SaaS & Software·Aug 2, 2026

EU Age Verification Project Mandates Hardware-Bound Attestation

Article URL: Comments URL: Points: 30 # Comments: 13

Hacker News2 min readSingle source
EU Age Verification Project Mandates Hardware-Bound Attestation
Image · Hacker News
The gist
5-point summary · 1 min

Article URL: Comments URL: Points: 30 # Comments: 13

  • The project invited alternative architectural proposals and said a dedicated security review and threat model would be published soon.
  • To prevent credentials from being copied, cloned, or reused by modified clients, the project relies on keys stored in protected hardware like Android TEE, StrongBox, or Apple’s Secure Enclave.
  • However, stricter checks like root detection, Google Play Integrity, and Apple App Attest are not universally mandated by the reference implementation and may be left to individual deployers.
  • Proof of Age providers are expected to issue credentials only to applications included in a list of compliant apps maintained by the European Commission.
  • Desktop Linux users could access a website and scan a QR code using a supported mobile wallet.
In this article

The European Union’s open-source age-verification project has drawn criticism after a maintainer confirmed that hardware-bound attestation is a mandatory architectural requirement, raising concerns about Linux, custom Android ROMs, and independently compiled applications. The debate began in the GitHub repository for the project’s Android app, where a user argued that tying credentials to specific hardware environments would make it more difficult to support open systems. “Hardware-bound attestation is a requirement of this project, not an implementation detail we can simply drop,” a maintainer responded. The project invited alternative architectural proposals and said a dedicated security review and threat model would be published soon. The solution lets users prove they are over a certain age without revealing their name, exact birth date, or full identity document. To prevent credentials from being copied, cloned, or reused by modified clients, the project relies on keys stored in protected hardware like Android TEE, StrongBox, or Apple’s Secure Enclave. However, critics claim that this approach endangers the system by making it dependent on a small number of approved devices, operating systems, and attestation providers. The project’s technical specification requires age verification apps to use native cryptographic hardware when available. However, stricter checks like root detection, Google Play Integrity, and Apple App Attest are not universally mandated by the reference implementation and may be left to individual deployers. This distinction matters because hardware-backed key storage does not require a server to approve the entire device, operating system, or application build. The maintainer’s wording leaves some uncertainty over how restrictive production deployments will be. There is also a separate governance limitation. Proof of Age providers are expected to issue credentials only to applications included in a list of compliant apps maintained by the European Commission. This means that publishing the source code does not automatically guarantee that a community-built version can use the real service. Importantly, Linux is not explicitly banned. Desktop Linux users could access a website and scan a QR code using a supported mobile wallet. However, the current architecture does not provide a native Linux wallet, and alternative mobile operating systems could struggle to meet the required trust conditions. So, as you can understand, the controversy goes far beyond a single Android implementation. For now, however, the project’s position is that hardware binding remains required. The expected security review and threat model may provide a more detailed explanation of why that trade-off was selected and whether alternative roots of trust or less restrictive implementations can still comply. Until then, the central question remains unresolved: whether an EU-funded, open-source identity system can meaningfully remain open when real-world access depends not only on available source code, but also on approved applications, supported security hardware, trusted operating environments, and the policies of credential providers.

Integrity note  ·  Xela does not rewrite or paraphrase article content. The excerpt above is the source publication's own words, sanitized for display. For the full piece — including any quotes, charts, or images — read it at Hacker News. Xela's rewritten version is off for this story, so there's no editorial angle attached — you're getting the source's reporting unfiltered. When the rewrite is on, we add a What this means block underneath with the operator/trader takeaway.

What people are saying

Discussion

Hot takes

0/280

Loading takes…

Comments

Discussion · 0

Sign in to comment, like, and save articles.

Sign in

Loading comments…

Keep readingSaaS & Software desk
See all in SaaS
Show HN: Draco – A single-binary, self-hostable Firecrawl alternative in Rust
·

Show HN: Draco – A single-binary, self-hostable Firecrawl alternative in Rust

Scraping modern websites has become a massive headache. You basically have two choices: pay for an expensive API like Firecrawl/Browserbase, or run a fleet of headless Chrome instances that eat 1GB of RAM per page and still get blocked by Cloudflare. I built Draco to fix this. It’s a fast, single-binary web scraper written in Rust. You point it at a URL, and it spits out perfectly clean Markdown or structured JSON for LLMs. The secret sauce is that it doesn't just boot a browser for every request. It uses a tiered escalation engine: Tier 1 (Stealth Fetch): Draco uses a custom TLS/JA4 fingerprint to perfectly mimic a real browser's network signature at the packet level. It turns out a lot of anti-bot walls will let you right through if your handshake looks correct. In my benchmarks against sites like Cloudflare and Target, Playwright ate ~500MB of RAM and timed out. Draco bypassed them in under a second using just 20MB of RAM. Tier 2 (V8 Isolate): If it hits a React/Next.js SPA that needs rendering, Draco boots an in-process V8 engine in single-digit milliseconds. It hydrates the DOM and intercepts the hidden JSON APIs the page is calling—giving you the raw data without the overhead of a graphical browser. Tier 3 (Real Browser): If it hits an absolute wall, it seamlessly falls back to detecting and driving a real browser on your machine. I also built in all the tooling to make it a complete drop-in replacement for the hosted services: Daemon Mode: Run draco serve and you get a persistent HTTP server with a Firecrawl-compatible REST API. You can swap out your API keys and self-host immediately. Built-in MCP Server: It natively exposes a Model Context Protocol server so you can plug it directly into Claude Desktop or your AI agents. Web Search: Built-in parallel multi-engine web search (bypassing the need for a Google Search API key). Interact Mode: Drive a page statefully like a devtools console, persisting cookies across navigations(for LLM's mainly). It’s completely open source (MIT/Apache-2.0). I just wanted to put this out there for anyone tired of fighting headless Chromium or paying per-page scraping costs. Grab the binary and throw a difficult URL at it. Note that it's still a WIP so there might be some unexpected breakages of uncommon sites but for the most part its quite capable, it can handle cf-protected sites and heavy SPA's while everything else fails partially or completely while taking longer or more resources. (tested on example.com, hackernews, cloudflare, glassdoor, bluff.com, target.com, stake.com and thrill.com) ┏━━━━━━┳━━━━━━━━━━━━━━━━┳━━━━━━━┳━━━━━━┳━━━━━━━━━━┳━━━━━━━━━┓ ┃ Rank ┃ Tool ┃ Score ┃ Pass ┃ Avg Time ┃ Avg RAM ┃ ┡━━━━━━╇━━━━━━━━━━━━━━━━╇━━━━━━━╇━━━━━━╇━━━━━━━━━━╇━━━━━━━━━┩ │ #1 │ Draco │ 769.7 │ 8/8 │ 3.45 │ 216.50 │ │ #2 │ Obscura │ 384.5 │ 4/8 │ 2.68 │ 87.59 │ │ #3 │ BrowserOxide │ 373.4 │ 4/8 │ 6.42 │ 105.95 │ │ #4 │ Playwright │ 342.2 │ 4/8 │ 1.71 │ 535.07 │ │ #5 │ Bouncy │ 196.6 │ 2/8 │ 0.59 │ 19.38 │ └──────┴────────────────┴───────┴──────┴──────────┴─────────┘ Repo: Comments URL: Points: 8 # Comments: 1

Hacker NewsSingle source
Newsletter

Track saas & software every morning.

Daily digest tuned to this beat. The 5 stories most worth your time. Unsubscribe anytime.