The European Union’s open-source age-verification project has drawn criticism after a maintainer confirmed that hardware-bound attestation is a mandatory architectural requirement, raising concerns about Linux, custom Android ROMs, and independently compiled applications.
The debate began in the GitHub repository for the project’s Android app, where a user argued that tying credentials to specific hardware environments would make it more difficult to support open systems.
Hardware-bound attestation is when a device proves the authenticity and integrity of its hardware/software using cryptographic evidence, with keys tied to secure hardware like Apple’s Secure Enclave or a TPM. It helps prevent attacks where a compromised device lies about its properties, uses an outdated attestation, or sends identifiers from a different device. - AI definition
…the central question remains unresolved: whether an EU-funded, open-source identity system can meaningfully remain open when real-world access depends not only on available source code, but also on approved applications, supported security hardware, trusted operating environments, and the policies of credential providers.