Settings

Theme

EU Age Verification Hacked in 2 Minutes: What Happened

pasqualepillitteri.it

19 points by bigbugbag a month ago · 16 comments

Reader

kelseyfrog a month ago

For the same reason, I don't use sudo. Despite being patched, the presence of prior vulnerabilities [1] and hacks makes it fundamentally not trustworthy.

1. https://app.opencve.io/cve/?vendor=sudo_project

  • free_bip a month ago

    What software are you willing to use then, considering your criteria would eliminate over 90% of OSS projects?

  • raxxorraxor a month ago

    The difference is that sudo is useful. The EU age verification app however...

  • throwawayk7h a month ago

    so do you just use su?

    • raxxorraxor a month ago

      Just run everything as root to circumvent security problems.

      Seriously, it is as if there would be a CVE because sudo allows privilege escalation.

      Of course such widely spread tools should be audited and have eyes on them. On the other hand many people are tired of security strategies because half of the time it is about a platform doing it for market domination. Our thoroughly shitty mobile OS come to mind. This age verification crap isn't too different, just slightly different goals where real security isn't really considered too much.

    • kelseyfrog a month ago

      No. Su also has a history[1] of vulnerabilities.

      1. https://app.opencve.io/cve/CVE-2025-71263

bigbugbagOP a month ago

How Paul Moore broke the EU age verification app in 2 minutes, the 8 confirmed vulnerabilities and the emergency patch 24 hours later. Full analysis.

GuB-42 a month ago

It is a good exercise, but in practice, what's the big deal?

Even if the app is bulletproof, age verification will get bypassed. Account sharing, file sharing, darknets, etc... It mostly prevents kids from stumbling upon content that isn't meant for them, but it won't resist deliberate attacks for long, especially if the parents are complacent. And for that, the EU Age Verification app looks fine, especially now what the easy bugs are fixed.

  • bigbugbagOP a month ago

    one has to understand that the point is not to protect kids, it never is, but to control online activities. also this is not an organic law, this is the result of intense lobbying by transnational corporations such as facebook, pushing hard for this and there are reports from inside the parliament that this is rushed to be release ASAP despite not being ready or properly tested.

    • GuB-42 a month ago

      Except that this kind of age verification is not what "transnational corporations such as Facebook" is pushing for. In fact such a system is probably the worst for them: they can't use the token for tracking, and it can make it harder for them to target children because it is likely to come with further restrictions.

      What the tech giants want is OS level attestation. They want to control what you can install on your device, to me the thing to avoid at all costs. This is not it, this is an open source app that you can run anywhere.

      The proposed solution is the closest you can get to one that is designed to protect kids more than to control online activities. The weakness of the system, where a determined kid can get through is a feature, not a bug! More than that and it becomes more about control and less about kids (who will get through no matter what).

      I am not commenting on how necessary age verification is. Personally, I am all for a wide open internet but many people actually want to "protect the children". The argument wouldn't be used as a justification for surveillance laws if they didn't.

  • raxxorraxor a month ago

    I would like my kids to be safe and that means no shitty gatekeeper app where they have to identify themselves. If a platform requires it, kid won't get access. Perhaps that is the real benefit here.

Woodi a month ago

Excuse me but why there are no parents in the loop ? They are first line of kids defence and best suited for that: truly biological need. Not to mention such secondary thing like law obligations. No technical system can bit that. Only make things half baked and stupid or abusive on privacy, logic and actual reality.

Kids are parents kids not some context-less socialist/bureaucracy/german invasive ideology creatures.

If you want to do inventory checking for all that future migrants generations do it like you do with actual humans and not via some outdated and hackable inferior piece of hardware.

  • subscribed a month ago

    Because this is the control / surveillance grab, not the genuine child protection.

    Notice how the latest mandatory age verification in iPhones in the UK has been introduced: not as a possible, easy switch one, but the default on, requiring adults to potentially deanonymise themselves. I repear: it's not something the parent could enable/lock in within a 10 seconds, it's something enabled with every adult's phone, something the kid will evade in the same way they buy tobacco or alcohol right now.

    That was never about the kids. Otherwise the governments wouldn't tolerate Meta openly admitting they've been knowingly hooking up kids, knowingly worsening their mental health, or Musk's X keeping CSAM generator open while all the world's governments just grimaced and kept legitimizing it.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection