Estonia Estonia e-Residency digital identity

Estonia's Browser-Edited Age Checks Show the Weak Link Is Acceptance Rules, Not the Digital ID

Minors editing Eesti.ee pages to enter clubs expose a gap between Estonia's secure eID stack and how venues check age. Narrow fixes beat new mandates.

Estonia's Eesti App ID Check People of Internet Research · Estonia 3 min QR code validity The code can only be read with the… 30 sec Verified data display Verified data is shown briefly via… €850,000 App development cost Total cost of building the Eesti a… 260,000+ Eesti app users Users reported when the 2028 agenc… peopleofinternet.com
Estonia's Eesti App ID Check People of Internet Research · Estonia 3 min QR code validity 30 sec Verified data display €850,000 App development cost 260,000+ Eesti app users peopleofinternet.com

Key Takeaways

ERR News reported that minors in Estonia are using browser developer tools on the state portal Eesti.ee to edit the personal data shown on their phone screens, then showing the altered page to get into bars and clubs. The Information System Authority (RIA) responded that venues must not accept the Eesti.ee web view as proof of age or identity. It said only the identity verification function inside the official Eesti app, which cannot be edited, is suitable.

The episode is easy to read as a failure of Estonia's famous digital identity system. It is closer to a failure of a habit: treating a screen as a credential.

The strongest case for tighter rules

The case for a heavy response is serious. Age limits on alcohol exist to protect minors, and a door check is a one-second decision by a tired worker. If a teenager can defeat it with a free browser feature, the check does nothing. Regulators could reasonably argue that venues cannot be trusted to tell a genuine credential from a fake, so the state should mandate one verified method, or restrict digital proof altogether.

That argument deserves respect. But it assumes the weakness is in the identity infrastructure. The reporting suggests it is in the last step: what the person at the door is looking at.

What the system was built to do

The Eesti app's verification function launched on 7 July 2025, according to ERR News. It lets a person prove identity with data from their ID card or passport. It was designed around exactly this threat. RIA's description of the app says the main method is a QR code valid for three minutes that can only be read with the Eesti app. Data is fetched through the X-Road data exchange platform, and the verified data is displayed for only 30 seconds. RIA's announcement of the feature adds that service providers must also log into the Eesti app to scan codes.

That is a challenge-response design. The venue's device queries the state's system, so nothing the customer's phone displays can be spoofed. A static web page, by contrast, is just HTML rendered on a device the customer controls. Developer tools can rewrite it in seconds. The cryptographic work behind Estonia's eID is intact. The trick works only when a venue accepts a page that was never meant to be accepted.

RIA also states the app 'does not show the document or create a new document type', and advises people to carry a physical document too. Estonia has not claimed that a phone screen replaces a passport.

The real gap is adoption

The more telling fact is why bouncers fall back on screen displays at all. The secure path has barely spread. An ERR report on adoption found that only two state agencies recognise the function and that just a couple of nightclubs and bars use it. It also found that development had cost €850,000.

The retail objections in that report are instructive. Selver said the cashier 'has no control over the authentication process' because only a visual display is shown, which 'can technically be manipulated.' That is a warning about the weak method, voiced in advance. Rimi cited missing technical infrastructure and the need for staff training. Soon after launch, ERR's experiment with bars and shops found major retailers had no plans to accept the app. RIA's view at the time was that 'the market will regulate itself.'

The market has produced an awkward middle state. Young people carry phones, not documents. Venues want to be accommodating. The properly secured method needs a scanner flow and some training. The insecure method needs nothing, and it works until a teenager opens the inspector.

Proportionate fixes

The state is already moving on the supply side. Under the plan reported by ERR News, state agencies must accept app verification from 1 March 2028. Local governments and the private sector stay voluntary. The app had passed 260,000 users at that point. That is a sensible sequencing: the state makes its own services the anchor customer first.

The response to the club incident should stay equally narrow:

What this says about digital ID policy

Governments elsewhere are building digital identity wallets and age-verification schemes, often under pressure to make them mandatory and centralised. Estonia offers a modest counter-lesson. Strong back-end cryptography does not protect anyone if the front-line check is a glance at a rendering. The fix is to make the verified path the easy path, and to say plainly which displays are not credentials.

This incident is also a small success story. The weakness appeared in a fallback that was never authorised. The authorised function was built to resist it, and the regulator named the difference within days of the report. Estonia should keep voluntary adoption, spend effort on making venue acceptance cheap, and avoid turning a teenage hack into a case for heavier mandates.

Sources & Citations

  1. RIA: Eesti app identity verification
  2. RIA: Eesti app will soon be available for identity verification
  3. ERR News: State app's identity verification function struggles to attract users
  4. ERR News: Identity verification in state app to become mandatory for agencies in 2028