Device-ownership erosion → OS-bound identity — repair, the Windows cutover, AI-native OS, and the ZK-still-needs-PII catch
Built 2026-06-14. Structured data + edges: digitalid-device-ownership-erosion.json. Companion to digitalid-os-hardware-stack (the enforcement layer) and digitalid-orchestration-real-incentive (the why). (Stranded-PC and e-waste figures are analyst/advocacy estimates; KB5063878 SSD causation and Pluton lock-in are contested.)
A single trust chain is being assembled from the silicon up: locked bootloaders + parts-pairing erode ownership; Windows is closing (mandatory account, TPM 2.0, the Windows-10 cutover stranding hundreds of millions of PCs); AI-native OS features bind you to a cloud identity; and on top sits OS-level identity/age-assurance enforced by device attestation — so only a blessed, account-linked, attested device can fully participate. And the privacy promise is hollow: even zero-knowledge age proofs require surrendering a government ID, passport-NFC read, or face scan to the issuer at enrollment — ZK only hides your birthdate from the website, and device-binding defeats true anonymity.
1. Ownership erosion — you license a device the vendor still controls
- Parts-pairing/serialization: Apple pairs component serials so genuine-part swaps lose function unless Apple "authorizes" them; John Deere locks diagnostics to dealers. Oregon (SB 1596) banned parts-pairing for devices made on/after 1 Jan 2025.
- Subscriptions + bricking: BMW heated-seat sub (~$18/mo, dropped 2023 after backlash); Mercedes ~$1,200/yr to unlock factory-capable acceleration; the Snoo bassinet paywalled features (dead on resale); Spotify remotely bricked the Car Thing (Dec 2024); Nintendo's 2025 terms reserve the right to render a Switch "permanently unusable."
- Locked bootloaders: US/Canada Snapdragon Samsung phones can't unlock; unlocking trips the Knox e-fuse permanently, killing Samsung Pay/Secure Folder — the same attestation root that later gates identity.
2. Right-to-repair — winning laws, blunted by attestation
- Laws: EU Right to Repair Directive (EU) 2024/1799 (transposition by Jul 2026); California SB 244; Oregon's parts-pairing ban; Colorado (wheelchairs, farm equipment, parts-pairing). FTC "Nixing the Fix" found "scant evidence" repair limits are justified by safety.
- John Deere: the toothless 2023 AFBF MOU was followed by FTC + Minnesota + Illinois suing Deere (Jan 2025); motion to dismiss denied (June 2025); a ~$99M settlement reported 2026 with a second suit pending.
- Self-repair criticized: Right to Repair Europe says Apple's program fails as genuine R2R because parts-pairing + post-repair "authorization" still gate function; France is investigating parts-pairing as a deceptive practice. The repair laws and the attestation chain pull in opposite directions.
3. Windows "Mac-ification" + the forced cutover
- Closing: Windows 11 requires a Microsoft Account at setup (local-account bypass being removed), TPM 2.0, Secure Boot, a supported-CPU list, and the Pluton security processor (root-of-trust shifted toward Microsoft — lock-in fears partly rebutted, control-shift critique stands). Start-menu ads arrived by default (KB5036980, Apr 2024).
- Windows 10 cutover: support ended 14 Oct 2025; consumer ESU runs only to 13 Oct 2026 — free only if you sync to a Microsoft Account, or 1,000 Rewards points, or $30. An estimated ~240–400M PCs can't meet the Windows 11 bar (estimate), drawing e-waste criticism (~1.06B lb cited).
- Breakage during the cutover: 24H2 caused SSD BSODs (Oct 2024); KB5063878 (Aug 2025) was linked by community testing to disappearing drives / data corruption (Microsoft couldn't reproduce — contested). The forced migration is happening while updates visibly break machines.
4. AI-native OS — the new lock-in
- Recall + Copilot: Microsoft Recall (May 2024) screenshots the screen into a searchable index; early builds stored passwords/financial data unencrypted, forcing a June-2024 pull and April-2025 relaunch (enclaves, encryption, opt-in) — but a searchable screen-history honeypot persists.
- Apple / Google: Apple Intelligence (+ Private Cloud Compute) is gated to recent Apple silicon + the Apple account; Gemini is increasingly the default Android assistant tied to a Google account. The assistant's memory binds to a cloud identity, raising switching costs beyond classic OS lock-in.
5. The catch — ZK age verification still requires PII at enrollment
- How it actually works: (1) an issuer (government / mobile-OS / bank) verifies your real identity + DOB — passport-NFC, ID scan, bank KYC, or face scan — and signs a credential; (2) only then can you present a ZK "over-18" proof to a website without revealing the birthdate. PII is disclosed to the issuer even when hidden from the site (confirmed by the EU blueprint and Google's own Wallet-ZKP description).
- Every method needs PII: eID, passport, ID card, bank KYC, or MNO identity — and even facial age estimation processes a biometric: Spain's AEPD fined Yoti €950k (Mar 2026) for unlawful biometric processing, invalid consent, and excessive retention.
- The honeypot is real: Discord's verification vendor leaked ~70,000 government-ID images (Oct 2025); the Tea app leaked ~72,000 images incl. IDs/selfies (Jul 2025).
- Honest framing: ZK cuts disclosure to the website, not the issuer; it requires trusting the issuer + an attested device; unlinkability/privacy-preserving revocation are optional/forthcoming. Device-binding means access is never truly anonymous — the only zero-PII option is no verification (EFF, Brave). A reported case had Yoti flag a GrapheneOS user during a console age check.
Convergence — it is one trust chain
Locked bootloaders + parts-pairing (ownership erosion) → secure boot + Pluton + hardware attestation (Play Integrity, Apple App Attest) → OS-bound identity/age-assurance: only a blessed, account-linked, attested device fully participates. This structurally penalizes repair (third-party parts break attestation) and OS freedom (custom ROMs fail integrity, digitalid-os-hardware-stack), and turns the device itself into the enforcement point for the control rail in digitalid-orchestration-real-incentive.
What is NOT asserted
- Secure boot, attestation, and on-device AI are genuine features — the point is they compose into an ownership/anonymity-eroding chokepoint.
- Stranded-PC (~240–400M) and e-waste (~1.06B lb) are estimates; KB5063878 data-loss causation and Pluton "lock-in" are contested.
- No claim ZK is cryptographically broken — the claim is narrower/stronger: ZK doesn't remove the enrollment-side PII disclosure to the issuer, and device-binding defeats anonymity.
- No motive imputed to any vendor; effects/incentives/composed capability are documented, intent is not inferred.
- Overlay edges are excluded from the SCC / Z3 / TLA+ proofs.
Sources: iFixit — Apple parts-pairing; PIRG — John Deere & right to repair; EU Directive 2024/1799; iFixit — California SB 244; MacRumors — Oregon parts-pairing ban; FTC — Nixing the Fix; BleepingComputer — Win11 account bypass removed; Tom's Hardware — TPM 2.0 / stranded PCs; Neowin — Win10 ESU $30; Microsoft — Extended Security Updates; Tom's Hardware — Start-menu ads; DoublePulsar — Recall security; Apple — Private Cloud Compute; Google — Wallet ZKP age verification; EU age-verification blueprint; EFF — ZKPs are not a digital-ID solution; Brave — ZKP age-verification limits; Biometric Update — AEPD fines Yoti; TechCrunch — Discord breach; Security.org — Tea app breach.
← Research index · structured data: digitalid-device-ownership-erosion.json · digitalid-device-ownership-erosion.md