Загрузка видео...
Не удалось загрузить видео
Bypassing #EU #AgeVerification using their own infrastructure. I've ported the Android app logic to a Chrome extension - stripping out the pesky step of handing over biometric data which they can leak... and pass verification instantly. Step 1: Install the extension Step 2: Register an identity (just once) Step... show more
1,182,258 просмотров • 5 месяцев назад •via X (Twitter)
Комментарии: 46

this is the core problem with ALL age verification bullshit its either trackable or its easily spoofable with no way of knowing

Bingo.

i just found out about you, and i really love this rabbit hole lmao. appreciate your work a lot

Appreciate that, thank you!

Yeah thats the issue I documented 5 months ago. The annoying thing will be that you need to find an implementation to extract the private keys from every 3 months.

So this is essentially less effective than simple "Are you over 18" popup.

I don't think we should be helping the EU harden this system. I wish security researchers would just refuse to touch it.

Double-edged sword Louis. I'm with you; I don't want to help build a surveillance state. But, it's coming regardless... and issues like these expose users to real-world risk. Better to expose them while there's minimal risk. I can tackle the bugs; the legislation is way beyond me.

>But, it's coming regardless Well yeah, if you help build it, it certainly is. >and issues like these expose users to real-world risk Yeah, which might get the EU to back down. >Better to expose them while there's minimal risk. You've just swapped out one risk for another.

Let me be clear: people getting hurt by this system *visibly and immediately* is the best possible outcome.

@Paul_Reviews Thank you

@Paul_Reviews I'm too autistic to let it slide🫡

It’s worse than amateurish – it’s a scam that must have cost the EU a fortune, and therefore us!!!!!

We get the point the app is not secure. But let's not offer them more free pentesting. Strategically I would argue that it's better to let them believe their own lies (it's secure, interoperable, etc) and fail miserably when confronted with reality (bypass, black market, etc).

curious how many millions and months did they spent on this app

This is not me bookmarking this post, move along.... As an EU citizen, all I can say is: "everything is ok"

Why are we iron manning the government plan? Let them fail - act like it’s perfect - stop helping them see where they can tighten the noose

Broken in under 2 minutes. The only fix is tying the key to your identity, which turns an age check into a surveillance system. This isn't a fixable bug. IT'S THE INEVITABLE OUTCOME OF CENTRALIZED VERIFICATION. The architecture was the decision. The flaw was guaranteed.

I'm starting to think that the obvious flaws are there by design in order to enforce worse dystopic controls down the line

Keep doing this please. If u stop, people forget, and nothing changes

If this shit gets leaked it will be a nuclear meltdown of privacy information.

🤯🤣🤣

And so the arms race begins. They will weaponize this to no end to prevent you from bypassing it, starting with arresting anyone saying or doing anything as you suggest, more technology, more integration into operating systems, force of law compliance for your ISP, your bank, your social networks... The amounts of money the EU is going to request and spend on enforcing this is going to be astronomically large and ever growing, which is exactly what they want. They are going to use your money to silence you, punish you and remove you from online civilization unless you comply with everything they tell you to do.

is this extension opensource?

Depends if I publish it. Unlikely at the moment... but hopefully those in charge will realise this is doomed to fail.

you should, no matter what. "the light of day is the best disinfectant"

The app is a proof of concept. The whole idea is that it is tied to your personal government data. However the idea is also that it generates a zero-knowledge proof, which means that once it's signed by the authorities based on government data, you don't need to verify it with them and it doesn't contain anything except "over 18". You're using a proof of concept that isn't cryptically tied to any particular government and going "omg look I can pretend to be a government!" with it. Well duh, of course you can.

Maybe i'm grossly overestimating our EU overlords, but couldn't this be a way to get 'the public' to 'demand' more security and move the discussion from 'yes' or 'no' to 'how secure should it be' (talking past the sale)?

Flaws in an early development demo? Unheard of! Preposterous! Has never happened on any other project's development.

President says "technically ready, check the code"... but it's a early prototype? Sorry, doesn't wash.

Too bad the president is just a spokesperson and not actually involved in the project. Any CEO will say their product is technically ready the moment they get it running on a single system too.

“Jarvis, activate the goyim control protocol. Make no mistakes”

Tbqh the extension with a non real id would be the best approach to mess with the cockroaches fascimoves

As long as you promise to always be over 18, the system is working very well 🫣

Do you have the source code somewhere? Happy to create an Open Source port for Safari on iPhone, iPad and macOS.

Not all heroes wear capes!

“Hackers & p*dos have found an unpatchable flaw in the system, we must PROTECT THE KIDS” –> tracking and monitoring.

extremely disturbing "This isn't a bug... it's a fundamental design flaw they can't solve without irrevocably tying a key to you personally; which then allows tracking/monitoring"

That's 4 million euro and half a year of bureaucratic software development down the drain in less than 48 hours. They might want to learn from this, next time they overstep their role.

Hahaha Von der Leyen and the EU look like complete fools. Good job Paul

So you manage to hack and bypass a thing made by EU chosen "expert" (i suppose) in less than a week... at this point the whole thing is an absolute joke in every regard.

Paul by any chance do you know who did the app for the stasi, i mean CE?

Where there's a will there's a way.

Great work! Does your extension work in Brave?

Side note: is it possible to port that to, let's say a DNS server like pi-hole and then let it handle all requests automatically? Asking for a friend of course...

Zeit, euch die Verantwortliche dafür mal vorzustellen

