Live data from Hacker News

Brussels launched an age checking app. Hackers took 2 minutes to break it

politico.eu

41–50 of 221 posts

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#41
post #11

Earlier quoted context omitted.

Just like anyone can take anyone's credit card and go shopping - but in contrast Phones are (or at least can be) much more secure.

That's not what you're competing with. Your competing with a drivers license with a photo (not a great photo) and some countries have pretty easily faked drivers licenses, but others have drivers licenses in hard plastic with holographic features. The credit card doesn't work as age verification.

We're talking about the EU here, where the standard form of ID is an ID card with very strict requirements, including multiple secure features and an NFC chip with the photo and some other information.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#42

Note that this is an implementation of eIDAS: https://www.eudi-wallet.eu/ The point of this is that you can use the credentials on your phone to prove that you are an adult to a website using zero-knowledge proofs to avoid disclosing your identity to anybody. If somebody who has access to your unlocked phone can access the data in the app, then this is something that should be tightened up but it’s a substantial priv…

> The point of this is that you can use the credentials on your phone to prove that you are an adult to a website using zero-knowledge proofs to avoid disclosing your identity to anybody. No it isn't. Literally that is not the scope document, and such a solution would not be permitted by the EU as compliant with the legislation. The app isn't zero knowledge. A prototype workflow has been designed for a one way transf…

Zero knowledge proofs are when the prover can prove the statement is true to the verifier without disclosing more information beyond the statement. It doesn’t mean the prover cannot talk to other systems to produce the statement.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#43
post #8

Earlier quoted context omitted.

Because people share phones with their kids. It's not rare or even mildly unusual. The problem isn't that the app needs to solve this. The problem is the app is useless, along with this whole bizarre "need for age verification" plot that poofed out of existence simultaneously around the whole globe mysteriously a few months ago.

Exactly. "Age verification" is the "think of the children" marketing campaign for "identity verification". Governments don't like anonymity; it makes it harder to find those they consider enemies. But it's hard to market something people don't want and get no benefit from. So, you dress it up in fear and make it easy to villify people who argue against it.

Stop with the scaremongering.

This is a reference app implementation that uses a detailed framework which explicitly has as a core tenet double blindness. The place you prove your age to has no idea about anything other than you being of age, and the thing you use to prove your age has no idea about where you're using that proof.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#44
post #23

Earlier quoted context omitted.

Whats the diff between today giving you phone to your 8-year and making sure /having trust that they do not use it to e.g. order a new toy from Amazon and tomorrow that he is not using to verify they are an adult? I mean, most things today (like accessing porn, buying alcohol) do not require any extra age verification. They can just do it using your phone/accounts.

Not everyone views their child as an enemy that just happens to be in close quarters with them. Most people trust their kids to generally not do bad things. People keep knives in their kitchen and kids, explain the danger, and kids are generally responsible enough to not play with them. If this is a concept that you can't grasp, then words will never convey it. It's simply a detachment from reality to think people ar…

> Most people trust their kids to generally not do bad things.

Okay, so trust them not to access age-gated sites using your credentials then.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#45
post #33

Earlier quoted context omitted.

You make it sound like having a phone in public is basically "open carry" which is absolute nonsense. What do you have on your phone that's dangerous? Phones aren't safety device, and they shouldn't be turned into one.

You make it sound like you put no effort in understanding my comment and just followed up with whatever supported your view. If you have anything on your phone that should be off limits to your child but make no effort to ensure that (give them the phone, no passwords, no supervision) because it’s too inconvenient you are failing the child. Can I put it in simpler words? > What do you have on your phone that's danger…

I don't like the idea of a central authority determining what "my child should be kept away from" and then implementing Orwellian surveillance laws to enforce it. "For the sake of the children".

Seeing something scary, disturbing, or sexual on the internet as a child does not result in a maladjusted adult. These laws are about one thing and one thing only - furthering the global surveillance network.

Everything else is a smokescreen. Pretending that a phone or any Internet-connected terminal is something that should be kept secured and away from children is a parenting decision, not a policy one, and any attempt to justify it as a policy decision is toxic nonsense at best and astroturfing for the surveillance state at worst.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#46
post #35
post #32

Earlier quoted context omitted.

> The point of this is that you can use the credentials on your phone to prove that you are an adult to a website using zero-knowledge proofs to avoid disclosing your identity to anybody. That's the theory. How is it in practice? In my opinion, it just means there is a single government database to hack to get copies of all IDs... By the way have the "security experts" checking this app evaluated that part? Or they'r…

> In my opinion, it just means there is a single government database to hack to get copies of all IDs... That doesn't make sense, all IDs are already in a single government database. Kind of by definition in fact, for IDs to be useful they need to be emitted by a central authority with associated security and revokability guarantees. The implementations I've seen rely on an app reading your physical ID and its NFC ch…

> That doesn't make sense, all IDs are already in a single government database. Kind of by definition in fact, for IDs to be useful they need to be emitted by a central authority with associated security and revokability guarantees.

Yes and those databases are decently protected. However for an "app" someone will do a web 4.0 or 6.0 bridge to access these databases. Maybe even vibe code it. That's what I'm worried about.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#47

Earlier quoted context omitted.

Not everyone views their child as an enemy that just happens to be in close quarters with them. Most people trust their kids to generally not do bad things. People keep knives in their kitchen and kids, explain the danger, and kids are generally responsible enough to not play with them. If this is a concept that you can't grasp, then words will never convey it. It's simply a detachment from reality to think people ar…

> Most people trust their kids to generally not do bad things. Okay, so trust them not to access age-gated sites using your credentials then.

Then just get rid of the age gating and verification entirely because it's useless.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#48
post #43

Earlier quoted context omitted.

Exactly. "Age verification" is the "think of the children" marketing campaign for "identity verification". Governments don't like anonymity; it makes it harder to find those they consider enemies. But it's hard to market something people don't want and get no benefit from. So, you dress it up in fear and make it easy to villify people who argue against it.

Stop with the scaremongering. This is a reference app implementation that uses a detailed framework which explicitly has as a core tenet double blindness. The place you prove your age to has no idea about anything other than you being of age, and the thing you use to prove your age has no idea about where you're using that proof.

If you trust mega corps and the government when they say they're not accessing and monitoring your personal info, then I think that's very interesting.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#49
post #46
post #35

Earlier quoted context omitted.

> In my opinion, it just means there is a single government database to hack to get copies of all IDs... That doesn't make sense, all IDs are already in a single government database. Kind of by definition in fact, for IDs to be useful they need to be emitted by a central authority with associated security and revokability guarantees. The implementations I've seen rely on an app reading your physical ID and its NFC ch…

> That doesn't make sense, all IDs are already in a single government database. Kind of by definition in fact, for IDs to be useful they need to be emitted by a central authority with associated security and revokability guarantees. Yes and those databases are decently protected. However for an "app" someone will do a web 4.0 or 6.0 bridge to access these databases. Maybe even vibe code it. That's what I'm worried ab…

Hence the second paragraph in my comment. The app is client side and reads the physical ID.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#50
post #33

Earlier quoted context omitted.

You make it sound like having a phone in public is basically "open carry" which is absolute nonsense. What do you have on your phone that's dangerous? Phones aren't safety device, and they shouldn't be turned into one.

You make it sound like you put no effort in understanding my comment and just followed up with whatever supported your view. If you have anything on your phone that should be off limits to your child but make no effort to ensure that (give them the phone, no passwords, no supervision) because it’s too inconvenient you are failing the child. Can I put it in simpler words? > What do you have on your phone that's danger…

[deleted]
Post reply on HN