EU age-verification app hacked twice in three months

In April of this year, security researcher Paul Moore showed he could hack the European Commission’s age-verification reference app in “under 2 minutes.”

Now, three months later he notes: “Despite 3 months of security hardening and genuine improvements across the board, the fundamental issue cannot be solved.” 

Moore has demonstrated two distinct bypasses of this newer version of the app. It could be bypassed using both a modified client and an automated relay to a legitimate remote device. Moore documented the modified-client bypass and the subsequent relay demonstration on X.

Ted Miracco, CEO, Approov had this to say:

“The security industry is largely built on the assumption that the user and the app owner are on the same side and the attacker is a third party. Age verification inverts this assumption, as the user becomes the adversary. Almost none of our collective defensive playbook was designed for a world where the person you’re protecting is the person trying to get around you. Pretending otherwise is how you end up calling a relay attack unfixable instead of just predictable.

“Half of what Moore demonstrated is solvable. A cloned app with the ID checks ripped out should never have reached a verification endpoint, as this is a solved problem. The spec mandates hardware-backed keys but puts app attestation explicitly out of scope. They protected the credential but left the client unverified. The other half, relaying the QR code to an adult’s real device, is not solvable by any attestation technology, ours included.”

The EU really needs to solve this issue and look at other items just like it. Otherwise it will end badly for them.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading