← All reports

EU Age Verification App Under Fire: Experts Slam Surveillance Overreach, Dismissing 'Responsible Disclosure' Tactics

Privacy & SurveillanceApr 18, 2026score 2.429 posts · 20 replies across 9 instances
Security researchers are scrutinizing the European Union's proposed digital age verification app, highlighting successful hacks that allegedly exposed vulnerabilities within minutes of the EU Commission's launch. The core subject is the necessity and security of the system designed to enforce the Digital Services Act. Opinion is deeply split on the appropriate resistance strategy. A significant bloc, including @[email protected] and @[email protected], argues the policy's mere existence is the fundamental problem, dismissing technical fixes. Others, like @[email protected], attack the concept of 'responsible disclosure' itself. Conversely, some, such as @[email protected], suggest the app addresses privacy concerns by being open-source and not storing private identifiers. The dominant critical sentiment views the entire verification mechanism as an inherently exploitative tool aimed at comprehensive surveillance, rendering technical patches insufficient. The strongest technical resistance demands abandoning the product entirely, focusing instead on high-level political pressure via local representatives, as suggested by @[email protected].

Key points

OPPOSE
The underlying purpose of the age verification system is viewed as a form of comprehensive exploitation, not mere age checking.
This is the most unexpected critical take, stating surveillance is the root goal, making technical fixes moot (@[email protected]).
OPPOSE
The focus of opposition must be the policy itself, not simply the technical flaws.
Pointing out security flaws only helps the policy survive; the policy needs to cease existing (@[email protected]).
OPPOSE
The established process of 'responsible disclosure' is fundamentally flawed and incapable of coordinated industry compliance.
The concept needs replacement terminology, as companies will not act uncoordinatedly (@[email protected]).
OPPOSE
Technical improvements are suspect due to inherent vulnerabilities in privacy-enhancing tech.
Even advanced tools like Zero-Knowledge Proofs risk downgrade attacks or fallback mechanisms that compromise privacy (@[email protected]).
MIXED
Resistance efforts should target local political representation rather than solely focusing on code exploits.
A counter-argument to technical disclosure is organizing citizens to contact local political representatives (@[email protected]).

Source posts

@[email protected]
Ok, fellow hackers, I propose a pact: That new EU age verification app thingy ... do NOT help improve it. Don't publish findings. Don't responsibly disclose insecurities. Don't facilitate them making it bulletproof. If personal data is directly at risk, by all means, slam their asses into the ground. GDPR them into oblivion. But on its core functionality this needs to be, to become, and to stay, the most insecure, the most easily circumventable piece of shit code on the planet.
470 boosts · 516 favs · 14 replies · Apr 17, 2026
@[email protected]
Embarrassing times for the European Commission after security researchers found flaws within minutes of using its age verification app. https://www.politico.eu/article/eu-brussels-launched-age-checking-app-hackers-say-took-them-2-minutes-break-it/ (ICYMI: I have a blog post on why age verification laws are a bad idea to begin with: https://this.weekinsecurity.com/papers-please-age-verification-laws-threaten-everyones-online-security-and-privacy/)
343 boosts · 254 favs · 15 replies · Apr 17, 2026
@[email protected]
# Think of the children! EU age verification APP cracked in 120 secs The hack was so easy it looks like the app was designed to be so weak https://cybernews.com/security/eu-age-verification-app-hack/ #InfoSec #EU #Age #Verification #hack #crack #programming #buffer #overflow #programming #Android
4 boosts · 7 favs · 0 replies · Apr 17, 2026
#android#overflow#buffer#programming#crack#hack
@[email protected]
EU unveils an age‑verification app to protect children online: users can prove age via passport/ID allegedly without revealing identity, using open‑source anonymous tech to help enforce the Digital Services Act. Read more: https://www.dw.com/en/eu-chief-urges-bloc-wide-push-on-age-verification-app-to-protect-children-online/a-76788202 🔒👶📱 #DigitalSafety #EU #Privacy #Security #Masssurveillance
2 boosts · 0 favs · 0 replies · Apr 17, 2026
#masssurveillance#security#privacy#eu#digitalsafety
@[email protected]
It is ironic that the European Commission has introduced a verification method by which its citizens must have their smartphones with them all the time. theprivacydad.com/a-first-look-at-the-eu-age-verification-app/ #eu #ageverification #mobilephones #privacy @vonderleyen @EUCommission
1 boosts · 0 favs · 0 replies · Apr 17, 2026
#eu#ageverification#mobilephones#privacy
@[email protected]
You think youll be safe from #ageverification now you that are in the #EU? WRONG BITCH WELCOME TO FUCKING #HELL. #News #Europe #EuropeanUnion https://www.politico.eu/article/eu-brussels-launched-age-checking-app-hackers-say-took-them-2-minutes-break-it/
0 boosts · 0 favs · 2 replies · Apr 17, 2026
#europeanunion#europe#news#hell#eu#ageverification
@[email protected]
European Commission rolls out age verification Anonymous + ID-based Security vs privacy debate Source: https://commission.europa.eu/news-and-media/news/european-age-verification-app-keep-children-safe-online-2026-04-15_en 💬 Thoughts? Follow TechNadu #InfoSec #Privacy
1 boosts · 0 favs · 0 replies · Apr 17, 2026
#infosec#privacy
@[email protected]
The EU launched an age verification app to protect children online. A researcher broke it in two minutes. That's not actually the problem. https://blog.ppb1701.com/highest-standards-available-for-about-two-minutes #privacy #infosec #security #blog #ageverification #eu #surveillance #userhostile
2 boosts · 0 favs · 0 replies · Apr 17, 2026
#privacy#infosec#security#blog#ageverification#eu
@[email protected]
I got a little annoyed about the headlines on the EU Age Verification app, so I put some of my thoughts on it into words. tl;dr: I'm not really convinced that these were serious vulns, and I don't buy the hype around them. https://www.linkedin.com/pulse/eu-age-verification-app-hacked-2-minutes-mi%25C5%2582osz-gaczkowski-ollhe/ #AgeVerification #bypassingAgeVerification #eu #privacy #infosec #cybersecurity
1 boosts · 0 favs · 0 replies · Apr 17, 2026
#ageverification#bypassingageverification#eu#privacy#infosec#cybersecurity