EU Age Verification Project Mandates Hardware-Bound Attestation
An EU age-verification initiative that mandates hardware-bound attestation is raising alarm over digital rights, device ownership, and competition. Critics argue it effectively forces citizens onto Apple or Google mobile platforms, erodes general-purpose computing (especially on Linux and older hardware), and lays groundwork for pervasive identity-linked tracking of online activity under a “protect the children” rationale. Supporters of stricter age controls counter that some form of trusted hardware is unavoidable for reliable verification, but opponents insist this could be achieved with less intrusive, more open alternatives and stronger regulation of advertising and platform incentives instead.
Scope of the Age-Verification Scheme
- Age-verification relies on hardware-bound attestation (TPM, Secure Enclave, StrongBox).
- Practically limits participation to modern iOS/Android smartphones; desktop OSes (including Linux) relegated to QR-code workflows via a “supported mobile wallet.”
- Many see this as de facto exclusion of older hardware and alternative OSes, contradicting EU goals like e‑waste reduction.
Impact on General-Purpose Computing
- Strong concern that once TPM/attestation becomes required for any routine online activity, non‑attested devices become unusable for much of the web.
- Fear that devices must run vendor-approved, locked-down OSes; rooted/custom ROMs and Linux desktops risk being treated as “tampered” and barred.
- Critics describe this as an “attack” on general-purpose computing: hardware is secured against the user, not for the user.
Security & Justification vs. Abuse Potential
- Proponents argue enforceable age limits inherently require trusted hardware; otherwise keys can be copied or spoofed.
- They draw analogies to passports, smart cards, and banking chips that must resist user tampering.
- Opponents reply that this creates a permanent government/corporate enclave on every device, easily reused for censorship, tracking, and DRM, with no realistic opt‑out.
Privacy, Tracking, and Identity Linkage
- Hardware attestation does not use ZKPs today; device IDs are technically exposed.
- Apple/Google and websites can potentially correlate ephemeral attestations back to unique device certificates and even purchase records.
- Many see this as a step toward universal, non-escapable real‑identity linkage for all online activity, undermining anonymity and tools like Tor.
“Think of the Children” vs. Structural Regulation
- One camp: current “unfettered” access harms minors (porn, gambling, social media addiction, predators); parental controls are inadequate; some form of robust age verification is necessary.
- Other camp: child protection is being used as a pretext for broad surveillance and control; unrestricted access also empowered learning and dissent.
- Alternative proposals:
- Strongly regulate or heavily tax online advertising (especially to minors), or ban ads on social media.
- Improve OS-level parental controls and content labeling instead of identity checks.
EU Policy, Antitrust, and “Temporary” Wallet
- Critics question where EU antitrust/anti-corruption oversight is, given effective compulsion to use Apple/Google ecosystems.
- Suggested remedies: mandate open bootloaders, ban or strictly limit remote attestation, enforce OS/hardware separation, fund open-source and EU-based attestation alternatives.
- EU narrative: the current app is a stopgap until a privacy-preserving Digital Identity Wallet with unlinkable credentials (e.g., BBS+, ZKPs) arrives around 2027–2028.
- Many commenters doubt the “temporary” claim, citing the persistence of past “temporary” measures.
Trajectory of the Internet
- Some foresee a splinternet: an ID-bound, highly regulated “Westernet/EUternet” vs. less controlled regions.
- Others expect arms races: black/gray markets for TPM exploits and keys, and ongoing attempts to bypass attestation, though effectiveness is unclear.