Brussels launched an age checking app. Hackers took 2 minutes to break it
101–110 of 221 posts
Re: Brussels launched an age checking app. Hackers took 2 minutes to break it
#102The EU let Ursula von der Leyen say a lot of false statements about this https://netzpolitik.org/2026/gesichtsscan-und-handy-zwang-vo...
Re: Brussels launched an age checking app. Hackers took 2 minutes to break it
#103Earlier quoted context omitted.
Can you give a brief explanation of how this is done with a zero-knowledge proof? That site is low information and painful to navigate, and it seems quite surprising to me that this is possible. ID verification, in the government sense, is ostensibly going to require matching an ID against a some other resource. If done locally then you can trivially spoof the result, akin to hacking a game, but if done remotely then…
https://blog.google/innovation-and-ai/technology/safety-secu... Basically you can prove that you have an identification document and that a certain property is true without revealing anything else.
For some contrast this [1] is an infographic from NASA about the Apollo program in the 60s. Enough details to inform one from a technical perspective, but also organized well enough that even if you know nothing about space or space flights, you could walk away with a pretty good idea of what's going on, and it might even spark your interest enough to research some things you didn't follow.
[1] - https://assets.science.nasa.gov/content/dam/science/psd/luna...
Re: Brussels launched an age checking app. Hackers took 2 minutes to break it
#104Earlier quoted context omitted.
Can attestations be rate-limited or is that the timing side-channel you are talking about?
Precisely. To rate-limit attestations you either need government somewhere in the loop so that they get notified and can revoke certificates when they detect abuse (but then they can correlate requests to prove adulthood with the service provider), or you need the proof of adulthood to be tied to the certificate in some way that the service provider can tell if a certificate is being re-used. But then anyone with a c…
Re: Brussels launched an age checking app. Hackers took 2 minutes to break it
#105Earlier quoted context omitted.
That's not what you're competing with. Your competing with a drivers license with a photo (not a great photo) and some countries have pretty easily faked drivers licenses, but others have drivers licenses in hard plastic with holographic features. The credit card doesn't work as age verification.
We're talking about the EU here, where the standard form of ID is an ID card with very strict requirements, including multiple secure features and an NFC chip with the photo and some other information.
Re: Brussels launched an age checking app. Hackers took 2 minutes to break it
#106Re: Brussels launched an age checking app. Hackers took 2 minutes to break it
#107These are the sources cited by the article: [1] https://xcancel.com/Paul_Reviews/status/2044502938563825820 [2] https://xcancel.com/paul_reviews/status/2044723123287666921 [3] https://csa-scientist-open-letter.org/ageverif-Feb2026 | "The saga is turning into a PR disaster for Brussels. " imo: mostly because the Author wants it be a disaster. The App has not launched, they published the source code in order to invite…
Not immediately deleting the selfie is a pretty fundamental and egregious mistake to make. People are particularly sensitive to selfies not being handled correctly after Discord lost thousands of them, despite promising to delete them after age verification occurred (and then not doing so) https://www.bbc.com/news/articles/c8jmzd972leo The damage is limited because the selfie is only retained on device, but it still…
Re: Brussels launched an age checking app. Hackers took 2 minutes to break it
#108Please stop saying "Brussels" to mean the EU. It's a nasty trick to give the idea that it's some kind of external entity forcing your country to do something. It's not. It's an assembly. And it's insulting to people from Brussels. I don't want this any more than you do.
In other words, sorry but it’s here to stay.
Re: Brussels launched an age checking app. Hackers took 2 minutes to break it
#109Obviously that won't stop motivated teens from taking their parents ID cards or similar mechanisms. Thst means any system that likes to prevent that needs to additionally ensure the identity of the card holder. And then you create a privacy nightmare.
So my proposal would be to accept that nothing is ever perfect and just use the card and ensure that system works as well as it could.
Of course "card " is a standin for all manner of hardware that can do it, including phones.
Re: Brussels launched an age checking app. Hackers took 2 minutes to break it
#110Why does this app even exist? Why is everyone in this thread so okay with more surveillance? It’s ironic that people are arguing over technicalities instead of tackling the moral and societal impact of age verification.