Post #1350484
2026-04-17 13:40 UTC
RE: https://ec.social-network.europa.eu/@EUCommission/116408720976324749
Unfortunately, this is not ready.
The current GitHub repository is a start - a (fairly expensive) prototype (https://github.com/eu-digital-identity-wallet/av-app-android-wallet-ui/issues). Before any wider rollout, however, this needs to:
* stabilize in its feature set (e.g., which form of app/device attestation);
* be verified in detail by independent audits - the quick checks done by some security/privacy researchers and developers at the moment do *not* replace a systematic code audit; and
* go through interoperability testing with different age credential providers (the Python demo code is certainly not production-ready)
as a minimum bar.
Of all the different approaches being discussed right now for age assurance (see our open letter at https://csa-scientist-open-letter.org/ageverif-Feb2026), this is the least-bad from a privacy and surveillance point of view. It's one of the few directions that might be acceptable in any shape or form - *if the general political decision is to do this at all* (see the letter for counter arguments that still need to be debated). But rushing it won't help. The privacy and security aspects are nuanced, and hard to get right in apps that should be deployed on a wide variety of Hundreds of Millions of smartphones. Let's settle these important details before announcing it as a "solution".
Replies (1)
-
@xot@someone.elses.computer 2026-04-27 05:45
@rene_mobile @stefan Indeed. See also my recent blog about exactly this issue https://blog.xot.nl/2026/04/09/online-age-assurance-raises-thorny-questions/index.html