August 2, 2026

ID check? More like vibe check

EU Age Verification Project Mandates Hardware-Bound Attestation

EU’s ‘open’ age-check plan sparks fury over needing Apple or Google to get in

TLDR: The EU’s age-check project says secure phone hardware is mandatory, which critics say could shut out Linux users, custom devices, and independent apps. The backlash is fierce because many see an “open” public system drifting toward Apple-and-Google-controlled access, and that raises both fairness and freedom concerns.

The EU wanted a neat privacy-friendly way for people to prove they’re old enough online without handing over their full identity. Sounds sensible, right? Enter the plot twist: the project has now confirmed that the system must be tied to secure phone hardware, and that’s where the comment section absolutely detonated. Over on the project discussion, critics said this turns an “open-source” idea into a velvet-rope club where your source code may be open, but real access depends on the right phone, the right app, and the right corporate gatekeepers.

The loudest reaction was basically: “So Linux isn’t banned… you just need a second non-Linux device. Cool, cool, very normal.” That line became the instant mood. One camp argued that secure hardware itself isn’t the villain; the real scandal is that the practical winners look suspiciously like Apple and Google. Another camp went even harder, calling it an anti-competition mess and asking where the EU’s own regulators are while a public system seems to lean on Big Tech accounts and approved app lists. In other words, the drama isn’t just about age checks — it’s about who gets to participate in digital life.

And yes, the hottest takes got wild. One commenter jumped straight to revolution rhetoric, while another warned that the privacy story may be less magical than advertised if device-level proof can still leave a trail. The jokes were dark, the trust was low, and the vibe was: “Open source, but make it permissioned.”

Key Points

  • A project maintainer said hardware-bound attestation is a mandatory architectural requirement for the EU’s age-verification system.
  • The system is designed to prove age eligibility without disclosing a user’s name, exact birth date, or full identity document.
  • The architecture relies on hardware-protected keys such as Android TEE, StrongBox, and Apple’s Secure Enclave to prevent credential copying or reuse.
  • The technical specification requires native cryptographic hardware when available, while stricter checks like Google Play Integrity and Apple App Attest are not universally mandated by the reference implementation.
  • Proof of Age providers are expected to issue credentials only to apps on a European Commission compliance list, and the current design does not include a native Linux wallet.

Hottest takes

"You’ll basically need a second non-Linux device if you want to use Linux" — WhyNotHugo
"Governments enforcing that you have a Google or Apple account to participate in society is transparently absurd" — afandian
"Plenty of hardware can keep a key safe and it doesn’t need Apple’s or Google’s blessing" — buran77
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.