Regardless of whether you personally use Android or iOS, I think that we can all agree that it is not right to be forced to use a specific platform in order to access almost any Internet services.
Two platforms that are not owned by companies in the EU. Effectively handing the keys to your state ID to private foreign enterprise.
What will you do when Apple/Google or the US Government effective immediately delete/block your app? The impact initially may be small but after a few years if widely used, you can break a country.
Don't fall for the trap. The question isn't how we should technically force age verification on anybody. The question is why they're pushing it onto everyone. I did not consent to this, neither did you.
I know this sounds bad, but when has consent mattered before? I agree with you wholeheartedly, but consent is simply not something these power structures value.
I and many others have been banned from Twitter for the last two weeks because of a new process[1]. I have to view all links in incognito tabs or hand over my biometric data to a trillionaire. Just don't use Twitter some may quip, well that would be a great group effort, but I can't do it alone.
'They' are not pushing age verification onto everyone. 'We' are pushing it onto ourselves. People want this. It is popular all over the world. If 'they' are doing anything, it is subverting what people want into something else. Which is the worry here, as people asked for age verification but didn't ask to be locked into the mobile phone duopoly. The system people want for age verification could be implemented as Firefox plugin. If it requires these attestation services for binary blobs provided by the government, it includes features someone else wants.
Some people consent to it, and they have a voice too. If they win and you didn't also consider the technical solution, you will find yourself not only with a law you disagree with, but also with a terrible technical solution.
So whatever you opinion is on the subject of forcing age verification, it is worth looking at the technical solution, especially if it is your domain of expertise.
Bruce Schneier goes on about this A LOT, and you’re exactly on point. If the knowledgeable tech people don’t get into policy, it will become law drafted by lawyers and MBAs. Man, I wish I knew how to get into policy…
Funny how the worry of "digital exclusion" of the elders who would never be able to use a smartphone has been thrown out of the window in recent years.
I guess it's that time of the week again. Do we have a sockpuppet account to welcome in you by any chance?
The (actual) complaint of the thread appears to be resolved already (which would make sense given this is old news):
> In the README, the following is listed:
>> App and device verification based on Google Play Integrity API and Apple App Attestation
The README.md does not appear to feature such a section (nor any of the other files for that matter).
Separately, the title is editorializing, and falsely suggests there's some big bad EU app, even though the app that does exist is merely a reference implementation, not for end user usage. There's a reason the repository you're linking a discussion thread from only holds specs.
Edit:
> the specification does not prohibit it
My account has been rate-limited, so I'm not able to reply directly. Nevertheless, I'm sure you can appreciate that your title is still quite the lie then. "Not prohibiting it" is very different from "forcing", after all.
What baffles me the most is how the EU commission constantly
works in favour of US corporations in the long run. This is
really strange. Something does not work in the explanations
given by the EU commission. To me it looks like US lobbyists
run the EU here.
The EU gets billions of dollars from fining US companies. That money is used to pay for a lot of programs and the bean counters don't wan't that source of funding to dry up.
This is the elephant in the room regarding the big "digital sovereignty" talks in the EU.
For the moment in the EU institutions the focus is mostly at the post-acceptance stage that everything must eventually migrate off US clouds. There is still some denial and hope that things will go back to "before" because it's going to be extremely costly to migrate, but at least high level EU civil servants start to see the strategic value of moving out.
However there is ZERO talk about mobile platforms... No alternative solution like linux for the desktop, no money or care given to the few alternative that tentatively exist, and zero talk about forcing companies (at least for the ones shipping android phones) to open up their firmwares and allow users to install alternative OS if they want to sell in the EU.
So whilst the backend guys more or less got the memo about sovereignty, I think there is still a lot of educational work to do regarding end user devices and what kind of digital slavery hole we're digging ourselves in...
Ok we get new HN articles every week now about migrating to EU solutions and digital sovereignty. At this point EU should just do as China, please: have EU their own cloud providers, softwares, hardwares, phones and also its own closed-EU only mini-internet barrier by a big EU digital policy border. Just like China, NKorea and Russia. They would be finally at peace with themselves.
Mobile is the UI/UX equivalent of… I don’t even know… a moon landing? A wonder of the world?
I’m not saying it can’t be duplicated. I’m saying if you want to build a mobile platform you need to approach it with appropriate respect for the incredible difficulty of making something that usable.
Indeed. Power management alone is a massive research area with never-ending complexity across a bunch of domains. And nailing the ecosystem correctly is very hard (both devices and software). Security is another bottomless pit of research and improvement. When trillion-dollar companies like Amazon and Microsoft ceded mobile to Google and Apple, it was a good demonstration of how hard a successful mobile platform is to get off the ground.
"zero talk about forcing companies (at least for the ones shipping android phones) to open up their firmwares and allow users to install alternative OS if they want to sell in the EU."
Complete public datasheets on how to program the hardware should be a requirement fit a DMA2.0.
The sovereignty thing is a theater. Many french unis use Google cloud because they're broke and can't maintain in-house services, and none gives a damn.
China made its own linux distros almost immediately. And as far as I know it is widely in use (Kylin etc.?).
Some nations in the western sphere seem to gladly outsource such critical infrastructure. Thinking about the Korean defence manufacturer whose contact mail was something@gmail.com in an advert I saw a few days ago. Perhaps Google will integrate some fast reply function for some instant AA ordnance delivery?
I agree wholeheartedly with the argument raised in this github issue, but I think people are wrong to be skeptical about the concept of a government-issued age verification app.
Thing is, the status quo is absolutely worse. My 13yo son likes making Roblox games. Suddenly, some months ago, Roblox made a change where you’re not allowed to share your games with friends unless you do “age verification”, apparently in some misguided bid to beat the pedos. In Roblox’ case, this means sharing your 3D likeness with some sketchy American business who pinky promises to delete said data after. I don’t want random American tech companies to have my kids’ biometric info like that, able to sell it to whoever asks. Nor my passport or anything like that.
I’d much prefer a government supplied app, that’s guaranteed to protect my privacy, and has no business incentive to sell my data, where I can see what data about me (or my son) is shared with Roblox or whichever sleazy business wants it.
Obviously this only makes sense if the government is less sleazy than the average American tech business, but for all its faults, I think that currently holds for the EU (and most of its member countries). There’s plenty precedent of EU governments doing privacy-conscious apps right (the Dutch covid tracking app comes to mind).
Same as for banks. Downloading some verification app with a confidence inspiring 1.2 rating on the app store, getting on a call with some random gig worker looking like they are taking the call in their living room and wiggling your ID around while giving a thumbs up is not the way I would like to prove my identity to a bank.
But there's no alternative. The EU digital identity wallet would be the alternative. You control and exactly see, what kind of information the bank is getting from you and you can be sure that it doesn't flow through some sketchy third-party identification service.
Here in the Baltics we already have an app for that. It's used to login to banks and government websites.
Recently one supermarket chain added it for age verification on their self-service checkouts (e.g. buying alcohol).
The problem with this is you do not know what information they get, I guess the supermarket gets my full name, date of birth, personal code, etc. Their privacy policy says it will not be stored, but that means nothing.
The original design intention of this approach was that wallet apps were independant and interchangable, with any wallet app able to talk to any attestation provider, to get age attestation tokens, and any site/app able to talk to any wallet. The wallet's job was merely to securely hold a bunch of attestations tokens, and dispense them to other sites/apps on request.
So you could use an open source app, or government provided one, or one provided by your bank, whatever you trust the most to not be recording data about relying parties and sending it somewhere you don't want.
The version of the document currently on GitHub has heavily deviated from that original intention. This is very unfortunate.
Even so this version is supposed to still be incapable by design of sharing any data with a relying party other than "over 18" and was designed such that the only way for a relying party to determine your identity is to be colluding with the attestation provider, or by colluding with the wallet app.
To attempt to address the first issue they have the unfortunately optional ZKP protocol. The original design assumed that users could find a wallet that they were certain would not collude with the RPs, and was considered a non-issue, but unfortunately it is a huge hole in the current version.
This entire issue is a disaster of a Github issue. It looks like its on the entirely wrong repository. I did eventually find the text in another repository; the one for the Android reference implementation: https://github.com/eu-digital-identity-wallet/av-app-android...
It was removed from there to clarify the entire "Hey, this application is not done yet"
It being in the reference implementation instead of the spec is a massive difference. One means that it's just there to show an example, and we should push national governments to do it better in their implementations, while the other would mean that it'd be a requirement for all implementations, which it doesn't appear to be.
We have a definition at the beginning, for "Social media and other digital services (in short, social media+)":
“Within the scope of this report, the terms ‘social media+’ and ‘social media and other digital services’, are used to broadly define services that may be available to minors and contain age-inappropriate and/or risky features (for example, addictive and harmful features, among which infinite scroll, autoplay, recommendation algorithms and persistent notifications) and/or content. Social media and other digital services providers include online platforms serving as intermediaries of content from third parties, such as social media, as well as app stores. AI systems posing risks to minors’ safety and development, including AI companions, video games exposing children to harmful commercial practices or dangerous contacts, and video-sharing platforms enabling age-inappropriate access to minors are also included.”
So, let's see, services that may contain age-inappropriate and/or risky content, "online platforms serving as intermediaries of content from third parties".
How quickly can you come up with something that wouldn't fall in that definition?
It seems that anything that allows user-contributed content (such as plain old forums) or communication among users would be comprised in it.
And, yes, to be sure we explicitly include app stores (I guess including e.g. F-Droid, and what about software repositories?) and video games with intercommunication features.
What is this definition used for?
Recommendation 1 of chapter 3: “A harmonised EU-wide access restriction to *social media and other digital services*, including AI companions, for children under 13 is necessary.”
This is a report, not law, but it was commissioned by Ursula von der Leyen and
“The report is intended to inform future actions to be proposed by the European Commission and EU Member States to reinforce child safety online.”
The issue is not the issue, the issue is what their "solution" enables for expanding the surface that governments have for controlling details of how you live your life in the future once accepted.
This is even more than just android, I'm sure there are plenty of us using AOSP forks that do not have google services installed. I think the EU will overturn this with enough noise though. Hopefully the UK doesn't do the same, I've avoided having to root my phone so far and would like to keep it that way if possible.
Tells us the us is some sort of failed democracy then implements China like access control for the population because they want to ensure they can prosecute you for wrong think in the future. Yeah Im loving this "liberal order" that looks more like good old facism dressed up to look "nice". Even how the passing of chat control was done has ensured I´m voting for any party that will dismantle the EU. EU Parliament is not a democratic of representative institution. Its about as legitimate and democratic as the Duma in Russia.
66 comments
[ 3.2 ms ] story [ 81.2 ms ] threadAre there any other Operating Systems than iOS, Android or Android flavors?
WebOS was nice but who is still using this? Symbian? Can you even use Social Media Apps with another phone OS?
What will you do when Apple/Google or the US Government effective immediately delete/block your app? The impact initially may be small but after a few years if widely used, you can break a country.
[1] https://old.reddit.com/r/Twitter/comments/1uk6a98/lets_confi...
So whatever you opinion is on the subject of forcing age verification, it is worth looking at the technical solution, especially if it is your domain of expertise.
The (actual) complaint of the thread appears to be resolved already (which would make sense given this is old news):
> In the README, the following is listed:
>> App and device verification based on Google Play Integrity API and Apple App Attestation
The README.md does not appear to feature such a section (nor any of the other files for that matter).
Separately, the title is editorializing, and falsely suggests there's some big bad EU app, even though the app that does exist is merely a reference implementation, not for end user usage. There's a reason the repository you're linking a discussion thread from only holds specs.
Edit:
> the specification does not prohibit it
My account has been rate-limited, so I'm not able to reply directly. Nevertheless, I'm sure you can appreciate that your title is still quite the lie then. "Not prohibiting it" is very different from "forcing", after all.
However there is ZERO talk about mobile platforms... No alternative solution like linux for the desktop, no money or care given to the few alternative that tentatively exist, and zero talk about forcing companies (at least for the ones shipping android phones) to open up their firmwares and allow users to install alternative OS if they want to sell in the EU.
So whilst the backend guys more or less got the memo about sovereignty, I think there is still a lot of educational work to do regarding end user devices and what kind of digital slavery hole we're digging ourselves in...
I’m not saying it can’t be duplicated. I’m saying if you want to build a mobile platform you need to approach it with appropriate respect for the incredible difficulty of making something that usable.
Complete public datasheets on how to program the hardware should be a requirement fit a DMA2.0.
The elephant in the room is that it is just talk, as always in case of EU.
Some nations in the western sphere seem to gladly outsource such critical infrastructure. Thinking about the Korean defence manufacturer whose contact mail was something@gmail.com in an advert I saw a few days ago. Perhaps Google will integrate some fast reply function for some instant AA ordnance delivery?
Thing is, the status quo is absolutely worse. My 13yo son likes making Roblox games. Suddenly, some months ago, Roblox made a change where you’re not allowed to share your games with friends unless you do “age verification”, apparently in some misguided bid to beat the pedos. In Roblox’ case, this means sharing your 3D likeness with some sketchy American business who pinky promises to delete said data after. I don’t want random American tech companies to have my kids’ biometric info like that, able to sell it to whoever asks. Nor my passport or anything like that.
I’d much prefer a government supplied app, that’s guaranteed to protect my privacy, and has no business incentive to sell my data, where I can see what data about me (or my son) is shared with Roblox or whichever sleazy business wants it.
Obviously this only makes sense if the government is less sleazy than the average American tech business, but for all its faults, I think that currently holds for the EU (and most of its member countries). There’s plenty precedent of EU governments doing privacy-conscious apps right (the Dutch covid tracking app comes to mind).
I hope they see reason and fix this here issue.
But there's no alternative. The EU digital identity wallet would be the alternative. You control and exactly see, what kind of information the bank is getting from you and you can be sure that it doesn't flow through some sketchy third-party identification service.
Recently one supermarket chain added it for age verification on their self-service checkouts (e.g. buying alcohol).
The problem with this is you do not know what information they get, I guess the supermarket gets my full name, date of birth, personal code, etc. Their privacy policy says it will not be stored, but that means nothing.
https://www.smart-id.com/
So you could use an open source app, or government provided one, or one provided by your bank, whatever you trust the most to not be recording data about relying parties and sending it somewhere you don't want.
The version of the document currently on GitHub has heavily deviated from that original intention. This is very unfortunate.
Even so this version is supposed to still be incapable by design of sharing any data with a relying party other than "over 18" and was designed such that the only way for a relying party to determine your identity is to be colluding with the attestation provider, or by colluding with the wallet app.
To attempt to address the first issue they have the unfortunately optional ZKP protocol. The original design assumed that users could find a wallet that they were certain would not collude with the RPs, and was considered a non-issue, but unfortunately it is a huge hole in the current version.
App and device verification based on Google Play Integrity API and Apple App Attestation
But I can't find that anywhere. Am I missing something?
It was removed from there to clarify the entire "Hey, this application is not done yet"
It being in the reference implementation instead of the spec is a massive difference. One means that it's just there to show an example, and we should push national governments to do it better in their implementations, while the other would mean that it'd be a requirement for all implementations, which it doesn't appear to be.
It also looks like the reference implementation removed that functionality entirely several months ago: https://github.com/eu-digital-identity-wallet/av-app-android...
"EU age verification app to ban any Android system not licensed by Google" 27-jul-2025 https://www.reddit.com/r/BuyFromEU/comments/1mah79o/eu_age_v...
and
"EU age verification app not planning desktop support" 24-sep-2025 https://news.ycombinator.com/item?id=45359074
We have a definition at the beginning, for "Social media and other digital services (in short, social media+)":
“Within the scope of this report, the terms ‘social media+’ and ‘social media and other digital services’, are used to broadly define services that may be available to minors and contain age-inappropriate and/or risky features (for example, addictive and harmful features, among which infinite scroll, autoplay, recommendation algorithms and persistent notifications) and/or content. Social media and other digital services providers include online platforms serving as intermediaries of content from third parties, such as social media, as well as app stores. AI systems posing risks to minors’ safety and development, including AI companions, video games exposing children to harmful commercial practices or dangerous contacts, and video-sharing platforms enabling age-inappropriate access to minors are also included.”
So, let's see, services that may contain age-inappropriate and/or risky content, "online platforms serving as intermediaries of content from third parties".
How quickly can you come up with something that wouldn't fall in that definition?
It seems that anything that allows user-contributed content (such as plain old forums) or communication among users would be comprised in it.
And, yes, to be sure we explicitly include app stores (I guess including e.g. F-Droid, and what about software repositories?) and video games with intercommunication features.
What is this definition used for?
Recommendation 1 of chapter 3: “A harmonised EU-wide access restriction to *social media and other digital services*, including AI companions, for children under 13 is necessary.”
This is a report, not law, but it was commissioned by Ursula von der Leyen and “The report is intended to inform future actions to be proposed by the European Commission and EU Member States to reinforce child safety online.”