- 3 hours
Gee. I totally not saw that coming.
These people who push for it are fascists, and the only way to deal with fascists is to kill them before they murder you.
- 3 hours
I have a solution to the age verification problem. There is a way to affirmatively prove someone is a real human adult without invasions of privacy. We can use the same ID verification system we’ve been using for centuries: public notaries.
Governments could hand anonymous cryptographic tokens to notaries. These contain no information on the individual. They’re simply a unique cryptographic token. You can go to a notary, pay a nominal fee, show your ID, and grab one of the tokens (possibly just a code printed on a card) from a large bin of them. You can then use this token to register for any number of sites. The notary themselves does not need to note which cryptographic token you grab. The notary doesn’t even know what token you received. The goal is merely to prove you’re an adult human, not to create a cryptographic key tied to your specific identity.
I would then let people do this as many times as they want. You can get a hundred such IDs. They wouldn’t cost much, a few dollar or Euros. This would be no barrier to individuals accessing the net, but it would make them unsuitable for mass spamming.
- 1 hour
It’s a legit idea, and there’s a thing like that, called Zero Knowledge Proofs (ZKP).
IMO it’s possible in theory. Like set up and managed in good faith, it can work mathematically, and you can prove it does.
My worry tho is that it wouldn’t be in good faith. It’ll be corrupted somehow. Or it turns out that enough other signals leak that it isn’t very effective. Like fingerprinting and stylometry and w/e allow ID’ing despite the ZKP layer.
- 6 hours
These kinds of laws will not succeed. People will choose to ignore them, like they ignore other laws, like they litter, jaywalk, drive 10 over the limit, run stop signs, etc. It will succeed in driving up prices on products from those companies who choose to comply, because they will be forced to hire in a lot more lawyers and compliance staff. These laws create lots of full time jobs in tech companies that few realize even exist. They have meetings every week, attend conferences, constantly send letters back and forth to each other. Then people wonder why their Gamepass fees went up $10 (its not actually the games)
- 13 hours
How I see it, ocurres when the laws are made by ancients which confuse an remote control with an smartphone.

- 15 hours
The solution lets users prove they are over a certain age without revealing their name, exact birth date, or full identity document. To prevent credentials from being copied, cloned, or reused by modified clients, the project relies on keys stored in protected hardware like Android TEE, StrongBox, or Apple’s Secure Enclave.
The project’s technical specification requires age verification apps to use native cryptographic hardware when available. However, stricter checks like root detection, Google Play Integrity, and Apple App Attest are not universally mandated by the reference implementation and may be left to individual deployers.
So there’s a chance that GrapheneOS will be supported. I mean, we can still decompile the app, modify it and then repackage it. Or someone will make a patcher app.
I would love to be wrong about this, but I don’t think it’s likely. Why would a government voluntarily spend money on making the app work for a minority of people running a privacy OS that politicians associate with criminals and gangsters?
Also, it’s not like the wallet app will actually be open source in the traditional sense where you can fork and compile it yourself, so I think getting any decent version of it seems like a long shot
- 6 hours
Graphene will likely ignore the EU, as will most Linux distros having no EU connections. Graphene’s very picky about hardware, which is why they stick with the Pixel, but anyone with the cash can pay an OEM to make a phone to their specs and install whatever Android or Linux mobile variant they want, then make 1000 or 10,000 of them to sell.
- 8 hours
I would expect it must be open source, so I don’t known why you’d decompile it
Unfortunately not, the wallet app must have source code available except for parts deemed too sensitive, which are exempt
- 7 hours
Because some member states argue that their implementation is better when proprietary. Also if you’ll want to build the app yourself, you’ll need the required certs.
- 20 hours
so bye anything that isn’t microsoft, apple or google? really tech independent of europe.
- 22 hours
Can’t wait for EU to ban general purpose computing. At some point ,everybody is just going to get a locked down Windows tablet where only EU approved software runs.
- 3 hours
I fear that is the inevitable whimpered ending of the personal computing era. Cory Doctorow called it back in 2011.
- 2 hours
Honestly, it’s something where I wonder if we’re doomed to end up there anyway.
I think that the AI companies vastly overstate the usefulness and danger represented by AI models. But the technology is only getting better, and the resources required to run models will decrease over time.
A common scenario brought up are AIs teaching people how to make biological weapons. Can existing LLMs actually do that? I really don’t know. I for one don’t feel like asking copilot, “please give me step-by-step instructions for obtaining and weaponizing anthrax, in steps simple enough someone with only a general science and engineering background can do.” I’m curious what copilot would say. But I won’t be asking copilot that, not because I’m incurious, but because I don’t feel like getting my house raided by the FBI.
But imagine a world where that actually is possible. Forget the claims of Sam Altman. Let’s look 50 years ahead in the future. Imagine being able to ask that question to an open-weight/model LLM, something you can run unmonitored on a home desktop, and actually getting a correct response. Imagine being able to ask endless follow-up questions. A good enough LLM could conceivably walk someone with only a high school education through all the steps needed to create weaponized anthrax from scratch.
Anthrax is something we actually can’t control the spread of. It occurs naturally in the soil and water in some specific locations and conditions. A sufficiently skilled biochemist could go out, collect it, and culture it. And having an LLM capable of giving you step-by-step instructions, dumbed down to whatever your skill level is? Able to coach you through it, perhaps even watch you do it and offer real-time feedback? If you just have to act as the hands of the LLM? Suddenly anyone can weaponize anthrax.
I don’t think existing LLMs are there yet. But what do we actually do if we reach a point where open-source LLMs are? What are we supposed to do when the knowledge to produce weapons of mass destruction becomes cheap and accessible?
A general trend in technology over time is that it has magnified the potential destructive power of a single individual. How can a society survive when anybody has the ability to kill everybody? I just don’t see how you keep society going except by locking down the tech. Maybe require a license for any computer over a certain power. And such computers are heavily surveilled. So you can have a free and private computer, but only if that computer does not make you a danger to everyone around you.
I just don’t know how else a civilization can survive the democratization of weapons of mass destruction.
- 1 hour
As much as I’m a privacy guy, those are legit concerns IMO. IDK where the future goes, but I see reasons to worry.
TBH I’m more worried about the overall infopocalypse that’s already in progress. But I also can’t rule out an AI teaching somebody unhinged how to make a devastating biological weapon. Something only accessible in the past to very highly trained ppl, who were not gonna do that.
But I also want my privacy! And I believe privacy is essential to a functional democracy. Feels like every choice is a bad choice.
- 1 hour
Yeah, that’s why in an ideal case, I could see a two-tier model developing. Similar to how we handle weapons today. At least in the US, handguns and rifles are pretty obtainable. But anything more than that is heavily restricted. Even 2nd Amendment folks don’t advocate for the private ownership of heavy artillery, FPV suicide drones, armed tanks, etc. We allow anyone to own the things that, while still dangerous, don’t give you the power to kill absurd numbers of people. Even with an AR-15, you’re only taking out so many people before you’re taken down. You’re not a danger to civilization by owning an AR-15.
Computers could work the same way. As AI technology improves, we’ll get a better understanding of the minimum level of compute needed to be dangerous. You then set a limit for unlicensed computing below that level. Unlicensed? Have all the privacy you want. This lets you play games and create text, video, and most any form of expression you want. If your creative medium is as an artist of fully immersive 4K virtual reality worlds, you might have some trouble. But pretty much anything you currently use a computer for would fall under the unlicensed compute threshold.
Above this threshold? Everything is locked down. Everything is logged. Everything is scanned. You’re using a tool that is as dangerous as a pile of plutonium, and we treat it with an appropriate level of respect. Dealing with this privacy violation is just a price you have to pay if you want to use these tools.
- 1 hour
IDK, I’m less sold on your proposed solution, than on your proposed problem existing. :)
- 17 hours
Can’t wait to become a shady dealer who sells pre 2026 computers with highly illegal software running on it (such as debian)
- 8 hours
There’s gonna be a whole black market for smuggling open computing platforms from China 🤣
- 19 hours
They’re gonna ban abacuss next, and then comes mental math, and suddenly 2+2=fish
The whole thing is wrongheaded in the first place; any child wanting to access adult-only content will use an adult’s account to do so; any adult attempting to access adult-only content is likewise going to use an adult’s account.
So unless they’re tying this to biometrics that are actually secure against an adverserial child, all the system really does is creates a registry of adults. And we already have those.
- 22 hours
Wasn’t there something about the effectiveness of the Australian law to restrict minors on social media? Ah…
Four in five under-16s in Australia using social media despite ban, study shows
Experts say law not enough to stop children accessing harmful content online and more ‘convincing strategy is required’ . More than 80% of under-16s in Australia said they were still using social media three months after legislation banning them from it came into force, research shows.
- 21 hours
It’s like any controlled substance ban — unless there’s a really invasive crack-down it just shifts the problem to a less safe black market.
Making things easy and safe to access with controls that are adjustable is always more effective than an outright ban that shifts the access fully into unregulated territory.
Jul@piefed.blahaj.zoneEnglish
1 dayCreating a registry of adults and what content they access is exactly the point of these laws. Always has been. “Protecting children” is just the easiest excuse to make it seem more urgent to violate people’s rights. Just like removing trans healthcare started with children and is now targeting adults.
Thing is, it doesn’t create a registry of what content adults access. Just what content their registered identity accesses.
- 3 hours
Which they, as the governments, can choose to legally treat as the same thing. “You are guilty of whatever someone does with your account” is not a new concept, it’s just one that most places have chosen to reject. It can always be overridden, such as for the Palestine Exception.
Jul@piefed.blahaj.zoneEnglish
1 dayBut in most cases, it is, because most adults are not that technically inclined to get around the logins. Sure there are some tech savvy ones who will bypass it. And maybe a few kids who will use their parents’ accounts rather than just bypassing the logins but it’s still the family accessing the information, but for the majority, it does work as a registry. And though it’s only on a few categories of sites now, the categories inevitably will expand. It’s not just porn, but info on reproductive and gender healthcare, LGBTQ+ dating, and many other subjects that “children must me protected from”, but really they want to know who’s gay, looking for abortions or transgender healthcare or information about whatever other rights their government is trying to force them to give up.
Yes. And perhaps, given time, accessing the wrong version of certain sensitive historic events could even be tracked that way.
Iirc a portrait photo is a part of the mandatory dataset for the EUDI now
- 1 day
Please explain… If I’m below the age of… Whatever they decide, what will or will not be accessible to me? Like, if I’m below a certain age, will some EU appointed DNS restrict what domains I can reach? Or, since this article is about hardware-bound attestation, are my devices going to prevent me from installing and using certain apps if I’m below the age? I don’t understand where the restrictions are going to lie…
Bonus: can’t I just buy, say, five phones right now, root them or install custom OSs before shit hits the fan and be happy?
-
The real explanation is that they want control. The children are a excuse.
-
No because you can go to jail for that, like the dude with his GrapheneOS in the US. They’re probably working on that next.
- Fluffy Kitty Cat@slrpnk.netEnglish15 hours
The fact that children can be deprived of rights with only the vaguest unproven assertion of “safety” is a critical threat to the rights of everyone
- 14 hours
No because you can go to jail for that, like the dude with his GrapheneOS in the US. They’re probably working on that next.
no… you can not go to jail, in the EU or the US at least, for having a phone with a custom OS. They are facing charge for using a duress code which wiped their phone. It is very different.
- 3 hours
He had a duress password, and told it to a border agent (who had no warrant, but that is no longer legally required for border checks), which then wiped his phone.
He was targeted for being part of the Stop Cop City protest movement (and they were likely looking for contacts), and now the feds are claiming that because he could have had anything, he should be allowed to be charged with possession of whatever they can think of (I.e. they already tried to claim in a press conference that he may have had CSAM, because they couldn’t search it to prove he didn’t).
- 22 hours
Sorry, what is the story about guy in USA with GrapheneOS?
Someone else linked the story, but do note that he isn’t in jail. Or wasn’t last I looked a week ago. He IS facing criminal charges, which is very serious. It will most likely become a Big Important Case and could even get appealed up and up until it reaches SCOTUS.
Current SCOTUS is corrupt. But sometimes they have managed to make good rulings anyway, such as in Carpenter v. United States, and Chatrie v. United States, about GPS location privacy.
I say this b/c social media leads ppl to believe extreme versions of events. There were allegations in another lemmy thread that this GrapheneOS Guy was in prison. He is not. He was at his own home. But he is facing a very stressful future as a criminal defendant. He may, hopefully, be exonerated. But it remains to be seen, how it will go. Anything could happen.
TL;DR he used a “distress code” or something like that to wipe his local device.
- D06M4@lemmy.zipEnglish24 hours
Duress. And yeah, as OP mentioned kids are an excuse to have an easier time defaming anyone pushing against it. “You wouldn’t steal a car” vibes. Suddenly everyone is a CSAM producer or thief unless proven otherwise, and I doubt there will ever come a time when an authoritarian figure has interest to prove someone they’re pursuing is innocent.
But I must say you can install whatever OS you want. The reason they placed federal charges against that guy was because he allegedly deleted incriminatory evidence. They told him they were searching for child pornography, something that was completely made up as they had been tracking him because of his links with activists that were trying to protect a forest. He gave the wrong code (and could say he did so by mistake) and whoever had the misfortune of taking the phone from him wiped the phone’s data when entering it.
- 7 hours
The reason they placed federal charges against that guy was because he allegedly deleted incriminatory evidence.
NAL, but it may be important that there was no legal case pending at the time he gave the duress code. And like you said, he didn’t even enter the code himself. But it’s tricky since there’s also some clause in the law about reasonable cause to believe there could soon be a case.
In the end, the case is purely politically motivated, and the allegations were made up out of nothing. Hopefully that makes the case fall apart once it reaches the courts. Which has happened in lots of other cases, like Reflecting Pool Olympian Guy. I hope the EFF will get some high powered legal rep spun up for this guy. Protip, donating to the EFF is good, so they can afford to do that for important civil rights cases.
I’m still NAL, but I’m hopeful that Graphene Guy will be exonerated by a jury. Ofc, it still sucks, b/c he has to spend his time and money dealing with this.
-
First of all,
I don’t understand where the restrictions are going to lie
Yes. That’s exactly the question.
The point of the… excitement around this is exactly the uncertainty. We simply don’t know what the EU or national governments of the EU will do with this.
The first problem is that the “hardware bound attestation” isn’t just hardware bound, it’s specifically Apple and Android’s attestation and NOT the more open standard. That means the device that can do this thing, whatever it’s going to be “necessary” for, MUST always be an Apple or Google device, with that bit intact. Tbh, I don’t really know how much rooting affects this, but I would be surprised if it didn’t.
The second problem is that once the infrastructure for blocking access to something and requiring this sort of authentication is in place, it’s just a list of targets. It’s very easy to add another platform, website, app or anything else behind it.
And the reason for this excitement happening now is that the specification that was given for all this to happen previously only said it should be “secure” somehow, but not detailing the “how”. They think they can do it as an implementation detail and pretend it’s not a big deal. So it’s very clearly something those bastards have tried to be sneaky about.
Can you use rooted phones
No, whatever the point of their efforts is, they will make sure to not leave obvious loopholes like that open.
- 1 day
The services themselves will probably be made to ask for verification and your devices will answer through the age verification app. Since custom mobile OSs (or desktop Linux) won’t provide hardware attestation, the app won’t work on them and the websites will treat you as underage. The types of services that require age verification aren’t specific, they can change based on EU decisions so eventually people not using “approved” OSs may be locked out of most of the internet.
- ParlimentOfDoom@piefed.zipEnglish10 hours
Oh neat, they broke the Internet, since everything is hosted on Linux…
This wouldn’t impact the backend of these services, the age checking stuff would run on the client, thus only breaking Linux (barring android) clients.
- 22 hours
so eventually people not using “approved” OSs may be locked out of most of the internet
Agree 100%. I hope everyone realizes this! I have seen too many ppl who think, “It’s OK, open source will save us”. But open source can’t. This is a legal and social prob, and needs a legal and social solution.
- 24 hours
And you can be damn sure this will infest necessary government services and apps that won’t allow you to contact the government in any other way.
- 8 hours
They won’t enforce it on you. They enforce it on the manufactures
So you’ll just have to pay more for an imported laptop that doesn’t have this
- 3 hours
You simply outlaw imports of noncompliant hardware. So you’re limited to smugglers. When general computing is outlawed, only outlaws will have general computers.
- 20 hours
even if you are forced to use their stuff for banking, state services and increasingly more?
at best we are looking at having private devices separate from corporate ones. we’d need both devices and services that are ours.














