EU Age Verification Mandates Hardware Attestation, Raising Open-Source Concerns

jedisct1 · x · 2026-08-03

The European Union’s open-source age verification project has sparked controversy after a maintainer confirmed that hardware-bound attestation is a mandatory architectural requirement, not an optional detail.

The solution allows users to prove they are over a certain age without revealing their name or exact birth date. However, to prevent credentials from being cloned or reused by modified clients, the system relies on keys stored in protected hardware like Android TEE, StrongBox, or Apple’s Secure Enclave.

Critics argue that this approach makes the system dependent on a small number of approved devices, operating systems, and attestation providers. This could effectively lock out Linux users, custom Android ROMs, and independently compiled open-source apps. The project team stated that a dedicated security review and threat model would be published soon and invited alternative architectural proposals.

Original post →

More from Safety

Safety channel →