EU digital identity wallet age-check plan faces GitHub backlash over Google and Apple ties

EU digital identity wallet age-check plan faces GitHub backlash over Google and Apple ties

N
News Editor
2026-07-15 03:17:58
The European Union’s planned age-verification framework for the EU Digital Identity Wallet is drawing mounting opposition after its proposed app and device integrity checks were linked to Google Play Integrity API and Apple App Attestation. An official GitHub discussion has attracted nearly 300 comments, with developers arguing that age checks should not depend on proprietary services controlled by two U.S. technology companies. Critics say the proposal clashes with the wallet specification’s own commitments to interoperability and open standards. They point to the Dutch identity app Yivi as evidence that age verification can work without Google services, and warn that government identity systems should not become dependent on private platform policies, service continuity, or security assumptions outside public control. The debate has widened to include security and inclusion concerns. Researchers cited in the discussion said they were able to reset an app PIN on Android in under two minutes by editing a plain-text preferences file, while others raised concerns about unencrypted personal data storage. Developers also warned that users on de-Googled systems such as GrapheneOS and e/OS could be excluded. Meanwhile, countries have taken different approaches: the Netherlands and Italy currently use Google Play Integrity, while Switzerland opted for Android’s built-in attestation mechanism instead.
EUDigital Identity WalletAge VerificationGoogle Play IntegrityApple App AttestationPrivacyPolicy and Regulation

The European Union’s proposed age-verification specification for the EU Digital Identity Wallet has triggered a wave of opposition after plans emerged to tie app and device authenticity checks to Google Play Integrity API and Apple App Attestation. An official GitHub thread quickly drew nearly 300 comments, with developers objecting to the idea that age checks should depend on proprietary services run by two U.S. tech companies.

The backlash has centered on a discussion titled “Do not add Google Play Integrity integration,” started by developer TheLastProject. The main complaint is straightforward: age verification for a public digital identity system should not be locked into Google and Apple infrastructure.

Developers say the proposal breaks with the wallet’s own principles

One of the first examples raised by opponents is Yivi, the Dutch identity app formerly known as IRMA. Commenters said Yivi already handles age verification without relying on Google services and can even be distributed through the open-source app store F-Droid. For them, that shows Play Integrity is not a technical necessity.

Critics also argue that the proposal cuts against the EU wallet specification itself. According to the discussion, the framework sets out three core principles, yet a mandatory link to Google and Apple’s private verification services would conflict with two of them: interoperability and open standards. That contradiction has become a focal point in the debate, with developers asking how an official specification presented as open could end up recognizing only two U.S. companies.

Digital sovereignty is another major concern. Several comments say government services should not depend on third-party external services. Every added dependency introduces another layer of security exposure, and if Google or Apple changes policy, withdraws a service, or suffers a systemic flaw, national identity verification systems could be affected at the same time.

Waag Futurelab warns of platform dependence

Dutch nonprofit Waag Futurelab has joined the criticism. In a piece titled “European digital ID wallets are a gift to Google and Apple,” the group argued that reliance on Google Play Integrity API and Apple’s device attestation tools would leave governments acting as enforcers of private platform policy.

Waag Futurelab also argued that the design of Google Play Integrity API could run into tension with the EU’s Digital Markets Act, or DMA, which is meant to curb the market power of large companies. For critics, that raises a broader policy question: whether the EU is creating new dependence on the same large platforms it is trying to regulate elsewhere.

Threat model questioned after researcher findings

The debate is not limited to market structure and openness. Commenters have also challenged the security model behind the proposed age-check setup. One line of criticism asks whether it is really worth binding the whole system to hardware-backed attestation in order to prevent a malicious actor from remotely compromising a device and using an “adult” credential to access adult websites.

Others have questioned whether age verification needs to be built as a native app at all. In the discussion, some developers argued that a modern web app using the Digital Credentials API could achieve the same result.

Those concerns have been reinforced by security testing cited in the thread. One researcher said that on Android, editing a plain-text preferences file, removing the encrypted PIN entry, and switching off the biometric boolean value made it possible to reset an app PIN and disable biometric login in under two minutes, while stored credentials could still be fully extracted. Another researcher said they reproduced the issue and documented additional problems, including personal data stored without encryption.

Exclusion concerns for open-source and de-Googled systems

The proposal’s exclusivity has become another point of contention. Developers warned that users who do not install Google or Apple software, as well as users of de-Googled operating systems such as GrapheneOS and e/OS, could end up excluded from digital identity services altogether.

Commenters have also repeatedly pointed to the Italian Wallet as a cautionary example, saying earlier problems with Play Integrity integration show the operational risks of making that route central to a public service.

Countries are taking different paths

National approaches are not uniform. The Netherlands and Italy currently use Google Play Integrity without conditions. Switzerland, by contrast, chose Android’s built-in attestation mechanism instead, citing data protection, data sovereignty, and user freedom of choice.

Vendors and open-source developers have tried to calm the debate by putting forward alternatives. Age-verification app provider Scytales has said its EU age-verification app will not rely on Google or Apple for integrity checks.

An open-source alternative has also been proposed. “Unified Attestation,” initiated by Volla Systeme GmbH, is built around short-lived integrated tokens and offline verification, and is designed to coexist with Play Integrity. Some participants in the GitHub discussion have described it as a compromise option.

A broader fight over privacy and public digital infrastructure

Several commenters identifying themselves as security professionals described the proposal as a “privacy and security nightmare.” Others went further and opposed online age verification or identity checks in any form.

What gives the dispute added weight is the EU wallet’s role as a model for other jurisdictions. The way its specifications are written is often treated as a template beyond Europe. If Google Play Integrity integration is ultimately adopted, critics believe it could become a default reference point for similar systems elsewhere. That is why the GitHub backlash is being watched as more than a narrow developer complaint.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.