logoalt Hacker News

EU Age Verification Project Mandates Hardware-Bound Attestation

83 pointsby RobotToastertoday at 8:44 PM31 commentsview on HN

Comments

big85today at 10:08 PM

All this ostensibly to keep teenage boys from watching Pornhub (when parental controls already exist).

The real reason, of course, is to force people to connect strong real-life identifiers to online activity. Mobile first, then Windows. Then Linux is too weak to oppose on its own, and will adapt or die.

show 1 reply
intrasighttoday at 11:02 PM

The article mentions "approved applications". What role, if any, do apps play in age verification if it's implemented in hardware?

afandiantoday at 9:26 PM

I don't understand where the all the EU anti-trust and anti-corruption regulators are here. _Governments_ enforcing that you have a Google or Apple account to participate in society is transparently absurd.

This isn't only a digital sovereignty issue, it's also an anti-competition issue.

show 3 replies
WhyNotHugotoday at 9:14 PM

> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.

That's a weird way of putting it. You'll basically need a second non-Linux device if you want to use Linux.

If your reason for using Linux is "I want to continue using old hardware instead of quickly-obsoleted devices", then you're shit outta luck: you'll have to buy a (potentially second) device from one of those vendors who'll use the profits to further lobby against your rights.

show 3 replies
teravortoday at 9:37 PM

note that hardware attestation does not utilize ZKP or blind signatures. so your hardware ID is technically exposed.

usually to make use of the exposure multi-party collusion is required. Google or Apple attestation intermediaries (they convert your static certificate into an ephemeral one) would need to be logging information and when combined with information from the party you attested to (done with the ephemeral certificate) they will have your unique device identifier (the unchangeable certificate burned into the silicon).

it's doubly insidious because nothing is preventing the manufacturer from recording the certificate identifier and connecting it to an order ID for the device. so not only can they tie together multiple accounts, they could tie it to the identity that purchased the device.

on mobile devices you can't even restrict this functionality as it's exposed via API (remote attestation and also DRM license request handshake initiation). not even grapheneos gives you to option to disable it.

also, the implication of the above is that there is no private way to have a google account on an android phone. they will know it's you or the previous owner of the device who sold it to you (makes VPN irrelevant).

0xfedcafetoday at 10:36 PM

Here comes the European freedom and free speech. With Chat Control it’s even more hilarious. Compliance list, another European Commission, as always.

xg15today at 10:22 PM

> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.

Considering a significant part of the internet will be behind age verification gates, how are they imagining this to work? I should pull out my iPhone or Google Android phone and get its approval every time I want to visit a website?

buran77today at 9:31 PM

> a maintainer confirmed that hardware-bound attestation is a mandatory architectural requirement

Hardware-bound is not a problem, limiting that to only iPhones and some Android phones is. Plenty of hardware can keep a key safe and it doesn't need Apple's or Google's blessing.

ChrisArchitecttoday at 9:41 PM

Related:

European "age verification" "app" forcing everyone to use Android or iOS

https://news.ycombinator.com/item?id=48903777

Stop Killing the Internet: No Digital ID and No Age Verification

https://news.ycombinator.com/item?id=49084938

userbinatortoday at 9:55 PM

I expect a gray/black market in TPM keys and the like will grow if this takes off, but hopefully the citizens will fight it very strongly before then...

...but then again, this is the EU, not the US.

83642736392today at 9:34 PM

We need another French revolution that gets rid of this corrupt EU regime for good.

show 2 replies
TacticalCodertoday at 10:12 PM

By an incredible coincidence, the (ex- ?) employee of a company known to lobby hard in the EU (Microsoft) and who's the author of a rube-goldberg kitchen sink many of you on HN loves so much (systemd), is now working on a system that's been described here as "an attack on general purpose computing". Attestations / Trusted Platform Module (TPM) / etc. are all in there:

https://news.ycombinator.com/item?id=46784572

How much do you love your systemd and the individual behind it now?

Can't wait to use your "amutable" Linux with hardware-bound attestation verifying your age now can you?

These people (the politicians behind such decisions, the people working on such platforms, those saying it's a good thing, ...) are enemies of freedom.

SnipeOfficialtoday at 10:25 PM

[flagged]