Loading video...

Video Failed to Load

Go Home

Bypassing #EU #AgeVerification using their own infrastructure. I've ported the Android app logic to a Chrome extension - stripping out the pesky step of handing over biometric data which they can leak... and pass verification instantly. Step 1: Install the extension Step 2: Register an identity (just once) Step...

1,182,258 views • 5 months ago •via X (Twitter)

46 Comments

beep boop's profile picture
beep boop5 months ago

this is the core problem with ALL age verification bullshit its either trackable or its easily spoofable with no way of knowing

Paul Moore - Security Consultant 's profile picture
Paul Moore - Security Consultant 5 months ago

Bingo.

artur's profile picture
artur5 months ago

i just found out about you, and i really love this rabbit hole lmao. appreciate your work a lot

Paul Moore - Security Consultant 's profile picture
Paul Moore - Security Consultant 5 months ago

Appreciate that, thank you!

Lilith Wittmann's profile picture
Lilith Wittmann5 months ago

Yeah thats the issue I documented 5 months ago. The annoying thing will be that you need to find an implementation to extract the private keys from every 3 months.

Vi iD's profile picture
Vi iD5 months ago

So this is essentially less effective than simple "Are you over 18" popup.

Louis Thibault's profile picture
Louis Thibault5 months ago

I don't think we should be helping the EU harden this system. I wish security researchers would just refuse to touch it.

Paul Moore - Security Consultant 's profile picture
Paul Moore - Security Consultant 5 months ago

Double-edged sword Louis. I'm with you; I don't want to help build a surveillance state. But, it's coming regardless... and issues like these expose users to real-world risk. Better to expose them while there's minimal risk. I can tackle the bugs; the legislation is way beyond me.

Louis Thibault's profile picture
Louis Thibault5 months ago

>But, it's coming regardless Well yeah, if you help build it, it certainly is. >and issues like these expose users to real-world risk Yeah, which might get the EU to back down. >Better to expose them while there's minimal risk. You've just swapped out one risk for another.

Louis Thibault's profile picture
Louis Thibault5 months ago

Let me be clear: people getting hurt by this system *visibly and immediately* is the best possible outcome.

Gingembre's profile picture
Gingembre5 months ago

@Paul_Reviews Thank you

Louis Thibault's profile picture
Louis Thibault5 months ago

@Paul_Reviews I'm too autistic to let it slide🫡

LE COLLECTIF 🅻🅴 🅲🅾🅻🅻🅴🅲🆃🅸🅵 🇫🇷's profile picture
LE COLLECTIF 🅻🅴 🅲🅾🅻🅻🅴🅲🆃🅸🅵 🇫🇷5 months ago

It’s worse than amateurish – it’s a scam that must have cost the EU a fortune, and therefore us!!!!!

Y4ss's profile picture
Y4ss5 months ago

We get the point the app is not secure. But let's not offer them more free pentesting. Strategically I would argue that it's better to let them believe their own lies (it's secure, interoperable, etc) and fail miserably when confronted with reality (bypass, black market, etc).

Anton Balakirev's profile picture
Anton Balakirev5 months ago

curious how many millions and months did they spent on this app

FactIndie 🔍's profile picture
FactIndie 🔍5 months ago

This is not me bookmarking this post, move along.... As an EU citizen, all I can say is: "everything is ok"

Rob's profile picture
Rob5 months ago

Why are we iron manning the government plan? Let them fail - act like it’s perfect - stop helping them see where they can tighten the noose

Aerendir Mobile's profile picture
Aerendir Mobile5 months ago

Broken in under 2 minutes. The only fix is tying the key to your identity, which turns an age check into a surveillance system. This isn't a fixable bug. IT'S THE INEVITABLE OUTCOME OF CENTRALIZED VERIFICATION. The architecture was the decision. The flaw was guaranteed.

eliothaise ✝️ ܝܫܘܥ's profile picture
eliothaise ✝️ ܝܫܘܥ5 months ago

I'm starting to think that the obvious flaws are there by design in order to enforce worse dystopic controls down the line

ivan@@'s profile picture
ivan@@5 months ago

Keep doing this please. If u stop, people forget, and nothing changes

AyC's profile picture
AyC5 months ago

If this shit gets leaked it will be a nuclear meltdown of privacy information.

O4T1S's profile picture
O4T1S5 months ago

🤯🤣🤣

Zaphod Beebelbox's profile picture
Zaphod Beebelbox5 months ago

And so the arms race begins. They will weaponize this to no end to prevent you from bypassing it, starting with arresting anyone saying or doing anything as you suggest, more technology, more integration into operating systems, force of law compliance for your ISP, your bank, your social networks... The amounts of money the EU is going to request and spend on enforcing this is going to be astronomically large and ever growing, which is exactly what they want. They are going to use your money to silence you, punish you and remove you from online civilization unless you comply with everything they tell you to do.

de augurkenkoning's profile picture
de augurkenkoning5 months ago

is this extension opensource?

Paul Moore - Security Consultant 's profile picture
Paul Moore - Security Consultant 5 months ago

Depends if I publish it. Unlikely at the moment... but hopefully those in charge will realise this is doomed to fail.

de augurkenkoning's profile picture
de augurkenkoning5 months ago

you should, no matter what. "the light of day is the best disinfectant"

IshayuG's profile picture
IshayuG5 months ago

The app is a proof of concept. The whole idea is that it is tied to your personal government data. However the idea is also that it generates a zero-knowledge proof, which means that once it's signed by the authorities based on government data, you don't need to verify it with them and it doesn't contain anything except "over 18". You're using a proof of concept that isn't cryptically tied to any particular government and going "omg look I can pretend to be a government!" with it. Well duh, of course you can.

Strawman's profile picture
Strawman5 months ago

Maybe i'm grossly overestimating our EU overlords, but couldn't this be a way to get 'the public' to 'demand' more security and move the discussion from 'yes' or 'no' to 'how secure should it be' (talking past the sale)?

castform5's profile picture
castform55 months ago

Flaws in an early development demo? Unheard of! Preposterous! Has never happened on any other project's development.

Paul Moore - Security Consultant 's profile picture
Paul Moore - Security Consultant 5 months ago

President says "technically ready, check the code"... but it's a early prototype? Sorry, doesn't wash.

castform5's profile picture
castform55 months ago

Too bad the president is just a spokesperson and not actually involved in the project. Any CEO will say their product is technically ready the moment they get it running on a single system too.

Jarvis's profile picture
Jarvis5 months ago

“Jarvis, activate the goyim control protocol. Make no mistakes”

Smarkie's profile picture
Smarkie5 months ago

Tbqh the extension with a non real id would be the best approach to mess with the cockroaches fascimoves

Lou Greenwood's profile picture
Lou Greenwood5 months ago

As long as you promise to always be over 18, the system is working very well 🫣

Jan 🌍🍣🍵😎🖖🦌🌲🍃🍍🏝️'s profile picture
Jan 🌍🍣🍵😎🖖🦌🌲🍃🍍🏝️5 months ago

Do you have the source code somewhere? Happy to create an Open Source port for Safari on iPhone, iPad and macOS.

Tim the Libertarian's profile picture
Tim the Libertarian5 months ago

Not all heroes wear capes!

Thomas's profile picture
Thomas5 months ago

“Hackers & p*dos have found an unpatchable flaw in the system, we must PROTECT THE KIDS” –> tracking and monitoring.

Merlin M's profile picture
Merlin M5 months ago

extremely disturbing "This isn't a bug... it's a fundamental design flaw they can't solve without irrevocably tying a key to you personally; which then allows tracking/monitoring"

Detlef C.'s profile picture
Detlef C.5 months ago

That's 4 million euro and half a year of bureaucratic software development down the drain in less than 48 hours. They might want to learn from this, next time they overstep their role.

Maanvis 🇳🇱 🍅's profile picture
Maanvis 🇳🇱 🍅5 months ago

Hahaha Von der Leyen and the EU look like complete fools. Good job Paul

Quentin's profile picture
Quentin5 months ago

So you manage to hack and bypass a thing made by EU chosen "expert" (i suppose) in less than a week... at this point the whole thing is an absolute joke in every regard.

Smarkie's profile picture
Smarkie5 months ago

Paul by any chance do you know who did the app for the stasi, i mean CE?

Secrets of Privacy | Make Yourself a Harder Target's profile picture
Secrets of Privacy | Make Yourself a Harder Target5 months ago

Where there's a will there's a way.

British Adventure News 🇬🇧's profile picture
British Adventure News 🇬🇧5 months ago

Great work! Does your extension work in Brave?

o/'s profile picture
o/5 months ago

Side note: is it possible to port that to, let's say a DNS server like pi-hole and then let it handle all requests automatically? Asking for a friend of course...

arbadacarba 🐈‍⬛🏴‍☠️'s profile picture
arbadacarba 🐈‍⬛🏴‍☠️5 months ago

Zeit, euch die Verantwortliche dafür mal vorzustellen

Related Videos