

Fair point. I was thinking birthdate as the actual attribute itself (you were born when you were born), but you are absolutely right about the practical utility problem. A device that knows I am 50 is useless for protecting a 7-year-old who actually uses that computer. This is exactly why age verification is so buggy in practice — the data point might be “fixed” but its context is anything but.


This is the core issue. Remote attestation fundamentally breaks user agency. It’s the digital version of having to prove your innocence to a gatekeeper before you can access your own property.
The consortium model is progress over the Google-only status quo. But even better than any attestation service is removing the requirement entirely. Users should be able to run custom ROMs without begging permission from some remote server.
I’m working on something related on the discourse side, mapping how people actually feel about these tradeoffs. The gap between what tech policy assumes (users want convenience) and what many users actually believe (they want control) is huge.
Open source alternatives matter. They matter even more if they actually work.