Cyber experts say the EU's age verification app has glaring privacy and security problems; after saying it was ready, EU officials say the app is “still a demo”
Politico
Context & Ripple Effects
The Commission had moved from a blueprint to be tested by France, Spain, Italy, Denmark, and Greece to an open-source app presented as a verification standard. This report interrupts that rollout arc by putting the implementation, rather than the policy goal, at issue.
The reversal from “ready” to “still a demo” is especially consequential because the EU is both promoting the tool and expected to meet a high privacy standard in deploying it. Related coverage of an EU privacy-rules breach underscores the sensitivity of that institutional credibility.
First-order effects
EU officials must treat the age-verification app as a demonstration rather than a production-ready tool, while privacy and security concerns require technical remediation before broader use.
The countries slated to test the blueprint and services considering integration face uncertainty over the app’s readiness and safeguards.
Second-order effects
The episode raises the bar for any identity, wallet, or verification provider seeking to align with the EU approach: technical openness alone will not establish trust without credible privacy and security controls.
Platforms and national authorities may need to preserve alternative age-assurance paths while the EU blueprint is hardened, complicating efforts to make one approach a common standard.
Third-order effects
If repeated, gaps between regulatory ambition and deployable privacy-preserving infrastructure could slow the EU’s ability to turn digital-policy requirements into interoperable implementation standards.
The longer-term contest will be over whether age assurance can be made both effective and minimally data-exposing; failure on either dimension risks weakening public acceptance of the model.
The trend: This is part of the broader shift from writing online-safety rules to building the privacy-preserving technical infrastructure required to enforce them.
Unsurprisingly, the EU's new age verification app ran into trouble almost immediately after release, with security researchers exposing practical ways it could be broken. …
Open-source code: good, because nerds and experts can kick its tyres. Red-teaming *before* you release your open-source app: better, so that they find the problems *before* the nerds and experts kick the tyres and embarrass you with the easily found issues you should have alread…
Given government plans in this area, and the enormously high stakes involved in verification, you'd think the EU could do better than this. Then again, experience shows it's hardly surprising - government isn't good at building apps.
The EU's unveiling of a mobile app to check people's age online has quickly turned sour, as cybersecurity experts found glaring privacy and security problems with the code and it took them 2 minutes to hack the app — www.politico.eu/article/eu-b...
Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. https://www.politico.eu/... (ICYMI: I have a blog post on why age verification laws are a bad idea to begin with: https://this.weekinsecurity.c…