European "age verification" "app" forcing everyone to use Android or iOS
github.com
github.com
However there is ZERO talk about mobile platforms... No alternative solution like linux for the desktop, no money or care given to the few alternative that tentatively exist, and zero talk about forcing companies (at least for the ones shipping android phones) to open up their firmwares and allow users to install alternative OS if they want to sell in the EU.
So whilst the backend guys more or less got the memo about sovereignty, I think there is still a lot of educational work to do regarding end user devices and what kind of digital slavery hole we're digging ourselves in...
(because you still need the hardware made, and it's not like the EU commission is even prepared to fix BSPs for that hardware)
The EU has endlessly sold critical infrastructure to US, India and China while actively sabotaging efforts to rebuild it and now want it back - for free. This is criticized as having a low chance of success, as well as being a pretty unreasonable demand.
https://arstechnica.com/gadgets/2018/07/googles-iron-grip-on...
Still amazes me how everyone isn't cynical-by-default about anything Google (or big tech in general) open-sources yet...
The point is that the signatures are compared against a database of certified builds - and that exists on Google servers.
If you want AOSP attestation, you need to build your own database to compare against.
It exists on Google's servers for lock in reasons alone.
Which makes sense for them - after all, that makes their competitors break and their ROM doens't.
These digital ID wallets do exactly that. Member states lose control of the ID infrastructure, which will now be controlled by the EU. There isn't much sovereignty left at national level...
It will totally not be used to sanction you the moment you become a nuisance to the EU elites by saying "wrong speech" that goes against their mandated doctrine or pointing out their acts of corruption or dismantling of democracy.
The EU building in Brussels even has the word "DEMOCRACY" plastered on the front in large bold letters[1], in case you forgot.
[1] https://audiovisual.ec.europa.eu/en/media/photo/P-069521
Add here shared border control since 2027 in eu, and chat control now.
And prominent names like democratic republics of Kongo and North Korea.
My previous comment should be taken in its entirety. The loss of sovereignty of individual countries is comprehensive across all domains and this is just one brick in the wall.
This is nothing new, this is what "European integration" means. I wanted to point out the very newspeak-esque use of the term "sovereignty" in Europe at the moment.
I would think the idea is to make services and ID documents more uniform across the union. I don’t see what the individual members state lose here? Apart from the cost of implementation. The individual EU citizen would seem to benefit from standardized documents accepted by all companies and governments, do you disagree?
(The US constitution originally required federal taxes to be apportioned for exactly that reason.)
https://citizens-initiative.europa.eu/faq-eu-competences-and...
Moreover, it's ignoring the context of the thread. The relevance is obviously that coercing someone to do something against their will and then saying they're still in charge because they're the ones doing it is a sham.
In the EU this appears to be classified into "exclusive", "shared" and "support" "competencies":
> the EU has competence to support, coordinate or supplement the actions of the Member States (article 6 TFEU) – in these areas, the EU may not adopt legally binding acts that require the Member States to harmonise their laws and regulations.
So for example, one of the areas in that category is industry.
The common trick to look out for in cases like that is that when they want to regulate something like "industry" they instead categorize the rules as something else, e.g. the US infamously regulates non-interstate non-commerce as "interstate commerce".
The Federal government using the withholding of funds to get the states to do what it wants is a well-documented phenomenon.
But is DOES require work - and it's much easier to complain than to put in work.
If you’re the sort of person that’s unable to distinguish between something that’s legitimately unjustifiable/ridiculous, and something that just upsets you, then you do you, but don’t bring this here pretending that it suffices as a discussion, because it doesn’t.
It requires age verification and provides code whose development was subsidized by the government, which third parties the user doesn't control will use, that creates a dependency on those platforms.
> there's nothing preventing those new OSes form providing proper security signals.
A network effect, far from being nothing, is a barrier the height of a mountain.
The purpose of attestation is to lock out competing platforms. It security value is a joke. Devices pass attestation with known vulnerabilities and fail it for being competitors, even if the competitors have better security.
Offering to make attestations nobody accepts is a farce. The problem to be solved is how to run existing software that was originally written for other platforms when the new platform is new and doesn't have enough users for third party developers to specifically target it, which is the exact thing that can't do. And without that it can't get enough users for third party developers to specifically target it.
This is kind of your... opinion man.
In reality pretty much all security sensitive applications require attestation from their side.
What it does do is require you to get one of those devices instead of a competing device or OS, thereby locking out competitors but not attackers.
I’m not saying it can’t be duplicated. I’m saying if you want to build a mobile platform you need to approach it with appropriate respect for the incredible difficulty of making something that usable.
The only thing they're improving on mobile these days are addictiveness and data collection.
Complete public datasheets on how to program the hardware should be a requirement fit a DMA2.0.
The elephant in the room is that it is just talk, as always in case of EU.
Some nations in the western sphere seem to gladly outsource such critical infrastructure. Thinking about the Korean defence manufacturer whose contact mail was something@gmail.com in an advert I saw a few days ago. Perhaps Google will integrate some fast reply function for some instant AA ordnance delivery?
Shifting this question benefits only those who want to force this upon us.
Ping me when people are physically tortured by police for facebook posts, because that's what happens there.
Since you seem unfamiliar with the following, I will leave this here for your perusal:
Seriously, there is something tremendously wrong with governance when politicians keep changing the whole world around us, without us having any say in it at all. The threat this measure poses to the internet and society is significant, yet it is being pushed through without any substantial debate or push back. This just is not how decent and actual democracies should function. What messed up timeline is this?
That's where you're wrong. Most people actually do agree with age verification. Just because a decision is stupid it doesn't mean it's undemocratic. Trump was elected democratically, twice. Brexit passed through a referendum.
It's just like democracy. Without the "dem(b)" part. Much better now.
We have such warm feelings about it! What could possibly go wrong with doing such strong governance and extreme-right parties polling at record highs in more than half the EU countries? We have warm feelings now. Or maybe the warm feelings the result of 30 years of climate action in the EU. Luckily, the extreme right is hard at work defending our right to airconditioning!
> Social media is destroying children's brains! Do you want access to be delayed until a certain age?
> Do you want children under a certain age to be banned from social media, which means that you will now have to give your ID, only with Android or iOS?
99% of people understand this as "you need a smartphone" which is not a problem in 2026, even for the elderly.
Maybe 99% of people have surrendered to Google/Apple (include me there), but the 1% has a valid point...
1. By doing this, the EU is killing any alternative operating systems for phones: no one will switch to one if they can't access online services. Banks are already making it extremely hard.
2. Google and Apple might be better regarded than Huawei, but they are not moral (or they are not guaranteed to remain so).
3. The very idea of a de facto state-enforced monopoly on operating systems is outrageous.
E.g. In a country of 100M people, if 60% agree with a bill and it becomes law, the country has imposed that law on 40M people against their will. That's just as true in a dictatorship as it is in a democracy. The more areas of our lives government involves itself in, the bigger this problem becomes.
No, it did not.
> E.g. In a country of 100M people, if 60% agree with a bill and it becomes law
That's not how that law was adopted.
People make dumb decisions and don't think about possible outcomes twice, or even once. But (unfortunately, in this case) this is a core principle in a democracy. People may be lied to, or at least they are fearmongered into thinking that age verification is needed and encryption needs to be weakened because they thing they have nothing to hide, but if in the end they elect the people that are pro-age-verification, it's perfectly democratic.
IMO the media (including, most importantly, social media) is the problem, not the politicians and/or the democracy or whatever. They all play their part, sure, but it's how people are influenced by the current state of media what's driving all these populistic forces.
On top of that, the relevant law they would have to comply with in those countries would be the laws of those countries, and those are the governments committing the genocides.
The Politician's Syllogism (or Fallacy) [0]:
1. We must do something.
2. This is something.
3. Therefore, we must do this.
The representatives elected by Europeans did though: 483 votes in favor, 92 against
I’m no conspiracy theorist, but it does seem that there’s an international influence outweighing democracy.
Cui bono?
But the null hypothesis is that there is no new legislation to vote on. It must have come from somewhere!
I’m in the UK and very anti Brexit. But were we still in, I would have no idea how to influence what happens behind those closed doors at the European Commision.
Granted the current UK Labour/ Conservative pact on these issues show they’re completely out of control. But I still theoretically know how I could influence policy.
I mean even in the EU there's theoretic ways to influence policy, it's just that the system is currently sabotaged and/or partly not strong enough to withstand politicians who want to actively work against it.
Not being for or against UK or Brexit, but I don't think this is a EU problem. These kinds of problems exist in all European democracies, at least this is what it feels like currently.
The Parliament and Courts keep the Commission in check, although their… misguided rule of majority is bound to allow some nonsense to pass. Especially since the Commission is, in my view, made up of people that do NOT want what the citizens do. You could argue they represent the majority of their specific countries, but even that is stretching things a bit given how many people actually vote.
So: the Parliament, the Courts (you can bring them issues), the European Citizens’ Initiative, and indirectly through your own country’s agencies (e.g. your local DPA).
It’s not that different from the high levels of indirection and bureaucracy in most democracies, I think. (Not that I’m defending the EU, there’s plenty to attack.)
[1] https://old.reddit.com/r/Twitter/comments/1uk6a98/lets_confi...
So whatever you opinion is on the subject of forcing age verification, it is worth looking at the technical solution, especially if it is your domain of expertise.
Thing is, the status quo is absolutely worse. My 13yo son likes making Roblox games. Suddenly, some months ago, Roblox made a change where you’re not allowed to share your games with friends unless you do “age verification”, apparently in some misguided bid to beat the pedos. In Roblox’ case, this means sharing your 3D likeness with some sketchy American business who pinky promises to delete said data after. I don’t want random American tech companies to have my kids’ biometric info like that, able to sell it to whoever asks. Nor my passport or anything like that.
I’d much prefer a government supplied app, that’s guaranteed to protect my privacy, and has no business incentive to sell my data, where I can see what data about me (or my son) is shared with Roblox or whichever sleazy business wants it.
Obviously this only makes sense if the government is less sleazy than the average American tech business, but for all its faults, I think that currently holds for the EU (and most of its member countries). There’s plenty precedent of EU governments doing privacy-conscious apps right (the Dutch covid tracking app comes to mind).
I hope they see reason and fix this here issue.
I don't think it's Godwin's Law when you are so spot on, exactly describing the worst case.
Governments likely already know your name, age, place of birth, so having an app with a standard API for verifying users isn't giving the government additional data.
so it will gather extra data, sell it sideways and leak like hell. (as they already do with all the data they already have)
https://digital-strategy.ec.europa.eu/en/factpages/blueprint...
First, the user downloads the app onto their phone and sets it up by certifying their age. This can be done with a biometric passport/ID card, a national eID (e.g. national ID Card or other electronic identification mean), a pre-installed third-party app (e.g. a banking app), or in person (e.g. at the post office). Only the information confirming that the user is over the age will be saved in the app. No name, no birthday, or any other data is saved.
After completing this step, the communication between the app and the provider certifying the user’s age (e.g. eID, third-party app) ends. No further data is exchanged.
https://digital-strategy.ec.europa.eu/en/faqs/eu-age-verific...
For me, it's enough that your activity could be linked to any unique identity. I don't want mandatory government apps on my phone, that's very chinese. We should strive for better.
Edited to add: your linked FAQ conveniently leaves open how the communication between the web site and the app happens. There are myriad of ways that ones behaviour leaks in this step.
https://www-bitsoffreedom-nl.translate.goog/2026/07/06/aivd-...
Amusingly fantastically wrong.
NL may have its own issues like you linked to, but more uniquely had their collected data abused more than other countries in probably the worst event in history.
However even if the app is secure the storage and handling of the information is a different matter and it has been shown that care is not always taken.
How is, of all things, an age verification app going to make that worse?
I mean I understand your argument in principle but it seems you’re arguing against ~every present-day functional government and not against an age verification app.
Like if I was the boss of a train company I would probably not put up a photo of Mussolini as a motivational poster. Well… maybe I would, but only ironically.
> How is, of all things, an age verification app going to make that worse?
What are you arguing for, here? If everything were perfectly anonymous, maybe. But NOT ONCE in history has governments decided to not abuse power. It'd be so easy to just put a tracker in there or something.
All these "think of the children" arguments are ALWAYS red herrings. Literally any action, any freedom denied, can be justified in the fight against CSAM. And so they get rushed through and abused.
The EU DNS filter (CSAADF) was literally IMMEDIATELY abused to block other things too.
"It's just age verification". Is it, though? How do you verify age without verifying identity? How do you verify its use, without tracking. Provably without tracking. Provably without what's called "turnkey tyranny"?
I think if your argument, which is an extremely common argument, is "I just want to block children's access to bad stuff on the Internet", then you cannot possibly have been paying attention to this debate that's been going on since at least the mid 1990s. Were you even born when this was being discussed? If that's your argument then you have about 30 years of catching up to do before you should speak.
[1] yes, I know Mussolini did not in fact make the trains run on time.
zero-knowledge proofs
the point is non-govt entities shouldn't get any information about you during age verification other than that you're over 18 and that's what ZKP can give you
I'm sorry, you can't just drop "quantum computer", or "zero knowledge proof", or "flux capacitor", and think that you have solved the problem.
Just dropping "zero-knowledge proof" as if it's a mic drop moment is like when Turnbull said "the laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia".
The devil in all this is in the details. Just saying "zero-knowledge proof" is just barely more productive than saying "won't someone please think of the children?".
If you don't have a complete solution, then you're "not even wrong".
In addition to that, you have misunderstood how zero-knowledge even addresses the main problems. Not the technical problems, and DEFINITELY not the meatspace problems.
Second: There was some substance. Maybe not six paragraphs worth, but there was some. Here it is: You, when you said "zero-knowledge proofs", did not give much substance. How, specifically, is that going to work?
It's a bit rich for you to be complaining that knorker didn't have any substance, when the problem is that you didn't give any.
I felt your comment was so uninsightfully vapid and arrogant that it's uselessness could not be described briefly.
But sure, it does boil down to "sigh, that's not even wrong", but I suspect you not only don't know what that means, but that you would not be curious enough about life to look it up.
I note that you still did not provide a solution. You didn't even describe the requirements, and the problem here starts with a problem definition that doesn't inherently lead to it being either logically unsolvable, or leading to turnkey tyranny.
Edit: I use punctuation because I was born in the 1900s. And was on the internet when this issue started in the 90s, which makes me react to your "why don't we just...".
And if you look carefully, you'll find my punctuation choices are clearly un-LLM-like.
To avoid rounding up the jews you... create a government that doesn't round up jews.
You don't fight arbitraty useful tools which then end up in bizarre situations like in US where people can't vote because of this bizarre idea that government shouldn't track voter lists.
EU governments mostly have a list of registered citizens with their birth dates and their adresses. And noone has been rounding up anyone for almost a century... something we can't say for another world country which apparently doesn't keep records of their voters (useful to prevent people of colors from voting!) and somehow is rounding up people on the streets right now.
But I have to point out that NL gov did not round up jews, but the bad outcome arrived anyway, from outside the system. So in the example we're talking about, that was not a solution.
Other than that, I agree.
Also, don't use Roblox, you can freely share games made with PICO-8, Löve, Godot, Rpgmaker, Game maker and the like, no need to go to the hell scape that is Roblox and its dark patern and locked down ecosystem.
Don't get me wrong. I agree roblox is a very shady operation, but that does not erase the fact that their platform is unmatched when it comes to letting kids make games.
There also Luanti, the new name of MineTest, which is closer to the Roblox experience (in the sense that there already a playable game there, and creating new stuff is closing to modding than to game making).
The only thing close is minecraft, which from what I heard already has similar restrictions on in game chat, plus other shady maneuvers from Microsoft.
It's the same network effect with other megacorp, we could argue the same about X/Instagram/Mastodon, the question could be changed to: Do you want your children to be groomed to use closed source ecosystem from shady companies or do you prefer they gain experience in using relatively open ecosystem ?
Luanti let you make multiplayer games/mods too. For Minecraft there way to play outside of Microsoft sanctioned versions and servers.
Nobody uses platforms because they are are looking to exercise billions of options. The point is easy commonality. You sit next to a kid, and, what do you know, they are into Roblox too. Cool. Wanna play?
For Minecraft random people are more of a nuisance than an asset, but for a Roblox obby there is an expectation that other people will check it out.
Ok, well then, toss your hands in the air and throw away all your principles then, I suppose.
How is the view in your FOMO dungeon?
I agree that Roblox is a hellscape when you want to make serious games, eg make money from it or sth, but if you just want to mess around making a “supermarket horror tower defense” game full of in-jokes and then have all five of your friends join it, and It Just Works, sorry but nothing comes close to Roblox.
Until they required age verification for that ofc.
Also, just don't ever buy any Robux and kids will auto steer away from the shitty games that need it. That filters out 95% of the badness of Roblox right out the gate.
S&B or other engine-as-game solve that by using the platform account system and master server for discovery and NAT punch through.
Besides the game engine, it provided central identity (optional - you could allow players to sign in as Guest), a website to browse games and servers, a forum to discuss games and programming, and an IDE with a built-in sprite editor (it was 2D), map editor and object browser.
This is a bit of a 64,000 euro question, though. Look very closely at what the government exemptions for GDPR are.
How about the option of the state not being so tyrannical in meddling about what people anonymously do online in their free time?
To the extent that it matters, I think the missing link here is "primary education should support a parent's intent to limit unrestricted internet access for their children." That is, during school activities where internet use is unavoidable, require supervision. (Maybe a lab monitor that can roam the room and see screens?) And for homework, don't assume the kid has internet access, because that is the parent's choice, and they may well not. On the flip side, if the parent trusts their kid with that access, or intends for them to learn through real world experience, let them. That should not be the state's decision.
The problem of course is that this idea in my head is a pipe dream. Schools seem to be well onboard with digital coursework, presumably for efficiency reasons? Unclear. I'm not sure what a more practical middle ground actually looks like.
I guess once you hand your teenager a smart phone (and all their friends have one too!) all bets are off. That's new, and wasn't a thing when I grew up. We were rural and on the tail end of dial-up, so I couldn't get online at home without someone hearing the modem. That sure limited my attempts to do so without permission!
I'd have hated this as a child. But the case for unrestricted internet and social media access for children being harmful, at this point, seems pretty shut.
For those who sadly cannot homeschool their children... well, we need to push for school choice and to dismantle the teachers' unions. Which probably ultimately is the same thing.
I am thankful to have had extensive access to technology as a (homeschooled) kid, and parents who encouraged curiosity.
Destroy "optimize for engagement" social media, which harms everyone, and stop pretending like this is some problem that only harms children.
Don't get me started. We try to restrict internet time, no Youtube (Shorts are poison/heroin), TikTok, etc. They go to primary school and there is a teacher that makes TikTok videos at school, they can play Roblox in breaks, etc. (Aside from this issue, the teachers are great though!)
There are only so many battles you can choose as a parent (not getting your kids photographed, put on Facebook, etc.).
In contrast to what the grandparent states, the government should unambiguously state: no smartphones, social media, and online games in primary school, period. That's the only way to make it work. Ironically, smartphones are forbidden in all high schools here.
I mean his classmates argue with their parents about whether they can install TikTok (and most parents lose). Meanwhile I’m denying my son the right to make a game together with a friend. It’s so creative and so educative and I’m saying no to it. It sucks and I hate Roblox for making something so cool and then taking it away for such stupid reasons.
I’d happily pay a license fee or sth. But I’m not gonna let them scan my son’s face.
“Sit down together” might be impractical here, if GP’s child’s friends are e.g. friends they made before a move, who are thus quite far away physically. Or friends with snobby parents who won’t let them come over to GP’s house for whatever dumb reason. Or friends with extra-curriculars such that their free time never lines up with GP’s kid’s free time—meaning that only async collaboration will work.
(That’s just a steelman position, though; in general I agree.)
This thread is like me complaining Google face-scan-gated Google Docs and people are saying “he can just sit down with the friend and learn LaTeX together!” Yeah, no.
Fwiw he does Godot too. It’s fun, but it’s purely solo. Godot’s answer to collaboration is Git, which is a complete non-starter for a 13yo. Note, I don’t judge them for it, they compete with Unity, not with Roblox.
Me siting down and explaining how government or corp. issued age verification is bad is really not going to make him feel better about sitting alone in his room night after night while all of his friends are online having a good time.
In any case, I think that age gating would not be needed if the platforms were regulated to remove addictive recommendation algorithms.
The app is an alternative for people who don't want to buy or carry around a card reader, but who already have a smartphone.
So it seems that the app is only an alternative in the case of government portals, but it is not an alternative for "age verification".
[I'm in the US, we're very ID-averse here, weird, but is what it is]
Smartphones can read that chip and the state as well as private businesses could in principle use this to do age verification – even the super minimal version of age verification that just asks for a certain age threshold and gets a binary response whether that threshold is met. (Which to me if we can achieve it is the perfect solution.)
The infrastructure is there and since 2017 those RFID chips are even actived by default when new ID cards are issued. (The cards are valid for ten years so nearly all ID cards have those active chips.)
The biggest issue currently is a network effect one: hardly anyone is using the chip so people don’t create their initial PIN, creating a UX hurdle for adoption. (If you want to use your ID card chip you have to find your initial PIN somewhere in your documents – if you didn’t throw it away – and then create your proper PIN, you can’t just start using it.)
I can sense usage increasing but exactly because of the poor initial use UX all sorts of private alternate solutions exist that are plain worse from a privacy preserving point of view. For example ones where you film your ID card from both sides (so the hologram is visible) which just suck. (You just share everything … which is just so unnecessary.)
To change this we would need a policy that requires age verification without sharing the birthdate or any other PII.
Unfortunately, we can't even get states to commit to our RealID requirements[1] (which doesn't even add a chip/PIN, it only strengthens validation of documents submitted at the time of application for a driving license). And the notion of a national ID is anathema to large swaths of the population.
Reference: https://en.help.roblox.com/hc/en-us/articles/39143693116052-...
Maybe they are expanding into other industries, but the safety focus predates that.
Is there a 'break glass' workflow in case you are not available (e.g., health incident)?
There is a big difference between: Government demands every website to have age verification, and government supported scheme by which service can opt into age verification.
As of now, American private spyware is actively filling the demand.
I get the feeling some privacy advocates are approaching the choice as a tier system, with government being the worst case.
I don't see it.
The only viable solution for the future of privacy is to not be dependent on the giant platforms in the first place.
Nah. Parental Controls are baked into every major consumer OS. If government cared about giving guardians the tools needed to care for the vulnerable ones they're responsible for, they'd require those parental controls to be beefed up [0] and that it be a requirement that online services and both local and remote software be required to honor the restrictions required by those Parental Controls.
Instead, what we get proposed is a system that cares very much about how old you are, and not one bit about the things that one's guardian understands one needs to be protected from. This system will work for some under-eighteens, but it will fail for many others, as well as every single dementia-damaged elder or brain-damaged/developmentally-stunted adult.
What's being proposed is absolutely not about protecting people... if it were, the mandate would be to beef up the existing fully-anonymous systems, rather than requiring identifying information from users.
[0] ...I mention this because I often hear in Internet discussion that these controls are insufficient, not because I have personal knowledge that they're inadequate.
Nope.
If you want the real reason, I'll provide a hint: it aligns with the underlying goal of DOGE.
Even the parental controls that are there are a train wreck. Our kid has an iPhone and the parental controls have all kinds of weird issues like, you give them 15 minutes of WhatsApp daily. First time on a day they start WhatsApp it says that all their time is up. Or suddenly they cannot run an application that was permitted by a parent. Then you uninstall and install the app again and suddenly it works.
It is unusable.
There web is also a huge hole in all of this. A lot of services you can also use as a website. A whitelist is too limiting and a blacklist is a daily task to maintain (and would require spying on your kid).
I also prefer to avoid age attestation altogether, but I am also not sure what the solution is. I think many people do not realize how much social pressure there is to use certain apps/games and how bad parental controls are. Yes, we say "no" to a lot of things, but you cannot say "no" to everything. Missing certain cultural touchstones (certain TV shows, certain games) makes your child an outsider.
As I said:
If government cared about giving guardians the tools needed to care for the vulnerable ones they're responsible for, they'd require those parental controls to be beefed up...
> There web is also a huge hole in all of this.and as I went on to say:
...and that it be a requirement that online services and both local and remote software be required to honor the restrictions required by those Parental Controls.
I expect that you don't, but if you'd like to argue that it's impossible for the government to do either or both things, then I'd argue that it's impossible for them to make age and/or ID verification work.Parental controls aren't baked in, they're bolted on and half-assed. One of them I've noticed over the years... I can't disallow Plex except at the app level (outside of Plex entirely). I can't easily give access to the educational libraries, but disallow it to the entertainment libraries. There are a million little anecdotes like that, because no one gives a shit about the problem.
Many parents, I think, are left with all-or-nothing choices. And it's not long before the reddit crowd starts insinuating that the reason your kid doesn't have a phone is so they can't call for help... from you.
It's a big clusterfuck.
I mean, parents, are -far and away- the most likely folks to abuse a kid, followed by friends of the family and close relatives. Stranger Danger was always fake, and teaching kids to be afraid of every adult who's not a family member is -and continues to be- a fantastic way to perpetuate child abuse.
But. Internet trolls are gonna troll and are best disregarded. If those folks seriously live in an area where an abused kid can never physically go to a teacher or other responsible adult for assistance, I'd recommend that they get the fuck out of whatever hellhole they're living in.
Ending section 230 might be a good start. Make platforms responsible for the damages done by whatever they distribute.
The issue is that a lot of voices you hear are from a big country which voted for fascists and those people now somehow think that technology will save them from the government they created. But that's not how it works unfortunately.
Privacy advocacy is losing the battle, because it is being framed as a choice between privacy and the status quo, and people vehemently dislike the status quo.
But cellphone access is different; it's assumed to be perfect, but it's increasingly being moderated by machine learning heuristics that serve as judge, jury, and executioner, severing your services if a couple of your actions trigger a fuzzy approximation to some of the training data.
AI moderation helps suppress spammers, but it's also punishing false positives, and there is just no recourse. Any ID system that piggybacks on "Apple | Google" is effectively shunning some non trivial portion of society. Governments of the people need to provision their own tech systems that are accessible to all citizens, even those who have run afoul of an AI moderation system.
It started when he signed up at a new bank, giving them his phone number. Somehow the bank enrolled his in their online banking system, which notified Samsung, who remotely initiated the "let's give your phone a pin" flow, presumably to protect him during online banking. (This happened without his knowledge -- he had not installed the bank's phone app.)
Later that day, when his phone went into a modal "let's setup a pin" screen, he panicked, assuming an attacker had gained control of his phone, since this was not something he initiated. No button would let him exit the screen, so he powered it down. Now, when he powers it up, it demands a pin, but he doesn't know what pin that would be. The only way to get the phone back would be to factory reset it, meaning he'd be wiping his data. He had the money to replace his phone, but that may not be true of every citizen, especially at his age.
People assume digital auth systems are perfect. But you don't hear from consumers who can't get online to tell you "I've lost access."
I've shared some other similar stories: a widow who got banned for life from facebook within minutes of making an account from an apple device on a consumer ISP with her real cell phone number.
A coworker attempted to sell his son's sporting goods on facebook marketplace and was banned for life with no appeal because AI thought it was "weapons."
Some high school students each made a gmail address from the same laptop one afternoon, only to be banned the next day. Each supplied their own cellphone number, but the accounts got shut down, presumably because multiple accounts were being created from the same device too rapidly.
AI moderation means there are a ton of unwritten rules, and private companies will keep you out of their platforms if you break them. That's fine, but it means governments have no business serving their citizens from these exclusive platforms.
> e signed up at a new bank, giving them his phone number. Somehow
Do you have a proof that this actually a thing? I don't see what mechanism exists to do this and I don't see why Samsung would even bother to do this.
No it's not. Government use of these platform or not, once they become big enough being cut out of them means being cut out of a significant part of society. We shouldn't accept "no recourse" and "no due process" just because its a private company.
Why is pedophilia such a problem on Roblox? It's because they heavily advertise towards children and one of the fastest ways for children to make money is asking their parents, then next is prostitution. Roblox is uniquely bad because they heavily advertise both products and the "self-made entrepreneur" image to children.
Putting the blame on nebulous "predators" when the system itself is clearly to blame is the very tacit Roblox relies on. Look at vehicular manslaughter are drunk and distracted drivers solely to blame for deaths? Clearly not since there are just as many drunks and phones in Europe as in the US. When the system creates more predators than exist otherwise then you know it needs to change.
If your son likes making games keep him on Godot. Your job as a parent is to find or build a good distribution system. you can see if he is generally interested or if he was pressured by an exploitative system grooming him into pumping out slop for the trough. Age verification is going to make the platform more exploitative in the business sense. Both in that it legitimizes bad practices and lets Roblox target their exploitative practices more effectively.
Very few kids are going to go though the incredible difficulty of making multiplayer work in something like Godot.
We don’t know what EU would become in 5 to 10 years in the future, and I would rather not have any identification information about me or family being stored by a government body or any other party that can track/link me or my family members
As an example if I’m obliged to share my ID data via government to open a twitter account how would I know that the government would not link my twitter account to my ID and later use that info keep track of me and prosecute?
People would think that it would never happen, but not long ago that actually happened in East Germany. The Stasi kept track/files on almost every East German and this would be a digital version of the same thing
I agree that governments should minimize collection of their citizen's data. I just don't see where it is supposed to happen in this case.
There is no guarantee that the app would stay open source and under public scrutiny forever. Governments have done way shady things in the past. Given the recent push for chat control, I would never trust anything put out by EU.
I don't fully trust my government. But I definitely trust it more than any American tech company.
I can also vote out my government. I can't do that for Big Tech.
No.
You can't. Not if you're in the minority. Tyranny of the majority is still tyranny.
You what you as an individual most certainly can do is stop using Roblox. Not ideal, but way easier than moving to a new country.
Is that a bad thing?
> you as an individual
I understand. Such is living in a society. No man is an island.
> Not ideal, but way easier than moving to a new country.
I've moved countries five times. I still haven't been able to get rid of my dependencies on Big Tech.
Meanwhile, all you need to do to get rid of a dependency on big tech is to log off.
People need to understand that having a majority opinion does not inherently give you the right to impose that opinion on everyone else. Such impositions must be done with extreme hesitancy and restraint.
That's why many democratic countries have a constitution which prevents the government from restricting certain individual rights even in the face of popular opinion. But ultimately, the constitution is just a piece of paper. If people are determined to impose their will on others, it can only do so much.
Democracy is the most fair way of doing so.
We're getting pretty deep into philosophical territory now, but I disagree. Human rights, to the extent they exist at all, are necessarily inherent properties of individuals.
E.g. If the majority decides people with dark skin are subhuman and therefore have no rights, the majority is most certainly not correct about that, because rights are not defined by the majority opinion. They are inherent.
The U.S. Declaration of Independence put it like this:
> We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness.--That to secure these rights, Governments are instituted among Men, deriving their just powers from the consent of the governed
I concur with this perspective; rights are inherent and inalienable, and the purpose of democratic government is to secure those rights (which already exist), not to create them.
What's sad is that there's a formulation that's actually correct. Rights are an inherent property of societies (or stable ones, at least). Note that I'm saying rights in an abstract sense, not necessarily any specific set of rights. Not every society will value the same things the same way.
>E.g. If the majority decides black people are subhuman and therefore have no rights, the majority is most certainly not correct about that, because rights are not defined by the majority opinion.
So it's an objective fact that they're incorrect? I.e. they can be shown to be incorrect without having to ask anyone's opinion? Okay, prove it.
>The U.S. Declaration of Independence put it like this:
That's an opinion. It's perfectly fine to think these things are so obvious they don't need to be justified, but I don't agree that that's true, even if I subjectively hold the same opinion.
Only if you believe in a creator that determined these right, which is not rooted in fact, but solely belief.
Personally, I do not believe a particular ethics exist as an absolute/scientific truth. It is just that some amount cooperation is generally better for everyone and virtually all humans want to avoid pain and seek happiness.
Even though I was a convinced utilitarianist when I was young, I think Kant's categorical imperatives are more powerful now: you should act only according to principles you would want everyone to adopt as a universal law. Or Rawls' original position [1].
Even though this might sound like an off-topic philosophical debate, I think it is very relevant to democracy. Purely egoism-based democracy would trample on the rights of minorities, etc. But in a democracy based on these principles, the majority would vote to project minorities, etc.
I am not sure how you would modify democracy to align with this. I think it is for a large part of education. E.g. if everyone thinks every choice is a zero-sum game (my loss is another's win and vise versa), democracy will go in a very dark direction.
The opinion of a few slave owners 250 years ago
> We hold these truths to be self-evident, that all men are created equal
For a given definition of "men"
> I concur with this perspective
Good for you. You have an opinion, doesn't make it a fact.
What we consider democracy went through a LOT of iteration, and continues to this day. Representative first-past-the-post is a form of democracy that can have the unfortunate side effect of the minority of the electorate establishing a tyranny of the majority. There is a lot of scholarship on how to make democratic systems more democratic.
And the northern states--they had slaves too.
Ulysses S. Grant, when asked why he didn't free his slaves until some time after the war, reportedly said something like "Good help is hard to come by these days." It's not easily verifiable in today's world of useless search engines and confidently wrong and/or lying AI, but this quote is, in one form or another:
"The sole object of this war is to restore the Union. Should I become convinced it has any other object, or that the Government designs its soldiers to execute the wishes of the Abolitionists, I pledge you my honor as a man and a soldier I would resign my commission and carry my sword to the other side."
- General Ulysses S. Grant, USA, in a letter to the Chicago Tribune, 1862
"My paramount object in this struggle is to save the Union, and is not either to save or destroy slavery. If I could save the Union without freeing any slave I would do it, and if I could save it by freeing all the slaves I would do it; and if I could save it by freeing some and leaving others alone I would also do that. What I do about slavery, and the colored race, I do because I believe it helps to save the Union; and I forbear because I do not believe it would help to save the Union."
- Abraham Lincoln, responding to Horace Greeley at the New York Tribune
https://archive.org/details/democraticspeake00caza
From page 32:
> Grant as a Talker
> He threatened to resign and cast his lot with the South.
> The editor of the Randolph Citizen recalls some interesting reminscenses of the great Reticent. He had a tongue at one time, it would seem:
> In the summer of 1861 General Grant, then Colonel of the Twenty-first Illinois Regiment of Infantry, was stationed at Mexico, on the North Missouri Railroad, and had command of the post. He remained several months, mingling freely with the people, regardless of the peculiar shade of any one's political opinions; and as the distinguished Colonel had then no thought of aspiring to the Presidency or a dictatorship, no occasion existed for the reticence to which latterly he owed the greater part of his popularity. Ulysses the Silent was then Ulysses the Garrulous, and embraced every fair opportunity which came in his way to express his sentiments and opinions in regard to political affairs. One of these declarations we distinctly remember. In a public conversion in Ringo's banking-house, a sterling Union man put this question to him: "What do you honestly think was the real object of this war on the part of the Federal Government?"
> "Sir," said Grant, "I have no doubt in the world that the sole object is the restoration of the Union. I will say further, though, that I am a Democrat--every man in my regiment is a Democrat--and whenever I shall be convinced that this war has for its object anything else than what I have mentioned, or that the Government designs using its soldiers to execute the purposes of the abolitionists, I pledge you my honor as a man and a soldier that I will not only resign my commission, but will carry my sword to the other side, and cast my lot with that people."
It's really quite remarkable that the victors of that war succeeded so marvelously in convincing people years later that it was about slavery--that the racist white people of the North went to war and died by the hundreds of thousands to free black slaves--and they have people utterly convinced of that to this day.
Lots of other enlightening stuff to be found in that book, and in other original sources. Get the facts now while you still can, and preserve them.
"This is only one among the many proofs I had witnessed of the fact, that the prejudice of color is not nearly so strong in the South as in the North. [In the South] it is not at all uncommon to see the black slaves of both sexes, shake hands with white people when they meet, and interchange friendly personal inquiries; but at the north I do not remember to have witnessed this once; and neither in Boston, New York, or Philadelphia would white persons generally like to be seen shaking hands and talking familiarly with blacks in the streets."
- James S. Buckingham, abolitionist
You can democratically trample the rights of minority groups.
Since it hasn't been linked in the tree of replies here, I'll add this for others: https://en.wikipedia.org/wiki/Tyranny_of_the_majority
And that I would definitely like to avoid.
This type of argument always sounds to me like someone was abused by their ex-partner, but now prefers their new partner who abuses them a little less.
This is a common negotiation practice in business as well as politics. You make some absolutely outrageous demand, and people protest, but then you give them the -originally planned- light version of it, and they will accept it; in light of the worse option.
There is no reason to endure this BS, hence I referenced manufacturing consent.
I sometimes can not believe how easily people allow themselves to be manipulated.
///
And you can vote out "Big Tech" - by refusing to use their products. Giving up your rights to play some videogame, as GP outlined, is an absolutely sad thing to witness. There are people who fought and died for the rights we have, and we allow them to be eroded for some silly consumerism.
That argument completely ignores network effects. Case in point, Twitter is, for better or worse, still where a lot of public figures post their updates and announcements. It also now randomly bans people unless they give their biometric data to an oligarch that supports right wing extremists: https://www.reddit.com/r/privacy/comments/1ukil0b/twitter_x_...
All in all, I'm not sure if it has anything to do with the original topic of EU being about to enforce 'age verification'.
My son had a similar "making games" interests and I just showed him the Godot engine. Roblox bosses are doing you a favor. Act now :D
- Netherlands, WWII: The Dutch civil registry meticulously recorded religion. It’s a major reason ~75% of Dutch Jews were killed, the highest rate in occupied Western Europe (vs ~25% in France, where records were poorer).
- US, Japanese internment: The Census Bureau provided block-level data on Japanese Americans in 1942 despite confidentiality guarantees; 2007 research showed individual names and addresses were shared too.
- Rwanda, 1994: Belgian colonial administrators had put ethnicity (Hutu/Tutsi) on national ID cards in the 1930s. Sixty years later those cards were the primary tool at genocide checkpoints.
There’s loads more. Europe may be safe now so it feels safe to give government this information. However, as shown in all the instances above, the information was collected for one reason and used for a wholly different reason when times changed.
Who knows what kinds of ethnicities, beliefs, behaviors or personal histories will be the focus of future regimes? It could be Roblox users, HN commenters, people who religiously repost x.com links as xcancel.com ones, anything. Whatever it is, they will have access to all the data on any system we allow them to record. This isn’t even a totally made up hypothetical from far away places, multiple governments in Europe were doing this kind of thing just decades ago. Historically speaking, we are all currently living in an unusually peaceful era, that will likely be temporary for many of us.
Records were poorer in France because René Carmille and the French resistance sabotaged the machines. Machines made by a large tech company which was a competitor to IBM.
> Who knows what kinds of ethnicities, beliefs, behaviors or personal histories will be the focus of future regimes?
Absolutely. But I do know who has that data -- big tech, and it's willing to sell it for a nominal price. No doubt that price will be higher for a deaparate government wanting to kill everyone with green eyes, but that just means a higher profit margin for facebook as they mine their shadow profiles.
I am not for collecting all data without a reason, sometimes probably too much is collected. But idiots can come with any rule if they want just to find someone to blame (I mean, they already use skin color or accent so if in need, they can come up with a rule like "born on a Monday").
[citation needed]
Actually the market leader app for scanning faces and documents is an Israeli company. They encourage to use mobile for scanning, for your convenience. They promise they delete the data. Yeah, if they're lying you can sue them in Israel.
But there's no alternative. The EU digital identity wallet would be the alternative. You control and exactly see, what kind of information the bank is getting from you and you can be sure that it doesn't flow through some sketchy third-party identification service.
Recently one supermarket chain added it for age verification on their self-service checkouts (e.g. buying alcohol).
The problem with this is you do not know what information they get, I guess the supermarket gets my full name, date of birth, personal code, etc. Their privacy policy says it will not be stored, but that means nothing.
So you could use an open source app, or government provided one, or one provided by your bank, whatever you trust the most to not be recording data about relying parties and sending it somewhere you don't want.
The version of the document currently on GitHub has heavily deviated from that original intention. This is very unfortunate.
Even so this version is supposed to still be incapable by design of sharing any data with a relying party other than "over 18" and was designed such that the only way for a relying party to determine your identity is to be colluding with the attestation provider, or by colluding with the wallet app.
To attempt to address the first issue they have the unfortunately optional ZKP protocol. The original design assumed that users could find a wallet that they were certain would not collude with the RPs, and was considered a non-issue, but unfortunately it is a huge hole in the current version.
"EU age verification app to ban any Android system not licensed by Google" 27-jul-2025 https://www.reddit.com/r/BuyFromEU/comments/1mah79o/eu_age_v...
and
"EU age verification app not planning desktop support" 24-sep-2025 https://news.ycombinator.com/item?id=45359074
It's not like it's a feature for you the end user, it doesn't solve any of your problems, on the contrary, it creates new ones.
Does Roblox sell them ? If no it's a non sequitur.
How much of a problem is the online availability of alcohol or cigarettes in the health of children ?
Additionally the amount of elderly that don't have or can't use a phone or don't have anyone that can help them with it will decrease rapidly anyway. In my experience it's mostly the same generation as the people that remember WWII.
These corrupt bafoons talk of sovereignty and then they pull stunts like this. Even if you're totally pro EU, vote with your actions if you can't outvote the Commission.
I am quite pessimistic. They couldn't care less about some 2% of people who just stop using their services.
It would be a difficult choice but would it really be so bad to be excluded from such a society? Don't a lot of people from silicon valley dream to be farmers in the wildlands?
You won't be able to open a bank account to receive your salary.
You won't be able to buy train or plane tickets.
My point is I am most worried that these kind of "digital verification" type things most impact actual necessities. The social media I couldn't care less about. "I just won't use it" isn't really a solution.
idk why people are so scared of it, do you really believe they don't know what you do on your personal internet connection linked to your name and payment data ?
Like yeah sure if you pay everything in cash and never use internet OK that's a big problem, but for the average HN shitposter who's already terminally online it really doesn't change much
Do you have to present this ID for every purchase you make or every website you visit? Will it be stored and processed by every shop you enter? If not, how is this relevant here? Currently, the personal data exists but is not accessed by anyone unless it is really required. And even then, the scope can be minimized if the user wants.
> do you really believe they don't know what you do on your personal internet connection linked to your name and payment data ?
Yes. I use Whonix on Qubes to access HN and other websites.
> but for the average HN shitposter who's already terminally online it really doesn't change much
Speak for yourself.
Basically yes, your mobile connection is attached to a name, your landline is attached to a name, your adresse too, the card you use to pay online too.
Many people in the Western Europe used, until very recently, prepaid anonymous mobile data cards that they recharged monthly with charging vouchers paid for in cash.
All this ended in the last 5 - 10 years. The U.S.-American corporate glass citizen slave mentality is actually a little tad bit new here, thus the outrage.
In Europe it was the norm far longer than in the U.S.A.
Prepaid card was just a payment thing, not anonymity thing. I know, because I functioned on prepaid cards for anonymity unrelated reasons.
I’m still having to deal with making some sort of legal agreement with EVERY website I visit over cookies constantly… I just don’t care anymore / click whatever.
Same goes for age ID things too.
https://addons.mozilla.org/en-US/firefox/addon/consent-o-mat...
It also exists for other browsers.
I am not affiliated,but I have it on my devices and even on my phone, it's quite good and I very rarely get cookie popups now.
unless it's one of the big guys, devs either sell the extensions or get hacked, it has happened multiple times.
That's the problem when you want to be pro-business while keeping the vague intent of protecting privacy.
They didn't mandate cookie banner, you can either not track or add a cookie banner. Of course businesses living off surveillance capitalism will chose the cookie banner. They could have banned tracking altogether, and chose not to because “it's bad for business”.
App and device verification based on Google Play Integrity API and Apple App Attestation
But I can't find that anywhere. Am I missing something?
Yes, that this post is propaganda.
Edit it was not visible from the discussion link but it is visible from the issue link below. Also it seems to be transferred over from a totally different repo?
https://github.com/eu-digital-identity-wallet/av-doc-technic...
It was removed from there to clarify the entire "Hey, this application is not done yet"
It being in the reference implementation instead of the spec is a massive difference. One means that it's just there to show an example, and we should push national governments to do it better in their implementations, while the other would mean that it'd be a requirement for all implementations, which it doesn't appear to be.
It also looks like the reference implementation removed that functionality entirely several months ago: https://github.com/eu-digital-identity-wallet/av-app-android...
Play Integrity is still recommended to be evaluated in the documentation, with no mentions of its consequences. https://github.com/eu-digital-identity-wallet/av-app-android...
As a netizen it's your duty to avoid, oppose, and circumvent anything that forces you to use your real identity.
What will you do when Apple/Google or the US Government effective immediately delete/block your app? The impact initially may be small but after a few years if widely used, you can break a country.
(Reminder: we know Persona's verification software already shares verification data with the federal government. It's a leap to modifying other apps, but within the realm of possibility of US government power. There is absolutely desire from them to gather blackmail material on politically important people, and age verification systems connected to adult sites/apps are a great way to do it)
We have a definition at the beginning, for "Social media and other digital services (in short, social media+)":
“Within the scope of this report, the terms ‘social media+’ and ‘social media and other digital services’, are used to broadly define services that may be available to minors and contain age-inappropriate and/or risky features (for example, addictive and harmful features, among which infinite scroll, autoplay, recommendation algorithms and persistent notifications) and/or content. Social media and other digital services providers include online platforms serving as intermediaries of content from third parties, such as social media, as well as app stores. AI systems posing risks to minors’ safety and development, including AI companions, video games exposing children to harmful commercial practices or dangerous contacts, and video-sharing platforms enabling age-inappropriate access to minors are also included.”
So, let's see, services that may contain age-inappropriate and/or risky content, "online platforms serving as intermediaries of content from third parties".
How quickly can you come up with something that wouldn't fall in that definition?
It seems that anything that allows user-contributed content (such as plain old forums) or communication among users would be comprised in it.
And, yes, to be sure we explicitly include app stores (I guess including e.g. F-Droid, and what about software repositories?) and video games with intercommunication features.
What is this definition used for?
Recommendation 1 of chapter 3: “A harmonised EU-wide access restriction to *social media and other digital services*, including AI companions, for children under 13 is necessary.”
This is a report, not law, but it was commissioned by Ursula von der Leyen and “The report is intended to inform future actions to be proposed by the European Commission and EU Member States to reinforce child safety online.”
As a european if I wanted to see the glass half-full I'd say: at least the good news is that from that headline we can name a gigantic loser... Microsoft.
Unrelated to the substance of the comment but this is a depressing example. Imagine having to verify your age and your identity to buy a movie ticket. This is pure insanity.
Dark times are ahead. Anyone that doesn't see we'll all be living in dictatorships within the next 10 years is putting their head in the sand.
It's actually disingenuous to think there won't be. This is a repository for a mobile app only.
Such a strong new legal framework must consider consumer hardware actually in use:
- Android variations Like GrapheneOS, Huawei's HarmonyOS, older phones running custom ROMs - Linux phones, which are sold in the EU and by EU companies
- Desktop operating systems
All of them can run Web Apps, and thus need age verification
The EU developed system excludes the 1% of people for which the popular mobile solutions do not work and also make the rest 99% totally dependent on the selected corporations.
Are there any other Operating Systems than iOS, Android or Android flavors?
WebOS was nice but who is still using this? Symbian? Can you even use Social Media Apps with another phone OS?
I remember a gov.uk team presentation. They had a usecase of someone using a PS Vita to access a government assistance program because that was the only device they had access to.
Among 450 million people in the EU there are definitely more OSes than just latest versions of iOS and Android.
Yes, there are many more: GNU/Linux, Windows, macOS, *BSD, etc.
This will prevent people who only own a computer and not a modern iOS/Android smartphone from accessing services and platforms.
This also sets a very strong anti-competition pressure. Which company will try now to invest on developing a new OS for smartphones if we already know users will not be able to access the most popular services & platforms with it?
Spanish speakers in Spain will just register services in Latinamerica sites with a VPN. Despite the dialect differences, non-jargon Spanish it's understood everywhere and once they got their user registered they can switch the country anytime.
Distros like Trisquel will just set their sites and mirrors outside the EU. And, well, if they provide a portable torrent client for Windows among the torrent the law would be utterly broken.
Switzerland absolutely complies to EU (and US) demands for a long time now, when it comes to prosecuting crimes.
Swiss privacy and anonymity is a myth from a bygone era.
Like Windows, MacOS and Linux?
There is GrapheneOS, HarmonyOS by Huawei, LineageOS for older phones and many more Android ROMs.
Additionally, Linux phones exist and are already sold in the EU to consumers, not just a prototype.
There's really no justification around limiting the OS selection.
There is also Linux, Windows, MacOS and many more operatint system not limited to phones.
There's also old versions of iOS and Android. We don't want to end up in a situation where people are locked into one of only two vendors and can be forced to keep buying the newest model to use an ID app that only supports the most recent software. That'd be even worse for the environment than the current disposable smartphone culture.
Everything to do with the age verification push is corrupt and stupid to begin with. There isn't even a legitimate cause behind all this for forcing ANY app, even if it didn't also force people to buy a specific, expensive, privacy-invading American product.
The (actual) complaint of the thread appears to be resolved already (which would make sense given this is old news):
> In the README, the following is listed:
>> App and device verification based on Google Play Integrity API and Apple App Attestation
The README.md does not appear to feature such a section (nor any of the other files for that matter).
Separately, the title is editorializing, and falsely suggests there's some big bad EU app, even though the app that does exist is merely a reference implementation, not for end user usage. There's a reason the repository you're linking a discussion thread from only holds specs.
Edit:
> the specification does not prohibit it
My account has been rate-limited, so I'm not able to reply directly. Nevertheless, I'm sure you can appreciate that your title is still quite the lie then. "Not prohibiting it" is very different from "forcing", after all.