10 ms·
EU Age Control: The trojan horse for digital IDs
https://web.archive.org/web/20260426040218/https://juraj.bednar.io/en/blog-en/2026/04/17/eu-age-control-the-trojan-horse-for-digital-ids/ https://web.archive.org/web/20260426040218/https://juraj.bed...
- wolvoleo 5mo agoSite seems slashdotted? Or HNd? Do we call it that here? :)
- QuantumNomad_ 5mo agoSome call it the HN hug of death. Same like with Reddit.
- vaginaphobic 5mo ago[dead]
- dmitrygr 5mo agoDEAD, archive: https://web.archive.org/web/20260426040218/https://juraj.bednar.io/en/blog-en/2026/04/17/eu-age-control-the-trojan-horse-for-digital-ids/ https://web.archive.org/web/20260426040218/https://juraj.bed...
- wolvoleo 5mo ago> In any case, it was always presented as a toolbox that countries should adapt into their apps – so judging the app by itself does not make much sense, it depends on how these techniques are implemented in each country’s verification app. There will be no single EU app, despite what the honchos of EU say. Even more reason to make the "demo" app do things correctly because it's very unlikely that all member states actually implement things correctly. > The internet is scary, parents think they can’t protect their children from many bad things happening, and someone came to provide a “solution." A simple solution is just not providing your kids with a phone or computer. Don't forget that many sources of porn will not obey this. Think the pirate bay will ask for age verification? If they obeyed the law they wouldn't even exist. It's a solution for nothing, as the article points out too.
- 6r17 5mo agoWhether there is a single app or not doesn't really matter - i'm more concerned about the database itself and the inter-connectivity between them and most importantly by which control acceptance protocol we abide between states. The idea that we want a single database or a network without any kind of control is frightening me
- delusional 5mo agoWhat do you mean by "control" here? It's my understanding that EU law afford citizens the right to correct data that is wrong about them.
- choo-t 5mo agoThe problem is not about the data being correct or not, it's about its existence in the first place. Why would you correct data about you very own surveillance ?
- delusional 5mo agoIs all data about you "surveillance". When your doctor produces a medical record after your visit, are they "surveilling" you? How about when the railway company stores your travels to bill you later? I'll assume your answer is no, and I that case surely you must see the value in that medical record being correct.
- choo-t 5mo agoAre you equaling mass surveillance to a doctor keeping track of your health for diagnostic accuracy purpose ? Concerning the railway example, they only need to store how much I owe them, not my travels. Storing travel history on their end is already surveillance. Data keeping purpose and consents are what make something surveillance or not. Forcing every citizen to use ID to access the web is surveillance plain and simple.
- coumbaya 5mo agoai;dr
- zetanor 5mo agoIt's HN, nobody reads articles even when they're not slop.
- mayama 5mo agoWith the way elections changed after social media became big. Govts want to have control back, like they did before. And are increasingly curbing open internet with boogeyman CP or terrorists, new fear of mass AI CP. Ultimately we'll get 2nd hand version of great firewall and social credit system. Some "liberal democracies" already have root of such systems implemented.
- delusional 5mo agoI don't know if it has anything to do with changes in elections directly. My government has been talking for a while making the case that social media use makes us dumber, sadder, and more scared. I believe it's true that they also see that playing out in elections, but that's not where they want to solve a problem. Wouldn't it be strange if solving a problem didn't affect elections?
- coldtea 5mo ago>My government has been talking for a while making the case that social media use makes us dumber, sadder, and more scared. I believe it's true that they also see that playing out in elections, but that's not where they want to solve a problem. The governments themselves are "dumber, sadder, and more scared". They are worried because social media puts regular people talking on equal footing to official propagandas (being able to reach everybody else). That's what they fear, because they have the lowest approval ratings and legitimization in over half a century, and they're also making everything shittier and shittier to the benefit of their corporate overlords.
- marsven_422 5mo ago[dead]
- big85 5mo ago[dead]
- coppsilgold 5mo agoIt seems unlikely that a true Zero Knowledge Proof system for things like age verification would ever be allowed. Also, remote attestation doesn't work that way and for good reason. Under a true ZKP system, a single defector (extracted/leaked/etc key) would be able to generate an infinite number of false attestations without detection.
- esperent 5mo ago> It seems unlikely that a true Zero Knowledge Proof system for things like age verification would ever be allowed This article is about EU age verification which is specifically and definitely stated as using zero knowledge proof in all technical docs that I've seen: https://eudi.dev/2.5.0/discussion-topics/g-zero-knowledge-proof/ https://eudi.dev/2.5.0/discussion-topics/g-zero-knowledge-pr...
- subscribed 5mo agoIn that case Google play integrity cannot be used. It certifies devices running on Oreo (because vendor didn't provide updates),meaning there are almost infinite vulnerabilities that will allow to leak the keys.
- narennayagam 5mo agoInteresting point about ZKP systems. The challenge with age verification is balancing privacy with enforcement — any centralized solution creates a honeypot for data breaches.
- grey-area 5mo agoDigital ids are inevitable in my view, just as digital currency has become inescapable because it is more convenient and efficient, these ids will be issued and things like paper proofs of identity will fall away over time. Physical tokens like bank cards and driving licenses are neither necessary nor a good solution in a networked world. Our focus therefore should be controlling what governments can do with them - for example disallowing blocking/removing someone’s id, just as we should disallow removing citizenship.
- fc417fc802 5mo agoI think even digital IDs will tend to exist as physical tokens? Also worth noting that you can have a digitized and cryptographically signed ID on "paper" which can serve much the same purpose (security, machine readability) as an electronic one. Where electronic tokens shine (for IDs or otherwise) is attesting to the physical possession of a single copy.
- izacus 5mo agoMany EU countries already issue a chipcard IDs which can be used to auth for government services (via NFC or a dedicated reader). So yeah, I'd expect those to move to a phone as an alternative to the card
- shevy-java 5mo agoThis is not the same. For instance, we can access the internet without needing that ID. But right now there are attempts to force a digital ID in order to access information on the www - this is the whole idea behind "age verification". The kids are just used as excuse here. It has never been about the kids.
- izacus 5mo agoI think you're jumping to conclusions that aren't supported by the digital ID proposal. Even with that: There's plenty of services dangerous to kids that we gate behind an ID check and I don't particularly see why internet is special in any way.
- mentalgear 5mo agoNot a fan, but unfortunately a "digital proof of citizenship" seems to inevitable due to the en-shitification of the internet, autocratic state actor's doctrines to destabilise free societies through disinformation that matches well with social media's en-rage-ment business model, and the more recent AI slopification / AI bots running wild. The question is whether citizens can build enough pressure for such verification systems to be state-based and truly zero-knowledge (akin to the EU's) versus having the private sector 'verify' each user to siphon data, profit off it (Thiel's Persona) and fortify surveillance-capitalism and autocratic administrations.
- phatfish 5mo agoAt the moment in the UK (where any mention of digital ID sends half the population mental) you have to email a whole raft of ID docs and personal data to estate agents, mortgage brokers, solicitors etc. to get an ID check done. Or use a private ID service that can have a cost associated and may not be any more secure than my passport scan sitting in someones M365 mailbox. You can't know. I'd be happy to have a government service replace all that nonsense, where a one-time challenge code could verify my ID. There is now a UK.gov "One Login" authentication used by other government services that is essentially a digital ID as far as I can see. It just needs to be made mandatory for ID checks by law. Such a service can also be used for age verification with the correct privacy controls in place, far better than all the dodgy age verification services that exist now. Digital ID and age verification are going to be a part of the internet going forward. I'd rather have a government service that (in a functioning democracy) has accountability to the citizens that use it. ID verification is also a natural monopoly, so the government picks a winner anyway.
- croes 5mo agoWhere is the big to what we have now? Not much more freedom, but the control is outside voters reach. Just ask Nicolas Guillou
- isodev 5mo agoWe’ve had eID for a long time and I’m fine with it becoming more prominent online. Same for age verification, once we settle on a way to do it without US/Palantir being involved in the process.
- deleted 5mo ago[deleted]
- shevy-java 5mo ago> There will be no single EU app, despite what the honchos of EU say. This shows that the EU commission is systematically lying. This problem used to exist in the past with Leyen - she is ultimately a lobbyist and that has to stop. Friedrich Merz too by the way - there is a reason why recent polls indicate that the german voters want him out of politics at once. The EU needs to reform. Right now lobbyists have too much abuse-power. The age sniffing is a great example here - isn't it suspicious how this goes in sync right now in so many countries? Who is paying for this? Nobody needs that, except for some companies. > Big platforms must verify age for certain content. But why is their concern, suddenly my concern? I see no need to be in support of any law that would require people to ID in order to access information on the world wide web. That's very obviously the real goal and agenda - everyone with a bit of brains sees this. > It is the same EU that hates these American corporations and wants EU alternatives for everything That's not true. The EU commission I consider a lobbyist group, for instance. They lie and lie and lie. The EU parliament is not much better - you can buy legislation quite easily: https://en.wikipedia.org/wiki/Qatar_corruption_scandal_at_the_European_Parliament https://en.wikipedia.org/wiki/Qatar_corruption_scandal_at_th... Nothing will seriously changed. The current way how the EU is structure is totally wrong; and it will not be fixed because those in the system, benefit from it financially. See the recent attempt to force EU taxpayers to pay more for those goons. They constantly try to inflate their own budget, at our cost. > yet no one can make a phone usable for age verification without the blessing of Google Indeed. We have total incompetence at the leadership level. It should be replaced with technical prowess, but as long as lobbyists such as Leyen are running the show, nothing will change. See the corruption scandals when she was still in Germany. Interestingly the AfD is also full of that, yet voters don't see it - Weidel was working for many years for Goldman sucks. So a next generation of lobbyists will replace the older generation soon. That's why this system how it is, is unfixable. It is broken by design.
- jeroenhd 5mo agoWhen did any EU representative ever lie about this? It has been very clear from the beginning that every member state would make their own apps. I don't really see what internal German politics and lobbying has to do with anything. As for the "Google" part, that's up to the member states to decide. In essence, the law states that apps should be secure and untampered. It doesn't specify any remote attestation partner, nor even the strict need for remote attestation although it's hard to accomplish any kind of phone-based authentication security without it. Android's native attestation solution also exists and works for phones sold without Google services, though it's an absolute pain to work with. Sailfish, pmOS, or any other mobile OS could implement the security requirements if they ever get enough serious popularity to convince governments to make apps for them.
- jeroenhd 5mo agoIt's not a trojan horse, it's spelled out in the decision, debates, and legal texts to be the explicit goal. The age verification requirement was picked both as a means to prove the technology is sound and as a simple starting point for a full digital ID solution. The EU already has some form of digital ID in fact, every government provides some kind of OIDC-like service tied to either smart cards or accounts that authenticate the user against a government. The digital wallet solution is an extension to that system that will allow foreign EU citizens to authenticate themselves more easily (eIDAS 2 already implemented an OIDC-like solution but implementation isn't automatic) as well as offer to store the (often mandatory to carry) ID on your phone. The "what if you buy alcohol for your kids" sscenario of somone giving someone else their age verification tokens is tired and nonsensical. You can already do that in the real world. We accept that risk and, depending on the country, make it a crime in case they do catch you. It hasn't made liquor stores send someone along to see you drink your booze or watch you enjoy your porn mag.
- tpm 5mo ago> The digital wallet solution is an extension to that system that will allow foreign EU citizens to authenticate themselves more easily Is there a roadmap and/or a timeframe for that? I have a Slovak ID same as the author, when will it be useful for accessing internet services?
- jeroenhd 5mo agoAge verification has taken about three or four years to reach the concept stage, and that's the first stage that will be rolled out. The legal framework behind all this was released all the way back in 2014 and has been officially adopted ten years later. Officially, by December 2026, each member state must have at least one official wallet solution available for its citizens. That said, eIDAS 2.0 also mandated that, as of this year, whatever Slovak digital identity solution has been rolled out so far must also work in other member states. In my experience, different governments adopt different foreign identity services at different paces, most of them seemingly missing the deadline. Banks and other private institutions permitted to ask for ID are supposed to accept the wallet solutions by late 2027. I expect deadlines to be missed given we've barely gotten the age verification PoC done, but with the groundwork laid out, things might just work out.
- snvzz 5mo agoTo understand the age verification push, got to follow the incentives[0]. 0. https://www.youtube.com/watch?v=RfukJ6uVHXs https://www.youtube.com/watch?v=RfukJ6uVHXs
- PunchyHamster 5mo agoMany countries have digital IDs for years now. It's not for digital IDs. It's for surveillance. Digital IDs are fine (and desired even) if you are only requiring it for GOVERNMENT (same entity that released them) communication. Push for age control is scheme to make that info available for private companies and that's the trojan horse here.
- jeroenhd 5mo ago> that info That info being: {"over_18": true} or maybe {"over_16": true, "over_18": false} with a government signature. Might be a problem if you've got a Vatican ID, I suppose? Though they don't participate in this system of course.
- bootsmann 5mo ago> Real cryptographic unlinkability schemes like BBS+ or CL signatures would produce uncorrelated proofs even on reuse. This is not that. This discussion was already led ad nauseam with the Swiss eID proposal (which is supposed to be EUID compatible) and the reason why the system relies on rotating signatures instead of ZKPs is that the cryptography hardware modules in most phones don't support algorithms such as BBS+. This creates a tradeoff where the states would have to essentially roll their own crypto storage and bank on this being safer than simply rotating through batches of signatures generated by the hardware cryptography modules (which is largely unproblematic in the grand scheme of things). The major advantage of using the hardware module is that it makes it much harder for attackers to extract the actual secret should the device ever fall into someone else's hands, something that happens to phones from time to time. Overall, as with every digital ID thread, it would help if some of the fearmon gering commentators would read the actually EUDI specs for once in their lives as it already addresses most of the concerns copy-pasted into these threads https://eudi.dev/1.6.0/architecture-and-reference-framework-main/ https://eudi.dev/1.6.0/architecture-and-reference-framework-....
- raverbashing 5mo ago> Overall, as with every digital ID thread, it would help if some of the fearmon gering commentators would read the actually EUDI specs for once in their lives Yeah I'm getting really really tired of the "crying wolf" crowd
- thomasingalls 5mo agoJust because the government is not out to get you at this exact moment doesn't mean that a future government won't be. Surveillance capacity seems to be a one way ratchet.
- bootsmann 5mo agoWhat surveillance capacity? In what way does the spec build surveillance capacity?
- jonathanstrange 5mo agoA digital ID not based on EU hardware should be taken down with prejudice. It's a direct threat to national security. US companies and, by extension, US government authorities have control over every popular endpoint (mobile phones, desktop OS). Besides, if someone wants a digital ID, it already exists in many countries. Phones with NFC chips can read many passports, e.g. Germany has an "electronic passport" since 2005. It's barely used, though, because it's bullshit.
- TacticalCoder 5mo agoHow's this going to work now that there are, arguably, already more AI agents online than humans? Or close to it. Most of the web if fake AI slop already. Many websites are more crawled by bots than by real people. We'll need to apply for digital IDs for bots and AI agents?
- pveierland 5mo agoIt's frustrating to see how shortsighted and tech-illiterate politicians are on these topics. This article from Norway today presents the attitude of the minister of digitization as simply "Social media companies are making billions and we expect them to adequately implement age verification systems with solutions that respect privacy and we will fine those who fail at doing this". The fantastic irony is that in some weak attempt to protect against the "evil big tech companies" they directly facilitate increased mass surveillance and removal of individual rights, instead of choosing more scalable and robust answers such as funding and promoting the development of protocols and open standards that can be applied voluntarily and in a decentralized manner to help mitigate these problems. I have computers side by side on my desktop running Linux, and it is amazing to me how I can call `wormhole send --message hello` and receive it on the machine next to me, knowing that only I can receive this message, without it running through an age approval mechanism, without it being client-side scanned, and without being logged in some government database. This is the century of AI and robotics - technologies which can facilitate great concentration of power and wealth. Gradually introducing mechanisms that facilitate digital fascism seems like a really bad way to guard us against this. https://www.nrk.no/norge/datatilsynet-bekymret-for-personvern-ved-aldersverifisering-1.17860495 https://www.nrk.no/norge/datatilsynet-bekymret-for-personver...
- lukeschlather 5mo agoA decentralized government ID system is a contradiction in terms. Government ID is and must be centralized. For me the decentralization is precisely the problem. I shouldn't end up with my government ID registered in a newspaper's database because I bought a newspaper subscription. Decentralization is not good here. In order for identification to work, decentralization requires that everyone who tangentially has access to your identity has persistent verifiable knowledge of your identity. Even in a centralized system it is hard to avoid this.
- sublimefire 5mo agoThere are slight contradictions in this open list of complaints with a bit of guesstimates. As mentioned digital ids are a thing and this is where everything is moving. The author mentions that it would be great to use it but does not believe it is possible and then says age checks will lead to it and it is bad. There are reasons why digital ids will be forced and one of the big ones is because bigtech companies do not want to invest into looking after the content, e.g. misinformation, bullying, etc. Not to mention the inability of companies to control the age of users, and everyone knows this is not in the interest of advertisers. Criticism is good but it also has to offer some options. Saying everything is bad bad does not help. All in all I have kids and it is very difficult to filter all of their internet traffic and I am not your average parent. Kids are reading crap and get brainwashed everyday, and the idea that you should just let them is ridiculous. Cyber bullying is a thing and I wonder what would you do when your kids get to be on the receiving side. IMO this is trying to blame politicians who represent their electorate who wants this without acknowledging that the issue is in huge ad funded companies whose interest is to gather all that private data without any supervision or filtering. BTW Data is constantly being leaked from large companies as well, not only gov entities. In relation to guesstimates the author jumps to possible conclusions without sufficient proof. What would the author suggest to fix the main issues though?
- imrozim 5mo agoI am 20.idea showing to govt I'd just to browse feels wrong even if the crpto works the habit of verifying Identity everywhere is the real problem.
- tpsvca 5mo ago[dead]
- sunshine-o 5mo agoIn the end the dilemma goes like this for most users: - If you rely on Big Tech for your identity and data you loose all privacy but can expect some security. - If you go with your government you still loose your privacy but also all security. I saw on HN just in the last month that the EU and France got hacked and very sensitive data is now on the Internet.
- moezd 5mo agoInternet used to be a cyberpunk escape hatch. Now we want to get rid of any and all anonymity at all costs, to the point of waking your phone up with a face id and your internet history tied to your government ID 1-1. This is just sad.
- Bender 5mo agoI do not know about others here but I will not be participating in anything that requires ID verification. Such domains will be blocked on my DoH servers both private and public though I doubt many here would want to use something other than Cloudflare DoH. Anyone else here planning on blocking sites that require age / ID verification? Are there any publicly available domain deny-lists that could be added to uBlock yet?
- sunnybeetroot 5mo agoI guess you can start by blocking every social media website?
- Bender 5mo agoYes. I think I would block the social media sites that implement Age/ID checks as they implement them.
- 1vuio0pswjnm7 5mo agoMay I share a different perspective "EU Age Control" is not a Trojan Horse. The software (app) does what it purports to do. No one _wants_ to use it The "Trojan Horse" is the corporate mobile OS. It's a "free gift". People such as the author happily accept it. These people _want_ to use the corporate mobile OS for what they believe it is, which is something other than software to defeat privacy for the benefit of Google, Apple and their advertiser business partners and customers People don't think of the software as performing that function. Meanwhile it is the core "business model" of its distributor. The corporate mobile OS is a Trojan Horse This is why the "age verification" app only works when using the corporate mobile OS. The author states: "The apps will not work unless you have a Google or Apple approved device. Forget Linux, GrapheneOS, Huawei, after-market firmwares. It's part of the security model." The bogus justification for requesting ID is not "age verification" it is "security". That's the nonsense reason why the computer owner cannot use an OS he/she compiles himself/herself and why people happily accept the Trojan Horse. The corporate mobile OS is an instrument of data collection, surveillance and online advertising but that's not how the author sees it. He does not see what's inside, he sees a beautiful "free gift"