Bypassing the #EU#ageVerification app - part 2.
This time, it's v2026.04-2 - which won't run on rooted devices & has encrypted shared preferences.
If we ignore the fact they've used a 6 year old deprecated library, they haven't actually solved the problem at all. An attacker can just as easily delete ciphertext as plain text.
Ironically, they've tried to solve a problem they don't truly understand... much like the concept itself.
.@vonderleyen "The European #AgeVerification app is technically ready. It respects the highest privacy standards in the world. It's open-source, so anyone can check the code..."
I did. It didn't take long to find what looks like a serious #privacy issue.
The app goes to great lengths to protect the AV data AFTER collection (is_over_18: true is AES-GCM'd); it does so pretty well.
But, the source image used to collect that data is written to disk without encryption and not deleted correctly.
For NFC biometric data:
It pulls DG2 and writes a lossless PNG to the filesystem. It's only deleted on success. If it fails for any reason (user clicks back, scan fails & retries, app crashes etc), the full biometric image remains on the device in cache. This is protected with CE keys at the Android level, but the app makes no attempt to encrypt/protect them.
For selfie pictures:
Different scenario. These images are written to external storage in lossless PNG format, but they're never deleted. Not a cache... long-term storage. These are protected with DE keys at the Android level, but again, the app makes no attempt to encrypt/protect them.
This is akin to taking a picture of your passport/government ID using the camera app and keeping it just in case. You can encrypt data taken from it until you're blue in the face... leaving the original image on disk is crazy & unnecessary.
From a #GDPR standpoint:
Biometric data collected is special category data. If there's no lawful basis to retain it after processing, that's potentially a material breach.
https://t.co/PKQ0DWSYzL
Our statement on the UK government’s demand that all content on all devices sold or used in the country be scanned, on the presumption of nudity, using a dystopian combination of age verification and content scanning. This proposal will not safeguard children. It endangers us all.
https://t.co/VdWe9uhi8p
You might think banning/restricting VPNs was the plan.
It's not.
The #onlineSafetyAct doesn't work. They know it.
Banning #VPNs won't work. They know it.
The next logical & entirely predictable step is banning #encryption entirely... "to protect children".
Mark my words.
2023:
Omegle closes; it's monumentally stupid to video stream children to strangers.
2025:
#ageVerification normalizes the process of turning on your camera to any website for "safety", then forget to disable the camera.
202x:
Millions of videos of children leak.
A gentle reminder to those supporting #ageVerification / #ageEstimation...
You're arguing that some sites should prevent your children possibly uploading pictures/videos to the web... by introducing technology which forces all sites to upload a video to every site they visit; trustworthy or not.
Do you realise how little live video/audio is required to create convincing #deepFake videos of your children? Do you really want them floating about the web?
Think on your actions. Don't fall for the rhetoric.
Ask @leicesterliz, @The_AVPA or indeed any proponent and you won't get a coherent answer.
Nonsense. It's made a measurable difference.
It's demonstrated in the most obvious, irrefutable way that no amount of legislation from technically illiterate folk will protect children from content they're actively trying to access.
But then, that was never the intention.
It has however (and entirely coincidentally) censored public discourse... which they quietly admitted was the real motivation.
Bypassing the latest #EU#ageVerification app (2026.07-1) with a Chrome extension... again.
Despite 3 months of security hardening and genuine improvements across the board, the fundamental issue cannot be solved.
Anonymous age verification doesn't work.
Bypassing #EU#AgeVerification using their own infrastructure.
I've ported the Android app logic to a Chrome extension - stripping out the pesky step of handing over biometric data which they can leak... and pass verification instantly.
Step 1: Install the extension
Step 2: Register an identity (just once)
Step 3: Continue using the web as normal
The extension detects the QR code, generates a cryptographically identical payload and tells the verifier I'm over 18, which it "fully trusts".
This isn't a bug... it's a fundamental design flaw they can't solve without irrevocably tying a key to you personally; which then allows tracking/monitoring.
Of course, I could skip the enrolment process entirely and hard-code the credentials into the extension... and the verifier would never know.
Hacking the #EU#AgeVerification app in under 2 minutes.
During setup, the app asks you to create a PIN. After entry, the app *encrypts* it and saves it in the shared_prefs directory.
1. It shouldn't be encrypted at all - that's a really poor design.
2. It's not cryptographically tied to the vault which contains the identity data.
So, an attacker can simply remove the PinEnc/PinIV values from the shared_prefs file and restart the app.
After choosing a different PIN, the app presents credentials created under the old profile and let's the attacker present them as valid.
Other issues:
1. Rate limiting is an incrementing number in the same config file. Just reset it to 0 and keep trying.
2. "UseBiometricAuth" is a boolean, also in the same file. Set it to false and it just skips that step.
Seriously @vonderleyen - this product will be the catalyst for an enormous breach at some point. It's just a matter of time.
TWITTER!!
They did it again!
You have to VERIFIY UR AGE or you dont See any adult Content now!
It Hit me this night and Heard it from other Friends before.
THIS IS NOT TO PROTECT UR KIDS, ITS TO GAIN DATA, SELL AND FEED IT.
do Not Fall for this! AND SHARE.
bro I hate it here
first the fact that a lot of posts got flagged as either "not appropriate" or as "not suitable for all ages" or whatever
now posts that are flagged like this, aren't even showing up anymore in the media tab
my only reason to check out artists is basically gone
Things you've missed.
>UK talks about Banning VPNS
>Russia Talks about Banning VPNS
>Cloudflare asked to ban VPNS in UK
>Kids bypassed the age verification with AI generated pictures or fortnite characters making me believe that in the future facial scan will be removed in favor for ID verification only.
>Itch io removed thousands of games.
>Horror games are now banned. You've mentioned Mouth wash but fear and hunger also got banned
>collective shout claims innocence they never wanted this, asks people stop engaging with them
>EU is passing a digital safety act next year which is the reason the sites are restricted
>Australia is passing an act too which is just as draconic if not more so than the one in UK
>Protests and anti imigration topics including a speech in the UK parlament by a politician is labled as "not safe for kids, despite kids at the age of 16 will be able to vote in UK"
Let me summarize everything that's happened in the last week
>Collective Shout contacts payment processors to get Steam and Itch io to remove adult games
>Steam removes 100s of games and creates a entirely new policy to lick the boots of Payment Processers
>Day later Itch io removes their entire Adult Game category
>UK "Online Safety Act" comes into effect restricting the internet for the entire country to "Protect Children"
>Within 24 hours UK creates a Police Task-force to monitor political opinions of its citizens
>Europe gets hit by "Age Restriction" in some sites too and they find out the "Restricted Internet" is coming for them too
>People find out American bill titled "Kids Online Safety Act" is introduced into Congress to do the same thing
>Wikipedia is being asked to censor itself for the UK
>Search Engines are now stuck in safemode for certain countries restricting internet
>Mouthwashing a horror game on Itch io is removed thanks to Payment Processors and Collective Shout
>UK is trying to force American companies to censor themselves after the "Online Safety Act" came into effect