48 comments

[ 0.36 ms ] story [ 27.0 ms ] thread
> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.

That's a weird way of putting it. You'll basically need a second non-Linux device if you want to use Linux.

If your reason for using Linux is "I want to continue using old hardware instead of quickly-obsoleted devices", then you're shit outta luck: you'll have to buy a (potentially second) device from one of those vendors who'll use the profits to further lobby against your rights.

I don't understand where the all the EU anti-trust and anti-corruption regulators are here. _Governments_ enforcing that you have a Google or Apple account to participate in society is transparently absurd.

This isn't only a digital sovereignty issue, it's also an anti-competition issue.

They already regulate the amount of rain water you can collect, or how much water you can take from your own well, or how many solar panels you're allowed to use

You feel bad because it touches your own personal toy, but if you zoom out you'll discover the vast majority of it was already fucked up

> a maintainer confirmed that hardware-bound attestation is a mandatory architectural requirement

Hardware-bound is not a problem, limiting that to only iPhones and some Android phones is. Plenty of hardware can keep a key safe and it doesn't need Apple's or Google's blessing.

I still contest that I should be able to solder together a basic computer in my garage and communicate with the internet so long as I follow the communication standards. There is never a reason to outlaw general purpose computing.
A lot of things get deprecated on the internet. You can shout in SSL and nobody will answer back.

Tying any solution to specific companies is the major problem. Because even if the rest of the age verification scheme is well thought out in the user's interest, tying it to Apple and Google not only forces people's dependency on foreign private companies, it also invalidates any pretense of privacy.

note that hardware attestation does not utilize ZKP or blind signatures. so your hardware ID is technically exposed.

usually to make use of the exposure multi-party collusion is required. Google or Apple attestation intermediaries (they convert your static certificate into an ephemeral one) would need to be logging information and when combined with information from the party you attested to (done with the ephemeral certificate) they will have your unique device identifier (the unchangeable certificate burned into the silicon).

it's doubly insidious because nothing is preventing the manufacturer from recording the certificate identifier and connecting it to an order ID for the device. so not only can they tie together multiple accounts, they could tie it to the identity that purchased the device.

on mobile devices you can't even restrict this functionality as it's exposed via API (remote attestation and also DRM license request handshake initiation). not even grapheneos gives you to option to disable it.

also, the implication of the above is that there is no private way to have a google account on an android phone. they will know it's you or the previous owner of the device who sold it to you (makes VPN irrelevant).

I expect a gray/black market in TPM keys and the like will grow if this takes off, but hopefully the citizens will fight it very strongly before then...

...but then again, this is the EU, not the US.

All this ostensibly to keep teenage boys from watching Pornhub (when parental controls already exist).

The real reason, of course, is to force people to connect strong real-life identifiers to online activity. Mobile first, then Windows. Then Linux is too weak to oppose on its own, and will adapt or die.

There should be real life identifiers connecting to online activity. Why should online actions be untraceable? That only empowers bad actors.
Yep. This is billionaire-led corruption of governments globally to buy legislation that takes away our rights. It benefits data brokers, intelligence agencies, and police.
Parental controls don't exist. Not ones that actually work. That's why governments want to do something about it in the first place.
> That's why governments want to do something about it in the first place.

Really ? Like what ? I never heard about mandated "working parental controls". I only heard about "protect the children" (where are the lawsuits against (church) rapists ?) and "protect about terrorism" ( where they twist the definition of "terrorism" to suit their political interests).

You know what Microsoft did with "parental controls" ?. It disabled Firefox. Of course you can still access ( "educational") porn sites through Edge.

> when parental controls already exist

The same parents who give smartphones to toddlers to keep them quiet? Good luck...

"Mobile first, then Windows. Then Linux is too weak to oppose on its own, and will adapt or die."

How about NetBSD, FreeBSD, OpenBSD, FreeDOS, Plan9

What's the timeline on this outcome

Anyone willing to place a bet on a prediction market

"Let me be direct about this: the likelihood of any legislature specifically targeting FreeBSD or OpenBSD with age verification mandates is close to zero."

https://freebsd.consulting/freebsd-dispatch-bsd-age-verifica...

> How about NetBSD, FreeBSD, OpenBSD, FreeDOS, Plan9

Good luck booting those OSs on a system with secure boot enabled

I bought a computer where a secure boot module was optional

I saved money by opting out of secure boot

If I needed it I could add it later

But I boot NetBSD from USB stick to RAM-based filesystem (e.g., mfs ,tmpfs), there is no internal HDD or SSD

I do not boot with "secure boot enabled" because the computer does not have a secure boot TPM

By an incredible coincidence, the (ex- ?) employee of a company known to lobby hard in the EU (Microsoft) and who's the author of a rube-goldberg kitchen sink many of you on HN loves so much (systemd), is now working on a system that's been described here as "an attack on general purpose computing". Attestations / Trusted Platform Module (TPM) / etc. are all in there:

https://news.ycombinator.com/item?id=46784572

How much do you love your systemd and the individual behind it now?

Can't wait to use your "amutable" Linux with hardware-bound attestation verifying your age now can you?

These people (the politicians behind such decisions, the people working on such platforms, those saying it's a good thing, ...) are enemies of freedom.

> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.

Considering a significant part of the internet will be behind age verification gates, how are they imagining this to work? I should pull out my iPhone or Google Android phone and get its approval every time I want to visit a website?

Here comes the European freedom and free speech. With Chat Control it’s even more hilarious. Compliance list, another European Commission, as always.
The article mentions "approved applications". What role, if any, do apps play in age verification if it's implemented in hardware?
Someone on HN suggested parents set devices up for their kids and Browsers and OS's gate by age. I haven't really been able to fault this idea.

State mandates verification and stuff like this makes me suspicious that this is much more than "protecting the children". More advocacy of alternative solutions please.

Indeed, I truly don't understand how simply enabling parental controls onto mobile devices handed to kids which then gets advertised to each website/app that they use isn't sufficient.

You make it an opt-in feature to "self-broadcast" that this device is being used by a minor. Solves 99% of the use cases. And for the remaining 1% — the really determined teenager — they'd never be stopped by this anyway. They'd social enginneer their way to access somehow.

That's the California approach. Devices whose primary user is a child will have to provide a way for parents to provide an age range for the child, and an API that apps and app stores can use to check that so they can avoid doing things that are supposed to be age restricted.

It has been discussed a few times here, and those threads are always full of people proclaiming that it will be the end of free and anonymous internet for all of us and allow tracking everything we do by both the government and any site we visit.

There it is. That's what this "age verification" nonsense was all about. Predictably, the unceasing "think of the kids" rhetoric came down to THIS.

Absolute control over people's computers.

It's not your computer anymore, it's the government's.

It should be noted that this app is temporary. The EU is aiming for a digital wallet app that you can store your identity documents in and that you can use to prove facts about those documents to third parties, in a way where the third party gets no extra information--just what you chose to disclose (e.g., just your age or just your country) and that cannot be used to link your real identity to your using the site even if the site and the government share logs (this is called unlinkability).

That will not be fully ready until around 2028. They wanted the age verification available earlier and that is this app. It does not have unlinkability.

Here's the expected timeline.

The first version of the wallet app is suppose to be out by the end of this year or early 2027. It will still not be unlinkable because Apple's Secure Enclave and Android's StrongBox don't support the cryptographic operations needed for the methods that will eventually be used for that, BBS+ anonymous credentials or ZKPs. There is a variant of BBS+ that can achieve unlinkability on existing phones, but unfortunately the hardware security modules (HSMs) currently used by government when they issue you your identity credentials cannot handle BBS#.

In 2027-2028 they are supposed to upgrade the government servers so they can support BBS# or zk-SNARK and update the wallet to use those, achieving unlinkability and anonymous age (and other data) verification.

The hardware security module does not need to change to support tying to a credentials. I showed how to do this years ago and the theory was known long before. Its just that the EU is making self imposed barriers to doing this right.
The downvoted comments here are very interesting, and it really shows a divide in beliefs here. I fear that there's no reconciling this, and in the end we'll need two internets: The EUternet and the USternet.
The US is moving in the same general direction, even if they take slightly different measures. The universal tracking of everyone is something all these governments can suddenly agree on.

If after this is enacted the firewalls aren't perfect, the internet will probably instead splinter into the Westernet and the everywhere-else-net for the rest of the countries that are too disorganized or uncaring to join in on the fun, maybe with a few safe havens of something resembling the old web in between.

Governments are not unified bodies, and attempts to introduce thought control on the internet have failed in the US, but easily passed in the UK. Illinois has recently passed a toothless age verification law and it's being hotly debated, but the UK is arresting people over facebook posts.
It doesn't really matter what is being done, what matters is the trend that countries are moving in. The UK started on a more authoritarian baseline than the US, so their laws are more restrictive. But by and large, everyone is moving in the direction of more control, and there's no reversal in sight. That's not to mention how big the disparity can be between individual US states, many of which are far more extreme than Illinois in anything they do.

They don't need universal international cooperation - sufficient cooperation is enough for their goals, and they may get it this time.

This is the most mind blowingly stupid thing I've ever witnessed..and in slow motion...I'm just astonished that the EU is cheerfully walking themselves into destroying the freedoms of their own citizens without much of fight.

The most privacy-obsessed people on earth are now handing a detailed log to their entire digital lives over to a group of barely-elected 3rd party overlords as well as foreign companies and intelligence agencies (if you think this won't be instantly compromised, you're tremendously naive).

...AND at the same time this is cementing monopolies for foreign tech companies within Europe. A double whammy of self-harm.

There's something very bleak about couching this under the 90s-era "protect the children" narrative too, given ultimately most Europeans care so little about children that they've rapidly stopped giving birth to them and in many countries have outsourced all childcare to the state.

It's not even a believable cover story anymore.

It seems more like the European officials looked over at the Chinese Communist Party's authoritarian control over the internet and thought to themselves, "Wow, look how little push back they get to their policies online! I want to do big fancy projects with other peoples money and have no accountability or transparency too!"

What happens if some social media site hosted in another country becomes popular and refuses to implement these age verification measures? Is the EU going to create a great firewall like China and start blacklisting sites? Are they going to ban VPN’s too? Seems like a slippery slope could easily get extremely invasive and restrictive.

It does seem like an effort to connect all online activity to real-world identities.

I searched this page for 'fascist', 'fascism', 'far left', and 'liberal' and there were no results.

A surprising little amount of criticism considering the rhetoric in any political right adjacent threads on this website. There are three mentions of 'trump'.

This is neither a far-left, far-right or centrist measure. It's a pure technocratic one, where the State and its minions believes optimize for control over the population, and matters like "privacy" or "resilience" don't appear in the cost function.
Cory Doctorow had a very profound talk about it very long time ago (10+years).

https://www.youtube.com/watch?v=HUEvRyemKSg

As the internet become the place where people do a lot of things, no government (and especially no security services) will be able to keep themselves from trying to control it or at least monitor it. And with the new LLM features they can automatically do much more than before.

Human nature is a constant and when the government sees an easy way to enforce something, many more bureaucrats will try to do it.

I predict that teenagers with irresponsible parents will continue to use social media and online anonymity will get worse.
What is the authority of the "repository maintainer" in question? It feels descisions like these far outstrip the pure technical.