It should be noted that this app is temporary. The EU is aiming for a digital wallet app that you can store your identity documents in and that you can use to prove facts about those documents to third parties, in a way where the third party gets no extra information--just what you chose to disclose (e.g., just your age or just your country) and that cannot be used to link your real identity to your using the site even if the site and the government share logs (this is called unlinkability).
That will not be fully ready until around 2028. They wanted the age verification available earlier and that is this app. It does not have unlinkability.
Here's the expected timeline.
The first version of the wallet app is suppose to be out by the end of this year or early 2027. It will still not be unlinkable because Apple's Secure Enclave and Android's StrongBox don't support the cryptographic operations needed for the methods that will eventually be used for that, BBS+ anonymous credentials or ZKPs. There is a variant of BBS+ that can achieve unlinkability on existing phones, but unfortunately the hardware security modules (HSMs) currently used by government when they issue you your identity credentials cannot handle BBS#.
In 2027-2028 they are supposed to upgrade the government servers so they can support BBS# or zk-SNARK and update the wallet to use those, achieving unlinkability and anonymous age (and other data) verification.
All this ostensibly to keep teenage boys from watching Pornhub (when parental controls already exist).
The real reason, of course, is to force people to connect strong real-life identifiers to online activity. Mobile first, then Windows. Then Linux is too weak to oppose on its own, and will adapt or die.
That's a completely unhelpful, overly simplistic straw man argument.
We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos. What we have now is essentially unrestricted access to pretty much anything and a fair assessment is that there is societal harm from that. We're creating gambling addicts (which is arguably the most harmful form of addiction), allowing predators to interact with children,, manipulating children through advertising and algorithms, flaming harmful behaviors like eating disorders, allowing mass cyberbullying and so on.
So saying "we should allow unfettered access to the internet" or even "it's the parents' responsibility" is naive, dismissive and has failed. The only question from here is what to d we do about it. You can say "nothing" but that's a losing argument.
I personally believe that the easiest thign to attack is advertising to minors. This will take away the financial incentive for these platforms to create addictive behaivors in minors. And most of these tech platforms have already built the infrastructure to do this. You don't allow advertisers to target an audience based on (actual or inferred) ages under 18. You extend that to proxies for age, like an interest in Minecraft. And you make advertising to children illegal.
Arguably, I'd go further and restrict certain features for minors, such as comments on Youtube and an algorithmic feed.
At the moment nobody is solving anything because it's simply a fight to move liability to someone else. Meta wants hardware vendors to be responsible because, guess what?, they have no hardware platform. Apple and Google likely want app to have to deal with it for the complete opposite reason.
I believe we should shift that liability to advertising.
What's simplistic and unhelpful is falling for the narrative that infinite scroll, boobies, and algorithmic feeds are somehow more harmful than ubiquitous government surveillance of the most powerful communication tool on earth. The Internet, more or less, has been around 30+ years and the Something awful and 4chan generations are now in charge. We're not much worse off. The Internet is actually way tamer these days than it used to be.
We can all agree that yeah sure this social media stuff isn't great, but that's the whole point of freedom. Fast food isn't great either but lawmakers aren't pushing for a junk food attestation framework to make sure you don't consume it more than twice a week. In other words, your best interest is not interesting to them at all. They are happy that you think it is somehow self evident that we should subject ourselves to undue surveillance through!
So, wonder why they're pushing for this so hard. I'll take the brainrot if it means criticism and ideas can spread without permanently being associated with a trackable, unchanging identity.
Don't know about boobies, but I would guess META/other infinite scroll products are this generation's cigarettes in terms of long term harm and we do a severe disservice to all young people that are exposed to this product. Moreover, asking parents to intervene is obviously not going to work because they, themselves, have been partially ruined by it and lack the critical thinking required to intervene and the prowess to execute. Same reason why we needed government to intervene for cigarettes.
I am not endorsing removing all anonymity from being online, but continuing the status quo with social media is a non starter for humanity. So tell me how we can help kids not get ruined by the internet without a mechanism specifically identifying that they're online in the first place?
Then the solution could be just like the solution to tobacco addiction: tax social media companies HARD, tax all advertising on social media 10x, 20x, or ban advertising on/for social media outright, ban advertising of kids products, ban showing use of social media in movies not rated 18, ... the problem will vanish just like cigarettes.
But no, that's not what governments are doing. They want control and surveillance.
It's going to take a lot more evidence to get me anywhere near consideration that this is a trade worth making. Again, we know that fast food can be attributed to hundreds of thousands of early deaths per anum, but we regulate that not at all. In fact it's sadly a staple of the average kids diet.
Passing laws out of fear is not how any competent legislature should operate.
> We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos.
These are not equivalent. Restricting access to a casino just requires showing an ID to a person. A few seconds later and that person has completely forgotten everything about you. They will not keep a record of your home address, etc. Perfectly privacy preserving. You have no such guarantee when you upload government IDs to a server.
I don't think anyone here minds restricting access, but that doesn't require completely destroying ownership rights over our own devices nor internet and device privacy.
All that really needs to be done is for servers to publish what type of content they show from a parental perspective in a machine-readable format and for devices to have parental controls that only allow access to servers that publish such info and which content is allowed by the parental settings.
This should be even more effective than solutions requiring uploading IDs since there's still going to be servers out there in other jurisdictions that simply don't care for such things.
> You have no such guarantee when you upload government IDs to a server.
The problem is that so many people here look at this purely from a USA perspective.
An age check in many European requires no uploading of any ID. It’s an API call toward an ID service, it will tell you which data the service gets access to, and there’s strict regulations and liability around data retention.
I’m not concerned about the government. If they become authoritarian enough to worry, they will impose far tighter surveillance anyway. What we have now is the naive idea that just by not doing ID check, government surveillance is a solved problem in the free democratic world. It’s not. Avoiding ID checks just makes the problem worse because it makes the regular person complacent. The surveillance is implicit and hidden. If we understand that it’s nearly impossible for a non-tech person to avoid being tracked by corporations and governments, then we start working on the things that really help: super tight regulations about what can and can’t be tracked. Requiring audits of large corporations. Solutions that give corporations access to only the data they absolutely need and nothing else (the lack of such things is how we end up by uploading whole ID documents)
> The surveillance is implicit and hidden. If we understand that it’s nearly impossible for a non-tech person to avoid being tracked by corporations and governments, then we start working on the things that really help: super tight regulations about what can and can’t be tracked.
We can't get perfect privacy so we should normalize not having any? Leave it to the government we're distrusting to handle our privacy?
> If they become authoritarian enough to worry, they will impose far tighter surveillance anyway.
What is this logic? Let's not worry about creeping there because if they want it they'll force it? That's not how it works. It needs acceptance, which is obtained by slowly heating the pot, which is what this is.
do parents not control routers and cell plans? I feel like it would be easy to look here for header based solutions. They probably exist tbh. Then just ban your kid from VPNs.
The market failure to provide an adequate solution wasn't natural. It was engineered by the tech companies and you are playing right into their hands. There is still a way to fix this from the root with software antitrust: force hardware vendors to ship their devices without an operating system.
Here's a more detailed explanation in a past comment about how the problem came to be in the first place, and why software antitrust can solve it:
What you're saying is correct - but it's used to push a much more comprehensive lockdown of devices that has absolutely nothing to do with protection of minors.
It's as if the government first let businesses install slot machines at every street corner, then suddenly went "I'm shocked, shocked! that we have a massive epidemic of gambling addiction here, we have to mandate anti-gambling shock collars for everyone to tackle this urgent problem! There is no alternative!"
This is the slippery slope fallacy and people in tech seem to love this argument. And you can argue in whichever direction you want with it.
For example, "unfettered Internet access is just a series of tubes (shout out to Ted Stevens for that one) for pedophiles to rape your children." So now what? Is it your hyperbole against mine?
The problem is that people are operating under a myth that they have anonymity. You don't. You're one subpoena away from being unmasked online and individuals can do it (eg [1]). When governments do it, they can do it in secret. National Security Letters, pen registers, FISA warrants, etc.
So the idea that "age verification is the first step to a more comprehensive" is flawed in both logical construction (being a fallacy) and that ship has already sailed.
But in this case, the slip just happened. This thread is about how an app that will be required for using a vast fraction of all websites will require hardware attestation and likely only run on closed, non-rooted mobile OSes. That's not a hypothetical scenario, it's literally what this thread is about.
>> "We're creating gambling addicts (which is arguably the most harmful form of addiction)"
---
I will need a source, because "arguably" is a very broad umbrella.
"Arguably" heroin addiction is the most harmful addiction because heroin is the most addictive substance, clouds judgement and drives the addict to all manners of sociopathic behaviour (not only theft or prostitition)
One big difference is that heroin is mostly illegal or, if not outright illegal, decriminalized for personal use. Gambling is legal in most places, can be advertised quite freely and restrictions can be easily circumvented with crypto. Crypto casinos have little to no age verification and typically operate extrajudicially (from the victim). Gambling addiction has a high outcome of suicide and tends to leave financial ruin affecting not just that person but their entire family.
Heroin addiction was largely created by the criminialization of cannabis (the first so-called War on Drugs under Nixon) as a tool to persecute black people and war protesters and the overprescription of opioids (eg the Sacklers/Purdue).
I don't understand where the all the EU anti-trust and anti-corruption regulators are here. _Governments_ enforcing that you have a Google or Apple account to participate in society is transparently absurd.
This isn't only a digital sovereignty issue, it's also an anti-competition issue.
My understanding is that you are not forced to use this. Sites in the EU that will be required to verify user age will be free to use any method they wish as long as they can show it is as effective as the app and it does not violate privacy laws.
Most analysts expect sites will offer multiple ways, for a variety of reasons.
Eventually when the full EU Digital Identity Wallet is available age checks can be done using that and the age-only app will go away. For the full wallet the rules explicitly require platforms to have fallback mechanisms for users who are not using the digital wallet.
And how, exactly, will one acquire this "full EU Digital Identity Wallet"? Will I be able to compile it from source and run it on a computing device of my own choosing?
Websites will do the easiest, lowest friction, and most user-familiar thing possible to comply with the laws. And that is just Google or Apple device attestation.
There is no "effective" method without hardware remote attestation. If I control the system, I can just spoof whatever "verification" it is you're asking.
The whole point of hardware attestation is to put a cryptographic key in the computer that the users can't ever get at, then use that key to prove the computer booted a corporate owned operating system that's 100% aligned with government and capitalist surveillance and other cyberpunk dystopia nonsense.
Install a custom system that you control and they will say you have "tampered" with your device, and that transgression will get you ostracized from digital society.
This is what will happen, and if we let it happen might as well close down this site because everything the word hacker ever stood for will have been destroyed.
The reality of the matter is that it is virtually impossible for Europe to even begin to displace Apple or Google devices, and especially not operating systems and all the ecosystem that goes along with it.
The EU politicians are just publicly paying lip-service to "digital sovereignty" while they quietly hope this all just blows over when Trump is gone in 2 years.
> it is virtually impossible for Europe to even begin to displace Apple or Google devices
It's hard for sure but they are not even trying, the non-duopoly alternatives are run by hobbyists in their free time and just get shit on by EU bureaucrats
Agreed, I doubt that a mega-behemoth like Google or Microsoft could emerge in Europe. Especially not on a compressed timescale.
But if they really wanted digital verification without the surveillance capitalism built in, I’m sure there are plenty of companies that could do it. Especially if it was around an open source framework.
Anti-corruption regulators are paid to look away. If they start investigating corruption like e.g. Ukraine does, then the EU countries will be perceived as corrupt. The goal of these institutions is to keep things under the rug so to speak.
That's why you barely see anything being done and yet everyone can see how corrupt things are.
> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.
That's a weird way of putting it. You'll basically need a second non-Linux device if you want to use Linux.
If your reason for using Linux is "I want to continue using old hardware instead of quickly-obsoleted devices", then you're shit outta luck: you'll have to buy a (potentially second) device from one of those vendors who'll use the profits to further lobby against your rights.
> The project’s position is that hardware binding remains required
I think you're downplaying the real risk: if TPM becomes necessary for any single routine activity (banking, communication, etc.) then the usability of any non-TPM hardware to access the internet approaches zero. What's the point of a Linux desktop that asks for attestation for every HTTP request? Or an Android phone that can't legally allow you to install APKs from beyond the Play Store?
I can't pay for things with NFC on my GrapheneOS phone because my bank doesn't trust the hardware. While this is a slight annoyance, it doesn't meaningfully affect my ability to use cards or type in numbers or authenticate with a fingerprint on my phone; however, the forced use of TPM to access anything should be rejected and protested at every step.
Encryption can never be stamped out, thankfully, but hardware is not within one's control: you get what is allowed to be sold.
And it's not just desktop _linux_ that's not allowed, but any desktop operating system, since this only works with "smartphones" not general-purpose computers.
(and of course even if they were to support computers, an age/id verification system either won't work at all or only work to be abused by those in power)
If you want to actually enforce age restrictions that can be checked via some kind of digital identity I don't see how we can avoid the "trusted" hardware requirement.
The key material must be DRM'ed, especially if some ZKP solution is used.
Otherwise all underage kids would download the cool older brothers private key and load it into their GNU Taler client, buy wine and be gateway'ed into heavier Stallmanisms. Before soon EMacs would be all the rage in highschool.
(Of course we can argue the bigger points, if X should require age checks, or if this even should be done digitally etc. But there's a reason why we don't allow the physical equivalent of self-signed keys for physical ID's, they're not trustworthy)
We need to remember how to operate without the Internet, and de-risk our dependence on it. Whether that's reducing the use of computers in our daily lives, or getting more open-source-software-runs-offline-on-my-machine.
We did it before. We forgot at the time when things were more-or-less free.
(I don't know how we do this. I'm as dependent as ever.)
note that hardware attestation does not utilize ZKP or blind signatures. so your hardware ID is technically exposed.
usually to make use of the exposure multi-party collusion is required. Google or Apple attestation intermediaries (they convert your static certificate into an ephemeral one) would need to be logging information and when combined with information from the party you attested to (done with the ephemeral certificate) they will have your unique device identifier (the unchangeable certificate burned into the silicon).
it's doubly insidious because nothing is preventing the manufacturer from recording the certificate identifier and connecting it to an order ID for the device. so not only can they tie together multiple accounts, they could tie it to the identity that purchased the device.
on mobile devices you can't even restrict this functionality as it's exposed via API (remote attestation and also DRM license request handshake initiation). not even grapheneos gives you to option to disable it.
also, the implication of the above is that there is no private way to have a google account on an android phone. they will know it's you or the previous owner of the device who sold it to you (makes VPN irrelevant).
> a maintainer confirmed that hardware-bound attestation is a mandatory architectural requirement
Hardware-bound is not a problem, limiting that to only iPhones and some Android phones is. Plenty of hardware can keep a key safe and it doesn't need Apple's or Google's blessing.
> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.
Considering a significant part of the internet will be behind age verification gates, how are they imagining this to work? I should pull out my iPhone or Google Android phone and get its approval every time I want to visit a website?
It's very commonly the anti-EU politicians who inevitably get into EU parliament (due to representative voting, ironically more democratic than the FPTP system we use in the UK, despite all the wailing about democracy) who endorse such obviously stupid ideas, as a way to undermine the credibility of the EU.
What's frustrating is that it works really well, and occasionally they get something truly stupid through- which goes a long way to whipping up anti-EU sentiment, but then they're forcing their countries to actually do the stupid thing... Nobody seems to call out this self-sabotage.
A good way to prevent this anti-EU sentiment would've been to not go through with these obviously stupid ideas. Weird that the EU doesn't seem to realize?
Or do you think, maybe, that there's a deeper issue here and the problem isn't exclusive to just these anti-EU politicians you want to scapegoat?
I think rejecting proposals from MEPs on the grounds that "it's against EU interests" would be very undemocratic and fuel the very anti-EU sentiment that it would supposedly combat.
No head of government is going to come out against what the government itself is doing, they have to defend every initiative, which is why they seem pretty ungenuine all the goddamn always.
I used to track the voting history of UKIP members, the site "VoteWatch Europe" used to make this easy, but it shut down in 2022.
UKIP were constantly voting for things to be discussed (when they bothered to vote at all), and then when they were discussed they would thump chest in the media about how the EU was talking about doing the thing they had voted to discuss (with the verbiage to suggest the EU would definitely do it, against the will of the British- forgetting entirely that we had a veto anyway...).
If it stick to its current trajectory it will implode in 10-20 years. France’s debt crisis will trigger Euro collapse and Germans would ditch Euro to not foot the bill for the French and the rest of the dominos would fall
Someone on HN suggested parents set devices up for their kids and Browsers and OS's gate by age. I haven't really been able to fault this idea.
State mandates verification and stuff like this makes me suspicious that this is much more than "protecting the children". More advocacy of alternative solutions please.
I expect a gray/black market in TPM keys and the like will grow if this takes off, but hopefully the citizens will fight it very strongly before then...
By an incredible coincidence, the (ex- ?) employee of a company known to lobby hard in the EU (Microsoft) and who's the author of a rube-goldberg kitchen sink many of you on HN loves so much (systemd), is now working on a system that's been described here as "an attack on general purpose computing". Attestations / Trusted Platform Module (TPM) / etc. are all in there:
How much do you love your systemd and the individual behind it now?
Can't wait to use your "amutable" Linux with hardware-bound attestation verifying your age now can you?
These people (the politicians behind such decisions, the people working on such platforms, those saying it's a good thing, ...) are enemies of freedom.
It should be noted that this app is temporary. The EU is aiming for a digital wallet app that you can store your identity documents in and that you can use to prove facts about those documents to third parties, in a way where the third party gets no extra information--just what you chose to disclose (e.g., just your age or just your country) and that cannot be used to link your real identity to your using the site even if the site and the government share logs (this is called unlinkability).
That will not be fully ready until around 2028. They wanted the age verification available earlier and that is this app. It does not have unlinkability.
Here's the expected timeline.
The first version of the wallet app is suppose to be out by the end of this year or early 2027. It will still not be unlinkable because Apple's Secure Enclave and Android's StrongBox don't support the cryptographic operations needed for the methods that will eventually be used for that, BBS+ anonymous credentials or ZKPs. There is a variant of BBS+ that can achieve unlinkability on existing phones, but unfortunately the hardware security modules (HSMs) currently used by government when they issue you your identity credentials cannot handle BBS#.
In 2027-2028 they are supposed to upgrade the government servers so they can support BBS# or zk-SNARK and update the wallet to use those, achieving unlinkability and anonymous age (and other data) verification.
All this ostensibly to keep teenage boys from watching Pornhub (when parental controls already exist).
The real reason, of course, is to force people to connect strong real-life identifiers to online activity. Mobile first, then Windows. Then Linux is too weak to oppose on its own, and will adapt or die.
That's a completely unhelpful, overly simplistic straw man argument.
We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos. What we have now is essentially unrestricted access to pretty much anything and a fair assessment is that there is societal harm from that. We're creating gambling addicts (which is arguably the most harmful form of addiction), allowing predators to interact with children,, manipulating children through advertising and algorithms, flaming harmful behaviors like eating disorders, allowing mass cyberbullying and so on.
So saying "we should allow unfettered access to the internet" or even "it's the parents' responsibility" is naive, dismissive and has failed. The only question from here is what to d we do about it. You can say "nothing" but that's a losing argument.
I personally believe that the easiest thign to attack is advertising to minors. This will take away the financial incentive for these platforms to create addictive behaivors in minors. And most of these tech platforms have already built the infrastructure to do this. You don't allow advertisers to target an audience based on (actual or inferred) ages under 18. You extend that to proxies for age, like an interest in Minecraft. And you make advertising to children illegal.
Arguably, I'd go further and restrict certain features for minors, such as comments on Youtube and an algorithmic feed.
At the moment nobody is solving anything because it's simply a fight to move liability to someone else. Meta wants hardware vendors to be responsible because, guess what?, they have no hardware platform. Apple and Google likely want app to have to deal with it for the complete opposite reason.
I believe we should shift that liability to advertising.
What's simplistic and unhelpful is falling for the narrative that infinite scroll, boobies, and algorithmic feeds are somehow more harmful than ubiquitous government surveillance of the most powerful communication tool on earth. The Internet, more or less, has been around 30+ years and the Something awful and 4chan generations are now in charge. We're not much worse off. The Internet is actually way tamer these days than it used to be.
We can all agree that yeah sure this social media stuff isn't great, but that's the whole point of freedom. Fast food isn't great either but lawmakers aren't pushing for a junk food attestation framework to make sure you don't consume it more than twice a week. In other words, your best interest is not interesting to them at all. They are happy that you think it is somehow self evident that we should subject ourselves to undue surveillance through!
So, wonder why they're pushing for this so hard. I'll take the brainrot if it means criticism and ideas can spread without permanently being associated with a trackable, unchanging identity.
Don't know about boobies, but I would guess META/other infinite scroll products are this generation's cigarettes in terms of long term harm and we do a severe disservice to all young people that are exposed to this product. Moreover, asking parents to intervene is obviously not going to work because they, themselves, have been partially ruined by it and lack the critical thinking required to intervene and the prowess to execute. Same reason why we needed government to intervene for cigarettes.
I am not endorsing removing all anonymity from being online, but continuing the status quo with social media is a non starter for humanity. So tell me how we can help kids not get ruined by the internet without a mechanism specifically identifying that they're online in the first place?
Then the solution could be just like the solution to tobacco addiction: tax social media companies HARD, tax all advertising on social media 10x, 20x, or ban advertising on/for social media outright, ban advertising of kids products, ban showing use of social media in movies not rated 18, ... the problem will vanish just like cigarettes.
But no, that's not what governments are doing. They want control and surveillance.
Taxing or banning advertising alone would fix literally everything that is wrong with the web.
> I would guess
It's going to take a lot more evidence to get me anywhere near consideration that this is a trade worth making. Again, we know that fast food can be attributed to hundreds of thousands of early deaths per anum, but we regulate that not at all. In fact it's sadly a staple of the average kids diet.
Passing laws out of fear is not how any competent legislature should operate.
> We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos.
These are not equivalent. Restricting access to a casino just requires showing an ID to a person. A few seconds later and that person has completely forgotten everything about you. They will not keep a record of your home address, etc. Perfectly privacy preserving. You have no such guarantee when you upload government IDs to a server.
I don't think anyone here minds restricting access, but that doesn't require completely destroying ownership rights over our own devices nor internet and device privacy.
All that really needs to be done is for servers to publish what type of content they show from a parental perspective in a machine-readable format and for devices to have parental controls that only allow access to servers that publish such info and which content is allowed by the parental settings.
This should be even more effective than solutions requiring uploading IDs since there's still going to be servers out there in other jurisdictions that simply don't care for such things.
> You have no such guarantee when you upload government IDs to a server.
The problem is that so many people here look at this purely from a USA perspective.
An age check in many European requires no uploading of any ID. It’s an API call toward an ID service, it will tell you which data the service gets access to, and there’s strict regulations and liability around data retention.
I’m not concerned about the government. If they become authoritarian enough to worry, they will impose far tighter surveillance anyway. What we have now is the naive idea that just by not doing ID check, government surveillance is a solved problem in the free democratic world. It’s not. Avoiding ID checks just makes the problem worse because it makes the regular person complacent. The surveillance is implicit and hidden. If we understand that it’s nearly impossible for a non-tech person to avoid being tracked by corporations and governments, then we start working on the things that really help: super tight regulations about what can and can’t be tracked. Requiring audits of large corporations. Solutions that give corporations access to only the data they absolutely need and nothing else (the lack of such things is how we end up by uploading whole ID documents)
> The surveillance is implicit and hidden. If we understand that it’s nearly impossible for a non-tech person to avoid being tracked by corporations and governments, then we start working on the things that really help: super tight regulations about what can and can’t be tracked.
We can't get perfect privacy so we should normalize not having any? Leave it to the government we're distrusting to handle our privacy?
> If they become authoritarian enough to worry, they will impose far tighter surveillance anyway.
What is this logic? Let's not worry about creeping there because if they want it they'll force it? That's not how it works. It needs acceptance, which is obtained by slowly heating the pot, which is what this is.
Any time I've been in an age-restricted venue here in Australia they have taken a picture of me and my ID at the door.
do parents not control routers and cell plans? I feel like it would be easy to look here for header based solutions. They probably exist tbh. Then just ban your kid from VPNs.
The market failure to provide an adequate solution wasn't natural. It was engineered by the tech companies and you are playing right into their hands. There is still a way to fix this from the root with software antitrust: force hardware vendors to ship their devices without an operating system.
Here's a more detailed explanation in a past comment about how the problem came to be in the first place, and why software antitrust can solve it:
https://news.ycombinator.com/item?id=49118578
We must do something.
This is something.
Therefore, we must do this.
What you're saying is correct - but it's used to push a much more comprehensive lockdown of devices that has absolutely nothing to do with protection of minors.
It's as if the government first let businesses install slot machines at every street corner, then suddenly went "I'm shocked, shocked! that we have a massive epidemic of gambling addiction here, we have to mandate anti-gambling shock collars for everyone to tackle this urgent problem! There is no alternative!"
This is the slippery slope fallacy and people in tech seem to love this argument. And you can argue in whichever direction you want with it.
For example, "unfettered Internet access is just a series of tubes (shout out to Ted Stevens for that one) for pedophiles to rape your children." So now what? Is it your hyperbole against mine?
The problem is that people are operating under a myth that they have anonymity. You don't. You're one subpoena away from being unmasked online and individuals can do it (eg [1]). When governments do it, they can do it in secret. National Security Letters, pen registers, FISA warrants, etc.
So the idea that "age verification is the first step to a more comprehensive" is flawed in both logical construction (being a fallacy) and that ship has already sailed.
[1]: https://chambers.com/articles/internet-harassment-lawyer
But in this case, the slip just happened. This thread is about how an app that will be required for using a vast fraction of all websites will require hardware attestation and likely only run on closed, non-rooted mobile OSes. That's not a hypothetical scenario, it's literally what this thread is about.
>So saying "we should allow unfettered access to the internet" or even "it's the parents' responsibility" is naive, dismissive and has failed.
How has it failed? Whats the measure of a successful freedom vs an unsuccessful one.
>The only question from here is what to d we do about it. You can say "nothing" but that's a losing argument.
No its the positive case for action that remains to be justified.
>> "We're creating gambling addicts (which is arguably the most harmful form of addiction)" --- I will need a source, because "arguably" is a very broad umbrella.
"Arguably" heroin addiction is the most harmful addiction because heroin is the most addictive substance, clouds judgement and drives the addict to all manners of sociopathic behaviour (not only theft or prostitition)
One big difference is that heroin is mostly illegal or, if not outright illegal, decriminalized for personal use. Gambling is legal in most places, can be advertised quite freely and restrictions can be easily circumvented with crypto. Crypto casinos have little to no age verification and typically operate extrajudicially (from the victim). Gambling addiction has a high outcome of suicide and tends to leave financial ruin affecting not just that person but their entire family.
Heroin addiction was largely created by the criminialization of cannabis (the first so-called War on Drugs under Nixon) as a tool to persecute black people and war protesters and the overprescription of opioids (eg the Sacklers/Purdue).
Fentanyl, no?
I don't understand where the all the EU anti-trust and anti-corruption regulators are here. _Governments_ enforcing that you have a Google or Apple account to participate in society is transparently absurd.
This isn't only a digital sovereignty issue, it's also an anti-competition issue.
My understanding is that you are not forced to use this. Sites in the EU that will be required to verify user age will be free to use any method they wish as long as they can show it is as effective as the app and it does not violate privacy laws.
Most analysts expect sites will offer multiple ways, for a variety of reasons.
Eventually when the full EU Digital Identity Wallet is available age checks can be done using that and the age-only app will go away. For the full wallet the rules explicitly require platforms to have fallback mechanisms for users who are not using the digital wallet.
And how, exactly, will one acquire this "full EU Digital Identity Wallet"? Will I be able to compile it from source and run it on a computing device of my own choosing?
"Most analysts" actually expect the opposite:
https://waag.org/en/article/european-digital-id-wallets-are-...
Websites will do the easiest, lowest friction, and most user-familiar thing possible to comply with the laws. And that is just Google or Apple device attestation.
> Most analysts expect
Total bullshit.
There is no "effective" method without hardware remote attestation. If I control the system, I can just spoof whatever "verification" it is you're asking.
The whole point of hardware attestation is to put a cryptographic key in the computer that the users can't ever get at, then use that key to prove the computer booted a corporate owned operating system that's 100% aligned with government and capitalist surveillance and other cyberpunk dystopia nonsense.
Install a custom system that you control and they will say you have "tampered" with your device, and that transgression will get you ostracized from digital society.
This is what will happen, and if we let it happen might as well close down this site because everything the word hacker ever stood for will have been destroyed.
The EU way is to think these things are “free” and then act surprised by the inevitable consequences five years later when it is irreversible.
Our AI gods cannot save us soon enough.
What are the "AI gods" going to do in this scenario?
AI is about many things, but a big factor is enclosure.
The reality of the matter is that it is virtually impossible for Europe to even begin to displace Apple or Google devices, and especially not operating systems and all the ecosystem that goes along with it.
The EU politicians are just publicly paying lip-service to "digital sovereignty" while they quietly hope this all just blows over when Trump is gone in 2 years.
> it is virtually impossible for Europe to even begin to displace Apple or Google devices
It's hard for sure but they are not even trying, the non-duopoly alternatives are run by hobbyists in their free time and just get shit on by EU bureaucrats
Agreed, I doubt that a mega-behemoth like Google or Microsoft could emerge in Europe. Especially not on a compressed timescale.
But if they really wanted digital verification without the surveillance capitalism built in, I’m sure there are plenty of companies that could do it. Especially if it was around an open source framework.
Anti-corruption regulators are paid to look away. If they start investigating corruption like e.g. Ukraine does, then the EU countries will be perceived as corrupt. The goal of these institutions is to keep things under the rug so to speak.
That's why you barely see anything being done and yet everyone can see how corrupt things are.
> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.
That's a weird way of putting it. You'll basically need a second non-Linux device if you want to use Linux.
If your reason for using Linux is "I want to continue using old hardware instead of quickly-obsoleted devices", then you're shit outta luck: you'll have to buy a (potentially second) device from one of those vendors who'll use the profits to further lobby against your rights.
> The project’s position is that hardware binding remains required
I think you're downplaying the real risk: if TPM becomes necessary for any single routine activity (banking, communication, etc.) then the usability of any non-TPM hardware to access the internet approaches zero. What's the point of a Linux desktop that asks for attestation for every HTTP request? Or an Android phone that can't legally allow you to install APKs from beyond the Play Store?
I can't pay for things with NFC on my GrapheneOS phone because my bank doesn't trust the hardware. While this is a slight annoyance, it doesn't meaningfully affect my ability to use cards or type in numbers or authenticate with a fingerprint on my phone; however, the forced use of TPM to access anything should be rejected and protested at every step.
Encryption can never be stamped out, thankfully, but hardware is not within one's control: you get what is allowed to be sold.
And it's not just desktop _linux_ that's not allowed, but any desktop operating system, since this only works with "smartphones" not general-purpose computers.
(and of course even if they were to support computers, an age/id verification system either won't work at all or only work to be abused by those in power)
If you want to actually enforce age restrictions that can be checked via some kind of digital identity I don't see how we can avoid the "trusted" hardware requirement.
The key material must be DRM'ed, especially if some ZKP solution is used.
Otherwise all underage kids would download the cool older brothers private key and load it into their GNU Taler client, buy wine and be gateway'ed into heavier Stallmanisms. Before soon EMacs would be all the rage in highschool.
(Of course we can argue the bigger points, if X should require age checks, or if this even should be done digitally etc. But there's a reason why we don't allow the physical equivalent of self-signed keys for physical ID's, they're not trustworthy)
> If you want to actually enforce age restrictions
I don't.
This "think of the kids" nonsense is a psyop to manufacture consent for this shit. People really need to stop falling for it.
We need to remember how to operate without the Internet, and de-risk our dependence on it. Whether that's reducing the use of computers in our daily lives, or getting more open-source-software-runs-offline-on-my-machine.
We did it before. We forgot at the time when things were more-or-less free.
(I don't know how we do this. I'm as dependent as ever.)
So much for the EU's mission to reduce e-waste.
note that hardware attestation does not utilize ZKP or blind signatures. so your hardware ID is technically exposed.
usually to make use of the exposure multi-party collusion is required. Google or Apple attestation intermediaries (they convert your static certificate into an ephemeral one) would need to be logging information and when combined with information from the party you attested to (done with the ephemeral certificate) they will have your unique device identifier (the unchangeable certificate burned into the silicon).
it's doubly insidious because nothing is preventing the manufacturer from recording the certificate identifier and connecting it to an order ID for the device. so not only can they tie together multiple accounts, they could tie it to the identity that purchased the device.
on mobile devices you can't even restrict this functionality as it's exposed via API (remote attestation and also DRM license request handshake initiation). not even grapheneos gives you to option to disable it.
also, the implication of the above is that there is no private way to have a google account on an android phone. they will know it's you or the previous owner of the device who sold it to you (makes VPN irrelevant).
Here comes the European freedom and free speech. With Chat Control it’s even more hilarious. Compliance list, another European Commission, as always.
> a maintainer confirmed that hardware-bound attestation is a mandatory architectural requirement
Hardware-bound is not a problem, limiting that to only iPhones and some Android phones is. Plenty of hardware can keep a key safe and it doesn't need Apple's or Google's blessing.
> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.
Considering a significant part of the internet will be behind age verification gates, how are they imagining this to work? I should pull out my iPhone or Google Android phone and get its approval every time I want to visit a website?
The article mentions "approved applications". What role, if any, do apps play in age verification if it's implemented in hardware?
Related:
European "age verification" "app" forcing everyone to use Android or iOS
https://news.ycombinator.com/item?id=48903777
Stop Killing the Internet: No Digital ID and No Age Verification
https://news.ycombinator.com/item?id=49084938
There it is. That's what this "age verification" nonsense was all about. Predictably, the unceasing "think of the kids" rhetoric came down to THIS.
Absolute control over people's computers.
It's not your computer anymore, it's the government's.
We need another French revolution that gets rid of this corrupt EU regime for good.
It's very commonly the anti-EU politicians who inevitably get into EU parliament (due to representative voting, ironically more democratic than the FPTP system we use in the UK, despite all the wailing about democracy) who endorse such obviously stupid ideas, as a way to undermine the credibility of the EU.
What's frustrating is that it works really well, and occasionally they get something truly stupid through- which goes a long way to whipping up anti-EU sentiment, but then they're forcing their countries to actually do the stupid thing... Nobody seems to call out this self-sabotage.
A good way to prevent this anti-EU sentiment would've been to not go through with these obviously stupid ideas. Weird that the EU doesn't seem to realize?
Or do you think, maybe, that there's a deeper issue here and the problem isn't exclusive to just these anti-EU politicians you want to scapegoat?
I think rejecting proposals from MEPs on the grounds that "it's against EU interests" would be very undemocratic and fuel the very anti-EU sentiment that it would supposedly combat.
I suppose you have a lot of data backing this claim?
The head of the EU, Ursula von der Leyen, isn't known to be anti-EU.
No head of government is going to come out against what the government itself is doing, they have to defend every initiative, which is why they seem pretty ungenuine all the goddamn always.
I used to track the voting history of UKIP members, the site "VoteWatch Europe" used to make this easy, but it shut down in 2022.
UKIP were constantly voting for things to be discussed (when they bothered to vote at all), and then when they were discussed they would thump chest in the media about how the EU was talking about doing the thing they had voted to discuss (with the verbiage to suggest the EU would definitely do it, against the will of the British- forgetting entirely that we had a veto anyway...).
If it stick to its current trajectory it will implode in 10-20 years. France’s debt crisis will trigger Euro collapse and Germans would ditch Euro to not foot the bill for the French and the rest of the dominos would fall
Someone on HN suggested parents set devices up for their kids and Browsers and OS's gate by age. I haven't really been able to fault this idea.
State mandates verification and stuff like this makes me suspicious that this is much more than "protecting the children". More advocacy of alternative solutions please.
I expect a gray/black market in TPM keys and the like will grow if this takes off, but hopefully the citizens will fight it very strongly before then...
...but then again, this is the EU, not the US.
Hardware attestation literally prevents that. That's why it's mandated.
By an incredible coincidence, the (ex- ?) employee of a company known to lobby hard in the EU (Microsoft) and who's the author of a rube-goldberg kitchen sink many of you on HN loves so much (systemd), is now working on a system that's been described here as "an attack on general purpose computing". Attestations / Trusted Platform Module (TPM) / etc. are all in there:
https://news.ycombinator.com/item?id=46784572
How much do you love your systemd and the individual behind it now?
Can't wait to use your "amutable" Linux with hardware-bound attestation verifying your age now can you?
These people (the politicians behind such decisions, the people working on such platforms, those saying it's a good thing, ...) are enemies of freedom.