CaraComp
CARACOMP DAILY · EP.7

EU Age Verification: App Bypassed in Under 2 Minutes · Video Briefing

April 18, 20263:29Watch on YouTube →
EU Age Verification: App Bypassed in Under 2 Minutes · Video Briefing
Chapter 1 of 3 · E.U. I.D. APP BROKEN IN MINUTES
0:00 / 3:29

Full Transcript

A security researcher named Paul Moore downloaded the European Union's new age verification app. He was inside someone's account in about two minutes. Brussels had just called it deployment-ready, aligned with the highest privacy standards. It wasn't. The app's PIN isn't cryptographically tied to the identity vault it protects. The biometric lock can be switched off by flipping a single setting named UseBiometricAuth. If you've ever trusted an app with your passport photo, this is the story telling you why that trust needs evidence.

E.U. I.D. APP BROKEN IN MINUTES ▶ 0:22

According to Cybernews, the brute-force counter meant to stop repeated PIN guesses sits in a plain file any attacker can reset. One hundred and thirty million Europeans are the target users.

Deployment-ready is a policy word. Bypass-resistant is a security one. Brussels announced the first and called it the second.

If a regulator can ship a broken door, what about the glasses already scanning your face?

A researcher walked into the R.S.A. security conference wearing Ray-Bans. He paired them with off-the-shelf facial recognition. Then he pulled names and social profiles off strangers in the room, live. No hack. No exploit. Just hardware working as designed. Seventy-five civil liberties groups have now asked Meta to kill its Name Tag feature entirely. Three U.S. senators demanded answers. For anyone who's ever stood in a coffee line next to someone in smart glasses, the question is suddenly practical, not hypothetical.


META GLASSES IDENTIFY STRANGERS ▶ 1:11

According to Engadget, the coalition wrote that this cannot be resolved through product design changes, opt-out mechanisms, or incremental safeguards. Meta's leaked memo suggested launching while critics were distracted.

The hardware is already out there. The software already exists. Meta's product decision is almost beside the point now.

Which raises a simpler question, why do these systems need so much of you in the first place?

Discord asked users one question. Are you old enough? To answer it, the company collected scanned passports and driver's licenses. Then seventy thousand of those I.D.s leaked. Nobody needed your home address to confirm you weren't sixteen. The system collected it anyway. Facial age estimation can tell a fifteen-year-old from an adult within about a year of accuracy. Google has already shipped a cryptographic token that proves you're over eighteen, and reveals nothing else.


DISCORD LEAK: 70,000 I.D.S ▶ 2:06

According to the Electronic Frontier Foundation, four hundred and thirty-eight researchers from thirty-two countries warned that age verification mandates create permanent data liabilities far worse than the problem they claim to solve.

The bouncer never needed your filing cabinet. He just needed to look at your face.

Three stories. One pattern. Europe shipped I.D. before it was secure. Meta built glasses that scan before anyone consented. Discord collected identities before asking whether it needed them. Speed keeps outrunning design, and the people being verified are the ones carrying the risk.

Links to every story and today's podcast deep-dives are in the description. See you tomorrow.

Sources

Stories in This Episode