Technology

Embarrassing data protection risk: EU age verification app already cracked

Expensive, flawed and quickly cracked: the EU’s planned app for age verification is currently proving to be a gigantic security risk. By simply interfering with configuration files, attackers can easily undermine data protection.

EU age test under criticism

The European Commission is planning an app for age verification on social networks. Commission President Ursula von der Leyen announced that the application could be launched shortly. It is intended to serve as a digital identification document and is based on the zero-knowledge proof process. Platforms only receive information about whether an age limit has been reached, but not the identity of the user. However, security experts express considerable doubts. They criticize the architecture of the open source application and point to security gaps.

A central point is the local storage of sensitive data on the end devices. A hasty start could damage trust in future digital identity projects such as the EUDI wallet. The IT security consultant Paul Moore shows in an article X Cancel that the system can be quickly bypassed. A PIN is assigned during setup. Although this is stored encrypted, it is not cryptographically linked to the identity information data store. This is considered a significant data protection risk. By removing certain values ​​in the configuration file, the PIN can be reset after a reboot while the verified ID data remains valid. Other vulnerabilities relate to the rate limit for PIN entries, which can be bypassed by resetting a counter. Biometric authentication can also be disabled by changing a single value.

Improvements are mandatory

The open source code allows for quick analysis by independent experts. The EU Commission defends the project, which costs around four million euros and is being developed by Scytales and Deutsche Telekom. Identity solutions of this type require complex cryptographic procedures, errors in implementation of which have repeatedly led to security incidents. According to the Commission, this is not yet a final version and is being continually revised.

Zero-knowledge systems are considered particularly demanding because they are designed to exclude conclusions about original data. The now known vulnerabilities primarily concern the interaction between local storage and cryptographic verification. Critics also doubt the effectiveness of technical age controls. Country restrictions can be circumvented using VPN, for example.

Recent Posts

GameStop boss: Game disks are completely irrelevant

GameStop does not see itself under pressure from the foreseeable end of physical PlayStation games.…

5 hours ago

Linux kernel update leads to performance decline on AMD GPUs

An upcoming Ubuntu kernel update brutally slows down AMD GPUs: The update to version 7.0.0-28.28…

5 hours ago

Tasteless but expensive: luxury gold cell phones honor Messi and Ronaldo

The luxury brand Caviar is celebrating the 2026 World Cup with exclusive special editions. The…

5 hours ago

Switch 1 & 2: Nintendo may be working on a smart universal dock

A patent that has surfaced suggests that Nintendo could be working on a universal dock…

5 hours ago

Steam Sales: Valve reveals dates for all discount promotions until July 2027

The dates for all upcoming sales on Valve's gaming platform Steam in the first half…

5 hours ago

Spotify: Former premium function is now free for all users

Spotify is unlocking a previous premium feature for all users. From now on, managed user…

5 hours ago