Indiscriminate messaging and chatcontrol: Last chance to protest
patrick-breyer.de
patrick-breyer.de
So if I understand correctly, this will be the end of E2E encryption? That would probably be the stupidest decision of the century. Governments are always lagging behind in terms of 'cyber' security, so my guess is that it will only be a matter of time before we can expect data leaks from widely used private chat services.
If there is a backdoor, it will only be a matter of time before the criminals get access to it. It would be the holy grail of data. If I were a foreign regime with bad intentions, I would put a lot of resources into getting access to those chats.
You could probably ruin anybody's life with access to their personal chats by extorting them, etc. It's going to create a whole new criminal sector. People sifting through other people's personal lives.
I'm not implying that these people may have committed an offence, there are many things I don't want anyone else to see other than the person I'm sending the message to. The "law-abiding citizen" / "Only criminals have something to hide" argument is complete bullshit.
With access to personal chats you can ruin careers, families, relationships, etc, etc. And what can happen, will -most likely- happen. E2EE prevents that.
Edit: Sorry, I misread the parent comment!
It's a variation on "if you ban guns only criminals will have them."
Most countries have banned guns and there are way less problems with guns than those countries that haven't banned guns.
Is this an argument for or against the EU proposal?
First, "most countries have banned guns":
Here, from worldpopulationreview.com is a list of countries that has kind of banned guns (at least made them hard to get):
"""
Today, we’ll focus on the nations around the world where restrictive policies are in place that make it illegal or extremely difficult for ordinary citizens to own a gun. Those nations are:
China - Restricted
Eritrea – Banned
India – Restricted
Indonesia – Restricted
Iran – Restricted
Japan – Restricted
Lebanon – Restricted
Malaysia – Restricted
North Korea – Banned
Singapore – Restricted
Taiwan – Restricted
Venezuela – Restricted
Vietnam – Restricted
"""...and yes by the way, while some of these are OK like Japan and Taiwan you are in some interesting company if your country joins that list.
Secondly: "there are way less problems with guns than those countries that haven't banned guns."
I give you Norway, Switzerland and Austria as a start. Probably Finland and a number of others as well:
All these have and have had loads of actual assault rifles (G3-s, HK416 etc, not semiautomatic AR-15s) complete with non trivial amounts of ammo around in private homes.
Yet I'd rather live in any of those instead of any of the ones on the list above.
So clearly something else is at play.
But it is true that the low gun ownership rate nations (<5 guns per 100) (ignoring ones in desperate povery where people can't afford guns) tend to, on balance, be much more authoritarian than the high gun ownership rate nations (>20 guns per 100 people). See the wikipedia article here:
https://en.wikipedia.org/wiki/Estimated_number_of_civilian_g...
> Most countries have banned guns and there are way less problems with guns than those countries that haven't banned guns.
to:
> OK, well, I have lived in the UK, Isle of Man, Australia and Germany, all of which restrict private ownership of guns, and don't appear on that list.
and you ask me for sources.
And sure, here it is: https://worldpopulationreview.com/country-rankings/countries...
it was literally just the first site that popped up when I looked for
countries were guns are banned
or something to that effect on duckduckgo.comNow, can you provide some kind of source at all for your claims except that you lived in four of them?
> Female programmers have had to fight against a constant discouragement from pretty much everyone in their lives, while male programmers have had nothing but encouragement.
Based on that and this one it seems fair to say that you have a tendency to make up facts as you need them.
Please stop doing that. It might be a nice party trick when one is young but it soon get really annoying for anyone who argues in good faith.
I for one as a very male programmer can at least say that the idea that
> while male programmers have had nothing but encouragement.
is patently false.
Your "women are weak and need help" attitude sucks.
> Your "women are weak and need help" attitude sucks.
Well, the women I helped didn't think my attitude sucks. I even got an honourable mention on a TedX talk on the subject [0] (by a woman). So I think I'll continue listening to them and not you. Maybe you should re-examine your attitudes on the subject?
Welcome to the working class! Where things are routinely shit, if "external discouragement" stops you from things, you will never get far in life.
It not about sex or gender, its resilience what matters. And resilience is what people from privileged backgrounds rarely have, because they had it good enough to never have to learn it.
Next time i see a damsel in distress i'll come back to you. Yes, im just making fun of you.
Good luck with your ongoing struggle.
I ran a one-day workshop to teach women to code (now https://shecodes.com.au/) based on discussions with female coders about their experiences getting into the industry. These workshops are always oversubscribed, and always there are women there saying "if only I'd received this kind of encouragement when I was younger".
I've seen multiple female colleagues harassed by male management until they leave the industry. Again and again, I've heard female colleagues talk about the discouragement and difficulties they've experienced in the IT industry. I've never heard a male colleague express this. From everyone I've talked to it seems to be a universal experience from men that they have been encouraged to learn to code and join the industry.
These are facts. They may be anecdotal, but that doesn't stop them from being facts. I am not making them up.
The US has a problem with gun violence. This is a fact [0]. I think it stems from the high rate of gun ownership in the US. That is an opinion, though it is supported by correlation [1]. I think it's fairly clear that I'm expressing an opinion in my original comment, but I'll take your comment as a caution that I need to be more clear whether I'm expressing an opinion or a fact.
[0] https://worldpopulationreview.com/country-rankings/gun-death... [1] https://www.ncbi.nlm.nih.gov/pmc/articles/PMC3828709/
In England and Wales guns are heavily restricted but aren't outright banned or extremely difficult to obtain. Effectively every adult that isn't disqualified from owning a gun (medical reasons, >3 years in prison, etc) should be able to obtain a smoothbore shotgun licence provided the security/storage requirements can be met, this may be very difficult for younger people living in shared accommodation or in very developed city centres but still. Once a shotgun licence is obtained you can effectively own as many shotguns as you can securely store.
The firearms licence in comparison is much harder to obtain, you need to demonstrate a legitimate reason to own each specific firearm (i.e., land you have permission to hunt on, sports shooting at a club), the local police issuing the licence have a lot more say on whether they issue licences or allow amendments to the licences (i.e., owning more firearms), etc, but it's in principle not much different to a shotgun licence and if you already hold a shotgun licence you very likely can obtain a firearms licence for a very limited number of firearms. In American terminology a shotgun licence is shall-issue where a firearms licence (and amendments) are may-issue.
When it comes to stats on whether a licence is granted(2), in 2019 98% of shotgun licences that were applied for were issued and 97% of firearms licences that were applied for were issued.
This is a very different story to guns being outright banned or extremely difficult to obtain, gun ownership in the UK is low partially because of these restrictions but also because there's no gun culture to speak of. In comparison to countries like Iran, China, Japan, much of Asia and Africa, etc, we're extremely liberal with gun ownership, private gun ownership in Japan is almost unheard of and it's effectively prohibited for the general population for example.
These things have to be taken into account when talking about whether a country restricts/bans guns, because otherwise there's only a handful of countries that have no restrictions on guns. Gun ownership may not be trivial in the countries you've lived in but it's at least legal for the general population.
(1) We can get into the semantics of how restricted guns are in the USA and how this changes between cities/counties/states but as private sale/transfer of guns are effectively unrestricted and the right to gun ownership is constitutionally protected we can say that the USA (and Yemen, arguably South Sudan and Greenland as well) may as well not restrict private gun ownership
(2) https://assets.publishing.service.gov.uk/government/uploads/...
Backdoored E2E (with an added government decryption key) will look just like proper E2E until you attempt to decrypt it.
You can also put your secure E2E communications inside backdoored E2E communications. The possibilities are endless.
No, that is not what the law is about. Nobody in the EU is about to prohibit encryption, in fact some projects rely on it (https://en.wikipedia.org/wiki/EIDAS).
The law lifts the prohibition to service providers to indiscriminately scan messages for the specific purpose of scanning for dangerous content. The idea that service providers will not be able to provide E2E encryption is speculative, some people just assume it will follow.
In any case relying on proprietary software for secure communication is not a good idea anyway, and you can still do E2E encryption yourself with open source software, nobody is going to come for you if you do.
I don't support this law by the way, I think that privacy regulation is a good thing, and it is not a good reason to weaken it.
https://www.patrick-breyer.de/wp-content/uploads/2021/05/202...
Perhaps I have a lot of stubborn blood in me, but I never see a date or a law as a last chance. Protesting can also take the form of people adding witty footers to their emails such as old propaganda slogans from WWII, periodic messages to chat or chat server status, links to simple how-to's for E2EE that maybe your non technical friends can follow. Put your E2EE solutions to the test. Have your child and a grand-parent follow the instructions. If a provider rejects your encrypted messages, switch providers. Money talks. This is just my opinion based on my limited anecdotal life experiences.
This question comes down to who or what controls the software on your device. The very existence of the proposal implies that the user of the device does not have this control. That is the real fight here.
Which covers a huge percentage of the private communications on the planet. That should not be overlooked.
It takes at least 2 people to communicate. What are you going to do, when you have to communicate with a non-technical user who has a gmail address?
Might I suggest that people check that before jumping to conclusions. My reading is that the main issue is putting limits on the companies that were already doing this (as mentioned, Google, fb, etc) and that's already privacy violating.
Protecting privacy and encryption is important, but I really think the Pirates cry wolf more often than not. I might be wrong, of course.
> In the case of technology used for identifying solicitation, such concrete elements of suspicion should be based on objectively identified risk factors such as age difference and the likely involvement of a child in the scanned communication.
> (17b) End-to-end encryption is an important tool to guarantee secure and confidential communications of users, including those of children. Any weakening of encryption could potentially be abused by malicious third parties. Nothing in this Regulation should therefore be interpreted as prohibiting or weakening end-to-end encryption.
If the EU were an oil company they'd write: "Our oil is not allowed to be used in activities that are harmful to the climate." Then they'd go on to sell oil as usual while constantly claiming to protect the environment.
So they're going to require Signal to break their E2E encryption if the app is to remain legal and readily available? Wow.
Regardless of what intentions the EU bureaucrats have, there's no way these requirements won't be abused. Imagine what insights could be gained from applying a little ML to the real-time chat of an entire continent. Who would you trust to have access to data like that?
I am a government. 20% of my population are tech savvy, a different very minorly overlapping 20% are criminals. Given the law of distributions this is probably pretty close to true.
Now, those 20% of criminals are very varied in their delights, violent, sexual or theft. Serious crime such as pedophilia or terrorism is very low probability overall.
However, as a government, I can't be seen to be weak on those extreme positions because they are highly visible; the 80% population simply will not allow me to argue in good faith for protections which _might_ help such extreme criminals operate easier.
The technical feasibility of good opsec for criminals is usually very low, and the FBI has a decent track record of targeted surveillance.
But I, the politician, cannot communicate effectively with 80% of people, when the populist says that I am weak on terrorists and pedophiles. I only weaken my own position and allow the populist access to power, because 80% > 20%.
--
The biggest benefit and the biggest problem with democracy is that everyone has a voice, even the uninformed.
If you listen to all politicans by numbers there will be liars and opportunists among them; then you're not uninformed, you're misinformed, and that's arguably worse.
Alternative voting systems (e.g. ranked choice systems) aren't some sort of political panacea, but they could help a lot with this issue. A populist thrives in an environment that does not support nuance. It would be harder for them to be successful if they were running against, say, 6 viable opponents rather than 1.
I hope we can address some of these major problems with democracy, because the alternatives generally aren't great.
EU Election system is _literally_ one of the fairest systems in existence[0] ensuring that every party get some measure of proportional representation. Compared to English First Past the Post (minority rule, and 2 party systems) or Scotlands Single-transferrable vote (which is still winner take all); but D'Hondts method means that people can be safe in the knowledge they'll be represented and it's proportional to the input.
It's not "perfect" but it's _literally_ the best humans have come up with.
[0]: https://en.wikipedia.org/wiki/D%27Hondt_method
[0.1]: https://www.youtube.com/watch?v=yhO6jfHPFQU
CGP Grey did some videos on these:
FPTP (England): https://www.youtube.com/watch?v=s7tWHJfhiyo&list=PLNCHVwtpeB...
STV (Scotland): https://www.youtube.com/watch?v=l8XOZJkozfI&list=PLNCHVwtpeB...
D'Hondt-esque (EU): https://www.youtube.com/watch?v=QT0I-sdoSXU&list=PLNCHVwtpeB...
2. Range voting is the best humans have come up with.
Picking nits, but isn't Sainte-Laguë better?
Anyway, I think GP was arguing that no matter how fair your voting method, it's of limited use if important concentrations of power are not covered by it.
[0] Mandatory voting, ranked choice, etc - Australia's voting system is as close to ideal as you can get
The minority of the population who are tech-savvy enough to know this is going to be a complete disaster are unimportant in politician's eyes - no-one listens to us nerds in the corner doing nerd stuff.
I'm sure you can find examples of EU overreach and a desire to get bigger, but this isn't that.
What is “this” — the EU parliament proposal? Or your workaround? Why would both have to be outside the EU?
Because email/chat is rarely a monologue
The workaround.
> Why would both have to be outside the EU?
Because if one party is within the EU then the contents of the message will be scanned even if one party is outside of the EU.
Prevent this law from passing. Call your MEP.
> your private communications can be searched by error-prone artificial intelligence technologies. Although these algorithms are meant to search for potential child pornography and grooming, up to 86% of the correspondence reported to the police is not criminally relevant and users are falsely being reported – including many minors.
> This takes place in a fully automated process and using error-prone “artificial intelligence”. If an algorithm considers a message suspicious, its content and meta-data are disclosed automatically and without human verification to a private US-based organization and from there to national police authorities worldwide.
The proposed legislation contains:
> (ac) the provider of the number-independent interpersonal communications services ensures human oversight of, and, where necessary, intervention in the processing of personal data using technologies falling under this Regulation, and ensures that no report of material not previously identified as child sexual abuse or of solicitation is sent to law enforcement authorities or organisations acting in the public interest against child sexual abuse without prior human confirmation
> (b) the technology used is in itself sufficiently reliable in that it limits to the maximum extent possible the rate of errors regarding the detection of content representing child sexual abuse, and where such occasional errors occur, their consequences are rectified without delay;
My conclusion as a layman: This is problematic, but if you wanted to write "good" anti-child-pornography legislation, this might be close to it?
1) They don't get tech. They are luddites. IT came from the US and they regard it suspiciously because it causes disruption, while EU is all about preserving the status quo and old money. Europe does not appreciate new money, self-made businessmen and entrepreneurship.
2) The two-level government. It should work in theory (after all, EU representatives are directly elected) but in practice it just removes any responsibility from those bureaucrats.
3) West European countries are oriented to the past. They can't innovate and evolve. Their rules and regulations are simply meant to preserve that past and stave off the future bringing all these damn changes.
In the end, it's about control. EU is obsessed about controlling its people and is horrified by those it can't control. Because they bring change, something unacceptable to the good old boys of Europe...
More likely, it's because the EU feels too removed from the people. There are plenty of reasons for that, and we're stuck in the pessimum place where democratic reform of the EU which would help bring it more in line with what people want is prevented because too many people don't like the EU.
This is basically what happened with the Treaty of Maastricht, and three decades later the situation has if anything gotten worse.
Have the US already forgotten who's at the helm of the FCC for example?
I also suspect there's a lot of hate for GDPR, even though it was a mostly good thing. It's just extremely poorly implemented by websites, and sure there are loopholes that should be plugged (the """legitimate interest"""), but it was a good first step which I'd like to see be developed further and enforced more systematically.
> Use of technologies by number-independent interpersonal communications service providers for the processing of personal and other data for the purpose of combatting [SIC] child sexual abuse online (temporary derogation from certain provisions of Directive 2002/58/EC)
Who believes the sincerity behind this? Children's rights? Child protection? Do they not see the violation of rights and the potential abuse this law would effectuate, or is it just intentionally designed for it?
I cannot believe anyone would be so brazen to give up a core right that is already established as part of 2002/58/EC, aka "ePrivacy directive", https://ec.europa.eu/digital-single-market/en/news/eprivacy-.... So, let's look into the proposal more closely, which is available in the top URL.
> CONTENT: the proposal aims to introduce a temporary and strictly limited derogation from the applicability of certain obligations of the ePrivacy Directive to enable providers of number-independent interpersonal communications services to continue using specific technologies and continue their current activities to the extent necessary to detect and report child sexual abuse online and remove child sexual abuse material on their services from December 2020, pending the adoption of the announced long-term legislation.
In case you are wondering, "number-independent interpersonal communications services", apparently covers communication technology and services that not explicitly rely on public identifiable numbers. So, any communication service that you can have separate from a personally identified user.
> As a reminder, the proposal aims to introduce limited and temporary changes to the rules governing the privacy of electronic communications so that over the top (OTT) communication interpersonal services, such as web messaging, voice over Internet Protocol (VoIP), chat and web-based email services, can continue to detect, report and remove child sexual abuse online on a voluntary basis.
The language here comes across as particularly dishonest. You cannot introduce "limited" ability to circumvent privacy. In order to monitor something, services will need to be able to monitor everything.
It goes on to mention safeguards:
> - a mandatory prior data protection impact assessment pursuant and a mandatory consultation procedure, prior to the use of the technology;
> - human overview and intervention is ensured for any processing of personal data, and no positive result is sent to law enforcement authorities or organisations acting in the public interest without prior human review
> - appropriate procedures and redress mechanisms are in place
> - no interference with any communication protected by professional secrecy
> - effective remedies provided by the Member States at national level.
> When no online child sexual abuse has been detected, all data should be deleted immediately, according to Members. Only in confirmed cases can the strictly relevant data be stored for use by law enforcement for a maximum of three months
---
It honestly strikes me as one of the worst proposals I've seen in a long time. I cannot imagine that child porn is regularly transmitted through chatting services on a p2p basis. Especially not to the extent that it vindicates an end of E2E encryption. Giving up such a core component of ePrivacy, you would think that a report that documents what the problem currently is, would be in order.
The document attached to this proposal, and the article on HN documents the issues quite well. https://www.europarl.europa.eu/doceo/document/LIBE-AM-661791...
> The proposal does not protect children but exposes law-abiding citizens to major risks (such as AI algorithms falsely flagging legal intimate depictions and conversations of children and adults relating to their health and sexual life) and violates the fundamental rights of millions of children and adults according to relevant jurisprudence. Analysing the content of all private messages is as unacceptable as if the post office opened all letters to check for illegal content. According to EDPS, neither the necessity nor the proportionality of the instrument have been demonstrated
---
A very important and separate issue to E2E discussion is the violation of privacy for whom this is intended to protect.
> Teenagers have the right to discover their sexual identity in a safe and private environment. The rise in reported numbers of online child sexual abuse material is also partially due to the emerging practice of teenagers who, in the development of their sexual identity and experiences, take explicit pictures of videos of themselves and send them to peers, or share such material without a sexual motivation. In addition, the age of sexual consent differs across Member States. If users have reached the age of sexual consent under national law, no reporting on solicitation of children should not be reported to law enforcement authorities
> Notwithstanding their legitimate objective, these activities constitute an interference with the fundamental rights to respect for private and family life and protection of personal data of the individuals concerned, namely all users, potential offenders and victims. Any limitation to the fundamental right to respect for private and family life, including the confidentiality of communications, cannot be justified merely on the ground that certain technologies were previously deployed when the services concerned did not, from a legal perspective, constitute electronic communications services.
https://www.europarl.europa.eu/doceo/document/A-9-2020-0258_...
---
I must say I am pleasantly surprised as to how transparent this process is, and it shows that the "common sense" objections are voiced and brought up.
Most of the harm of content with anti-vaccination stuff or whatever comes when it becomes publicly available. We could still have private communications but block (or annotate with "see COVID Center with actual science") those conspiracy videos when they get posted on public feeds, such as youtube, instagram or whatever. Until the pandemic subsides, that is.
Please use arguments that arent fundamentally based on biases. There is definitely value in a European government, even if the way it's currently setup is very questionable, as the citizens have no realistic way to influence decisions on that level.
Please accept my humble apologies. I am not worthy of your sublime attention. I am so lucky you exist and are leading me to new heights of progress and civilization. Thank you, sir.
They only become necessary if you're using something like Google analytics, which documents every action taken.
The fact that almost all pages have to show them is another sad example how broken our current internet culture is.
Btw, you can actually delete most banners with the ublock origin annoyances filters, that makes me forget that they exist sometimes
They could stop voting for parties/MEPs that have mass surveillance and weakening of civil rights as part of their election programs and core identities. Alas a majority of European citizens doesn't seem to care.
anyway. it needs to go. and then its need to be re-implemented differenlty. no idea how. but not in this way.
So who should you be angry at? Some make believe distant evil council, or your local parties? They are the ones sending over the people who vote on these things, you can complain locally about the policies “far away”.
So I am not saying laws like these aren’t wrong, they are and it is very frustrating that wrong decisions like these might influence stuff happening in my own country, but let’s not pretend that the EU is run by aliens from some sort of Death Star. Pretending like that is the case is what makes accountability seem impossible.
but the whole circus in Brussel is a huge black box bureacracy run by politicians that no one really knows. the politicans that are sent there by local parties are usually not very well known by the local populace, and even if, their doings are not really of influence on how poeple view their local parties. heck I bet 95% of voters cannot even name 5 eu politicians in the parlament and to which local party they belong to.
and thats the power. the citizens are busy with national politics and in the meanwhile the death star aliens can do whatever they want.
and yes. its not an unsolvable problem. people could educate themselves. all the info is there. but its a very laborous job. so maybe the media is just doing it wrong?
EU Parliament is by-in-large more transparent and direct than the UK one (not sure where you're from, but I'm from the UK so that's the lens I have).
But you're absolutely right, for some reason the EU "feels" quite closed off, and it's almost entirely the medias fault. Media is driven on eyes, and the further away a thing is the more difficult it is to have eyes on it.
It takes huge issues to get international attention, natural disasters that kill hundreds in another EU country are barely mentioned on british media.
It's also very boring, so it's not surprising.
But, it's actually very easy to read the EU parliamentary, commission documents, and the documentation on how all the processes work is quite clear (even if it's a bit alien on first look because you're taught your own system and have to "unlearn" that a bit first).
I'd give it a go, it's not as intimidating as it first appears. But I fully agree that the media should do this, it's literally their job.
The truth is usually that eurosceptics have no desire to see the EU work and they will support legislature that makes the EU look untenable, stupid and bureaucratic.
I suspect this is true for other countries.
I’m going to just grab a couple from my phone but I’m sure it would be easy to dig into many others, it’s not a hidden thing really but most people don’t even check who their MEPs are let alone hold them to account on voting records:
Tim Aker, voted against subsidising farmers from volatility (a key impact for UKIP voter base and a campaign promise of UKIP: protecting British farmers) and voted for renegotiating to give Greece more capital: https://yourvotematters.eu/en/profile/ec/tim-aker
and Stuart Agnew, a prominent UKIP MEP has intentionally slowed things down with farcical no confidence resolutions https://www.europarl.europa.eu/meps/en/96897/JOHN+STUART_AGN...
There is no accountability because no one holds them to account and people repeat what you just wrote like gospel, including people writing for newspapers - and that has to stop.
You can pressure the EU as much as you can pressure your national government, all you need to do is put the pressure on your national government. Add your MEP on top, but the national governments are enough if you don't want to go the extra step.
Hopefully he's right.