Live data from Hacker News

Brussels launched an age checking app. Hackers took 2 minutes to break it

politico.eu

141–150 of 221 posts

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#141
There's something that is written between the lines here.

EU is often portrayed as overly bureaucratic, slow moving. The way this app was developed seems more in the line of "move fast, break things".

I don't know if that says something about the EU, or about the EU-naysayers, but I thought it was worth pointing out.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#142

Note that this is an implementation of eIDAS: https://www.eudi-wallet.eu/ The point of this is that you can use the credentials on your phone to prove that you are an adult to a website using zero-knowledge proofs to avoid disclosing your identity to anybody. If somebody who has access to your unlocked phone can access the data in the app, then this is something that should be tightened up but it’s a substantial priv…

Then why does the linked GitHub explicitly state it uses OpenID4VP?

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#143

Why does this app even exist? Why is everyone in this thread so okay with more surveillance? It’s ironic that people are arguing over technicalities instead of tackling the moral and societal impact of age verification.

As a society, we broadly agree shops should check ID before selling kids alcohol. It is not that crazy to extend that online.

Showing my ID at the store doesn't register this on a government OpenID4VP server, and the store doesn't copy my ID.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#144
This is not the problem the title makes it out to be.. It's still in development.

> "Now, when we say it's a final version, it's ... still a demo version." He added the final product is not yet available for citizens and "the code will be constantly updated and improved … I cannot today exclude or prejudge if further updates will be required or not."

The whole idea of this age requirement is ridiculous in the first place, changing the focus to how good or bad the unnecessary tools are is nothing but a nice distraction.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#145

This all feels a bit like letting children into a nightclub and then needing to see ID every time you buy a drink.

... isn't this how most bars/pubs work?

The metaphor still works, minors in pubs are, presumably, under the supervision of their parents, otherwise they have not business being there in the first place.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#146

Oh God not this stupid tweet again. He's "hacking" it from a rooted phone. You can't just willy nilly edit those files like that on a normal phone. Fml I would've written a CN under that. On top of that they didn't infiltrate anything.

Adding onto that: the app is open source. Finding possible weak points was the very reason of this exercise.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#147

Earlier quoted context omitted.

It’s very common throughout English. The Russian government is refered to as Moscow, US as Washington. It’s the same and doesn’t refer to residents. It’s known as synecdoche. In other words, sorry but it’s here to stay.

If there was a major event in Belgium, which city would the news outlets refer to in order to avoid ambiguity?

It's usually used in place of a person/active participant in something.

So ‘Brussels suffered a deadly fire’ will always refer to the city. ‘Brussels decides on new aircraft regulations’ will almost always refer to either the city government, the Belgian government, or the EU Parliament headquartered there. Brussels is just an exceptional case because there is so much based there, as opposed to the Hague or the Vatican.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#148
post #74

The “hack” in question is pointing out that the app forgets to delete images of the user's face and ID (stored). A lot of people have pictures of their face already on the phone, and often their ID as well so this is hardly a security flaw in any real sense.

"Lots of people choose to keep their key under their mat, so our lock not stopping anyone is hardly a security flaw in any real sense".

But it's not “lots of people,” it's everyone. Everyone has a picture of their face on their phone. And the information is encrypted because phones use disk encryption by default. “Someone can get a photo of your face and passport if they have full unencrypted access to your phone's hard drive” is like saying “someone could turn off your alarm and make you late for work if they break into your house.” There are simply bigger concerns in that situation.

Re: Brussels launched an age checking app. Hackers took 2 minutes to break it

#149

Please stop saying "Brussels" to mean the EU. It's a nasty trick to give the idea that it's some kind of external entity forcing your country to do something. It's not. It's an assembly. And it's insulting to people from Brussels. I don't want this any more than you do.

It’s very common throughout English. The Russian government is refered to as Moscow, US as Washington. It’s the same and doesn’t refer to residents. It’s known as synecdoche. In other words, sorry but it’s here to stay.

It's more a metonymy than a synecdoche
Post reply on HN