EU "Chat Control" and Mandatory Client Side Scanning
berthub.eu
berthub.eu
Of course CSAM is bad, shouldn’t we do everything in our power to prevent it? If you implement client-side scanning, you will catch some rookies. Some old pervs that don’t know how to use encryption manually, or use Matrix. They will use them to show how effective the system is…
with the exception that it doesn’t work against anyone who knows anything about computers. And I think the regulators know it, they aren’t dumb (imo). It’s, like I said earlier, an excuse to expand the scope of scanning later.
Europol wants unfettered, unfiltered access to all scanned data, regardless if there's a crime or not.
And they want to inject all of that into their Police AI (which they also want unregulated).
It's going to be awesome future.
So much for the transparency and accountability they’ll no doubt promise will be there for the process of accusations (not that this makes the idea any better, useful, or more palatable), which need not apply to themselves.
1. The meeting tool place after the commission made it's proposal, meaning that contrary to the way the article sets it up, the meeting couldn't have shaped the proposal. 2. The screenshot of a meeting report states that Europol wants access to the same info as Member States for specific cases, contrary to your summary it doesn't say anything about access to all data. 3. That police agencies want to include further areas into the legislation is not unusual. That doesn't guarantee it will happen, nor does the police body speak for the executive or legislators or represent the EU views as a whole.
I do think the proposals go a bit too far, on the other side the whole tech world assumption that anything has to stay lawless is just absurd. No one can deny there is a problem with pedophile material and to say to protect the purity of free speech all such issues have to stay unaddressed is just a position blind to reality.
This is not about free speech at all. Free speech is about the government not censoring public speech and publication. Publishing this kind of material is already an exception of free speech and nobody disagrees with that.
This proposal is about the private communication of all citizens. Not only is it a disproportional measure, it's also ineffective. It will not reduce the demand for this material and will only stop a particular method of distribution. The bad actors will just move to other methods including non-digital or steganography, on unmonitored or hacked devices. Just like the war on drugs doesn't work, they will find a way.
But in the meantime this will deeply undermine the privacy of all people and this tooling will inevitably be used for more purposes than originally proposed. As this linked article shows.
And in order for this to work it will basically have to make FOSS operating systems illegal because as long as the user can modify their OS they can remove this scan. This is one of the reasons I consider it disproportional. Or if implemented on the messaging side only (which is easier to bypass than in the OS), it will make open messaging apps illegal.
This is not the whole tech world's position. Why make up an equally bad opposing position instead of just saying "this regulation is going too far"?
I'm more concerned about the original abuse. The pictures are obviously an issue as they create a market _for_ abuse, but if you're not targeting the original crime, I don't think you stand a chance of actually improving the world by destroying rights.
by these two actions combined this anti-freedom garbage (further consolidating and centralizing powers) will work effectively
Are they thinking of the children when they raid dad's home because a picture of a kids genitals went to a physician for tele-medicine?
Are they thinking of the kids when they come for dad when dad really doesn't like his pictures scanned and self-hosts his infra and uses a Linux based phone?
The EU legislator Martin Sonneborn, member of the German satirist party "Die Partei", is proven he was right when in beginning of the legislature he just enumerated all the criminal and semi-criminal acts of several members of the current EU commission. Led by von der Leyen who also has a horrible track record in German politics. "Europa nicht den Laien überlassen"
It's actually not funny anymore because those people are destroying everything.
From my understanding, Johansson is also the Commissioner who, after it coming to light that the Europol had had a little too much fun mass collecting data and gleefully violating EU citizens' privacy rights, stepped into action that resulted in an effort to pass a new law that retroactively made everything the Europol did legal.
any chance anyone can link or give some suggestions of search terms to try to find this?
It's the 1,5min speech where Sonneborn enumerated some cases, unfortunately in German. AFAIR when he held it, I researched a couple of names and issues he mentioned that didn't look too polemic. In general, he (and his team) is doing what I'd call "trustworthy research" packed up into satire.
I want to see some quick animation that shows each image sent being inspected for nudity, children, weapons, and a list of other things. I want to see the probability of each item shown to the user. I want the decision thresholds to be shown, and the animation showing the rest of what will happen to them if the threshold is exceeded (ie. "Report to police", "fired from job", "Judge", "Prison").
If whatsapp manage to manage to convey all that in a 3 second animation whenever an image is sent, I think users will baulk and the law will be removed.
The thing is the Tech community doesn't have a clear and simple response to CSAM, although CSAM has proliferated with the growth of the internet. Nobody cares about the technical excuses; people care about the absence of any clear effort to reduce its availability and spread. Absent technical measures, people will continue to demand legislative ones.
The Automotive community doesn't have a clear and simple response to bank robbery. Nor are they expected to, because they are not a law enforcement agency.
https://www.sfgate.com/cars/article/Front-license-plate-cars...
This is exactly my point. Yet we have people trying to get tech corporations to act in the role of law enforcement, which they ought not to be doing and certainly ought not be to required to by law.
> nor have I ever heard anyone in that industry vocally minimizing the problem of vehicular crime to avoid some commercial inconvenience.
If you have people demanding that all cars come with government tracking devices under the pretext they could be used in bank robberies and someone in the auto industry notices that bank robberies aren't actually all that common, what should they do? Pretend it to be otherwise?
This is not a matter of commercial inconvenience. The economic cost of writing or installing the code is not the issue. The issue is that this is totalitarianism which once installed would not be limited to enforcing laws against child abuse. One of the reasons privacy is a human right is to protect the public against abuses of the state. It doesn't cease to be a right because the state finds it inconvenient -- the state is meant to find it inconvenient.
It also kind of defeats the entire concept of self-driving cars, which is that they can work without that. They have to be able to work in places with bad wireless reception or a power outage in the traffic control system, not only because of the single point of failure but because things like that could happen while the vehicle is in motion.
Meanwhile there is no legitimate reason to make them mandatory because people already have the incentive to use a system that provides quicker routes. There is no law requiring people to use Waze, but they do.
Measures against auto theft are well established to have brought down incidence of robbery, because it makes it harder to get a getaway car. And the auto industry has absolutely been given the responsibility of overseeing that.
Measures against theft are driven by the market because car buyers don't want their cars to be stolen. Some incidental effect on getaway cars is nothing they had an obligation to provide.
And it's questionable whether that is even true, because anyone could just steal an older car or different make with no such anti-theft features, or use their own car and steal someone else's license plate.
Does that seem reasonable? If not, then phone scanning probably is not reasonable either.
Do you know if actual child abuse also proliferated?
As far as I know, we don't have official numbers (at least not shared as part of the discussion). But what we know is, those scanners have a significantly high error rate and will overwhelm law enforcement with false-positives. What we also know is that law enforcement is simply not competent enough, there was a case in Germany where they just removed links in a Forum forgetting to sweep the according link targets to file hosters.
Your comment unfortunately exemplifies the problem of tech people trying to define the problem away rather than directly address the harms involved or propose privacy-respecting technical solutions to proactively mitigate it.
It is the primary reason that it's prohibited, outweighing any other reason by an order of magnitude.
> I find it hard to believe that a long time technology advocate like yourself is unaware of the fact that the circulation of older CSAM continues to hurt people who were abused in its manufacture.
That depends on how they feel about it. If it is the case that dissemination of existing material reduces the production of new material, no one could be faulted for wanting what they went through to prevent someone else from being forced to go through it too, if at all possible.
> Your comment unfortunately exemplifies the problem of tech people trying to define the problem away rather than directly address the harms involved or propose privacy-respecting technical solutions to proactively mitigate it.
There isn't any known privacy-respecting technical solution and it may not even be possible for one to exist. You can't tell if someone's secret is unlawful without knowing what it is, but anything with access to all of everyone's secrets is inherently a comprehensive violation of everyone's privacy. Any technological solution that could be used for this could not be limited to being used for this.
Fundamentally what you're asking for is the technology to violate everyone's privacy, so that you can violate the privacy of child abusers. But the technology doesn't care what you use it for. It can't be limited to only being used against bad guys.
Then you get the constant negligible sentences when "good" people are found to be pedophiles, the constant victim blaming in courts (apparently "well look how they were dressed", "they were drinking", etc are still real defenses in the US). Look at the abuse received by people who reported that "great" coach in the US, when suddenly sports was more important than child abuse. Then of course you have the constant church coverups that are routinely ruled legal, and then the victims get called scammers.
This is before you get to the abuse of children allowed by people who are trying to "stop their child being LGBT", which is literally torture, but again 100% ok because the people doing it are the conservatives who fight actual meaningful changes to protect children.
Instead what we get is police saying we need to have an unauditable system to report the content of people's phones with no warrant. Ignore the immense cost of false accusations, ignore the documented failures of these systems, ignore the incredible scope for abuse by other people (is it CSAM, or is just LGBT content? because plenty of US states and countries consider them equal). Is it reporting to parents? Plenty of child abusers will want to know if their children are looking at anything LGBT related so they have an excuse to abuse their children.
Or maybe it's protest pictures, or pro-democracy material - once you've shipped this for CSAM, plenty of countries will immediately say "now you can do that, also include this opaque database of criminal images".
Or it could be Iran saying "images of women without a hijab should be reported".
You need to understand, once you say "a persons device should report a specific kind of content on a device to any entity", the technology is in place, and the original "specific kind" becomes whatever the country says a legal requirement, and it's legally required to report to the government.
More generally, the EU has some stupid laws but also plenty of important ones that either bring greater good (safe products in the supermarkets, trade standards, common procurement rules, accountability of what national governments do on economic policy and debt levels, ...) or good for a specific sector (strong data protection and rights for instance, tech standards like usb c, etc). Here the discussion is not even about a law but about a proposal for a law where different people and bodies express different views. EU lawmaking is lengthy and quite transparent so you have these discussions often and at various points in the process, which is unusual compared to many national contexts. And it lends itself to viewing and overstating different views. It doesn't help that there are many lobby groups that sound like semi-EU bodies when they are in reality just industry groups of various kinds that make broad demands which are then echoed in the press as some kind of EU positon.
I'm sorry you've been led to have such a negative emotional reaction to the EU, but it just doesn't mirror the actual facts.
> which has no real equivalent in Europe
> which has no real equivalent in Europe
What a joke, now I know you're just trolling or are just that ignorant of history.
“Private market will regulate itself” isn’t some technical term with a precise meaning that can be misused. It can “regulate itself” by not having any restrictions imposed on it, but i can also be said to “regulate itself” by exploring different solutions to challenges presented by legal requirements with no clear solution path.
However, I see your point here, because most of the time when people just say “private market will regulate itself”, they talk about heavily unregulated market situations.
Not that we should give law enforcement everything they want to do their jobs, but a voice coming from people with actual experience would help.
I get the sense that nearly everyone on both sides of this issue is entirely guessing.
That is the entire answer for "is there any interest in solving sex crimes". If the police do not have the time or the money to do the most basic work possible having already made rape victims sit through the incredibly invasive process of taking the rape kit, why should we think that anything that gives them access to the content of people's devices is going to be used for any kind of sex crime inquiry?
Police do not care about sex crimes. CSAM detection is just their new angle to get unfettered warrantless access to everyone's data. Europol representatives have already explicitly stated that that's what they want this for.
I would hope that people base their political positions on strong evidence and/or the voices of subject matter experts. Alas, political positions are more based on what people want to be true, rather than what is true.
What I've heard is that the only this is a proposal that child rights NGOs has been lobbying for, which I think we can both agree, are not expert in anything tech.
How often do communications done through a wide variety of channels that wouldn't satisfy a cypherpunk from email to Whatsapp show up on evidence before court, even if the people involved knew that they could end up in court? Weren't a bunch of criminals fooled by a literal FBI phone?
I am often dumbfound by the exsessive paper trail people leave for all kind of things...
It's far more difficult than that.
Most Linux contributions are made by multi-billions companies like IBM/Redhat. They would not risk to contravene to law. For example that it conforms to the law, look at WiFi drivers. There are many requirement by local laws on which band to use, what kind of traffic is authorized, etc. The WiFi drivers (most of them opaque binaries) conform to each country law.
To make Linux not lawful, you would have to create your own kernel with your own altered drivers, except you can't modify binaries.
Even then how could you make you system unidentifiable? How would you have control over booting your modified Linux in a commercial computer that uses UEFI? How would you know that the commercial CPU is not phoning home through the Intel Management Engine?
You would have use a FPGA CPU, your own designed hardware and a trusted OS but at the end you will always rely on the work of thousands people and hundred companies.
If literally every jurisdiction on Earth makes it a crime, then I guess this option would go away, but that seems unlikely to me.
The source code is published on the internet under the GPL. Anyone who doesn't like any of their contributions can take that one out and keep any of the others. Do you expect the Kali Linux people to include a backdoor?
> To make Linux not lawful, you would have to create your own kernel with your own altered drivers, except you can't modify binaries.
You can in fact modify binaries, it's just more work. For one person, once. Although that's fairly irrelevant because there exists hardware that doesn't require binary-only drivers.
> How would you know that the commercial CPU is not phoning home through the Intel Management Engine?
You install a firewall in front of it to detect or prevent this. Also, because it can be so easily detected and would be a scandal, it's very likely to be public knowledge if any commercial hardware in widespread use actually did this.
Then you use default deny and allow only e.g. a VPN connection.
This would require the hardware backdoor to be aware of and integrate with the specific VPN that you used, which could be a version of the code published after the hardware shipped.
> Is in possible to have a VPN provider which guarantees not having any Intel machines on the network?
Irrelevant unless the code on your side could hook the VPN, though of course you could.
The better attack would be to have the compromised firmware send its packets using the addresses and ports of some existing connection regardless of its contents, and then have a compromised ISP read them. But even that could be detected by logging the packets at the clean firewall. If it records any that aren't a part of the VPN connection then you've got yourself a rat and a scandal.
Remember, these are politicians. What they do doesn't have to make sense or be possible. All they have to do is pass laws. If it makes everyone a criminal that's good. The law just won't be enforced unless you rock the boat. Much like with the CFAA in the USA or GDPR in Europe.
eventually either nobody will use that, or they'll just jump the shark and outlaw such things
I know that for example in Canada, because taxes, ALL restaurants are (were?) FORCED to use a specific sets of devices else they're branded as tax-avoiders and dealt with accordingly
I've already had trouble using banking stuff under linux, I have had to cancel some cards because they became useless without a smartphone app (the real punchline is that I got a new card that's only works on a smartphone. but at least it was like this when I signed up; they didn't change how it works under my feet)
Either a Matrix Server or even NextCloud chat will do the job just fine. Then just sideload an APK which is rather trivial
But it might be a good way to attract the attention of law enforcement. People running PGP phone services have been arrested and prosecuted because their networks were primarily used by criminals. If you run a encrypted chat service to circumvent the law you might be held accountable for what users use your encrypted chat service for.
Me a father, hard working, tax paying, I just don’t want my messages scanned, are they going to put me in prison?
That might be the best way to get authorities interested in you, once that shit starts going down.
"We ought to put this guy on a list for using encryption (HTTPS, Matrix) everywhere" ->
"We can't use dragnet surveillance because the people are on the list for evading dragnet surveillance" ->
"There's too many people to monitor, too many small servers to crack and backdoor, and the list is mostly just people running their own innocuos server anyways"
Subsequently, you may draw some attention at first, but if you spread attention thin enough it can effectively round to zero - especially if the activity drawing attention becomes moderately commonplace.
Normal citizens on the other hand are presumed guilty unless proven otherwise...
But what if a friend of mine sends me a handmade meme with a child that is not recognized as safe by the AI?
Well, I guess that there will be thousands of parents under investigation and in the news before I pick my turn from the random distribution of the false positives. It's going to be interesting for the politicians in charge.
It's a "all devices need to scan all data and report if anything looks illegal". So yeah, if someone sent you malicious data you could end up being arrested and paraded through the press before silently being release with your life and google search forever tainted.
It's particularly stupid because the government is essentially saying "manufacturers must search your device, and then report the content, and that is probable cause to justify a search warrant", which is obviously absurd.
This is the mentality that made Brexit happen. We can't let this Orwellian surveillance happen and then later try to fix the damage they've done.