I think there is a flaw in EU’s way of acting and functioning. European countries seem to be sharing the same cultural values yet there are different deeper values hidden to the foreigner from country to country. For example we look at Middle East, Africa, Asia and we easily spot cultural differences. Yet we fail to see the gaps between our countries inside EU. Holland and northern countries had for years a culture of child protection on computing devices,and not only,that 20 years ago I found strange. There is an industry for that in there and thriving. What they just did was to apply their normality to us, without them understanding the gap. They just don’t understand the issue. Controlling children like that is normal for them.
post
Gee. I totally not saw that coming.
These people who push for it are fascists, and the only way to deal with fascists is to kill them before they murder you.
The whole thing is wrongheaded in the first place; any child wanting to access adult-only content will use an adult’s account to do so; any adult attempting to access adult-only content is likewise going to use an adult’s account.
So unless they’re tying this to biometrics that are actually secure against an adverserial child, all the system really does is creates a registry of adults. And we already have those.
Can't wait for EU to ban general purpose computing. At some point ,everybody is just going to get a locked down Windows tablet where only EU approved software runs.
Can't wait to become a shady dealer who sells pre 2026 computers with highly illegal software running on it (such as debian)
I fear that is the inevitable whimpered ending of the personal computing era. Cory Doctorow called it back in 2011.
They're gonna ban abacuss next, and then comes mental math, and suddenly 2+2=fish
so bye anything that isn't microsoft, apple or google? really tech independent of europe.
Fuck EU.
Also fuck absolutely every politician who focuses on "supporting" incompetent parents... All this does is to allow them to become even more incompetent and then the government has to do even more parenting...
How I see it, ocurres when the laws are made by ancients which confuse an remote control with an smartphone.

I have a solution to the age verification problem. There is a way to affirmatively prove someone is a real human adult without invasions of privacy. We can use the same ID verification system we've been using for centuries: public notaries.
Governments could hand anonymous cryptographic tokens to notaries. These contain no information on the individual. They're simply a unique cryptographic token. You can go to a notary, pay a nominal fee, show your ID, and grab one of the tokens (possibly just a code printed on a card) from a large bin of them. You can then use this token to register for any number of sites. The notary themselves does not need to note which cryptographic token you grab. The notary doesn't even know what token you received. The goal is merely to prove you're an adult human, not to create a cryptographic key tied to your specific identity.
I would then let people do this as many times as they want. You can get a hundred such IDs. They wouldn't cost much, a few dollar or Euros. This would be no barrier to individuals accessing the net, but it would make them unsuitable for mass spamming.
No. There is zero need for this shit, don't normalize it.
It would only work if the law mandated that this token cannot be stored or tracked across the web.
It's a legit idea, and there's a thing like that, called Zero Knowledge Proofs (ZKP).
IMO it's possible in theory. Like set up and managed in good faith, it can work mathematically, and you can prove it does.
My worry tho is that it wouldn't be in good faith. It'll be corrupted somehow. Or it turns out that enough other signals leak that it isn't very effective. Like fingerprinting and stylometry and w/e allow ID'ing despite the ZKP layer.
It’s all silly because computers are not paired with any specific body. You could toss your “18+ accessible phone” to your kid, etc.
Unless they do implants, which is nightmare land because we know they’ll want more than just your birthday.
I didn't like the age verification law either, but as it would be introduced everywhere, yes or yes, at least it's mandatory to search an privacy protecting methode, which isn'y not so easy, Because of this I asked Sketchapedia, which shows an zero knowledge system, the service provider only receive an OK or Not OK with it.

In problems which I can't avoid, I always prefer to search solutions or at least workarrounds to fix it.
The solution lets users prove they are over a certain age without revealing their name, exact birth date, or full identity document. To prevent credentials from being copied, cloned, or reused by modified clients, the project relies on keys stored in protected hardware like Android TEE, StrongBox, or Apple’s Secure Enclave.
The project’s technical specification requires age verification apps to use native cryptographic hardware when available. However, stricter checks like root detection, Google Play Integrity, and Apple App Attest are not universally mandated by the reference implementation and may be left to individual deployers.
So there's a chance that GrapheneOS will be supported. I mean, we can still decompile the app, modify it and then repackage it. Or someone will make a patcher app.
I would love to be wrong about this, but I don't think it's likely. Why would a government voluntarily spend money on making the app work for a minority of people running a privacy OS that politicians associate with criminals and gangsters?
Also, it's not like the wallet app will actually be open source in the traditional sense where you can fork and compile it yourself, so I think getting any decent version of it seems like a long shot
These kinds of laws will not succeed. People will choose to ignore them, like they ignore other laws, like they litter, jaywalk, drive 10 over the limit, run stop signs, etc. It will succeed in driving up prices on products from those companies who choose to comply, because they will be forced to hire in a lot more lawyers and compliance staff. These laws create lots of full time jobs in tech companies that few realize even exist. They have meetings every week, attend conferences, constantly send letters back and forth to each other. Then people wonder why their Gamepass fees went up $10 (its not actually the games)
Please explain... If I'm below the age of... Whatever they decide, what will or will not be accessible to me? Like, if I'm below a certain age, will some EU appointed DNS restrict what domains I can reach? Or, since this article is about hardware-bound attestation, are my devices going to prevent me from installing and using certain apps if I'm below the age? I don't understand where the restrictions are going to lie...
Bonus: can't I just buy, say, five phones right now, root them or install custom OSs before shit hits the fan and be happy?
-
The real explanation is that they want control. The children are a excuse.
-
No because you can go to jail for that, like the dude with his GrapheneOS in the US. They're probably working on that next.
No because you can go to jail for that, like the dude with his GrapheneOS in the US. They’re probably working on that next.
no... you can not go to jail, in the EU or the US at least, for having a phone with a custom OS. They are facing charge for using a duress code which wiped their phone. It is very different.
The services themselves will probably be made to ask for verification and your devices will answer through the age verification app. Since custom mobile OSs (or desktop Linux) won't provide hardware attestation, the app won't work on them and the websites will treat you as underage. The types of services that require age verification aren't specific, they can change based on EU decisions so eventually people not using "approved" OSs may be locked out of most of the internet.
First of all,
I don’t understand where the restrictions are going to lie
Yes. That's exactly the question.
The point of the... excitement around this is exactly the uncertainty. We simply don't know what the EU or national governments of the EU will do with this.
The first problem is that the "hardware bound attestation" isn't just hardware bound, it's specifically Apple and Android's attestation and NOT the more open standard. That means the device that can do this thing, whatever it's going to be "necessary" for, MUST always be an Apple or Google device, with that bit intact. Tbh, I don't really know how much rooting affects this, but I would be surprised if it didn't.
The second problem is that once the infrastructure for blocking access to something and requiring this sort of authentication is in place, it's just a list of targets. It's very easy to add another platform, website, app or anything else behind it.
And the reason for this excitement happening now is that the specification that was given for all this to happen previously only said it should be "secure" somehow, but not detailing the "how". They think they can do it as an implementation detail and pretend it's not a big deal. So it's very clearly something those bastards have tried to be sneaky about.
Can you use rooted phones
No, whatever the point of their efforts is, they will make sure to not leave obvious loopholes like that open.
top 50 comments