Europol sought unlimited data access in online child sexual abuse regulation
balkaninsight.com
balkaninsight.com
And no I am not into conspiracy theories. It’s same as with attempts at “breakable encryption”, it’s offered up under the guise of fighting child-abuse/terrorism/<insert-terrible-thing-everybody-has-to-agree-is-terrible>, but the goal is to increase government access to all communications between civilians.
I actually think that it's coming to the point that the gains of technology, even large bits such as 'the internet' or mobile phones, are so inhuman that it's not worth it. I think modern tech can easily be characterised an almost entirely subsumed for governmental and corporate control. If we thought giving banks licenses to print money was bad, giving these nefarious entities control over everyone's data will be far worse.
But time and time again the outcome of such actions (when left un-countered) does seem to end up with more spying on civilians.
A good example of this in the UK is the Regulation of Investigatory Powers Act [0] that constrains anti-terrorist surveillance and investigation, but which ended up, amongst other things, being used by local councils to track whether children lived in particular school catchment areas, tracking fly-tippers, etc.
[0] https://en.wikipedia.org/wiki/Regulation_of_Investigatory_Po...
https://www-svd-se.translate.goog/a/ona477/kandisbolaget-tho...
https://www.lemonde.fr/en/les-decodeurs/article/2023/09/26/t...
"...Those aforementioned media reports point to alleged close working relationships between the European Commission and a broad network of tech companies, foundations, security agencies and PR agencies, including Thorn and WeProtect Global Alliance, indicating possible undue influence in the drafting of the proposal. Of particular concern are the allegations that the solutions laid down in the legislative proposal to fight CSAM supposedly replicate the solutions designed by those groups, contributing thereby to furthering their economic interests..."
This is of course, the same Ashton Kutcher, who recently wrote a letter advocating leniency for a Scientology member convicted to 30 years in prison for rape, after his sentence.
https://www.reddit.com/r/nextfuckinglevel/comments/qrx02w/sh...
https://www.reddit.com/r/wholesomememes/comments/a8dral/asht...
https://www.reddit.com/r/nextfuckinglevel/comments/mo7krd/as...
https://www.reddit.com/r/news/comments/5uh8rq/ashton_kutcher...
https://www.reddit.com/r/gatekeeping/comments/ca386l/ashton_...
https://www.reddit.com/r/HumansBeingBros/comments/aki1c1/ash...
Afaik all of these threads reached the front page. And that's just the oh so skeptical Reddit community
Reducing him to a single act would work make sense if he was consistent in bad judgement.
https://www.cnbc.com/video/2019/01/14/watch-cnbcs-full-inter...
https://www.mercurynews.com/2023/09/12/ashton-kutcher-remind...
It was a calculated decision and it is reasonable to think he had enough information from lawyers and friends to know how it would be received and how it looks. In spite of this, he still decided to bat for his convicted double rapist friend who, beyond just his crimes, has his connections in Scientology ruin the lives of many women brave enough to speak up against him.
It's not just the single act, it's that it was an act that he had a lot of time to think through and fully understand. It was an act which the years of his advocacy should have given him an understanding of the damage these types of men do to women and girls when they're free. That's what makes it so egregious for me.
Advocating for a convicted double rapist isn't a crime of passion, a poor choice of words, or a drunken fight.
I see this argument often, it's basically taken as an obvious truth in tech circles at this point, but I've seen very little evidence of that happening so far.
To be clear, I think these anti-CSAM laws are pretty terrible, but I wouldn't attribute malice where simple incompetence suffices, as the saying goes.
Child pornography is another beast difficult to solve - again, I am quite sure that they are able to find groups etc on a more frequent basis than we think. When they don't, I don't even want to think about it.
What tools do current investigators have? If you were a detective investigating a case, what would you do or use?
Basically everything useful is either 1) illegal, or 2) technically almost impossible to do (e.g, decrypting https which takes still years to brute force). You could try to ask for a favor left and right to get to a search warrant or install spying devices and "fix" (1) but how the hell do you break (2)?
Communication is happening online and a "military grade encrypted channel" has basically become the standard way of communicating with each other. The few who still use outdated clients or protocols - shame on them.
So, yeah, I really do understand the fact that governments want access to data for their own nasty purposes, however, what can we do as a society to make it 1) difficult for average Joe to use military grade encryption to act criminal, 2) easier for police to find criminals?
I know a knife can be used to cut bread or to kill someone, however, we're talking here about groups of hundreds of people sharing child pornography - that's not a knife, it's a freaking weapon of mass destruction in the hands of people who shouldn't ever ever have access to them.
No, I don't want the Chinese way, but what can we do to avoid getting there?
Can you think of something?
Encryption is a solved problem. Easy to implement solutions are available everywhere. (yes, post-quantum cryptography is not yet solved, irrelevant for the current discussion).
That means that even if it were technically possible to create "legally-breakable-encryption", criminals would simply use real encryption and law abiding citizens would be stuck with broken "encryption" and be vulnerable to government surveillance... and to said criminals. I.e.: there are only downsides. And government experts know this just as well as anyone. Which makes their agenda very clear.
More in general, imho, the benefits have to outweigh the costs: even if breaking all encryption would have offered a small benefit in fighting bad guys, that still does not outweigh the costs of a total loss of privacy (think china) for everyone.
Any time a specific ability is granted or is available to law enforcement, it will expand to broaden surveillance on everything. CSAM is horrific, despicable and devastating. But the way law enforcement treats it as an easy “in” to push for more surveillance and more powers for itself is shameful.
Pretending they aren't is part of the problem, as it empowers those who would push them to publicly advertise the latter good in a vacuum of silence from the tech side.
Something like 'Personal privacy is more important than maximizing law enforcement efficiency, including of CSAM' is a more honest, complete position.
It's not at all obvious whether stopping CSAM is really the primary goal of some of the people who are pushing these regulations. It seems just like a justification to invade personal privacy.
Let's take the issue in vacuum first. Either you hold your privacy as more important than X, or you are willing to compromise some of your privacy in the name of X-- there's no third option. Eg. in case of airport security or CCTV in some public space suddenly everyone is OK compromising personal privacy in the name of personal life and safety.
Now finally let's get back to those other people whom you suspect of having an agenda to surveil everybody. If they honestly tried to combat child abuse, how do you see them going about it?
Not everyone is OK – lots of people argue it's a security theatre.
Detective work, stake outs, researching who makes this stuff, convicting the actual producers, convicting people who do direct abuse... In general, taking real steps instead of reading everyone's dairy and then doing nothing.
So, physical surveillance. Idk if you are aware but this means physical surveillance on everyone, because with Tor you can't narrow this stuff geographically. Would you rather to be physically surveilled.
> researching who makes this stuff, convicting the actual producers, convicting people who do direct abuse
First it already happened when they used to expose identifying details. Those days are over.
Second, more importantly, what you described does nothing about resellers, aka the people who keep the abuse economy running and make money from it.
And please. Hash matching is not dairy reading.
And on the likely chance my dairy happens to have 1:1 collision with a know cp video, I would not mind if someone being able to look at it if it meant they also can look at the actual thing and identify reseller/perpetrator. How can you think differently?
Presumable the content is actually produced at some specific physical location.
> Hash matching is not dairy reading.
The article is not talking about has matching, though. Quote from one of the Europol officials:
“All data is useful and should be passed on to law enforcement, there should be no filtering by the [EU] Centre because even an innocent image might contain information that could at some point be useful to law enforcement,”
Yeah and how to find that location? If you are opposed to any measure that compromises your digital privacy, physical surveillance is the only way
> The article is not talking about has matching, though
Sure. In context of this subthread you are correct. But remember when Apple tried to do it with hash matching? They published a white paper detailing their algorithm. Remember how everyone here instantly whined about total surveillance? It was just like last year. The sentiment is always the same "my privacy may not be compromised if it concerns safety of helpless victims whom I don't care about"
These are not really comparable. Even without CCTVs you can't really expect that no one will observe you public areas (it's just that cost of doing so would be significantly higher).
Also it's something you have much more control over and it's significantly less intrusive than monitoring personal communication. e.g. an equivalent would be the government opening and reading every single letter you sent or received back in the days when people still sent them (or having the option to, which to be fair is something they probably had it was prohibitively expensive to do at scale). That is not something most people living in free societies found acceptable.
> If they honestly tried to combat child abuse, how do you see them going about it?
By actually directly targeting it as the other comment describes? Instead of using "think of the children!" as a vail to justify unlimited government surveillance.
> You are speculating about intents some other people might have.
Yes. Are you implying there is something fundamentally wrong with that? Do you always accept everything politicians say at face value? If so, perhaps you're on the market for a bridge?
Airport security literally checks the inside of your body (if they want to) through xray or other means. How you consider this not comparable in privacy invasiveness?
> By actually directly targeting it as the other comment describes
Please your own take. That comment didn't contribute anything useful.
> Are you implying there is something fundamentally wrong with that?
I can't believe this is a question. You realize you are putting your own thoughts in another person's head?
How is that comparable to having access to someone's personal communication? What's so particularly private about the 'inside' of anyone's body? Physically checking the outside seems much more invasive. But yeah, overall I agree that compromises can and should be made in certain cases when the potential harm to society might outweigh certain individual rights (I don't see how that might be the case in this situation).
> Please your own take. That comment didn't contribute anything useful.
I don't agree and to be fair more or less the same can be said about your previous comment.
> You realize you are putting your own thoughts in another person's head?
No. I'm trying to infer what thoughts might exist in another person's head when they do or say certain things. I don't really understand what are you implying (that we should never assume that no politicians have any hidden agendas and they they all are perfectly honest?)
Seriously? If your body is not private to you, then what's so particularly private about your communication?
> I don't agree
That's not an answer to "how would they go about it if their goal was to actually combat child abuse, as opposed to some conspiracy to surveil that you imagine"
> I'm trying to infer what thoughts might exist in another person's head when they do or say certain things
Exactly. It is what you think they think, not what they think, and such says more about your mind than theirs.
Those who seek this kind of power over others are themselves EVIL by definition
They only have to succeed once, and the law is written and stamped.
Calling Apple's CSAM detection "ill thought out" seems to me to be letting the perfect be the enemy of the good.
Remember when everyone was up in arms about W3C standardizing DRM? Yes, the world would be better without DRM. But the DRM exists and will continue to exist. Arguing for not standardizing DRM isn't arguing for DRM to not exist, it's arguing for it to not be standardized. The encrypted media extensions let me watch DRM-protected content on Linux instead of being locked out of it all because none of the proprietary DRM everyone's using works on anything but Windows/OSX. Linux and Firefox and a DRM blob so I can watch Netflix is better than being forced to use Windows 10 with all its telemetry, Microsoft proprietary DRM, and a browser from Google or Microsoft to watch things.
Yes. It would be better if the government stayed the hell away from my files. Apple not implementing their CSAM scanning didn't get rid of the underlying issue or argument. It just means that it's no longer the tech industry setting the standard for how this will work--it's going to be the government.
Apple's implementation[0] was about as privacy preserving as we can hope for. It only scanned media that was about to be uploaded to their cloud service. It did scanning on device and used crypto to ensure, mathematically, that they couldn't even access the _hash_ of matching images until such a point that enough images matched to cross a threshold. They had client devices feed in fake matches to obscure even the number of potential matches that occur before reaching the threshold. At any no point in any of this is it possible for them to retrieve even the hash of an image that does not match, even after you've passed the threshold.
Would it be better if none of this happened at all? Sure. Is this a _fuck_ of a lot better than what we're seeing Europol pushing for? Absolutely.
Apple cancelling their scanning was a short term win. This isn't a new problem, and this isn't one that's going away. We can throw all the technical solutions we want at it, but it's not a technical problem. ("Sorry, can't scan user's content it's all end-to-end encrypted!". "Don't care. You wrote the encryption. Work around it.". "It's impossible!". "Okay, enjoy your new regulation that all encryption has to have a backdoor HTH HAND.")
I'd rather lose the battle and win the war. Let's put the most privacy-preserving CSAM scanning we can in place and take that card out of play. Let the regulators come out and try and explain how "Well yeah, you're scanning every image for CSAM but, uh, it's not enough. We do really need to see _all_ the images people have on their phones!". We're not making an argument, we're drawing a hard line and standing in place. The Europols of the world are not going to stop pushing. Apple's big, but not "override the EU" big.
When push comes to shove, we will lose. The EU _will_ respond with regulations. Maybe not now, but it should be obvious the way the winds are shifting. I'd bet my left testicle their vision for this is much more onerous than what Apple was proposing.
But hey, at least we can tell our children (away from our phones or any other electronics, and probably standing somewhere deep in the woods) that we were proudly defiant to the end.
[0]: https://www.apple.com/child-safety/pdf/CSAM_Detection_Techni...
I'm really surprised how well that actually turned out.
Whatever you say about DRM (and I'm no fan of it myself), at least W3C's version is as open as it can be. You're prevented from making a copy of whatever you watch (which, to be entirely honest, is a very reasonable precaution in the age of streaming), but you can still write browser extensions[1] or even custom Electron apps[2] that interact with the video element in other ways. If you want automatic skipping of intros, changing playback rate where such functionality isn't supported, access to community subtitles or subtitle-related tools useful when learning foreign languages[3], automatic subtitle reading (with a synthetic voice) or even a completely custom Multi View interface, it's all possible. You can even do synchronized playback across multiple users[4], as long as all of them are authorized to play the relevant media. You could have achieve none of this if you had to use a Flash-based player with no programmatic access to its state whatsoever. It's the best compromise we could have hoped for.
[1] https://chrome.google.com/webstore/detail/netflix-extended/g... [2] https://multiviewer.app/ [3] https://chrome.google.com/webstore/detail/netflix-dual-subti... [4] https://www.teleparty.com/
You're just advocating for frog boiling.
https://www.nytimes.com/2022/08/21/technology/google-surveil...
And to be clear, once you’ve established the capability and the principle of the thing, the technical details will not remain static. The EU regulation already requires scanning for novel CSAM content and “grooming conversations,” because the people proposing this tech think hash-based photo scanning is insufficient. Having conceded the need to scan users’ private data Apple would have found itself mired in a long-term losing argument about specific technologies, one that the public wouldn’t understand or care about. And the other side would have the force of law behind them.
What precisely was Apple’s plan to maintain this “balance” then? Refuse to obey the law? Leave Europe? To paraphrase apocryphal Winston Churchill: there is one point at which you can defend your stance on principle, once you abandon that everything else is just haggling on price.
An absolutely stupid and disastrous move.
Except all of the cloud providers are already scanning uploaded photos for CSAM and have been for years. Trying to blame Apple for this is insane.
Apple was going to scan local photos, not cloud stored ones.
No matter the source, no matter the app.
And the phone will report you to the police if the algorithm marks any local photos as ones reported by the police using a "neural hash", which has a non-zero amount of hash collisions.
https://github.com/AsuharietYgvar/AppleNeuralHash2ONNX/issue...
At the point of upload to the cloud service -where they would be scanned anyway-.
> if the algorithm marks any local photos
No, it required a threshold of N photos to match before they were submitted for human verification.
> which has a non-zero amount of hash collisions
Hence the threshold and human verification step.
... that matches a specific fingerprint.
But also this is a flawed analogy because the scanning is not 24/7, only when you are uploading to iCloud. It's more like "letting people in for dinner and them seeing blood splatter on your walls; after a few visits with different blood splatters, they might well suggest that someone have a look and check it's not just an accident-prone haemophiliac living there."
You're missing the point though. The broadband sensors acting on another's behalf is the problem because all that'll happen is more and more liberties will be taken with the concept of ownership/post-purchase monteization, then god knows who is watching what. Hell, it's a security exploit away from becoming a home invader's wet dream.
So scan them there? Why ahould the phone scan local photos? And icloud is enabled by default, guess who's going to disable it if that would've been implemented?
> No, it required a threshold of N photos to match before they were submitted for human verification.
Yay, private photos leaking to companies employees because of a flawed algorithm, makes perfect sense.
To avoid doing it in the cloud? Then you can turn on end-to-end encryption on uploaded photos.
> private photos leaking to companies employees
Where N of them have matched known CSAM hashes at the point of being uploaded to iCloud, they will be presented for human verification, yes. How is this worse than the photos being scanned in iCloud and being flagged for similar verification?
Known CSAM hashes is incorrect. The sources of the hashes are known to contain false positives. And true positives are not limited to depictions of sexual abuse.
In the very early days of cloud computing (AKA the 2010s) when “upload to cloud” typically involved clicking a button and sending a photo to a server, a subset of cloud companies began scanning photos for CSAM content. Many of these companies exclusively scanned shared content rather than unshared repositories, because the purported goal was to stop distribution (allegedly Dropbox did this, recognizing that “upload” was an automated feature of their system and “share” represented a user choice.) A few companies were blurry on the distinction and just scanned everything, perhaps because it was technically easier.
What’s important is that this was never widely advertised to users, nor was there ever any sort of public debate about whether it should be SOP, particularly for “uploads” produced by default-on cloud backup software like iCloud. When people say “Apple started this” what they mean is that the first real instance of widespread public debate around this feature I know of was in 2019 when Apple very publicly announced their plans, and the feedback from customers was apparently so negative that they abandoned the idea. Moreover, Apple “started this” in a second sense of the term: they developed the first system capable of scanning end-to-end encrypted photos by conducting the scanning on-device, thus providing a technology demonstrator for the ideas in the new EU regulation.
The only way to stop them doing this is for folks in the right places to make it technically impossible.
In a similar note: The fact that its taken years to roll out TLS ECH and DoH which would make a lot of passive surveillance of the internet much more difficult is only enabling bad faith actors like Europol et al.
Sure. Then they'll pass legislation making it a crime to implement technical measures preventing such data collection, and simply lock up everyone you are talking about.
What's the real solution?
Politician 2: Look! The RustyMondayCo startup already made Technology X!
Politician 1: Drat! Foiled again! Now we can’t possibly outlaw it!
This is peak nerd-delusion to think that the state will somehow be stopped by your cypherpunk schemes. It was already a delusion 20 years ago, and now to make things worse, all those guys that used to hang out in those hacker spaces promoting those attractive but silly ideas work for big corporations and governments.
It's the widespread part that confounds cypherpunks, and why PGP, Signal, Let's Encrypt are important despite the bikeshedding they attract from purists.
Oh come on. That was his flippant response to a smartarse question.
The only way for any state to prevent the use of crypto they can't break is to wind back all the things that can perform it, meaning all computers, not just all internet banking and other things that are everywhere now and can't be used safely without it.
States are free to do so, because a state can outlaw physical devices, seize them at the border, etc. — but that is what it would take to do this. I doubt they will, but that's the only option.
Unfortunately, we also have the problem that political factions both native and foreign regularly try to undermine states; doing so in secret is a necessary but not sufficient part of this, and thus getting past crypto is IMO absolutely necessary[0] to keep any state from being usurped.
Fortunately (from the POV of a state) "getting past crypto" can also be Van Eck phreaking, not just weak crypto.
Unfortunately for everyone, just as any crypto backdoor is almost certain to be exploited by criminals gangs to get valuable information, so so are the non-crypto surveillance possibilities: not just Van Eck, there's more than one way to use wifi as a wall penetrating radar to violate your privacy; laser microphones can listen on you remotely for pennies; smart dust is just about starting to be a serious possibility rather than a tech demo.
My current vibe here is that each new invention creates a power vacuum that takes 15 years to properly fill, and we're currently creating new tech too fast for either states or organised crime to fill the gaps.
[0] despite the previous "but not sufficient" because Swiss cheese defence: https://en.wikipedia.org/wiki/Swiss_cheese_model
Beware, they are attempting this.
It's a big project; UEFI, secure boot, and the end of General Purpose Computing. But they will throw absolutely everything they have into this Hail Mary plan, and the chip fabs are a chokepoint...
Do you have something that can XOR two blob of data? Doesn't matter how, if this is JavaScript on a web page, or an app: if it can XOR, it can do a one-time-pad, which is unbreakable encryption.
The hard part of that way of encrypting things has always been sharing the key, but if you're in a criminal gang, or if you're actually trying to undermine a government, you can share the key in person.
None of the things you've listed are even remotely sufficient to prevent unbreakable cryptography. Strictly speaking you don't even need computers: even a handful of transistors soldered up right would do this.
Another alternative is forcing these devices to be designed in such a way that installing unauthorized crypto tools isn't possible.
We're already very close to this point. PCs have Secure Boot, which prevents installing non-approved operating systems. Windows 11 won't boot unless it is enabled. It also requires TPM, which can prevent modification of system and user files by putting the hard drive in an unencumbered computer. Windows Smart screen really doesn't want you to run apps not certified by Microsoft, although it is still possible. Web browsers are doing more and more to prevent you from visiting websites not secured by TLS, outright blocking some APIs if HTTPS isn't enabled.
The tech is here, all it takes is a regulator to tighten up the screws. It's not unimaginable for the EU to ban all motherboards with Secure Boot that can be disabled, to force Microsoft to refuse uncertified apps, to force Microsoft-certified browsers to require TLS with a specific set of root CAs, and to require those root CAs to only issue certificates to those the EU deems worthy. The EU isn't terribly likely to do these specific things out of right-to-repair concerns, though those concerns could probably be assuaged if the certification was done in a fair way by a third party, possibly the government itself, instead of tech companies.
This way, you can have perfectly secure crypto with your bank while still giving the EU the ability to access your messages at need.
On the plus side, this does mean no more JavaScript and no more Excel spreadsheets. Unfortunately we'd have to ban nice things too, as those are only two of the things you'd have to ban to make this happen.
Don't get me wrong, the government behaviour you describe is plausible — turning those screws to make it harder is highly likely IMO — I'm just saying such limited things will never actually allow them to achieve their goals, and that unless they want to outlaw possession of computers at least as advanced as the Z1 from 87 years ago[0], they need to do their surveillance in a different way that doesn't break crypto.
(And that everyone else being able to do that surveillance necessitates substantial social change, but that's a different topic).
Probably true about Excel (or at least non-cloud Excel), but not JS.
You can apply the App Store model but for websites. Require ID to get a TLS certificate, block anything which doesn't do TLS, allow certified websites to execute arbitrary code with a few technical restrictions. If somebody violates the law and is discovered, through either manual or automated means, they can be blocked via TLS revocation lists.
Nonsense. Encryption is legal.
We got rid of the ITAR restrictions on encryption. We prevented Key Escrow and the Clipper Chip Mandate.
We won.
PS, governments hate bitcoin more than anything else on earth, and yet it is still worth half a trillion dollars. We're still winning.
A better example would be Snowden given nobody was done for lying to congress, but even then he changed things by revealing so much.
1. Mass spying is unpopular. The only reliable support base is a small-ish group of unlikable busybodies.
2. Reducing civil liberties tends to come back to bite the people who implement it. The best part of the Trump backlash is watching the intelligence apparatus come down on the Republicans. Karma in a nutshell, they were one of the major enablers of all that stuff after 9/11. All these ideas like free speech and private communication are ultimately to protect politicians.
3. It is practically difficult to stop. Any country that tries to stop encrypted messengers would have to cripple their own economy by bringing in such limited computers that they can't do anything. And they'd be hopelessly vulnerable to foreign espionage.
This is not that hard of a political fight. They tried to ban strong encryption back in the PGP era and look how that went - SSL is everywhere, encrypted protocols are everywhere, we have cryptographically based assets and every company is encrypting everything they can lay their hands on at rest. The ban-encryption camp has a track record of complete failure. And The Children have been Thought Of and are living in the best era ever to be children.
As a start, moving away from UDP is an improvement
This is something it took me a long time to integrate.
Politicians, especialy politicos with their backs against a wall, face demands to "do something about it" that they can't resist. The result is often a treatment that is worse than the disease.
If that's true, the corrollary is that we shouldn't mock politicians when they come up with "solutions" that are ineffectual - provided they're just ineffectual, and not Trojan horses for some more insidious plan. Perhaps the best answer to "something must be done" is to do something - anything - that doesn't cost too much, and doesn't do much harm.
Cancer is high on my list of problems that cannot be solved, we’re getting older, old age comes with decline of your body, spending money on a lost cause is a huge waste.
As a rule of thumb, good politicians tend to fight for transparency in the government and privacy for their citizens. Bad politicians push the opposite view.
That's not a real disjunctive. In my current country, where politicians are accountable and mass surveillance is not (yet) a thing, the country is not run by organized crime, and children and young women are not exploited. But I have lived most of my life in a country with mass surveillance (Cuba. And no, you don't need client-side scanning, a sufficiently high number of police riding bicycles will do just fine.) The chilling effect on public speech and thought has brought untold misery. All politicians are corrupted party-folk chosen from above. Young men and women enthusiastically jump at the opportunity of being sexually exploited for a chance to escape the country. There is the bottom of the dumpster where the slippery slope of totalitarianism takes us.
> Cancer is high on my list of problems that cannot be solved, we’re getting older, old age comes with decline of your body, spending money on a lost cause is a huge waste.
I would recommend you visit the aforementioned Cuba. A cancer prognosis there is better than it was during the middle ages, but far worse than it is in a first-world country. So, cancer is not unsolvable, it's just that there are different levels of progress across time and places. Same goes for aging, but there we have this cultural brick you have so brightly illustrated that says even trying to do something is a "huge waste".
If you inverse it and instead allow those running the country to spy on the public but not the other way around then when organized crime takes over running the country they have an insanely powerful tool to use to stay in power and accomplish their evil goals.
The true enemies of freedom aren't shadowy cabals scheming in back rooms – they are your neighbors, your coworkers, some of your friends, and possibly even some of your family members.
The "true enemies" are the folk scheming in backrooms who hope to succeed by the ignorance of the rest of the folk you listed. Are my neighbors, coworkers, etc. a problem in this battle? Yes, absolutely, but they're not the ones acting with malicious intent.
And ironically, the false idea that the population is ignorant of every important issue is yet another argument for invasive, controlling regulation of everything...
The entire point of representative democracy is that the elected representatives are the ones who work with subject matter experts to reach solutions that work best for the people. Thus, it is the representatives who are, at worst, malicious/evil for not listening to subject matter experts in favor of their political games.
This is all still just framing and you're only falling into the trap.
One of the many strong arguments against this kind of government surveillance is it's the sort of thing authoritarian governments use to commit atrocities. People can certainly understand that Nazis are bad and technologies that protect people from Nazis are good. Now all you need is to point to the proponents of the scanning and ask why they want to help Nazis.
It's the same tactic they're using. And then they use counter-tactics, like weaponizing Godwin's Law even in cases when you actually are discussing authoritarian government policy.
It has nothing to do with the nature of the issue and everything to do with the fact that the proponents of these measures are professionally trained propagandists who know exactly what they're doing.
Maybe we need a corollary to Godwin's Law. Let's call it Lovejoy's Law:
As the length of a policy debate increases, the probability that someone implores you to Think Of The Children approaches 1, and the person to do this loses the argument.
Ergo, encryption helped Nazis.
Only because they are not informed about what this is actually about. It's all about framing.
* Do you want the police to have better tools to fight child abuse? -> Of course!
* Do you want the police to see what private messages you are sending to your loved ones so that they can ensure that you are not a pedophile? -> Hell no!
Most people doesn't even care anymore, they know they're always spied on when they use messenger or instagram (covering the whole age spectrum here), they'll always hit you with the "I don't have anything to hide"
What exactly is your justification for regarding your right to privacy in your communication with your loved ones is more important than the right of the police to fight child abuse?
I believe most people would not agree with this exact proposition, but with a different one: that once the police is given the power to fight child abuse, which can only be given by allowing them to access private communications of anyone suspect of being involved in such crime, then there will be abuse of power and they will use that access to also fight other crimes or even for political gain, as tends to happen in authoritarian states.
I would absolutely be willing to forego my right to privacy under certain circumstances given that there were strong enough guardrails in place to prevent abuse in the future if that would allow child abuse and other hideous crimes to be prevented - it would be immoral to not do so. However, as most other people in tech, I have enough knowledge to understand that it would not be possible at all to prevent abuse with current technology - once the power exists at all to break into communications, anyone with enough motivation and resources available will be able to do it, not just the intended receipients of such power, unfortunately.
If you really want people on the other side of the debate to understand you, you need to stop being so simplistic - there are very good justifications for their positions if you remove the practical limitations of being able to stop abuse - which they do not understand, and I suspect a lot of people in tech even also fail to comprehend.
I would even go as far as to say that future technology may change this: it may be possible to have completely abuse-proof technologies in the future which, if it existed, would make me change my position on this matter.
For example, something that uses blockchain technology to make it cryptographically impossible for the police to access someone's communications without having a warrant?? And making that warrant only usable by the police if it was also approved by a number of different, independent groups, including groups advocating for privacy (something like a "smart contract" could do this?)??
You can say these are stupid ideas, and I would probably agree... but my point is that this may not be impossible, and perhaps people who are really concerned about privacy while also having an understanding of why the police may need this sort of power should be actually trying to find ways to do this properly instea d of just keeping repeating the mantra that no, this is impossible and we'll have to live with child abuse , terrorism etc. forever?!
Violation of privacy is harmful. The police is not supposed to cause unnecessary harm. Given that the vast majority of people are not child abusers, there will be a great amount of harm for no gain. And most child abusers will find ways to evade the surveillance. This is not even remotely close to a reasonable bargain.
> If you really want people on the other side of the debate to understand you, you need to stop being so simplistic
We were talking about the general population and how they perceive the same topic given different framings. Most people think in simplistic terms when it comes to topics that they don't actively engage with.
> there are very good justifications for their positions if you remove the practical limitations of being able to stop abuse - which they do not understand, and I suspect a lot of people in tech even also fail to comprehend.
Are there very good reasons to fight child abuse? Of course. But if non-technical people believe that there is a magical technology that can deliver what politicians claim then you have to challenge them to explain where their beliefs come from. And precisely because they actually don't understand the technology they have to admit that they actually can't form a well-founded opinion on it. You might not be able to make them understand why the practical limitations make this a bad idea, but you can make them understand that there is an important gap in their knowledge on the topic. And something that everyone can understand is: Not every solution is actually a good or even effective solution.
Most conversations I have with non-techy people, they end up saying "Yes" to both.
Later her friends agreed that it happens for them too and didn't believe me when I suggested other possibilities.
[1] In reality, most likely ad targeting based on her online habits works as intended.
There are ads utilizing this trope now
Then mention that disease a few times in the presence of your Alexa, Siri, or Google whatever. Talk about the disease to your wife on a phone call once or twice (make sure she's in on it, so she knows never to type the disease into a search engine).
See if you start getting ads for treatment for that disease.
It's a little crazy, but I'm not convinced it's impossible. I've something similar to me happen a couple times, but not under rigorously controlled circumstances, so maybe it was google searches by a relative or friend who overheard me, and I was marketed to by association? Maybe somebody with that disease visited my house and their location was broadcast and linked to my wifi?
Unsettling, any way you cut it.
I like Switzerland (where I currently live,) because they have direct voting on topics, mixed with electing representatives. There's a filter so the people don't have to vote on everything, but for the big questions, there's already a system in place to ask the people. That must have sucked 100 years ago, when communication was more limited, but today, I think every nation should move to it. It also keeps the people engaged (voting on 3-4 topics every quarter,) and not just something that happens every four years.
Maybe that would have saved Sweden from the extreme sides of (nationalist) politics, and from banning investments into nuclear for 40 years before ripping that up. Mind you the nuclear disinvestment was based on a (non-binding) ballot vote, but my problem is no one dared challenge it, or have a process to re-ballot the question, in 40 years. Even in light of new climate information.
It's (the EU's) authoritative to companies by suppressing them with penalties and bueacratic laws, but allows itself (the governments and states) unending tolerance in whatever it does.
> but allows itself (the governments and states) unending tolerance in whatever it does.
Could you clarify what are these horrible things the EU has done that you're referring to?
And soon what's coming is even worse: digital markets act. Which allows the EU to fine companies up to 10% of their yearly revenue.
That's just the obvious stuff that I can write about. I live here and have experienced it personally how Germany treats businesses.
I have high hopes digital markets act will be as good.
It's hard to imagine that his data is so important, that he's so wanted, that people care about his so much, that GDPR will make any difference whatsoever on his life. On the contrary, the world is burning, clock is ticking, and you're complaining about me being aggressive on HN?
Are you saying that you liked how Facebook and Google could cross-site track every single (logged-in or not) European and use that for targeted ads as well as share it with the NSA?
Thank GDPR (and Apple) for stopping that around ~2018.
Yeah, a couple small good things in GDPR doesn't outweigh the bad and damage. Not even close.
I'll state that I'm happy that your libertarian/anarcho-capitalistic views on regulations, taxes and government is an extreme position here and not the status quo.
It's one and the same thing.
They disregard property rights and order everyone about.
The reason this seems strange to you is you didn't care when they did that to Web site operators.
'Authoritarian supporters of privacy' is a position it's possible to take.
Which begs the question of whether democratic/authoritarian or surveillance/privacy is the more important characteristic.
you got it backwards
eu: cookies/tracking is bad, don't do it. if you _really_ need to, you have to ask.
big-tech: fuck this! of course we need to track users. we're just gonna ask everyone all the time and put the blame back on you.
Aha, you first. Oh, this lady only meant our data, not theirs.
Stuff like this happens because people at large lose their shit, or at least pretend to, when it comes to "child safety". Impossible to even have a straight conversation. It's straight up dangerous
Can't wait for the competent police officers at my local station to call me in order to have full access to my phone based on some photos I sent to my mom regarding her niece (my daughter).
This will have a Streissand effect like no other.
Is this a typo? I can't imagine how this would work without some familial intermingling.
And there it is, just as anyone would expect. It’s never just about Protecting The Children™.
Like the war on terror and drug war and all kind of "icky things" previously. Just excuses and a red herring to implement something dubious.
https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...
The other argument could be that it increases the chances of someone moving on from the consumption state to the abuse state.
But having to train models on real materials is a major moral issue.
This is actually my opinion but I have no hard data on this. Is it feasible to apply the same logic as with video games where realistic killing is depicted and the argument is that this doesn't make people killers in real life?
South Korea has jailed a man for using AI to create sexual images of children
The issue is that hash-based scanning will be rendered irrelevant by AI-generated images because there could be an unlimited number of them, and they could be produced by general-purpose image generating software that isn't itself illegal.
Esp. in cases like isolated virtual machines running old versions of say Windows or Linux where child molesters and pedophiles don't have to worry about the scanning software.
I can't pretend to be an expert on the subject, but isn't a VM in a separate area of RAM where it doesn't bleed out?
That said, continuous RAM scanning would be incredibly resource intensive.
Looking around quickly, it seems to be Secure Encrypted Virtualization (SEV):
The chatcontrol law requires scanning on the ISP level and on the internet service level.
That means:
* ISPs are required to check for connections to flagged servers. They also have to check for illegal URLs (yes, HTTPS will make that pointless)
* Services like chat/e-mail/file-sharing services need to effectively check if a user is sending illegal material (no, the law doesn't take into account the complexity of open source ecosystems and the many options you have for client software and server hosting options)
How could this not run afoul of that?
I thought the EU had learned something from the Data Retention Directive.
>What does the Prohibition of a General Monitoring Obligation mean? The prohibition of a general monitoring obligation means that companies cannot be obliged to introduce measures that will result in blanket monitoring of the activity of users of their service, nor obliged to seek out illegal activity.
Unfortunately, the commission doesn’t care about passing illegal legislation (DRD, the 3 EU-US transfer agreements, etc.), and the CJUE is not fast.
Actually, the view of those lawmakers in this thread seems to be some sort of caricature of self-interested future despots, as if most of commenters here are not living in democracies.
It would be astonishing if it was not routine on HN...
Sure maybe the moral tradeoff is worth it and privacy is top priority. Then I'd recommend to focus on all other areas of life that violate privacy first. Ban airport security, CCTVs etc. After that feel free to move on to banning measures that protect victims, who unlike most of you grown-up functioning adults, can't even stand up for themselves. And address the gravity of that tradeoff, or you're just making nonces out of yourselves.
Furthermore, a lot of the same forces that are trying to get rid of end to end encryption are explicitly trying to take their parts of society back to that.
A line must be clearly drawn in the usage of such "military" grade systems.
Criminals get easier access to online CSAM, then law enforcement should get easier access to user data. If you think that trade is unfair, take it up with the criminals.
They can catche them without such stupid measures, that will make any secure communication impossible for the masses.
We can not always get what we want.
Instead, we entrust the police a monopoly on violence, physical detainment, and violation of privacy, and hold them accountable if they can be shown to disregard their duty and responsibilities. As a civilian, your duty is to weigh your personal sense of discomfort against the societal benefits of improved child abuse detection.
No. Not your personal sense of discomfort... this isn't a case of privileging one person's selfishness versus the whole world. You have to weigh the harm to _all_ of society from loss of privacy, against the societal benefits of improved child abuse detection.
Including the future harm to those children as they live their lives with lost privacy.
Civilians are not supposed to worry about future children as they live their lives with abuse. They get too emotional.
Russia is certainly still trying that now (I assume the US is too, but haven't heard of it recently).
Giving any group legit access to this risks those spies having a convenient and easy way to find anyone with dirty laundry (even mild, legal stuff), and blackmail them into helping the spies.
This problem still exists even if we don't have the system for legit access, I'm only saying an official system makes it worse.
We still have to alter our societies so that nobody has anything secret to be ashamed of. This necessarily means making society radically more transparent, and I think the only way this is possible is to also make society radically more inclusive and tolerant. Why also tolerant? Because I've heard people typically commit 3 felonies a day (don't trust random factoids), and at that rate transparency without liberty turns the whole nation into a prison.
But it won't happen though an Interpol investigation and leave a formal audit trail.
It is just turning "think of the children!" into "think of the sexual blackmail!".
Be very careful with sharing explicit photos online. Your settings and encryption must be very strong, or people other than your mom may get access to it.
If these others then get investigated for child abuse, it should come out to the investigators that they joined a semi-private Facebook group and have access to beach photos of children. Their credit card number also should show up in registering for CSAM forums.
It is a wonderful idea to protect you and your family by taking precautions. Lock your doors. Don't accept requests from people you don't know, educate your mother on online security, and think long and hard about if it is worth it to send your mother a picture of your naked child, for there is a possibility this will end up everywhere.
Everyone has something to hide and to worry about:
> It came in 2003 when Townshend, now 74, was arrested for using his credit card to access a website offering child pornography, though no images were downloaded.
> Rock star Pete Townshend reveals today how his arrest on child pornography charges saved his life after it indirectly led him to discover he had cancer.