EU Updates Age Verification App After Security Flaws Found
The European Commission is updating its new open-source age verification app after security experts demonstrated the system could be compromised in under two minutes.
The European Commission is updating a newly unveiled age verification app after independent developers and security experts identified critical vulnerabilities. Designed to protect minors from online harm while maintaining anonymity, the tool aims to replace traditional age-confirmation pop-up banners. President Ursula von der Leyen initially stated the app was "technically ready," but shortly after its presentation, security expert Paul Moore and hacker Baptiste Robert demonstrated that the system could be compromised in under two minutes.
Findings revealed that attackers could bypass PIN codes and biometric authentication. Furthermore, the app failed to delete sensitive facial images from device storage following crashes or failed scans. While the Commission claimed these hackers tested an outdated demo version, the experts denied this. Additional critiques from the Hasso Plattner Institute and the University of Hamburg suggested that the use of pseudonyms could still allow website operators to track users.
To maintain transparency and allow community testing, the EU published the app's code on GitHub. EU officials acknowledged the system can be bypassed via virtual private networks (VPNs) and other manual workarounds. Despite these flaws, the Commission is proceeding with its rollout schedule, supported by eight heads of state, while taking immediate steps to release a corrected version of the software.