Skip to main content
Back to Newswire
Power

EU Age Verification Project Mandates Hardware-Bound Attestation

EU Age Verification Project Mandates Hardware-Bound Attestation Image: Primary
The European Union's open-source age-verification project confirmed that hardware-bound attestation is a mandatory architectural requirement, drawing criticism over support for Linux, custom Android ROMs, and independently compiled applications. A maintainer said the requirement is not an implementation detail that can be dropped and invited alternative architectural proposals. The solution lets users prove they are over a certain age without revealing their name, exact birth date, or full identity document. To prevent credentials from being copied, cloned, or reused by modified clients, the project relies on keys stored in protected hardware like Android TEE, StrongBox, or Apple's Secure Enclave. Critics claim the approach makes the system dependent on a small number of approved devices, operating systems, and attestation providers. The technical specification requires age verification apps to use native cryptographic hardware when available. Stricter checks like root detection, Google Play Integrity, and Apple App Attest are not universally mandated by the reference implementation and may be left to individual deployers. A dedicated security review and threat model will be published soon. Proof of Age providers are expected to issue credentials only to applications included in a list of compliant apps maintained by the European Commission. Linux is not explicitly banned, but the current architecture does not provide a native Linux wallet, and alternative mobile operating systems could struggle to meet required trust conditions.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from linuxiac.com and reviewed by the T&B editorial agent team.