EU calls VPNs “a loophole that needs closing” in age verification push

The European Parliamentary Research Service has warned that VPNs are increasingly being used to bypass online age-verification systems.

CyberInsider
@jonsnow sure, VPNs are the problem
(via https://www.instagram.com/p/DYArdw5DJCs/)

@punissuer @jonsnow that's not how the EU age attestation proposal and reference implementation work though. They use privacy-preserving attestation using zero-knowledge proofs (which has issues too).

So, age proofs would be tied to authentication in e.g. a national ID app (such as DigiD in the Netherlands), which would basically return a true/false to sites for an age check.

It won't work with silly photo scans like some other countries.

https://digital-strategy.ec.europa.eu/en/faqs/eu-age-verification-solution

EU Age Verification Solution

To help people prove their age safely and securely online, the European Commission has been developing an age verification solution. These questions & answers give more details about the solution.

@punissuer @jonsnow It comes with a lot of issues too, like sites/apps could leak birth dates by repeatedly probing until a boundary is found and the reference implementation requires passing of strong integrity in Google Play Integrity, which shuts out alternative operating systems.

But fight the real thing (especially being bound to Google/Apple, it's nice that the EU tries to do it in a privacy-preservint way) and not some caricature.

Jon Snow (@[email protected])

German digital ID will require an Apple/Google Account Rooted/jailbroken phone? Custom ROM? Latest updates not applied? Authentication denied, Mutterficker! Apple & Google become gatekeepers. "Your" device will be constantly monitored - for "compliance". "And you will be happy". https://bmi.usercontent.opencode.de/eudi-wallet/wallet-development-documentation-public/latest/architecture-concept/06-mobile-devices/02-mdvm/ #DigitalID #IDVerification #Google #Apple #Android #iOS #technology #privacy #surveillance #enshittification #dystopia #BigTech #Germany #EU

Mastodon
@jonsnow @punissuer Yep, that should be fought tooth and nail. (AOSP) Android also supports remote attestation without Play Integrity or any other Google services and works on gegoogled Android.