Incomplete and non-public security audit won't "increase transparency and trust in the age verification blueprint" #52
Replies: 5 comments 3 replies
|
Don't worry. 90% of voices will stop when they will create a European Big Brother. Think Apple, but an European company decides what apps you can have — that is just as bad. In reality, there should always be the option not to have a Big Brother. |
|
The spec intentionally focuses on RP-RP collusion and not AP-RP collusion, and chooses algorithms that do not guarantee any real ZK. Because it was designed specifically so the AP (EU Offiziers) can deanonymize everyone and see everything they do. That is the only long term purpose of this spec and repo. |
|
The proposal also appears to rely too heavily on trust assumptions that are not applicable to real-world security engineering. For example, the specification repeatedly assumes that a user-controlled device can reliably enforce policy decisions and report verification results accurately to the relevant parties. From a security perspective, this is a fundamental weakness. A client device is always part of an environment controlled by an attacker. Rooting, instrumentation, modified operating systems, replay tooling, API interception and alternative clients are standard features of the modern internet. This is important because the proposal is essentially attempting to implement geographically restricted access control on globally accessible networks. In practice, users outside the intended jurisdiction can easily bypass such controls using VPNs, remote browsers, tunnelling or delegated access. We have already seen this pattern repeatedly with national age-gating and social media restrictions. The result is an architectural mismatch:
The proposal also introduces a significant centralisation of trust. The specification explicitly defines centrally maintained trusted lists for attestation providers and verification infrastructure. While this is understandable from an interoperability perspective, such systems become extremely attractive targets for attackers, hostile states, organised cybercrime and commercial surveillance actors. Even if the cryptographic design is sound, centralised trust and verification ecosystems tend to accumulate scope over time. Infrastructure initially introduced for 'age verification only' can later be expanded legislatively into broader identity-gated access systems without requiring a major technical redesign. This risk is particularly important because the architecture already establishes the following:
These are precisely the technical primitives required for broader access control and identity enforcement systems. A more realistic threat model should therefore explicitly acknowledge the following:
Failing to address these issues directly means the proposal risks prioritising theoretical compliance over deployable and resilient security. |
|
Thank you for your interest in the project. GitHub issues are intended for technical issues related to the specifications or the open source code of the EU AV solution. I am converting this into a discussion to allow for a broader exchange of views on the topic. Please also note that the thread model will be published in addition to the source code audit results. |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Further:
If you want to hear my personal advice (well, i obviously know the answer but still): Spare yourself the effort. Just close any kind of skeptical issue and continue to ignore inconvenient questions (you already made a good start by not letting anyone comment on your supposed "transparency and trust increase" - at least it is honest as to how welcome/relevant comments really are).
This whole thing will get rolled out no matter how broken, risky or badly coded it is. I and many others have seen the type of "care" applied to the code (personally i wouldn't leave function returns unchecked since the "later" regularly never comes but then i am just a random guy and not tasked with building your-life-in-a-box for millions and millions of people) just as i and many others have seen the childish meme-filled (if Dwight Schrute says that "No one will know" then it obviously must be true - it is nice to know how the whole endeavor is taken very seriously) presentation taunting how we will soon prove our income (as in it obviously has some kind of access to everyone's bank statements, tax data, employment contracts and/or other financial data) and rent cars using this app while it is "made for the (developer) audience".
People either don't and won't have much of an opinion or their minds are already made up. There is nothing to be won here by making some kind of "token effort". Like i have said in one of the closed issues i am left with nothing but shaking my head at the people who sold their souls to build this. As sad as it is i don't think there is any kind of turning back or fixing things up at this point. This is your mess. Enjoy.
All reactions