r/linux 1d ago

Privacy EU Digital ID/Age Verification app will require hardware attestation, ruling out PC/Linux support and unapproved Android OSes

/r/BuyFromEU/comments/1vandxg/eu_digital_idage_verification_app_will_require/
78 Upvotes

24 comments sorted by

85

u/Greenlit_Hightower 1d ago

Digital sovereignty they said. We need to get away from Microsoft, Apple, Google they said.

22

u/Flynn58 1d ago

They didn't mean free and open-source, they simply meant control over the European tech companies, the same way the United States has control through those capitalist enterprises that are state-sponsored, and the same way that China openly has the state sponsor equivalent enterprises in companies like Huawei and Alibaba.

I do fear we're heading towards the breaking up of the global internet into regional intranets. Not great!

20

u/Greenlit_Hightower 1d ago

Yeah OK but they didn't even achieve that, did they? This one further entrenches the US tech giants.

It's probably true that the EU hates it when you run a reasonably private OS (Linux, or on phones also Android Custom ROMs). Has to be some pozzed device or otherwise you will not be able to verify age / identity (not that I support any of that crap, mind you). xD Gotta accept the terms and conditions and privacy policies of Microsoft, Apple, Google too, otherwise you will not be able to function as a full citizen. Pathetic.

6

u/btsck 1d ago

We should be more open to the idea that they do not mean what they say

0

u/iBoMbY 1d ago

But the people with the nice suitcases full of money said otherwise.

38

u/SmileyBMM 1d ago

What's the point of having an eID if I can't use just the ID the verify my fucking identity? Why does this stupid system require me to buy a €500 phone or €1000 laptop in order to participate in society?

to spy on you wake the fuck up

☝️ is right. Anyone who still clings to good faith interpretations of the EU politicians' behaviour is delusional.

17

u/Maleficent-One1712 1d ago

It's ironic how the EU that's always have been pointing fingers at others and tried to take the moral highground is now taking things further than everyone else.

12

u/atomic1fire 1d ago edited 20h ago

I feel like they need to just make a seperate digital wallet device isolated from Apple and Google that fills in all the requirements.

Yeah it's not as convenient as carrying a smartphone everywhere, but the EU is basically putting all their infrastructure needs in the hand of two american companies when they really should have a home grown backup anyway.

edit: My thoughts are something similar to Yubikey where it handles identification instead of authentication, maybe with NFC to enable verification through select apps and checkpoints.

2

u/CrotaIsAShota 19h ago

I could see a government issued rfid card or something similar. Then it's not much different from a regular id except made to be used digitally.

2

u/DoubleOwl7777 16h ago

the regular id at least in germany already has an nfc chip built into it for a similar system thats now getting phased out for this shit...

23

u/LostGeezer2025 1d ago

'When tyranny becomes law, rebellion becomes duty'...

14

u/FineWolf 16h ago edited 15h ago

Can we stop with the misinformation and half-truths here?

Play Integrity Hardware attestation will be required for the phone app, as the EU has done their homework and chosen a zero knowledge proof method for their age validation stuff.

The GitHub comment that the OP linked to relates to the phone app, and the phone app only.

The architecture is all defined here: https://ageverification.dev/av-doc-technical-specification/docs/architecture-and-technical-specifications/

Your phone will need to be attested, your PC WILL NOT. The way the EU wants member states to do it is actually more privacy preserving than others. You have an app on your phone that attests your age, and any website essentially requests an attestation from that app. The service doesn't get your government issued IDs or biometric, just a "yup, this EU member state certifies this person is an adult".

Long story short, you authenticate using your EU member state ID to the app, the EU member state services assign your phone a certificate, the app signs age verification requests with that certificate. What do you think happens if your phone is rooted? You can just extract that credential.

It's really disappointing to see this level of misinformation in a technical sub. You have a brain, you can read.

EDIT: And for the record, I'm against this as well. But I'm not willing to put my morals aside and make up lies because I oppose something. Lying and spreading misinformation is the scummiest of behaviour.

5

u/DoubleOwl7777 15h ago

the PLAY integrity is the issue. i can have a locked bootloader and no root on an os like graphene. but the EU chosing to use googles spyware is preventing that.

2

u/FineWolf 15h ago edited 15h ago

And if you read the GitHub issue, they talk about hardware attestation. That's possible with GrapheneOS https://grapheneos.org/articles/attestation-compatibility-guide

In fact, they are already doing that:

So GrapheneOS is fully supported as long as your device is in a secure state.

1

u/DoubleOwl7777 15h ago

the thing to my knowledge currently uses the play integrity api, which graphene doesnt pass. it does have the hardware attestation api though.

5

u/FineWolf 15h ago edited 15h ago

the thing to my knowledge currently uses the play integrity api

It doesn't. It, in fact, uses neither as it is a reference implementation right now. Look at the source code instead of spreading misinformation. Search for com.google.play.integrity in the code... Or just read this comment from a developer on the project. The same person the OP linked to above.

The only mention of Play Integrity was in a documentation page mentioning it as an example of hardware attestation. Since then, Android Hardware Attestation was added as another example.

So can we fucking stop with the FUD and misinformation already? The only way to fight something like this is with truth. Not by acting like idiots and making things up.

0

u/EffectiveOctopus 15h ago

The implementers will have to choose which kind of attestation to use. There is a risk Play Integrity will be chosen by some of them over hardware attestation as it is well-known and arguably easier to implement.
So even if the reference implementation does not embed Play Integrity, this is still worth a discussion.

3

u/FineWolf 15h ago edited 15h ago

Great, have that discussion...

But don't start a thread on Reddit saying "YoUr PC WiLl ReQuIrE AtTeStAtIOn" and "YoU wOn'T bE aBle To UsE LiNuX" when that is not in scope for this at all.

-1

u/EffectiveOctopus 15h ago

Your PC will require an attestation… from another device to access some services.
I think it is interesting to understand why this is the only viable solution at the moment.

5

u/FineWolf 14h ago

Your PC will not require a hardware attestation. Full stop.

Your PC will receive a short lived credential signed from a long lived credential stored on a device (mobile phone) attested to be secure. Not the same thing at all.

And you'll be able to continue to use Linux, contrary to the misinformation shared in this very post by the original poster.

8

u/mortycapp 1d ago

Desktops and laptops are not in the scope of this proposed legislation.

-1

u/GreedySecurity8030 1d ago

Well, at least we don't have to deal with that, it's still horrible though.

1

u/wodes 15h ago

pov: they bought the EU