Germany opposes EU plans for client-side scanning
tutanota.com
tutanota.com
Is the problem that people can send encrypted things back and forth to each other? Requiring that companies put snooping software on their device is basically the thought police. Not hyperbole but the actual thought police. Today it’s saving the children, tomorrow it’s basically any problem the governments of many nations want to try to solve.
And once they've normalized "your computer will spy and inform on you", is there any reason to think that won't expand to things which aren't colloquially "computers" but in fact are now computers?
What about "smart houses"? All your IoT toys are computers. Once phones, laptops and PCs as mandatory reporters has been normalized, is there any reason to think all the other microphones and cameras already in people's houses won't become mandatory reporters too? If they make it illegal to disable client-side scanning on computers, might they also make it illegal to remove the crime-detecting cameras in your own home?
Modern cars already narc on people, logging and uploading GPS traces that can be fed into police dragnets, just like phones. Cops can ask for a log of who's been inside a 'geofence' and where does that data come from? Phones and cars reporting on their owners, generally without their owners knowing anything about it. The 'slippery slope' isn't actually a fallacy if you have enough datapoints to legitimately draw a trend line. And I think we certainly do.
> We presented participants with a reminder of death and a critique of their in-group ostensibly written by a member of an out-group, then experimentally decreased both avowed belief in God and out-group derogation by downregulating pMFC activity via transcranial magnetic stimulation. The results provide the first evidence that group prejudice and religious belief are susceptible to targeted neuromodulation, and point to a shared cognitive mechanism underlying concrete and abstract decision processes.
[0] https://pubmed.ncbi.nlm.nih.gov/26341901/
[1] https://www.sciencedaily.com/releases/2015/10/151014084955.h...
Cars logging their location history and police getting that data: https://www.forbes.com/sites/thomasbrewster/2021/04/01/these...
Geofenced dragnets: https://harvardlawreview.org/2021/05/geofence-warrants-and-t...
Eerie, isn't it?
Also what if some hackers put something on my phone to intentionally trigger this in order to blackmail me or ruin my reputation?
This is the thinking behind NSA's 'Nobody But Us' saying. If you hoard 0day, assume someone else will discover it given enough time.
Yet we have learned nothing from KGB, STASI, CIA etc.
> Also what if some hackers put something on my phone to intentionally trigger this
"We just found 5 gramms of Mary jane in your pocket".
Religion will come back. "Repent or god will punish you" /s
I think this is the case, except it’s a feature not a bug. The predictable characters will shoehorn in the concern angle[1].
[1]: https://en.m.wikipedia.org/wiki/Four_Horsemen_of_the_Infocal...
So they move the scanning to the device.
It honestly seems to me like they thought they could negotiate a middle ground without pissing off the Feds or the customers, but they maneuvered it quite badly.
Oh cool, didn't know that. It's this new "advanced data protection" feature that makes everything in iCloud e2ee except the classic mail/contacts/calendars combo that wouldn't really work with that. https://support.apple.com/en-us/HT202303 is a nice resource on this, and I wish more companies would publish things like this.
I'm a bit too chickenshit to try it, as losing my devices is all too likely, but I'm glad it's available for those who need it.
Not capable of what, running software? Communicating with a HTTPS endpoint? Having library code? Running stuff in the manufacturer's interest rather than your interest? All those things happen already in some form or other, and there isn't a cutoff to make the phone incapable of it without hobbling the phone.
> "That's one big step closer to the described full-private scanning (and just a flag flip away)."
iPhone already does scan offline private photos for face and object recognition purposes. And run big blobs of unknown Apple-provided code. It's only your trust in Apple that makes you think it doesn't report anything back now - and nothing at all stopping them from being arm twisted by the authorities to make that scan for something the government dislikes and report on it, as you say a flag flip away. It already does send your location and your surrounding WiFi signals and your voice when you use Siri unless you toggle the privacy settings, and that all came in quietly on regular updates.
Apple walked a fairly narrow line when they announced it, and when they publicly stated that if the authorities asked them to extend the scope of the scanning that they would refuse.
I don't know why they chose to do it on the endpoints rather than in the cloud, but acting like doing it on the cloud would give you any level of protection from them putting intrusive software on your phone is not reality. (Same with Google, Samsung, et al).
Not loaded with trained models on illegal content and wired up to alert the authorities if it finds a match, with presumably several teams within Apple built around that feature. I'm thinking about more than the technical aspects of this.
> It's only your trust in Apple that makes you think it doesn't report anything back now
Yeah, exactly. I trust them enough right now to run tons of stuff without my knowledge on my phone. I don't have the time or knowledge to audit my phone, even if it were Android. If they announced that new feature is going live like it's a thing customers are meant to be ok with, I'd trust them a lot less.
It's a slippery slope that ends up with your phone/computer snooping on texts, call contents, or anything else and then submitting your "crimes" to the authorities.
> "Such an expansion would use the exact same justification as the iCloud-bound content scanning."
One of the justifications was that Apple are/could be legally responsible for criminal images hosted on their servers, that exact same justification wouldn't apply to offline content scanning.
> "It's a slippery slope that ends up with your phone/computer snooping on texts, call contents, or anything else and then submitting your "crimes" to the authorities."
Not "crimes" in quotes, crimes without quotes. Generally people think law enforcement is important, especially regarding crimes against children. "A slippery slope" which leads criminals being punished is not the argument winning logical fallacy you think it is. The argument against it is around invasion of privacy, rights not to self-incriminate or to remain silent, ownership of device and software, freedom from unreasonable search without prior evidence, whether you can be found guilty by algorithm, et al.
You're missing my point. Content scanning will start with the Four Horsemen of the Infopocalypse[0]. Then it'll move on to "crimes" like blogging about a public figure[1].
[0] https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp... [1] https://www.flsenate.gov/Session/Bill/2023/1316/BillText/Fil...
There was no way to separate the private photos from iCloud-uploaded photos. It was all-or-nothing, like Android permissions: “Allow govt to scan all your private pictures, or do you wish to have no backup?”
I was perfectly feasible to design the ability to have private photos, but Apple chose not to. Or Apple, in collaboration with the government, chose not to.
(Yes it was feasible to design the ability to have a local photo store which isn't uploaded to iCloud, separate from other photos which are, and call it "private photos", but that's another matter).
Yes there can be private conversations between two people, but there can't be private conversations between two people where one of them isn't trusted but can hear the conversation and simultaneously, what, can't hear it to keep it private?
> The media erroneously reported [a statement from September 2021] as Apple reversing course.
Linking to an article from December 22, 2022 in which Apple is quoted as literally saying “We have further decided to not move forward with our previously proposed CSAM detection tool for iCloud Photos.”, ie actually and literally reversing course.
If this person cannot comprehend an article, should I trust that they actually checked that what they were seeing was what they were paranoid about?
Btw, the screenshot shows an interaction with api.smoot.apple.com, which is known to be used for spotlight and related services: https://news.ycombinator.com/item?id=8479958 ; mediaanalysisd is used for visual lookup, where macOS tries to identify landmarks and other items in an image to help you find more information about it (https://appleinsider.com/articles/23/01/21/tests-confirm-mac...).
In short, paranoid people are good to use as indicators for further investigation, but are rarely to be trusted as sole sources—even less so when they attempt to ascribe intent.
Your note about that domain is interesting though. I don't regularly use Apple devices, so I'm not particularly concerned by that anyways.
Since late 2022 Apple has enabled Advanced Data Protection, which encrypts all photos before they’re uploaded to cloud storage. With ADP on, my photo library is “private” not just in the common-language sense (it contains extremely personal data I have not shared with others) but also in an opinionated technical sense that these files are accessible only to me. If Apple’s CSAM scanner was deployed today, it would be scanning those photos in cleartext on your phone before unreadable data was sent up to the cloud. You could argue that Apple was making a trade: “hey, it doesn’t matter whether we can read the private data you’re storing, the price of sending even unreadable encrypted private data to our infrastructure is that you must run local software that scans the private photos on your phone,” and that’s a trade you might accept or reject on the merits. However I think it’s extremely important to say it exactly this way and not play language games. Apple was going to mandate local scanning of private photos as the cost of using their infrastructure even to store opaque private bits.
> "If Apple’s CSAM scanner was deployed today, it would be scanning those photos in cleartext on your phone before unreadable data was sent up to the cloud."
Or enabling Advanced Data Protection could have disabled the scanner, we don't know. Even if it went the way you said, you could still not use iCloud and have private photos on your device, whereas your phrasing is trying to imply that there would be no option to do that.
I think we will have to agree to disagree about the idea that turning on cloud backup suddenly makes my private photo library “not a private photo library.”
[1] https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
It did a great job at freaking people out hearing about their photos getting scanned and it could be defeated by making a 1 pixel change to any photos a pedo would hide on their phone (since any changes to the image would totally change the hash).
This isn't the way those hashes work. A 1 pixel change would still hash similar enough to be matched. Maybe there are adversarial 1 pixel changes that could break the hashing, but I doubt it.
Even cropping, watermarks and other manipulations like that would still match. "Perceptual hashing", very different to cryptographic hashing. It's basically checking if an image looks "similar enough".
I believe this is why they needed multiple matches, because otherwise there must have been too many false positives.
This may be too oversimplified, but imagine that in a series of CSAM images, there might be, for example, a wall or furniture or something, that could appear similar enough to a wall in one of your own photos. That's a match, off to the gulag with you!
So the lesson is clear - avoid Google as much as possible and use services from separate companies. Email from one company, Chat/IM from a different one and so on. So that if one of your accounts gets suspended for one reason or another - it would not affect the rest.
It's nice how iPhones do the neat AI photo search and montages all client-side, with my Mac backing things up. They're really catering to the less common use case there.
This is how most rights get taken away, not just encryption. Also, we're talking about countries that already have pretty restricted speech. Encryption has to consistently remain popular to survive there, and there are plenty of ways to undermine that.
Were there a shred of consistency in actually advocating for children's quality of life, I could forgive those who are duped by these underhanded tactics. As it stands, there's no actual concerted "save the children" bandwagon that we're being invited to hop on to.
Maybe one should be created, with a prioritized list of issues, and loudly inform people that if issues at the bottom are being prioritized the proponents may have other motives than the ones they claim.
Clearly nobody is suggesting that on average men flock towards more dangerous higher paying professions which until recently also meant higher wages.
Wouldn't want people to make the connection between risk and reward as a factor in economics.
Plus what does this have to do with mortality in children again?
But yes, the transition between CEO and homeless is surprisingly sudden. It’s indeed a risky job.
Are you sure about that? In the US, firearm-related injuries became the leading cause of death among people aged 1 to 19.
It's got nothing to do whether the law would be actually effective at curbing such abuse, whether it will have harmful (seemingly-) unintended consequences, whether other solutions would be more effective or have less potential for unintended consequences, or whether the problem is actually widespread enough to even worry about compared to other risks that affect children.
Unfortunately this is uncomfortable for some people (understandable, it's pretty awkward to talk with a 7yo about sex), but it's what politicians should be pushing if they were really about "saving the children". Monitoring cell phones is not it.
There is already snooping software on most company devices: Microsoft software and Google software and the Western internet.
It's already snooping on everybody for the government (through at the very least NSA).
It already makes sure the traffic is (hopefully/maybe) only encrypted for everybody else.
This goes for the EU as well. Most Western countries legalized and extended what Snowden revealed about government surveillance.
It's already being used in a dragnet surveillance thought police type of way for decades. At least no doubt in my mind. Call me paranoid, don't care.
Let's just agree it's a problem everywhere?
Let's just not, because the ones carrying the baton of "liberty" are the ones that ought be measured by that same stick
China or other countries do not fall on the hypocrisy of saying that your info won't be part of the dragnet, this is not the case with said western govs which then proceed to decry the evil non-western countries for doing the exact same thing and expecting their populations to somehow do something about it¿? ¿? ¿ It is indeed nauseating
In some places they say you are free and have rights, but you don't.
In other places you know you don't have certain rights and act accordingly, because people are not stupid, if they know there's a potential danger ahead, they become more cautious (or they carefully comply, because there are no alternatives).
I would say the first group of counties is more dangerous, because it gives people a false sense of security, lowering their natural defenses, while corporations profit from knowing everything about them, things they said they should never have had access to in the first place, because you have rights, right?
the west talks big, but in reality western countries are the biggest slimiest dirtiest hypocrites the world has ever known
Room 641A was leaked in 3 years. And that was one room with one domestic telecom provider. https://en.m.wikipedia.org/wiki/Room_641A
To keep a secret that spans supply chains, across multiple companies, many with substantial international ownership and/or interests? Not gonna happen.
From a CAP theoretic point of view, the info is Available, but there is still a hefty Partition in that there is a significant degree of the population that isn't Consistent on this fact.
I think the same will likely be true for legally-enforced client side scanning. It is already the case that few people simultaneously have both the knowledge and inclination to "jailbreak" their phones. Throw in stiff legal penalties for doing so and even fewer people will do it. A few people still will, but if most people don't then the ban will still be effective even though it's possible to squeeze through the cracks. In both cases, instructions for circumventing the law may be found online by anybody that cares to look. But most people won't.
I don't think it's a good comparison. It's pretty much unenforceable outside of apple cellphones and very hard to detect.
Yes, and it mostly works! Bans on piracy work well already, most people don't torrent games or movies. And locked down platforms exist, demonstrating the technical feasibility of even greater control. Software piracy in particular is much more difficult on the sort of computers that manufactures deliberately design to be locked down, like modern video game consoles and iOS devices. It is still possible, but has been made sufficiently difficult to stop the majority of the population from doing it.
Piracy has been mitigated through better services at competitive prices offered by the likes of Steam, iTunes, Spotify or how Netflix used to be and not at all by law enforcement.
As long as that remains permitted by Apple/Sony and your government, yes. If either of them decide to ban Plex or VLC, it will become effectively impossible for most people with normal levels of motivation and technical know-how.
> You can install VLC or similar software on your iOS device and watch a downloaded mkv.
Presently, you can. And yet presently, relatively few people do.
These sort of bans aren't ever 100% effective; you'll probably always be able to squeeze through the cracks if you try hard enough. That guy in Japan managed to make a homemade shotgun that was good enough to kill the ex-PM, but the simple fact remains that gun control generally works in Japan. And so do anti-piracy measures even today, before the full technical means of authoritarian control have even been brought to bear.
Locked bootloaders exist and mostly work. The fact that you can presently buy computers without locked bootloaders doesn't change the fact that the technical means of control have been demonstrated to work. Political policy is all that protects us today.
And as far as I know - XBox One, Series X and PS5 haven't been jailbroken at all.
> yet
Key word.
The technical means for that sort of thing have also been demonstrated. The only thing holding us back from a highly effective digitally-enabled police state is political policy. Software piracy is presently easy on some platforms, but much more difficult on others. With the right political impetus, those controls could be extended to the presently free platforms. "Just buy an Android" doesn't work when the law requires Google to implement the same sort of controls as iOS. "Just buy a PC" stops working when the government permits or even compels Microsoft, Dell, etc to implement locked bootloaders like a Sony Playstation and only permit applications to run if they've been signed by an organization accountable to the law.
edit: How will it work in practice? Say I make some Open Source messaging app. Now I need to add some/the government approved algorithm to detect malicious content and then feed this to some government instance. I guess the government will provide me some key/certificate to ensure that my reports of malicious content are legit. But how will this work if this is public, the signing stuff can be abused to file false reports. I have no clue how this will work in practice. The death of Open Source email, chat and messaging apps?
For three years (2016–2019), open-source software couldn't be certified, but since 2019, they consider any 'major modifications' of the software by any user, including the end-user, a reason to certify that forked software. So you can use and modify open-source software for your POS, with that condition if you want to use it for professional reasons. (though I have no idea how it's enforced)
Swedish info; if yo have the same for from france I would be interested. It's not easy to translate the PDF:s into something useable sadly.
Webpage about this process: https://skatteverket.se/foretag/drivaforetag/kassaregister.4...
Cryptographic control unit: https://www4.skatteverket.se/download/18.7d4d4f0515244e542f5...
Requirements of the POS: https://www4.skatteverket.se/download/18.566df4d617d171254ec...
Not if you compile it yourself. Clearly bullish for gentoo and arch users.
Computers are going to become more like cell phones with locked bootloaders. TPM is already a mandatory feature thanks to Windows 11.
No, but they might ban "bespoke" devices.[0] Maybe you're smart and brave enough to build and maintain your own illegal device, but good luck trying to persuade other people to do the same so that you can communicate with them securely online. Also, the government might force ISPs to block access to devices that don't pass remote attestation checks.
[0] https://cyberlaw.stanford.edu/blog/2023/02/my-comment-uk-gov...
Years later, we find out the mind crime courts use ~IRC over SSL~ (edit: emacs org mode over sshfs) to organize their docket, and they eventually have to give RMS access to a libre terminal from his jail cell, so he can help them finish his own processing.
At this point, the backstory is established and our story begins…
Of course it doesn’t really matter the few big companies which control 99%+ of the market will end up complying..
Seems like EU is set on reenacting 1984 for some bizarre reason…
[0] https://matrix.org/blog/2022/03/25/interoperability-without-...
[1] https://goodereader.com/blog/tablet-slates/apple-will-allow-...
More here
https://mullvad.net/en/blog/2023/2/1/eu-chat-control-law-wil...
* About 1 in 4 girls and 1 in 13 boys in the United States experience child sexual abuse.
* Someone known and trusted by the child or child’s family members, perpetrates 91% of child sexual abuse.
https://www.cdc.gov/violenceprevention/childsexualabuse/fast...
WHO:
"1 in 2 children aged 2-17 years suffered violence in the past year"
https://www.who.int/health-topics/violence-against-children
It's a sad joke that child protection is the driving argument for surveillance. The actual numbers are _horrifying_, but almost nothing is done about it even in "developed countries". None of the organizations looking into actual violence against children is advocating for such measures. It is a completely fake and bullshit argument.
> Indiscriminate messaging and chat control wrongfully incriminates hundreds of users every day. According the Swiss Federal Police, 80% of machine-reported content is not illegal, for example harmless holiday photos showing nude children playing at a beach. Similarly in Ireland only 20% of NCMEC reports received in 2020 were confirmed as actual “child abuse material”.
All machine flagged reports must be checked by a human. Somebody will check your photos.
"European Security Officials Double Down on Automated Moderation and Client-Side Scanning" - https://www.lawfareblog.com/european-security-officials-doub...
“Thorn, a U.S. 501(c) (3) organization founded by Hollywood star-turned venture capitalist Ashton Kutcher and his former partner Demi Moore, has been a central force lobbying for the legislation.”
I would guess they are simplying sponsoring this legislation sincerly without understanding the privacy ramifications if it passed.
"There's a company called Thorn that is lobbying for the scanning contract and would love to get a government mandate for its software to be installed into your chat clients," he said.
Apparently Apple didn't want to pay and developed their own in-house, only to scrap it after complaints from the public.
https://www.theregister.com/2022/10/13/clientside_scanning_c...
On a more serious note though I'd also like to know. I never paid attention what Hollywood actors do in their spare time, but it's well known around the world that there are politicians and lobby groups pushing for authoritarian measures under the guise of doing it "to protect the children".
In any case, they must be stopped at all cost. Freedom is priceless in the literal sense of the word, or people would not be willing to die for it.
Germany has a historic responsibility (after two totalitarian regimes that spied on its cities in its past), which thankfully means a substantial part of the population was educated in school enough about the dangers that they would not support any party who let that kind of nonsense creep in, probably even regardless of which party is in power.
I wish it were so, but alas no. We have strong historic privacy laws, data protection authorities with teeth and a working court system constantly overturning new anti-privacy laws. Most of us Germans simply do neither care about privacy nor understand why "it all has to be so hard". The parties most people here vote for are also the parties that constantly enact laws eroding our privacy, only to then have them overturned by the courts. If not for those safeguards, Germany would again be on its best way on turning into an authoritarian police state again.
The only reason Germany is opposing this right now is that we currently have both the Liberals and the Greens in the government coalition. The Social Democrats (SPD) would have just winked it through and the Christian Democrats (CDU/CSU) would have fiercely supported it.
which makes sense. but there’s a reason why victims of crime aren’t allowed to be jurors of their own case.
The commission is even worse. Most countries just send their loudest/incompetent/etc idiots to get them out of the way for a few years. Just look the commission president…
Commissioners and the President of commission are appointed (elected) by the Parliament who is in turn elected by the people.
Same way the American president is elected by "electors" who are chosen by the parties, which are voted by the people. People only vote directly for the congress in the US.
It's the same thing for the European institutions, I don't see the problem here.
Is Jim democratically elected? Or does he have some democratic mandate?
In most countries this would be corruption. Government projects like that have to go through an open bidding process and even after that Jim would not be considered to have any democratic mandate.
The difference between Jim and an EU commissioner is which job he is appointed to.
I think in practice the EU commission isn't that bad (so far) - almost all of the people on it are/were big name politicians in their respective countries. I might disagree with a lot of what they have to say, but they did/do represent a sizeable portion of the voters in their country.
They can say no, the same way electors could vote whoever they like as president of the USA.
It doesn't make the POTUS any less an elected figure.
p.s. EU single state Parliaments are elected too, they don't come from space.
No parliament appoints any Jim to build any road in democratic countries.
Jim's company needs to win a regular tender and have to respect a very long list of regulatory and financial requirements.
Jim's company is a supplier, commissioners are regulators.
Much like in my country (and many others in Europe) ministers are appointed by the Prime Minister who is not elected, but appointed by the parliament, by a majority of the votes.
It doesn't make the Prime Minister and all the ministers equal to an average Joe who's been called to fix a squeaking door.
Yes, because without this bidding, the process falls into corruption. No such process exists for appointing EU commissioners. There's no "regular tender" that the candidate has to win.
>ministers are appointed by the Prime Minister who is not elected, but appointed by the parliament, by a majority of the votes.
The ministers answer to the PM. They are effectively one governmental unit, EU commissioners are not part of it. If the government gets a vote of no confidence then the government is dissolved as a group. EU commissioners can't be recalled mid-way through their term though, which isolates them from this.
I'm really struggling to understand why you keep lying about this.
First of all, there is no such process for any politician everywhere in the World.
Because they are not building roads where people drive their kids on and they are not the solely responsible for building them, in democratic countries there's a lot of them contributing to a synthesis, there's government, there's opposition, there's third parties (so called because... you know!)
Secondly, There's no "regular tender" it's bullshit.
Of course there is, nobody would be candidated to be a commissioner if there's no ground.
I wouldn't be chosen by any party, ever!
Because I have no chances of winning the tender.
Thirdly, and most importantly, there's a vetting process in place in the EU, and any of the commissioners there has more enemies than supporters, including those who are competing for the same seat.
So please stop your anti-EU propaganda and talk about the points you think are problematic in EU, not some fantasy issue that does not exist.
> The ministers answer to the PM. They are effectively one governmental unit, EU commissioners are not part of it.
Just because the mechanic is slightly different it doesn't mean it's wrong.
In France the President is elected directly, in Italy it isn't, in USA it's somewhat in the middle. it's the process that makes institutions democratic, not the system you chose.
> EU commissioners can't be recalled mid-way through their term though, which isolates them from this.
It's the same for parliament members in Italy unless they either die or resign, so what?
Candidates for the remaining Commission portfolios have to go through a tough parliamentary vetting process too.
The European Council, in agreement with the Commission President-elect, adopts a list of candidate commissioners, one for each member state. These Commissioners-designate appear before parliamentary committees in their prospective fields of responsibility. Each committee then meets to draw up its evaluation of the candidate's expertise and performance, which is sent to the President of the Parliament
After the President and Commissioners have been approved by Parliament, they are formally appointed by the European Council, acting by a qualified majority.
Might not give the best of results sometimes, but people in Europe go to the ballots and cast a vote to send people there.
It's not like the board of Amazon or Elon Musk buying Twitter.
And the parliament is a joke it can’t even propose legislation they just rubber-stamp what’s sent to them by the commission. They also don’t get a say in appointing individual members of the commission only the president. However the current president was probably the most incompetent high ranking politician in Germany so maybe they shouldn’t get a vote on that either… the parliament is just a way for local parties to send away noisy politicians away for a few years by giving them a cushy job or just a place to retire for older popular ones.
Hardly anyone in Europe takes it seriously which is reflected in its composition…
That's not how EU works, I know, I worked for them.
> They also don’t get a say in appointing individual members of the commission only the president.
That's false.
Everything is online on the EU website, it's no use to lie about it when everyone can read the original regulation directly from the source.
> Hardly anyone in Europe takes it seriously which is reflected in its composition…
That's utter bullshit, your misinformation doesn't work here.
Which means that the commission members are already elected by those governments.
> The parliament only gets a vote whether to confirm the commission in its entirety
The parliament doesnt only vote for that. Every law that passes Eu-wide must be voted on and approved by the parliament.
Moreover, any law that comes to the parliament must be proposed by a parliament member.
I'm not going to be cynical and say this is just about the money but... Ah who am I kidding, this is just about the money.
Just like it always is.
I've seen a few Kutcher talks and he seems very genuine about his desire to do this work and save kids from the worst of fates.
To reduce pedophilia they would need therapists not chat control.
Here the proposal , scroll down to 'Article 1' for content.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=COM%3A20...
I am not kidding. Ashton Kutcher and Demi Moore are involved.
https://www.nextinpact.com/article/71087/le-senat-propose-re...
Heads of state, like the POTUS, are meant to officially embody the state itself. So if Trump while President says a thing, it is reasonably conventional to describe that as "America said..." But that isn't what happened here. In this case you don't have a head of state saying anything about the subject. The article is about various people (including "IT experts, civil libertarians, law enforcement officials and even child protectors" who aren't even elected representatives at all) giving their opinions to German Parliament. This is not a "Germany says.." situation.
https://www.tagesschau.de/inland/innenpolitik/chatkontrolle-...
… whereas the largest party in the government coalition, the SPD (25.7%) of chancelor Scholz is not only largely in favor of such client-side scanning (of course there are also exceptions within the party), but also the party that holds the relevant ministry (interior) and thus the participation in the EU-side negociations.
The current coalition contract kinda forces the SPD to oppose such client side scanning at the EU level - and we'll see to what extent they keep their word or try to play foul against the contract, but there is no doubt imho that if the next government was again a "grand coalition" of SPD and CDU without the liberals to block such stuff, then such client side scanning would be waved through by the same SPD that currently is contractually bound to oppose it.
The danger of such attacks against our liberties is still very much there, and it takes a constant watchful fight for our liberties to prevent the authoriarian statists from getting through with such stuff. They never stop trying to push through ever more of their liberticide ideas.
You cant 'play foul' against coalition protocols. The moment you do, the government falls.
… but that would usually hurt them enormously more than their infringing bigger coalition partner, especially if the infringement of their partner against the coalition contract is about something that the majority of voters doesn't care enough about, if it's something that the bigger coalition partner can publicly spin as TINA(*)-necessary due to changed conditions or anything they can sell as a "crisis" or if the polls are currently less favorable for the smaller party than at the last elections.
Ending a coalition is something that would typically come at an extremely high price for the smaller party who'd do it. Which is why it happens much more rarely than unilateral infringements against coalition contracts by the bigger coalition partner.
Honestly the "for the kids" we know is BS, they say it's for the kids, even if they parade a group of well meaning people around bringing an awareness there's a problem (IMO, honestly double or treble the amount of police or IT entity around the world to penetrate the vile pedo groups) - but instead such actions proposed are almost always for other more powerful interests who see a fraction of the web as a major problem for some perceived idea they lose money to this fraction's activities.
The reality is any group up to no good will simply migrate to a protocol that permits sending a file from a usb or other external source, but such file will be encrypted unlike any previous known encryption. Then the same process as the good work done presently will save the kids, agencies will slowly penetrate such groups, discover the encryption and member contacts ...
At the end of day like many here have already said, it's a slippery slope. Some people are happy to use devices they really don't own the content to do as they please, they put up with google running their phone apps ... when I couldn't clear my cheap android phone's disk space of the junk which left no room for anything else, without having to reset, that was the point I gave up on smart phones - it now exists only to take texts and calls and create a wifi hotspot.
The other half of my brain says: "Indeed... I really need to be able to control which software runs on MY devices."
Nobody forces you to use Apple softeware. I have never owned a single Apple device and never will.
The point is that the technical means for control have already been demonstrated by iOS, not that anybody is forced to use iOS specifically. Governments could require that Google and other manufacturers implement similar controls. The walls of this sort of prison have already been designed and shown to work, all that remains is the political will to herd people in and lock the gates.
And controls like that would mean death to open source OSes like Linux, because you can't develop and test an operating system on a locked down device.
I didn't say iOS was the first to do it. I didn't say that you are presently forced to buy such devices. And I certainly didn't say that desktop Linux would survive the sort of totalitarianism the tech industry has invented the means to implement. You're missing the point so severely that it's hard for me to understand where my explanations could be falling short. Are you trying to get a rise out of me?
Well if you're running an Intel powered device, there is the Intel Management Engine[0], which is a minus ring zero backdoor with unfettered access to everything. It even runs MINIX! It's not really your computer.
[0] https://puri.sm/posts/deep-dive-into-intel-me-disablement/
In 2016, a voting majority of the UK population decided to give up their valued influence in the EU, and we miss them dearly (not sarcasm - they were a much-needed voice for common sense). This event is commonly referred to as "Brexit" or Britain's exit from the European Union, and eventually from the European Council, which it once was a founding member of.
Ha! That voice for 'common-sense' you dearly miss voted itself out.
More information at https://en.wikipedia.org/wiki/Directive_on_Copyright_in_the_...
[1] - https://www.diyphotography.net/meta-wants-teens-nudes-to-sto...
This is crazy when you think that it used to be a core value and people fought for this.
https://everyoneneedsencryption.gavinhoward.com/
Comments and feedback welcome. I'd like to make these arguments irrefutable.
I was a child before the internet and was used for pedo hunts before the internet, usually having to try on underwear in the UK store Littlewoods, the number of adults that attracted, who struck up conversations with my state employed masonic parents was quite astounding!
Ergo, I think parents should be put under the spotlight!
Throw in a variety of drugs which can make people forget stuff or put them into a chemical trance if its not hypnosis, and people of all ages can be manipulated into actions they wouldn't have otherwise. What age can you start hypnotising kids? Some of these drugs are found in pharmacy and supermarket shelves with no checks if paying cash.
This is why I say people need to have 24/7 unhackable surveillance on them at all times, in order to prove whats been done, as victims, especially those drugged wont know or realise whats been done to them, sometimes for decades if at all.
Drugs/chemicals have been used to hack people for Millenia.
And some parents just see their kids as cash cows, after all the mindset used to be to have a big family so they could look after you when you got too old, and this was before the socialist elements of the state in todays sense introduced things like state pensions and benefits payments.
Thats why I say the state is virtue signalling when they claim to be protecting kids, but dont teach kids how to protect themselves or teach them the law to know what activity's are criminal. This isnt anything new either, its been going on for thousands of years, but history gets sanitised under the pretence of not giving anyone any ideas.
(a bit /s, a bit not)
The problem is the precedent, globally, of killing encryption is well documented. There is no good solution that doesn't harm everyone. Here in the states, the Clipper Chip [0] was the textbook example of politicians trying to legislate mathematics. You wouldn't even be able to do something like "give us a copy of your private keys" because then you'd go down the path of playing wackamole with every distribution, every slightly recompiled GnuPG, etc. It's an intractable problem. We, in the US, would've gone a long way by stripping Dorothy Denning's CS PhD from her [1] after her outspoken support of such measures. Instead she has received many awards for her "work" in the field of rights erosion.
The US seems to have settled on making attempts at Clipper 2.0 every decade or so. In the meantime encryption is considered a weapon legally which is how the DAs get their fill. Germany appears to have flat out opposed it...but it's only a matter of time. The EU will force them to bend the knee because historically they always have. It's a fantastic effort. Unfortunately, done by one of the biggest pushovers in Europe.
There's no hope for the technical among us. The people with power who do understand, the technocrats, are behind these efforts. The people that don't understand are behind these efforts. It's only the intractability of the problem that makes legislating it dangerous. Once someone clever enough makes it tractable there won't be encryption anymore. Pre-crime is the way the world has worked since 9/11 and encryption is #0 on the list of things to legislate to death. In the US, there are likely hundreds of billions of taxpayer dollars being spent to store every last bit of communication in Utah for this eventuality.The EU has a similar program. Those tax dollars have to be justified somehow. So when you ask "who would support this"... just follow the money.
How do you envision this would work in general - an angry Twitter mob demands that academic degrees are revoked, and when the mob gets sufficiently large and angry, the university who awarded the degree buckles under the pressure?
If not a Twitter mob, then who makes these decisions? The Central Committee of the Party? The Committee for the Promotion of Virtue and the Prevention of Vice?
It is not twitter mobs. Its about holding people to a standard and not allowing them to corrupt the meaning of computing for financial, or tyrannical, gain. In recent history we have done almost nothing to hold anyone accountable for their actions. Academia being the most impervious to such punishments.
The ACM and ABET would make the decision. The same people who issue the certifications to the schools who award the degrees. Yes, these organizations are generally spineless cowards, but in a perfect world it would be them. Iron-fisted responses to tyrants is the only way you can insure the purity of a field and freedom from their destruction. I assume you will take this to it's natural conclusion and say any CS degree holder working for the NSA/Military/FBI/etc should also be similarly stripped of their title. To that I say, yes, if they are violating the computing rights of others willfully we as a society cannot allow such people to hold the credential. Otherwise a code of conduct is simply a list of suggestions. In which case it should not exist at all.