Introduction
The European Union's age verification project has recently sparked debate by mandating hardware-bound attestation. This requirement raises concerns, particularly for Linux users, custom Android ROMs, and independently compiled applications. Why such a decision, and what are its implications for the open-source ecosystem?
Hardware-Bound Attestation: Why and How?
The project aims to allow users to prove they are above a certain age without revealing their full identity. To achieve this, it relies on keys stored in protected hardware like Android's TEE, StrongBox, or Apple's Secure Enclave. This approach seeks to prevent credentials from being copied, cloned, or reused by modified clients.
However, by binding attestations to hardware, the project restricts access to only approved devices, which is a major concern for open-source advocates.
Consequences for Linux and Custom ROMs
Critics of this approach point out that it could marginalize Linux users and those using custom Android ROMs. The technical specification requires age verification apps to use native cryptographic hardware when available but doesn't universally mandate checks like root detection or Google Play Integrity.
For example, a Linux user could still access a website and scan a QR code with a supported mobile wallet, but the increased reliance on hardware raises questions about long-term compatibility.
Implications for Open Source
The project also has implications for open source in general. Proof of Age providers are expected to issue credentials only to applications included in a compliance list maintained by the European Commission. This means that publishing the source code does not automatically guarantee that a community-built version can use the real service.
This restriction could limit innovation and flexibility, which are key elements of the open-source philosophy.
Next Steps and Alternatives
The project has invited alternative architectural proposals and plans to publish a dedicated security review and threat model soon. These steps indicate an openness to discussion and improvement but remain to be confirmed by concrete actions.
Conclusion
The EU's age verification project, with its hardware-bound attestation approach, raises critical questions about accessibility, compatibility, and open-source innovation. Decision-makers must carefully navigate between security and inclusivity to avoid unnecessarily restricting the digital ecosystem.
Let's discuss your project in 15 minutes.