<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app.]]></title><description><![CDATA[<p>Embarrassing times for the European Commission after  security researchers found flaws within minutes of using its age verification app. <a href="https://www.politico.eu/article/eu-brussels-launched-age-checking-app-hackers-say-took-them-2-minutes-break-it/" rel="nofollow noopener"><span>https://www.</span><span>politico.eu/article/eu-brussel</span><span>s-launched-age-checking-app-hackers-say-took-them-2-minutes-break-it/</span></a> </p><p>(ICYMI: I have a blog post on why age verification laws are a bad idea to begin with: <a href="https://this.weekinsecurity.com/papers-please-age-verification-laws-threaten-everyones-online-security-and-privacy/" rel="nofollow noopener"><span>https://</span><span>this.weekinsecurity.com/papers</span><span>-please-age-verification-laws-threaten-everyones-online-security-and-privacy/</span></a>)</p>]]></description><link>https://board.circlewithadot.net/topic/33bd5c9d-1d71-4473-9150-a5328e3c36a2/embarrassing-times-for-the-european-commission-after-security-researchers-found-flaws-within-minutes-of-using-its-age-verification-app.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 07:02:10 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/33bd5c9d-1d71-4473-9150-a5328e3c36a2.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 17 Apr 2026 13:21:24 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 21:28:01 GMT]]></title><description><![CDATA[<p><span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> </p><p>Awesome!  The way I see it, an age verification app should be trivially breakable, and any kid who breaks it should have full adult privileges.  </p><p>Start 'em Young!</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/lemgandi/statuses/116422166541026767</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/lemgandi/statuses/116422166541026767</guid><dc:creator><![CDATA[lemgandi@mastodon.social]]></dc:creator><pubDate>Fri, 17 Apr 2026 21:28:01 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 19:39:46 GMT]]></title><description><![CDATA[<p><span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> <br /><span><a href="/user/eucommission%40ec.social-network.europa.eu">@<span>EUCommission</span></a></span> <br /><span><a href="/user/echo_pbreyer%40digitalcourage.social">@<span>echo_pbreyer</span></a></span> </p><p>instead of having age verification, </p><p>since we're supposedly pursuing online safety</p><p>why not take cues from industrial safety, </p><p>and mandate a BIG red button on a yellow background for every post/user/channel that when clicked, <br />immediately hides and unloads that post/user/channel's content for the person pressing it, with a pop-up to report the post/user/channel to the moderation staff of the service?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/breathOfLife/statuses/116421740901958782</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/breathOfLife/statuses/116421740901958782</guid><dc:creator><![CDATA[breathoflife@infosec.exchange]]></dc:creator><pubDate>Fri, 17 Apr 2026 19:39:46 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 19:21:09 GMT]]></title><description><![CDATA[<p><span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> <br />What I really don't understand, especially when it comes to security-relevant software, is why the code isn't reviewed and the software isn't tested by independent external experts before release? Such an embarrassing situation, just like in the case of the electronic patient record (ePa), could be avoided.</p>]]></description><link>https://board.circlewithadot.net/post/https://social.anoxinon.de/users/gemini/statuses/116421667666143163</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.anoxinon.de/users/gemini/statuses/116421667666143163</guid><dc:creator><![CDATA[gemini@social.anoxinon.de]]></dc:creator><pubDate>Fri, 17 Apr 2026 19:21:09 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 18:22:07 GMT]]></title><description><![CDATA[<p><span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> </p><p>Told you so…</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/xs4me2/statuses/116421435523528744</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/xs4me2/statuses/116421435523528744</guid><dc:creator><![CDATA[xs4me2@mastodon.social]]></dc:creator><pubDate>Fri, 17 Apr 2026 18:22:07 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 18:02:46 GMT]]></title><description><![CDATA[<p><span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> *crazed* hahahahahahaha</p><p>And these are the people that people in country keep putting in charge. Here in the USA, we are the example of what not to do. We should be a warning, not a model to follow.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/atraidez/statuses/116421359473113218</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/atraidez/statuses/116421359473113218</guid><dc:creator><![CDATA[atraidez@infosec.exchange]]></dc:creator><pubDate>Fri, 17 Apr 2026 18:02:46 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 17:30:18 GMT]]></title><description><![CDATA[<p><span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> let's stop doing <a href="https://mastodon.social/tags/europe" rel="tag">#<span>europe</span></a> 's work for them. Citizens of the <a href="https://mastodon.social/tags/eu" rel="tag">#<span>eu</span></a> are going to need every single one of these exploits to circumvent this <a href="https://mastodon.social/tags/euwallet" rel="tag">#<span>euwallet</span></a> </p><p>This is the single edge case in which ethical disclosure of software vulnerabilities works against the community. Let's STOP fixing this <a href="https://mastodon.social/tags/software" rel="tag">#<span>software</span></a> 🫡<img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f64f.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--pray" style="height:23px;width:auto;vertical-align:middle" title="🙏" alt="🙏" /></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116401107525975086/statuses/116421231824209671</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116401107525975086/statuses/116421231824209671</guid><dc:creator><![CDATA[dazrunner@mastodon.social]]></dc:creator><pubDate>Fri, 17 Apr 2026 17:30:18 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 17:23:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/kaidu%40mastodon.social">@<span>kaidu</span></a></span> <span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> </p><p>It stores medical presciptions, driver's licences, educational qualifications</p><p>All exchanges of data with third-parties are tracked ie. it knows who you verified your data with</p><p>It uses the app stores to install on your phone ie. Google and Apple - so you know it's trustworthy. lol.</p><p>I examined the repo closely. I took out 6 key points. I also shot a highlight video if you're interested?</p><p><a href="https://mastodon.social/@DazRunner/116410668945303557" rel="nofollow noopener"><span>https://</span><span>mastodon.social/@DazRunner/116</span><span>410668945303557</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116401107525975086/statuses/116421205199947966</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116401107525975086/statuses/116421205199947966</guid><dc:creator><![CDATA[dazrunner@mastodon.social]]></dc:creator><pubDate>Fri, 17 Apr 2026 17:23:32 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 16:39:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> by starting + get reviews and tips &gt;&gt; there will come something nice I guess </p><p>Comitees are also just people <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f609.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--wink" style="height:23px;width:auto;vertical-align:middle" title="😉" alt="😉" /></p>]]></description><link>https://board.circlewithadot.net/post/https://social.vivaldi.net/users/EllisLove/statuses/116421031350673594</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.vivaldi.net/users/EllisLove/statuses/116421031350673594</guid><dc:creator><![CDATA[ellislove@social.vivaldi.net]]></dc:creator><pubDate>Fri, 17 Apr 2026 16:39:19 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 16:37:25 GMT]]></title><description><![CDATA[<p><span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> I also now read your blog post and for me it seems that the eu age verification app seems to adresss all your concerns:<br />- it does not store private data (except for age)<br />- it does not use an ID<br />- it is not run by a private company <br />It is even open source!.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/kaidu/statuses/116421023859165353</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/kaidu/statuses/116421023859165353</guid><dc:creator><![CDATA[kaidu@mastodon.social]]></dc:creator><pubDate>Fri, 17 Apr 2026 16:37:25 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 16:30:36 GMT]]></title><description><![CDATA[<p><span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> HACK THE AGEVERIFICATION APPS!</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/ap/users/116213669892773543/statuses/116420997069804610</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/ap/users/116213669892773543/statuses/116420997069804610</guid><dc:creator><![CDATA[rogue_cells@chaos.social]]></dc:creator><pubDate>Fri, 17 Apr 2026 16:30:36 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 16:24:56 GMT]]></title><description><![CDATA[<p><span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> isn't that the point of being open source? So that everyone can hack it and show where the flaws are? So that it can be improved. I'm not sure about your experience with apps, but I receive updates several times per week, sometimes multiple times a day. This project is not even in its released form yet and so many people have doomed it already. I don't understand the dooming as if everything is lost and over. You can never have perfect software from the first try.</p>]]></description><link>https://board.circlewithadot.net/post/https://androiddev.social/users/luboganev/statuses/116420974787072925</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://androiddev.social/users/luboganev/statuses/116420974787072925</guid><dc:creator><![CDATA[luboganev@androiddev.social]]></dc:creator><pubDate>Fri, 17 Apr 2026 16:24:56 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 16:17:23 GMT]]></title><description><![CDATA[<p><span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> Don't fully understand the complaints. The app is just that: an app on your phone to simplify the verification process. I don't think it is even necessary to "hack" it, you could just write your own fork of the app, right?<br />The age verification process itself seems to be unrelated to that problem.</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/kaidu/statuses/116420945114418600</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/kaidu/statuses/116420945114418600</guid><dc:creator><![CDATA[kaidu@mastodon.social]]></dc:creator><pubDate>Fri, 17 Apr 2026 16:17:23 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 16:05:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/zackwhittaker%40mastodon.social" rel="nofollow noopener">@<span>zackwhittaker</span></a></span> </p><p>Full disclosure: I am very much opposed to this very, very bad idea.</p><p><a href="https://infosec.exchange/@avuko/116412737384374405"><span>https://</span><span>infosec.exchange/@avuko/116412</span><span>737384374405</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/avuko/statuses/116420896548581833</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/avuko/statuses/116420896548581833</guid><dc:creator><![CDATA[avuko@infosec.exchange]]></dc:creator><pubDate>Fri, 17 Apr 2026 16:05:02 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 16:02:14 GMT]]></title><description><![CDATA[<p><span><a href="/user/zackwhittaker%40mastodon.social" rel="nofollow noopener">@<span>zackwhittaker</span></a></span> </p><p><a href="https://digital-strategy.ec.europa.eu/en/news/commission-releases-enhanced-second-version-age-verification-blueprint" rel="nofollow noopener"><span>https://</span><span>digital-strategy.ec.europa.eu/</span><span>en/news/commission-releases-enhanced-second-version-age-verification-blueprint</span></a></p><blockquote><p>"Work is ongoing to include zero-knowledge proof technology [...] this technology will further underscore the commitment to privacy-focused innovation.</p></blockquote><p>From the documentation: </p><p><a href="https://github.com/eu-digital-identity-wallet/av-doc-technical-specification/blob/main/docs/architecture-and-technical-specifications.md" rel="nofollow noopener"><span>https://</span><span>github.com/eu-digital-identity</span><span>-wallet/av-doc-technical-specification/blob/main/docs/architecture-and-technical-specifications.md</span></a></p><blockquote><h1>Zero-Knowledge Proofs</h1><p><strong>A</strong> <em>next version</em> of the Technical Specifications for Age Verification Solutions will include as an experimental feature the Zero-Knowledge Proof (ZKP) solution [...]</p></blockquote><p>"A next version", "experimental", but fully committed to privacy-focused innovation.</p><p>It includes this gem:</p><blockquote><p>This backward compatibility allows AVIs to gracefully fall back to traditional protocols in environments where ZKPs are not supported.</p></blockquote><p>Not a cryptographer, but this backwards compatibility (on something that doesn't exist yet, but let's ignore that) feels like a downgrade attack waiting to happen.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/avuko/statuses/116420885537984155</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/avuko/statuses/116420885537984155</guid><dc:creator><![CDATA[avuko@infosec.exchange]]></dc:creator><pubDate>Fri, 17 Apr 2026 16:02:14 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 15:49:34 GMT]]></title><description><![CDATA[<p class="quote-inline">RE: <a href="https://mastodon.social/@zackwhittaker/116420253095786124" rel="nofollow noopener"><span>https://</span><span>mastodon.social/@zackwhittaker</span><span>/116420253095786124</span></a></p><p><span><a href="/user/zackwhittaker%40mastodon.social">@<span>zackwhittaker</span></a></span> <br />Yep, two minutes to hack or break.</p><p>Bet my grandchildren ccould do it in one minute. </p><p>Age verifaction apps, software will never work for there intended purpose. And who alone knows their unintended consequences. Bad idea best left alone.<br /><a href="https://mastodon.social/tags/ageverification" rel="tag">#<span>ageverification</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116294774733552831/statuses/116420835697775204</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/ap/users/116294774733552831/statuses/116420835697775204</guid><dc:creator><![CDATA[mediocreman@mastodon.social]]></dc:creator><pubDate>Fri, 17 Apr 2026 15:49:34 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 15:46:37 GMT]]></title><description><![CDATA[<p><span><a href="/user/zackwhittaker%40mastodon.social" rel="nofollow noopener noreferrer">@<span>zackwhittaker</span></a></span> what do youcexpect with <a href="https://jorts.horse/tags/Zensursula" rel="tag">#<span>Zensursula</span></a> at the helm of <span><a href="/user/eucommission%40ec.social-network.europa.eu" rel="nofollow noopener noreferrer">@<span>EUCommission</span></a></span> ?</p><ul><li>Her biggest <a href="https://jorts.horse/tags/FailToFame" rel="tag">#<span>FailToFame</span></a> was insulting <em>everyone</em> who was more <a href="https://jorts.horse/tags/TechLiterate" rel="tag">#<span>TechLiterate</span></a> than her (aka. able to change <a href="https://jorts.horse/tags/DNS" rel="tag">#<span>DNS</span></a> settings) as <em>"hardened pedo criminal"</em> almost 20 years ago, to the point that CSA victims had to tell her to <em>'STFU!'</em><ul><li>I still demand her <em>personal apology</em> to this day, <em>with interest</em>!!!</li></ul></li></ul>]]></description><link>https://board.circlewithadot.net/post/https://jorts.horse/users/kkarhan/statuses/116420824077995304</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://jorts.horse/users/kkarhan/statuses/116420824077995304</guid><dc:creator><![CDATA[kkarhan@jorts.horse]]></dc:creator><pubDate>Fri, 17 Apr 2026 15:46:37 GMT</pubDate></item><item><title><![CDATA[Reply to Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. on Fri, 17 Apr 2026 14:08:32 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/zackwhittaker%40mastodon.social" aria-label="Profile: zackwhittaker@mastodon.social">@<bdi>zackwhittaker@mastodon.social</bdi></a> I'm not sure you can call it a hack. You can change the app pin from outside the app if you have access to the phone and it's unlocked.</p>
]]></description><link>https://board.circlewithadot.net/post/https://toot.pouyan.net/objects/694226bc-dd34-487d-a78e-2a78c431d4f9</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://toot.pouyan.net/objects/694226bc-dd34-487d-a78e-2a78c431d4f9</guid><dc:creator><![CDATA[i@toot.pouyan.net]]></dc:creator><pubDate>Fri, 17 Apr 2026 14:08:32 GMT</pubDate></item></channel></rss>