Earlier quoted context omitted.
so do you just use su?
No. Su also has a history[1] of vulnerabilities. 1. https://app.opencve.io/cve/CVE-2025-71263
EU Age Verification Hacked in 2 Minutes: What Happened
11–17 of 17 posts
Re: EU Age Verification Hacked in 2 Minutes: What Happened
#12Earlier quoted context omitted.
one has to understand that the point is not to protect kids, it never is, but to control online activities. also this is not an organic law, this is the result of intense lobbying by transnational corporations such as facebook, pushing hard for this and there are reports from inside the parliament that this is rushed to be release ASAP despite not being ready or properly tested.
Except that this kind of age verification is not what "transnational corporations such as Facebook" is pushing for. In fact such a system is probably the worst for them: they can't use the token for tracking, and it can make it harder for them to target children because it is likely to come with further restrictions. What the tech giants want is OS level attestation. They want to control what you can install on your…
Start here: https://news.ycombinator.com/item?id=47361235
And here's from the larger organisation, from another angle: https://techoversight.org/2025/07/29/bloomberg-meta-google-l...
Re: EU Age Verification Hacked in 2 Minutes: What Happened
#13Excuse me but why there are no parents in the loop ? They are first line of kids defence and best suited for that: truly biological need. Not to mention such secondary thing like law obligations. No technical system can bit that. Only make things half baked and stupid or abusive on privacy, logic and actual reality. Kids are parents kids not some context-less socialist/bureaucracy/german invasive ideology creatures.…
Notice how the latest mandatory age verification in iPhones in the UK has been introduced: not as a possible, easy switch one, but the default on, requiring adults to potentially deanonymise themselves. I repear: it's not something the parent could enable/lock in within a 10 seconds, it's something enabled with every adult's phone, something the kid will evade in the same way they buy tobacco or alcohol right now.
That was never about the kids. Otherwise the governments wouldn't tolerate Meta openly admitting they've been knowingly hooking up kids, knowingly worsening their mental health, or Musk's X keeping CSAM generator open while all the world's governments just grimaced and kept legitimizing it.
Re: EU Age Verification Hacked in 2 Minutes: What Happened
#14For the same reason, I don't use sudo. Despite being patched, the presence of prior vulnerabilities [1] and hacks makes it fundamentally not trustworthy. 1. https://app.opencve.io/cve/?vendor=sudo_project
so do you just use su?
Seriously, it is as if there would be a CVE because sudo allows privilege escalation.
Of course such widely spread tools should be audited and have eyes on them. On the other hand many people are tired of security strategies because half of the time it is about a platform doing it for market domination. Our thoroughly shitty mobile OS come to mind. This age verification crap isn't too different, just slightly different goals where real security isn't really considered too much.
Re: EU Age Verification Hacked in 2 Minutes: What Happened
#15It is a good exercise, but in practice, what's the big deal? Even if the app is bulletproof, age verification will get bypassed. Account sharing, file sharing, darknets, etc... It mostly prevents kids from stumbling upon content that isn't meant for them, but it won't resist deliberate attacks for long, especially if the parents are complacent. And for that, the EU Age Verification app looks fine, especially now what…
Re: EU Age Verification Hacked in 2 Minutes: What Happened
#16For the same reason, I don't use sudo. Despite being patched, the presence of prior vulnerabilities [1] and hacks makes it fundamentally not trustworthy. 1. https://app.opencve.io/cve/?vendor=sudo_project
Re: EU Age Verification Hacked in 2 Minutes: What Happened
#17Earlier quoted context omitted.
one has to understand that the point is not to protect kids, it never is, but to control online activities. also this is not an organic law, this is the result of intense lobbying by transnational corporations such as facebook, pushing hard for this and there are reports from inside the parliament that this is rushed to be release ASAP despite not being ready or properly tested.
Except that this kind of age verification is not what "transnational corporations such as Facebook" is pushing for. In fact such a system is probably the worst for them: they can't use the token for tracking, and it can make it harder for them to target children because it is likely to come with further restrictions. What the tech giants want is OS level attestation. They want to control what you can install on your…
The service for EU age verification app requires Google Play Integrity API check. So as much as you "can" run the app itself anywhere, you are forced to do it on whitelisted build of an OS on a whitelisted device.