All this ostensibly to keep teenage boys from watching Pornhub (when parental controls already exist).
The real reason, of course, is to force people to connect strong real-life identifiers to online activity. Mobile first, then Windows. Then Linux is too weak to oppose on its own, and will adapt or die.
That's a completely unhelpful, overly simplistic straw man argument.
We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos. What we have now is essentially unrestricted access to pretty much anything and a fair assessment is that there is societal harm from that. We're creating gambling addicts (which is arguably the most harmful form of addiction), allowing predators to interact with children,, manipulating children through advertising and algorithms, flaming harmful behaviors like eating disorders, allowing mass cyberbullying and so on.
So saying "we should allow unfettered access to the internet" or even "it's the parents' responsibility" is naive, dismissive and has failed. The only question from here is what to d we do about it. You can say "nothing" but that's a losing argument.
I personally believe that the easiest thign to attack is advertising to minors. This will take away the financial incentive for these platforms to create addictive behaivors in minors. And most of these tech platforms have already built the infrastructure to do this. You don't allow advertisers to target an audience based on (actual or inferred) ages under 18. You extend that to proxies for age, like an interest in Minecraft. And you make advertising to children illegal.
Arguably, I'd go further and restrict certain features for minors, such as comments on Youtube and an algorithmic feed.
At the moment nobody is solving anything because it's simply a fight to move liability to someone else. Meta wants hardware vendors to be responsible because, guess what?, they have no hardware platform. Apple and Google likely want app to have to deal with it for the complete opposite reason.
I believe we should shift that liability to advertising.
What you're saying is correct - but it's used to push a much more comprehensive lockdown of devices that has absolutely nothing to do with protection of minors.
It's as if we first let businesses install slot machines at every street corner, then suddenly go "I'm shocked, shocked! that we have a massive epidemic of gambling addiction here, we have to mandate anti-gambling shock collars for everyone to tackle this urgent problem! There is no alternative!"
I don't understand where the all the EU anti-trust and anti-corruption regulators are here. _Governments_ enforcing that you have a Google or Apple account to participate in society is transparently absurd.
This isn't only a digital sovereignty issue, it's also an anti-competition issue.
The reality of the matter is that it is virtually impossible for Europe to even begin to displace Apple or Google devices, and especially not operating systems and all the ecosystem that goes along with it.
The EU politicians are just publicly paying lip-service to "digital sovereignty" while they quietly hope this all just blows over when Trump is gone in 2 years.
> it is virtually impossible for Europe to even begin to displace Apple or Google devices
It's hard for sure but they are not even trying, the non-duopoly alternatives are run by hobbyists in their free time and just get shit on by EU bureaucrats
> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.
That's a weird way of putting it. You'll basically need a second non-Linux device if you want to use Linux.
If your reason for using Linux is "I want to continue using old hardware instead of quickly-obsoleted devices", then you're shit outta luck: you'll have to buy a (potentially second) device from one of those vendors who'll use the profits to further lobby against your rights.
And it's not just desktop _linux_ that's not allowed, but any desktop operating system, since this only works with "smartphones" not general-purpose computers.
(and of course even if they were to support computers, an age/id verification system either won't work at all or only work to be abused by those in power)
We need to remember how to operate without the Internet, and de-risk our dependence on it. Whether that's reducing the use of computers in our daily lives, or getting more open-source-software-runs-offline-on-my-machine.
We did it before. We forgot at the time when things were more-or-less free.
(I don't know how we do this. I'm as dependent as ever.)
note that hardware attestation does not utilize ZKP or blind signatures. so your hardware ID is technically exposed.
usually to make use of the exposure multi-party collusion is required. Google or Apple attestation intermediaries (they convert your static certificate into an ephemeral one) would need to be logging information and when combined with information from the party you attested to (done with the ephemeral certificate) they will have your unique device identifier (the unchangeable certificate burned into the silicon).
it's doubly insidious because nothing is preventing the manufacturer from recording the certificate identifier and connecting it to an order ID for the device. so not only can they tie together multiple accounts, they could tie it to the identity that purchased the device.
on mobile devices you can't even restrict this functionality as it's exposed via API (remote attestation and also DRM license request handshake initiation). not even grapheneos gives you to option to disable it.
also, the implication of the above is that there is no private way to have a google account on an android phone. they will know it's you or the previous owner of the device who sold it to you (makes VPN irrelevant).
> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.
Considering a significant part of the internet will be behind age verification gates, how are they imagining this to work? I should pull out my iPhone or Google Android phone and get its approval every time I want to visit a website?
> a maintainer confirmed that hardware-bound attestation is a mandatory architectural requirement
Hardware-bound is not a problem, limiting that to only iPhones and some Android phones is. Plenty of hardware can keep a key safe and it doesn't need Apple's or Google's blessing.
I expect a gray/black market in TPM keys and the like will grow if this takes off, but hopefully the citizens will fight it very strongly before then...
By an incredible coincidence, the (ex- ?) employee of a company known to lobby hard in the EU (Microsoft) and who's the author of a rube-goldberg kitchen sink many of you on HN loves so much (systemd), is now working on a system that's been described here as "an attack on general purpose computing". Attestations / Trusted Platform Module (TPM) / etc. are all in there:
How much do you love your systemd and the individual behind it now?
Can't wait to use your "amutable" Linux with hardware-bound attestation verifying your age now can you?
These people (the politicians behind such decisions, the people working on such platforms, those saying it's a good thing, ...) are enemies of freedom.
It's very commonly the anti-EU politicians who inevitably get into EU parliament (due to representative voting, ironically more democratic than the FPTP system we use in the UK, despite all the wailing about democracy) who endorse such obviously stupid ideas, as a way to undermine the credibility of the EU.
What's frustrating is that it works really well, and occasionally they get something truly stupid through- which goes a long way to whipping up anti-EU sentiment, but then they're forcing their countries to actually do the stupid thing... Nobody seems to call out this self-sabotage.
No head of government is going to come out against what the government itself is doing, they have to defend every initiative, which is why they seem pretty ungenuine all the goddamn always.
I used to track the voting history of UKIP members, the site "VoteWatch Europe" used to make this easy, but it shut down in 2022.
UKIP were constantly voting for things to be discussed (when they bothered to vote at all), and then when they were discussed they would thump chest in the media about how the EU was talking about doing the thing they had voted to discuss (with the verbiage to suggest the EU would definitely do it, against the will of the British- forgetting entirely that we had a veto anyway...).
If it stick to its current trajectory it will implode in 10-20 years. France’s debt crisis will trigger Euro collapse and Germans would ditch Euro to not foot the bill for the French and the rest of the dominos would fall
All this ostensibly to keep teenage boys from watching Pornhub (when parental controls already exist).
The real reason, of course, is to force people to connect strong real-life identifiers to online activity. Mobile first, then Windows. Then Linux is too weak to oppose on its own, and will adapt or die.
That's a completely unhelpful, overly simplistic straw man argument.
We restrict certain activities and places in the real world from certain people all the time. For example, not allowing people under 18 or 21 (depending on your country) into casinos. What we have now is essentially unrestricted access to pretty much anything and a fair assessment is that there is societal harm from that. We're creating gambling addicts (which is arguably the most harmful form of addiction), allowing predators to interact with children,, manipulating children through advertising and algorithms, flaming harmful behaviors like eating disorders, allowing mass cyberbullying and so on.
So saying "we should allow unfettered access to the internet" or even "it's the parents' responsibility" is naive, dismissive and has failed. The only question from here is what to d we do about it. You can say "nothing" but that's a losing argument.
I personally believe that the easiest thign to attack is advertising to minors. This will take away the financial incentive for these platforms to create addictive behaivors in minors. And most of these tech platforms have already built the infrastructure to do this. You don't allow advertisers to target an audience based on (actual or inferred) ages under 18. You extend that to proxies for age, like an interest in Minecraft. And you make advertising to children illegal.
Arguably, I'd go further and restrict certain features for minors, such as comments on Youtube and an algorithmic feed.
At the moment nobody is solving anything because it's simply a fight to move liability to someone else. Meta wants hardware vendors to be responsible because, guess what?, they have no hardware platform. Apple and Google likely want app to have to deal with it for the complete opposite reason.
I believe we should shift that liability to advertising.
What you're saying is correct - but it's used to push a much more comprehensive lockdown of devices that has absolutely nothing to do with protection of minors.
It's as if we first let businesses install slot machines at every street corner, then suddenly go "I'm shocked, shocked! that we have a massive epidemic of gambling addiction here, we have to mandate anti-gambling shock collars for everyone to tackle this urgent problem! There is no alternative!"
Here comes the European freedom and free speech. With Chat Control it’s even more hilarious. Compliance list, another European Commission, as always.
I don't understand where the all the EU anti-trust and anti-corruption regulators are here. _Governments_ enforcing that you have a Google or Apple account to participate in society is transparently absurd.
This isn't only a digital sovereignty issue, it's also an anti-competition issue.
The reality of the matter is that it is virtually impossible for Europe to even begin to displace Apple or Google devices, and especially not operating systems and all the ecosystem that goes along with it.
The EU politicians are just publicly paying lip-service to "digital sovereignty" while they quietly hope this all just blows over when Trump is gone in 2 years.
> it is virtually impossible for Europe to even begin to displace Apple or Google devices
It's hard for sure but they are not even trying, the non-duopoly alternatives are run by hobbyists in their free time and just get shit on by EU bureaucrats
The EU way is to think these things are “free” and then act surprised by the inevitable consequences five years later when it is irreversible.
Our AI gods cannot save us soon enough.
What are the "AI gods" going to do in this scenario?
AI is about many things, but a big factor is enclosure.
> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.
That's a weird way of putting it. You'll basically need a second non-Linux device if you want to use Linux.
If your reason for using Linux is "I want to continue using old hardware instead of quickly-obsoleted devices", then you're shit outta luck: you'll have to buy a (potentially second) device from one of those vendors who'll use the profits to further lobby against your rights.
And it's not just desktop _linux_ that's not allowed, but any desktop operating system, since this only works with "smartphones" not general-purpose computers.
(and of course even if they were to support computers, an age/id verification system either won't work at all or only work to be abused by those in power)
We need to remember how to operate without the Internet, and de-risk our dependence on it. Whether that's reducing the use of computers in our daily lives, or getting more open-source-software-runs-offline-on-my-machine.
We did it before. We forgot at the time when things were more-or-less free.
(I don't know how we do this. I'm as dependent as ever.)
So much for the EU's mission to reduce e-waste.
note that hardware attestation does not utilize ZKP or blind signatures. so your hardware ID is technically exposed.
usually to make use of the exposure multi-party collusion is required. Google or Apple attestation intermediaries (they convert your static certificate into an ephemeral one) would need to be logging information and when combined with information from the party you attested to (done with the ephemeral certificate) they will have your unique device identifier (the unchangeable certificate burned into the silicon).
it's doubly insidious because nothing is preventing the manufacturer from recording the certificate identifier and connecting it to an order ID for the device. so not only can they tie together multiple accounts, they could tie it to the identity that purchased the device.
on mobile devices you can't even restrict this functionality as it's exposed via API (remote attestation and also DRM license request handshake initiation). not even grapheneos gives you to option to disable it.
also, the implication of the above is that there is no private way to have a google account on an android phone. they will know it's you or the previous owner of the device who sold it to you (makes VPN irrelevant).
> Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.
Considering a significant part of the internet will be behind age verification gates, how are they imagining this to work? I should pull out my iPhone or Google Android phone and get its approval every time I want to visit a website?
> a maintainer confirmed that hardware-bound attestation is a mandatory architectural requirement
Hardware-bound is not a problem, limiting that to only iPhones and some Android phones is. Plenty of hardware can keep a key safe and it doesn't need Apple's or Google's blessing.
Related:
European "age verification" "app" forcing everyone to use Android or iOS
https://news.ycombinator.com/item?id=48903777
Stop Killing the Internet: No Digital ID and No Age Verification
https://news.ycombinator.com/item?id=49084938
I expect a gray/black market in TPM keys and the like will grow if this takes off, but hopefully the citizens will fight it very strongly before then...
...but then again, this is the EU, not the US.
By an incredible coincidence, the (ex- ?) employee of a company known to lobby hard in the EU (Microsoft) and who's the author of a rube-goldberg kitchen sink many of you on HN loves so much (systemd), is now working on a system that's been described here as "an attack on general purpose computing". Attestations / Trusted Platform Module (TPM) / etc. are all in there:
https://news.ycombinator.com/item?id=46784572
How much do you love your systemd and the individual behind it now?
Can't wait to use your "amutable" Linux with hardware-bound attestation verifying your age now can you?
These people (the politicians behind such decisions, the people working on such platforms, those saying it's a good thing, ...) are enemies of freedom.
We need another French revolution that gets rid of this corrupt EU regime for good.
It's very commonly the anti-EU politicians who inevitably get into EU parliament (due to representative voting, ironically more democratic than the FPTP system we use in the UK, despite all the wailing about democracy) who endorse such obviously stupid ideas, as a way to undermine the credibility of the EU.
What's frustrating is that it works really well, and occasionally they get something truly stupid through- which goes a long way to whipping up anti-EU sentiment, but then they're forcing their countries to actually do the stupid thing... Nobody seems to call out this self-sabotage.
I suppose you have a lot of data backing this claim?
The head of the EU, Ursula von der Leyen, isn't known to be anti-EU.
No head of government is going to come out against what the government itself is doing, they have to defend every initiative, which is why they seem pretty ungenuine all the goddamn always.
I used to track the voting history of UKIP members, the site "VoteWatch Europe" used to make this easy, but it shut down in 2022.
UKIP were constantly voting for things to be discussed (when they bothered to vote at all), and then when they were discussed they would thump chest in the media about how the EU was talking about doing the thing they had voted to discuss (with the verbiage to suggest the EU would definitely do it, against the will of the British- forgetting entirely that we had a veto anyway...).
If it stick to its current trajectory it will implode in 10-20 years. France’s debt crisis will trigger Euro collapse and Germans would ditch Euro to not foot the bill for the French and the rest of the dominos would fall