Cyber experts say the EU's age verification app has glaring privacy and security problems; after saying it was ready, EU officials say the app is “still a demo”
Cyber experts say they have found holes in Brussels' age verification app, despite claims by the EU executive that it is “technically ready.”
Politico
Context & Ripple Effects
The Commission first positioned a common age-assurance blueprint for testing in five member states, then presented an open-source, ID-based app as a model for verification technology. The latest reporting puts the implementation gap—not the policy objective—at the center of the rollout.
That gap matters because the EU is attempting to make privacy-preserving age checks deployable across services while retaining credibility on data protection after prior scrutiny of its own privacy practices.
First-order effects
EU officials must recast the app from a deployment-ready tool to a demonstration, while addressing the reported privacy and security weaknesses before broader use.
The national testers and online services expected to rely on the blueprint face uncertainty over implementation timing and whether the app can safely handle identity-linked age checks.
Second-order effects
An open-source release lets independent researchers find flaws early, but it also increases pressure on the Commission to show a transparent remediation process rather than rely on readiness claims.
Platforms and national authorities may keep evaluating alternative age-assurance methods or delay integrations until the EU blueprint’s security and privacy properties are validated.
Third-order effects
If age-verification systems become a recurring target for security and privacy failures, trust in ID-linked online safeguards could become the limiting factor in enforcement, not merely legal mandates.
The episode reinforces a broader design requirement for digital regulation: public infrastructure meant to protect users must be independently auditable and privacy-resilient before it can serve as a cross-border standard.
The trend: The EU is moving from setting online-safety obligations to confronting the operational challenge of building verification infrastructure that can meet both child-protection and privacy expectations.
The EU's unveiling of a mobile app to check people's age online has quickly turned sour, as cybersecurity experts found glaring privacy and security problems with the code and it took them 2 minutes to hack the app — www.politico.eu/article/eu-b...
Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. https://www.politico.eu/... (ICYMI: I have a blog post on why age verification laws are a bad idea to begin with: https://this.weekinsecurity.c…
Open-source code: good, because nerds and experts can kick its tyres. Red-teaming *before* you release your open-source app: better, so that they find the problems *before* the nerds and experts kick the tyres and embarrass you with the easily found issues you should have alread…
Given government plans in this area, and the enormously high stakes involved in verification, you'd think the EU could do better than this. Then again, experience shows it's hardly surprising - government isn't good at building apps.
Unsurprisingly, the EU's new age verification app ran into trouble almost immediately after release, with security researchers exposing practical ways it could be broken. …