惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
Engineering at Meta
Engineering at Meta
A
About on SuperTechFans
T
The Blog of Author Tim Ferriss
I
InfoQ
博客园_首页
G
Google Developers Blog
爱范儿
爱范儿
Last Week in AI
Last Week in AI
量子位
阮一峰的网络日志
阮一峰的网络日志
雷峰网
雷峰网
酷 壳 – CoolShell
酷 壳 – CoolShell
Vercel News
Vercel News
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
GbyAI
GbyAI
月光博客
月光博客
The GitHub Blog
The GitHub Blog
V
Visual Studio Blog
N
Netflix TechBlog - Medium
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
博客园 - 司徒正美
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 聂微东

MEDIANAMA

India in talks with US, Anthropic for Mythos access; no Indian firms in Project Glasswing yet Including OTTs in TRAI’s spam protection draft rules a ‘regulatory overreach’: IAMAI Eternal Q4FY26: All Users Pay Higher Platform Fee, Only Some Get Discounts Amazon, Meta to challenge PhonePe-Google Pay dominance as UPI cap delayed since 2020 Meta failed to protect the safety of under-13s: European Commission If markets and regulators are ready for network slicing, we are ready: JIO Why defining ‘news’ won’t fix the free speech problems of draft IT Rules? #NAMA Eternal Q4FY26: Goyal Dismisses AI Disruption Risk as Zomato Quietly Builds Agentic Commerce Infrastructure Karnataka files appeal challenging the bike taxi ban lift in the Supreme Court How did WhatsApp turn 17 govt. flags into 9,400 digital arrest scam bans? Google Wallet integrates Aadhaar as digital ID, expands India’s mobile identity ecosystem Kerala HC issues notice on MediaOne’s Facebook page block in India MeitY warns VPN providers against enabling access to blocked betting platforms Shreya Singhal targeted private censorship. Today’s threat is the State #NAMA Amazon scales its quick delivery service ‘Amazon Now’ in 100 cities Can MeitY issue binding rules via advisories? Experts raise alarm over draft IT Rules #NAMA How 2019 election code of ethics became India’s three-hour content takedown mandate #NAMA Australia proposes new levy on big tech to fund news, opens draft law for consultation ‘judge, jury, executioner’: experts warn of Inter-Departmental Committee (IDC) overreach under New draft IT Rules Lowdown: TRAI flags low deployment under PM-WANI in public Wi-Fi consultation paper Why the NBFC licence matters for MobiKwik China blocks Meta-Manus deal, asserts origin-country jurisdiction: what this means for India ‘No transparency’: experts warn of expanding powers to block online speech in India #NAMA X launches standalone iOS messaging app XChat with encryption in India How India’s content takedown framework was built and where It has gone wrong #NAMA Claude Mythos puts India on alert: CERT-In, telcos, banks assess unprecedented cyber risks Explained: why did the RBI cancel Paytm’s banking licence? Meta now instantly blocks content in India Govt. asks ZEE5 to halt ‘Lawrence of Punjab’ web series release Online Gaming Rules notified, to be in effect from May 1, what are the major changes?
EU’s “safe by design” age-verification app cracked in min...
Ann Mary Pet · 2026-04-20 · via MEDIANAMA

The European Union’s new age-verification app, promoted as a privacy-preserving tool to protect children online, has been found critically vulnerable. Security researchers report it can be hacked in under two minutes. This flaw, identified soon after launch, has increased scrutiny of the EU’s broader approach to online age verification and digital identity systems.

‼️🇪🇺 The EU's new Age Verification app was hacked with little to no effort.

When you set it up, the app asks you to create a PIN. But that PIN isn't actually tied to the identity data it's supposed to protect. An attacker can delete a couple of entries from a file on the phone,… pic.twitter.com/kqaC7rfFwa

— International Cyber Digest (@IntCyberDigest) April 16, 2026

Critical Flaws Undermine “Safe by Design” Claims: The European Commission introduced the app as an open-source tool to verify user age across platforms, enabling users to prove eligibility without sharing personal data.

Cybersecurity experts quickly identified significant design flaws. Storing user PINs locally allows attackers to bypass authentication controls with minimal effort.

Security consultant Paul Moore demonstrated that editing local configuration files allows attackers to reset PIN protections, disable biometric locks, and access stored credentials.

Moore warned that these vulnerabilities could make the system “the catalyst for an enormous breach,” posing risks to both individual users and platforms relying on the app for compliance.

Broader Pattern of Weaknesses in Age-Verification Tech: The incident underscores a wider challenge – building age-verification systems that are both effective and privacy-preserving.

Globally, these systems increasingly rely on government IDs, biometrics, or AI-based estimation, each with trade-offs among accuracy, accessibility, and data protection.

Previously, a hack in an age verification firm exposed identity documents of 70,000 Discord users, which shows how sensitive this data is when compromised.

Experts warn that even “privacy-first” architectures can fail if basic security practices, such as secure credential storage and tamper resistance, are not rigorously implemented.

A Surge in Cybersecurity Threats Across Platforms: The vulnerability discovered in the EU app surfaced amid a wave of significant cybersecurity incidents that underscored growing digital risks. Major data breaches at organisations such as a European fitness operator, Basic-Fit and Booking.com exposed sensitive customer information, raising concerns about data protection practices. At the same time, the social platform Bluesky experienced a disruptive DDoS attack, though it did not result in any data loss.

As governments worldwide expand age-check mandates, a key challenge persists: verifying identity online without increasing risks of surveillance, exclusion, or large-scale data breaches.

Also Read: