EU Age Verification Project Mandates Hardware-Bound Attestation

The EU’s age verification project confirms hardware-bound attestation is mandatory, raising concerns over Linux, custom ROMs, and open-source access.

The European Union’s open-source age-verification project has drawn criticism after a maintainer confirmed that hardware-bound attestation is a mandatory architectural requirement, raising concerns about Linux, custom Android ROMs, and independently compiled applications.

The debate began in the GitHub repository for the project’s Android app, where a user argued that tying credentials to specific hardware environments would make it more difficult to support open systems.

Hardware-bound attestation is a requirement of this project, not an implementation detail we can simply drop,” a maintainer responded. The project invited alternative architectural proposals and said a dedicated security review and threat model would be published soon.

The solution lets users prove they are over a certain age without revealing their name, exact birth date, or full identity document. To prevent credentials from being copied, cloned, or reused by modified clients, the project relies on keys stored in protected hardware like Android TEE, StrongBox, or Apple’s Secure Enclave.

However, critics claim that this approach endangers the system by making it dependent on a small number of approved devices, operating systems, and attestation providers.

The project’s technical specification requires age verification apps to use native cryptographic hardware when available. However, stricter checks like root detection, Google Play Integrity, and Apple App Attest are not universally mandated by the reference implementation and may be left to individual deployers.

This distinction matters because hardware-backed key storage does not require a server to approve the entire device, operating system, or application build. The maintainer’s wording leaves some uncertainty over how restrictive production deployments will be.

There is also a separate governance limitation. Proof of Age providers are expected to issue credentials only to applications included in a list of compliant apps maintained by the European Commission. This means that publishing the source code does not automatically guarantee that a community-built version can use the real service.

Importantly, Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet. However, the current architecture does not provide a native Linux wallet, and alternative mobile operating systems could struggle to meet the required trust conditions.

So, as you can understand, the controversy goes far beyond a single Android implementation. For now, however, the project’s position is that hardware binding remains required. The expected security review and threat model may provide a more detailed explanation of why that trade-off was selected and whether alternative roots of trust or less restrictive implementations can still comply.

Until then, the central question remains unresolved: whether an EU-funded, open-source identity system can meaningfully remain open when real-world access depends not only on available source code, but also on approved applications, supported security hardware, trusted operating environments, and the policies of credential providers.

Bobby Borisov

Bobby Borisov

Bobby, an editor-in-chief at Linuxiac, is a Linux professional with over 20 years of experience. With a strong focus on Linux and open-source software, he has worked as a Senior Linux System Administrator, Software Developer, and DevOps Engineer for small and large multinational companies.

18 Comments

  1. John

    EU is turning so fast into a total dicatorship, like North Korea, China, Russia that is totally disgusting and I don’t like it anymore, at all.
    I also want my country out of it!

  2. we4v3r

    Europoors gonna be stuck playing catch up for a long time if not forever now xD

  3. ADarkGerm

    The only way forward is comprehensive accountability for online activity. Pandora’s box has already been opened; there is no realistic path back to a less connected digital world.

    One possible solution is a system where every internet user has a verifiable digital identity. For example, passports or other government-issued IDs could be linked to secure hardware authentication devices, such as a YubiKey, allowing people to prove they are adults or otherwise verified without necessarily revealing their personal identity in every interaction.

    In such a system, illegal online activity could be tied to a verifiable identity, making crimes more difficult to commit anonymously while preserving privacy for lawful users through cryptographic proofs.

    Cryptocurrencies have also transformed the economics of online crime. They provide a borderless, censorship-resistant method of transferring value, which has enabled ransomware, darknet markets, fraud, money laundering, and other criminal enterprises to operate at a far greater scale than was previously possible. While cryptocurrencies have legitimate uses, they have also become a powerful financial infrastructure for many forms of digital crime.

    At first glance, this sounds like dystopian science fiction. However, if designed with strong privacy protections, transparency, and legal safeguards, it could also increase accountability, not only for individuals but for governments and corporations. Those with power would need to be subject to the same standards of traceability and oversight, helping ensure that corruption and abuse cannot simply be hidden behind institutional authority.

    1. Anonymous

      Bad bot

    2. Londo

      Absolute drivel. It should be obvious to even the thickest skulls that this “age verification” nonsense is the thin edge of the wedge for a mandated, global Digital ID. It has nothing to do with fighting crime of any kind. All those Flock security cameras and the millions around London have done absolutely nothing to reduce crime whatsoever. Nevermind the panopticon in Beijing.

      Nothing about “age verification” and having a government tracked ID will stop or even slow down crime. The real crime is anyone defending this stupidity.

  4. Bill C. Finger

    What you unfortunately still call an “EU Age Verification Project” is part of a dystopian kleptocracy.

  5. toto

    Europe is against computer freedom & privacy.
    They want to track us everywhere.
    They already do with smartphones & credid card.
    Last step is computers.
    Can you imagine, we have an app on smartphone in France that can attest our idendity on the web.
    Needed for some governmental websites.
    It’s the paper (identidy card) thing but scanned.
    Sorry for my english.

    1. Anonymous

      DeGoogle

    2. Donald

      Do you use Google or Apple or any American tech? Guess what, you’re already heavily tracked.

    3. Incredible

      So you are afraid of the government/EU because they are limiting your privacy, but corporations doing it for over 20 years now is fine with you? From those two I’d much rather have EU spying on me than some US corporation.

      1. Monsa

        Most braindead comment ever

      2. John doe

        False dichotomy, how about not acceping this nonsense regardless of if its the EU or US corporations. Both suck.

        1. Anonymous

          Thank you for pushing back against this nonsense

        2. Anonymous

          real

  6. jadiri

    it bad enough that any age verification is invasion of privacy and illegal with out a dont in any democratic nation as is the rest of the mindless poorly thought out plan Freedom is for everyone regardless of age, race creed color and yes Age a new born if it were possible should be able to use the internet with out being doxed by it own Government period or the country is not Free and either are its people .

    1. nah

      IMO we should ban all social media and most popular apps with social elements. Then we wouldn’t need to have age verification. Though best option would be if parents simply used the built-in tools in every device and OS (including Linux) – called parental controls.

  7. flx1s+ Linux phone

    how is EU even considering age verification, let alone US based system attestation. Bonkers!

    1. AC

      They hate anonyomity, because it limits their ability to identify and target dissent.

      This isn’t about protecting anything but their slipping grasp on power, and their worldview is so absurdly wrong about literally everything that even the slightest dissent is an intolerable threat to them.

      The fundamental problem, and this is not unique to the European Union, is that the government is genocidally hostile toward the people of Europe. This fundamentally undemocratic government – all real power is held by unelected bureaucrats – is entirely illegitimate, and the only way for it to remain is to exercise increasingly totalitarian control over the populace.

Leave a Reply

Your email address will not be published. Required fields are marked *