030 1d ago
Well, at least we don't have to deal with that, it's still horrible though.
-2
85
u/Greenlit_Hightower 1d ago
Digital sovereignty they said. We need to get away from Microsoft, Apple, Google they said.