Age-verification vendor Yoti auto-reports GrapheneOS users to law enforcement
A GrapheneOS user trying to complete an age check through Yoti, a UK-based identity and age-verification provider, received a support message stating that Yoti automatically flags any device running GrapheneOS and forwards those instances to both its internal security team and law enforcement. Screenshots of the exchange circulated on Reddit and the GrapheneOS forum, where users pointed out the obvious irony: a hardened, privacy-focused Android distribution is being treated as inherent evidence of wrongdoing by a company whose entire business is verifying identity.
The incident crystallizes a tension that privacy advocates have been warning about as age-verification mandates spread across the UK, EU, and US states. Vendors building gatekeeper infrastructure for these regimes have strong incentives to treat anything that resists fingerprinting — degoogled ROMs, hardened browsers, VPNs — as fraud signal rather than legitimate user choice. Once “running a privacy OS” becomes a reportable event, the chilling effect extends well beyond whichever service triggered it.
For GrapheneOS specifically, the project has long argued that attestation and anti-fraud systems should distinguish between rooted or tampered devices and verified alternative OSes that pass hardware-backed integrity checks. Yoti’s blanket treatment ignores that distinction and sets a precedent other verification vendors are likely to copy as compliance pressure increases.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.