Signal: Will leave the EU market rather than undermine our privacy guarantees
twitter.com
twitter.com
----
According to the latest draft regulation dated 28 May (Council document 9093/24), which is presented as “upload moderation”, users of apps and services with chat functions are to be asked whether they accept the indiscriminate and error-prone scanning and possibly reporting of their privately shared images, photos and videos. Previously unknown images and videos are also to be scrutinised using “artificial intelligence” technology. If a user refuses the scanning, they would be blocked from sending or receiving images, photos, videos and links (Article 10). End-to-end encrypted services such as Whatsapp or Signal would have to implement the automated searches “prior to transmission” of a message (so-called client-side scanning, Article 10a). The initially proposed scanning of text messages for indications of grooming, which is hardly being used to date, is to be scrapped, as is the scanning of voice communication, which has never been done before. Probably as a concession to France, the chats of employees of security authorities and the military are also to be exempted from chat control.
----
Strange times we live in. Entertaining, but strange.
[1] - https://www.patrick-breyer.de/en/majority-for-chat-control-p...
No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks.
Bugging communications by investigators with special approval is already an exception to this principle. Government bodies that make sure that laws conform to the constitution should veto any exception broader than that, so this draft should basically be pointless.
It feels like there are social/political mechanisms at work that allow that to however happen. They pave the road to Hell little by little, one stone at a time, and this is neither strange nor entertaining. To me, the beginning of this century has similarities with the beginning of the previous, which is quite worrying.
the reality is, if anyone is seriously determined to commit what they know are crimes then there are many solutions, of admittedly varying quality, for having private communications outside of the mainstream apps available on the app store. even signal itself has an apk you can install on android from their website.
so, it's unlikely this will indeed help in the fight against CSAM or whatever else is purportedly motivating this legislation. the end result will be mass surveillance 24/7 on the vast majority of the population who aren't commiting any crimes at all. it seems to me like big brother's wet dream. ironic that this is exactly the thing the US/EU political leadership have been bashing the chinese for since forever.
there's a good reason for that. it's not controlled by and for the benefit of our oligarchs.
Of course. Your "privacy" is very important for Microsoft, Google and Apple because of the "geopolitical situation". /s
Seems to be targeting platforms. Will it be illegal to send encrypted texts, what is keeping anyone from using crypto on top of existing messaging?
While I do not want to dive into any details on adverse effects of such stupidities, the EU seems to be actually taking a strange road to tech dependent overengineered regulation. It seems that this mostly driven by lobbyists that want to sell compliance services. Also it seems that there is more value in creating regulation rather than making sure it is enforcible.
Seems about right for the EU.
Maybe there's an unintended upside to all this regressive business legislation. With all the focus on the "platforms", then maybe, just maybe, this will be yet another nail among the thousands of nails needed to finally kill them off.
Strange times indeed.
Half of the reason Microsoft is pushing "AI PCs" with special hardware is so they can push their spying to on-device and reduce all the extra costs the data processing they're imagining for things like automatic-screenshot-analysis-every-x-seconds will need.
And they're pretty much experts on spying on users. They've been collecting so much data for so long that apparently they've found a way to utilize what they collect in a way that makes the costs balance out in the end. Whether thats with government access, preferential antitrust treatment, or some actual financial method that directly affects the bottom line, I don't know. Somehow it's worthwhile for them. BUT -- when even Microsoft is looking for more efficient ways to spy on people, and forcing new hardware to support that effort, you know the data collection and analysis technique is definitely not ready to be made a legal mandate.
It doesn't make sense at all for some EU decision makers to decide it's acceptable for their citizens to bear the cost of so much data processing.
....wait, how much do large players in AI contribute to these politicians campaigns? Or if not them, who is really pushing this? It seems like someone should really try following the money on this one.
It's just a matter of lesser evil in my humble opinion.
At least on a mass scale, if we worry about back doors.
This SaaS fad is the underlying technical enabler of the spying and need to go away.
I guess Google is the main culprit by making P2P coms hard.
Asking faceless corps to open their users' mailboxes willy nilly is way easier then asking the voters to.
We don’t own our devices anymore and we now have very limited control of what is executed or not so there is nothing stopping developers to run those legal spywares on the device since our only option if we don’t like what an app does is to not use it.
We have linux phones these days, caly, and grapheneos. There really isn't reason to give up on general computing. (Ignoring the propriety baseband blobs.)
Sadly, nothing else comes even close to Apple in terms of security and privacy, especially for someone who is not an infosec specialist and doesn't have time to read CVEs all day.
Even for someone that is not an infosec specialist, they should be using something like Graphene for phones and something like Qubes for their OS.
Apple isn't great at all honestly, at least in terms of MacOS security - they mostly benefit from not being worth the time to target.
The slope is so slippery that it's ot worth the risk, imo. It paves the way to reduce general computing even further, which is already quite restricted on apple devices to begin with.
The problem is not going away, we in tech are partly responsible and we should promote good ways to deal with it. If we don't then a solution will be found anyway, it'll just be a bad one.
Finally, free from WhatsApp voice notes, stickers and images clogging my phone storage. Adieu.
If this law passes, bye bye.
dont misrepresent
dont misrepresent
If true, then it seems unnecessary to "leave the EU market" with respect to text messages and voice calls.
Additionally, it says photos, videos, links, but you can make any data represented as other files e.g. text, slowscan, steganography, etc.
As far as I know, most messaging platforms allow you to send regular files too. Wouldn't "the bad guys" simply use that as a loophole and continue with their day?
I know the real reason behind the law isn't to actually protect children, but, you know...
So it won't stop CP, or any other criminal activity that's in the slightest bit cluefull.
They must know this, so I'm left scratching my head wondering what they are actually up to.
I took that as a given and therefore described what I would see as scan-creep of the gov implementation regardless of the exact verbiage of the law.
My point was that anyone expecting to use the file type as a loophole would likely ne compromised, and the only way to ensure bypass of the scan would be to locally encrypt before transmission, as any text or binary entered into an app affected by this law should be assumed to be fully mined, scanned, and reported to the gov regardless of its contents.
Shit criminals will just meet and swap usb drives lol, like i don't get how this solves the crime issue. This is like banning monero or crypto because its used illegally.. meanwhile CP and other crimes have used Euro and USD paper money for long before crypto lol but yet "crypto seems shady" is enough reason to point at it as the reason crime exists lol.
I want to see the riots when EU cell phone consumers have to pay for text messages again.
Some men just want to watch the world burn...
In fact, most of the protests seem to neatly fall into the "police violence" (usually against minorities) and "austerity" buckets.
Occasional war here and there not directly involving any of the member states is incomparably better than what came before.
Edit: I am *obviously* not talking about surcharges for roaming but cost in plans, which I think is the point of the OP when he asks who pays for texts. Pricing is not regulated and has nothing to do with the EU.
Thats a LOT of compute.
Ban all “non-intelligible” content?
Who can stop me from hiding information in very normal looking sentences?
If you want privacy, there will always be a way.
You can just send anyone you want an encrypted e-mail or message, but Signal can't facilitate that without the required provisions set out in those laws. If these dumb laws get enacted, Signal cannot get away with just pretending you are sending gibberish whilst providing true end-to-end encryption without any client-side scanning or whatever to you, but you are well within your rights do so yourself on top of Signal (if that's even possible); they just can't provide an automated means to do that for you.
Or ... they develop their own darknet webrtc based chat lol, like its silly to enforce this on the general populace when its so obviously circumvented by the people looking to do scary shit.
What I'm wondering is whether two separate applications can be set up to communicate automatically, with one handling messaging and the other being responsible for encrypting and decrypting the data.
What would be against the law in that case? The messaging app? The encryption app? Or the interaction you are doing in that moment?
Of course these laws are dumb, but that doesn't mean they can't be (mis)used to get the desired effect.
Actually police and various agencies do, because when most people aren't encrypting, the few that do are suddenly interesting. Some of them will turn out to be organized crime, but some of them are just adults who want to communicate privately.
Does Android facilitates IPC and services?
That might be the next step. Banning encryption. We live in a strange world right now.
What some law-and-order types (globally) want, is the means to scan, peek, or otherwise access private communication, especially if that communication is provided by a service used by millions. You can encrypt all you like, but if you use WhatsApp or Signal, laws like these force those services to create a way to eavesdrop. How is probably not defined in the law. Client-side scanning before encryption, having those services act as men-in-the-middle for each conversation; this is all fine, and can use encryption as usual. As long as certain agencies get to have a peek somewhere between those strongly encrypted tunnels.
I understand Signal is handicapped now, but I couldn’t care less about Signal. I only care about being able to communicate in private. Why don’t we implement this stuff at a lower layer?
Surely the guys on top must see this is an endless game that they will never win? It’s not an arm’s race, it’s fundamentally impossible.
This is about making it hard (or impossible) for some perceived group of miscreants to communicate privately. People sharing CSAM (however you define that) or dealing drugs, and stuff like that. Anyone can encrypt their communication, but most people don't do this consciously; the masses just use WhatsApp and Signal and what have you.
You and your special keyboard are not of interest, and unless you start selling these along with a service to route the encrypted messages to thousands of users, you are not the target of this legislation. Take away Signal and WhatsApp and sending an end-to-end encrypted message to your drug dealer without exchanging keys and agreeing on a protocol suddenly isn't as easy as just opening an app. That's the point of this law.
It's a dumb law, but you won't make it go away by playing silly semantic games.
They may be coming down the pipe, after the soft version gets people macerated.
> at which point you won't be living in a democracy
But you will be hearing from talking heads that you are, and Russia and North Korea are the real dictatorships.
And maybe they will be right, because what is democracy? The word has different meanings to different people, and it won't be difficult to shape the discussion about what our liberal democracy is all about. Maybe it's about accepting who has power now and about protecting the vulnerable. We have seen a bit of this stance and real capabilities in recent years.
Point is that dangerous people will use specialty devices/services and being legal is certainly not one of the requirements.
If this sort of surveillance stuff gets accepted, in time, you're gonna get noticed, put into database, and maybe called for questioning. Why are you using encryption, people that have nothing to hide do not use it.
“The semester begins in three more weeks. We've obtained 19 confirmations for studies in the faculty of law, the faculty of urban planning, the faculty of fine arts and the faculty of engineering.” — Mohamed Atta
“Two sticks, a dash and a cake with a stick down. What is it?”[2] — Mohamed Atta
“The first semester commences in three weeks. Two high schools and two universities. ... This summer will surely be hot ...19 certificates for private education and four exams. Regards to the professor. Goodbye.”[2] — Abu Abdul Rahman
Even in China with extreme surveillance and censorship in place, Chinese people have been quite creative in their ways of circumventing censorship. An example approach is cutting and pasting official political videos together in a way that changes their meaning ever so slightly. Automatic censorship algorithms are fooled, and human analysis and censorship are necessary and very expensive to carry out. Other examples are playing with the sounds of words, or using memes or rapidly-changing euphemisms.[3] It's too difficult to automatically censor stuff where people have taken a normal word such as "chair" and send each other images of chairs as a sign of protest. An image of a chair and a birthday cake with a number of candles could indicate a date of protest. Or a chair in a picture with a number of ducks in the background, or a number of chairs stacked on top of each other. And if censors start blocking all chairs, everyone just shifts to buses, or pieces of paper, or bananas, or whatever.
[1] https://community.apan.org/cfs-file/__key/docpreview-s/00-00...
[2] https://www.nytimes.com/2004/12/20/business/technology/on-th...
[3] https://en.wikipedia.org/wiki/2022_COVID-19_protests_in_Chin...
And I disagree. You take for granted all the good regulating and all the things enabled by the EU, and focus on the one bad regulation we're discussing, which is not even a law yet. I, personally, am not looking forward to the future without EU (I remember my country before it joined and the progress is immense).
Try the largest German-speaking subreddit, for example.
I think elsewhere online this may happen.
Also, some public broadcasters use the "far right" word group suspiciously often, almost as if it was some kind of effort to softly suggest to people how not to vote, but I must be imagining things, because they would never do that:)
1. https://en.m.wikipedia.org/wiki/Greens%E2%80%93European_Free...
[1] For example, while being the Vice Commissioner for Human Rights (vice ombudswoman) in Poland, she stated that "It is worth, first of all, stating a few facts. First, violence has a gender, whether we want it to or not. Women and children are the victims, and men are the perpetrators." (video transcript translated with https://www.deepl.com, source in Polish: https://wiadomosci.onet.pl/kraj/dr-sylwia-spurek-przemoc-ma-...).
> men and women were equally likely to experience nonconsensual sex, and most male victims reported female perpetrators. [1]
[1] https://www.scientificamerican.com/article/sexual-victimizat...
Also, if I correctly understand this table [2], then "Renew" (formerly "ALDE") is also opposed, so you don't need to adopt the leftist political ideology of the Greens as a package, just to get pro-privacy representation in the European Parliament. "Renew" does seem to be a viable "libertarian" alternative there. They also make some pro-privacy representations on their website. I don't follow European politics much, so I may be mistaken here. For example, I haven't looked into their voting record.
[1] https://www.patrick-breyer.de/en/posts/chat-control/ [2] https://www.patrick-breyer.de/en/posts/chat-control/#negotia...
[1]: https://mepwatch.eu/9/vote.html?v=134463
[2]: https://mepwatch.eu/9/vote.html?v=167712
However, its not that easy to find these results. I was looking quite a while to find this one.
[1] https://volteuropa.org/policies/european-democracy-act/open-...
Also - there is the question of EU legitimacy. Its structure is highly problematic, as are its politics vis-a-vis the US, NATO, Russia, Arab countries etc - and I'll naturally not open that whole discussion; my point is that I would also consider supporting dissolution of and/or secession from the EU. Not because friendly and cooperative inter-relations are bad for European countries - of course they are - but because the EU is not a good vehicle for that, it's a vehicle for realizing elite-minority political and economic interests.
Excuse the confusing mistype :-(
Voting for a party is a signal for other people and for the party itself. It may not be today but next time that they get that seat.
- tell you they couldn’t have know it would end this way
- they really were right, except for this one unpredictable thing that broke their master plan
- hide/pretend they were never pushing for this
- ask for help
- tell the rest to take a hike (the ones that managed to still benefit)
And there is no way for people in the present, who see this coming to prevent it or to ensure proponents are help accountable on the future. You will end up with lawsuits that take 20 years, watered down verdicts, weasel politics, etc.
cite? I somewhat kid, of course, but this generally seems the last, if ever, step forward considered.
XMPP FTW.
That page in particular is a pile of FUD; it keeps banging on about "impressive collection of private data being sent to Matrix central servers, even when you use your own instance" which is simply categorically untrue; it looks like they misread the privacy policy of the Matrix.org server at https://github.com/element-hq/policies/blob/master/docs/matr... and somehow assumed it applied to everyone's server instances. It doesn't, any more than https://www.w3.org/policies/privacy applies to a given random webserver on the internet :|
[1]: But like I said in another thread, who knows if they would directly complain to me.
It doesn’t matter if the relay service is centralized or federated. Apple can ban apps that don’t comply with the new law. Even self-distributed apps under the new sideloading provisions of the DMA can be censored by Apple by revoking the notarization.
Protocols, not platforms, people!
I believe its this post here, but someone correct me if this is the incorrect link: https://signal.org/blog/the-ecosystem-is-moving/
So I guess it didn't, and they'll find a reason why this won't either.
All meaningless talk.
Their strategy then as it seems to be now, is to do nothing but say they disagree and wait for the regulators to forcibly remove them from the market.
That is if they did themselves non-compliant with a countries laws, they'll do nothing and wait to be evicted rather then comply or voluntarily leave.
My understanding is that the law empowers the regulator (Ofcom) to require the use of accredited scanning technology if they consider it necessary and proportionate. No further changes to the law are necessary for that to happen.
But as of now, no such accredited technology exists. It seems likely that any client-side scanning technology that the EU mandates would also get accreditation in the UK.
https://www.gov.uk/government/publications/end-to-end-encryp...
All that happened is the government accepted that it was not currently practical to implement what they desired. So 'promised' not to require any providers to do so yet. If they deem it practical one can expect them to instruct providers.
Hence Apple and Signal both ignored their prior statements, and continue to provide their respective encrypted message and speech services.
Laws can be ammended faster than implementations.
True.
> Laws can be ammended faster than implementations.
Really, really false.
It's extremely possible to solve political issues using technology. If you consider the government infringing people's right to put whatever substance they want into their body to be a political issue, it's been pretty much entirely solved by crypto and darknet markets for drugs.
postnote: this comment was Authored on Firefox under Wayland running on Linux 6.
As far as the mainstream I believe Gnutella, the protocol, had massive success with the LimeWire client.
https://gtk-gnutella.sourceforge.io/#:~:text=gtk%2Dgnutella%....
Yeah, that's why Windows has been by far the most used OS by the mainstream
https://gs.statcounter.com/os-market-share#monthly-200901-20...
> And who will you message then? I assume most of your contacts will stay where they are.
You are out of luck if you can't convince people to install PGP/GnuPG in their favorite e-mail clients. And e-mail doesn't scale for spontaneous communication like chat does.
I take it this should apply to any web comments and messaging platform, and therefore require that all websites and web services comply if they can be accessed within the EU?
I’m not sure how that’s even remotely doable.
I don't rely on Signals encryption, since there is no way to verify that it works in the way that it does, and even if, there is no way to know that the recipients are as careful as you are. If there is something I don't want others to find out, I just don't write it down. No encryption is fool proof.
Since we're specifically talking about Signal, I think that it's worth mentioning that Signal is uniquely predictable here. They published their entire cryptosystem, it's been extensively inspected by the cryptography community, there are multiple open-source implementations that agree with the published mathematics, and I strongly suspect that more than a few people have sat down to verify that the bytes coming out of the app are actually produced by the published protocols. Claiming that that's not "working the way it does" is reaching out into territory along the lines of Trusting Trust, the unproven existence of trapdoor functions, and the Problem of Induction.
Totally. Not everyone is a cryptographer to review the code and ensure the app they're downloading is what was compiled by the aforementioned vetted code. That's what F-Droid and cybersecurity audits attempt to solve (and Apple's vetting process, though I think their mandatory $100/yr developer license is what drives malware off the platform).
The one reason to use Signal is privacy, and its replacement of Meta apps is under that umbrella.
The EU has shot itself in the foot with demanding alternate app store exist, and then Signal has shot itself in the foot by not being open enough to be distributed on any app store by anybody.
The answer to these encryption laws, is to use their other laws against them. You want the iPhone to be an open platform? Great, here's a bunch of open platform chat apps that cannot be banned because they are decentralised.
Perhaps Matrix will be the future after all?
They have been building a walled garden for a decade. They talk about "market": they want to make Signal profitable.
Which I find very naive and destructive, but that's how it is.
The second phone will be very basic with open source hardware and self installed open source software, simple enough that you could build it yourself if you wanted. Its sole purpose will be secure communications and it would just use your phone as the communications medium.
Bonus: you get a real keyboard.
Terrible Shannon's Limit although.
A quick search didn’t lead me to any proof of concepts about this idea but on the surface (I don’t have any knowledge of the hashing algorithm used in these content filters) it seems like a plausible idea, depending on a lot of factors.
Also something where features work? Since this week my Signal "Something went wrong with you username, it no longer is connected to you. You can try to get a new one"
Of these, https://simplex.chat/ seems the most promising, thanks to a level of decentralization.
Decentralized protocols
They poke a hole in signal and all secure messaging /communication is screwed. it wont matter what "other" product you use.
But, I'm in Europe (France) and I wonder who actually uses Signal? There was a move a couple of years ago to quit WhatsApp and go to Signal. Some groups did make the move, and then everyone went back. Today I have dozens of WhatsApp groups, and just one Signal group (and it's dying).
If no one uses Signal in Europe then obviously this threat is moot.
Signal has become the default video conferencing app for several of my larger groups, and it works surprisingly well! This is a trick WhatsApp currently can't do.
Signal has been great but they won't be able to stop it.
Or we could encrypt the messages before pasting them in the messaging app so the CSS will be neutered.
Either way, I won't have the EU stasi look over my shoulder each time I send a message to a loved one.
Very understandable, but not particularly interesting.
Just send the image as a base64 encoded text string.
Decode when received.
Signal developers really seem to have some misconceptions about the priorities of their users…
[0] It‘s not a limitation of iOS itself but that Signal doesn‘t want to allow to store data and keys in a way that would ‚leak’ them to Apple - not even if I, the user, wouldn’t mind that.
Signal without the privacy obsession has no reason to exist. If you don’t value privacy, it is just a niche, hard to use messenger.
I'd have to give my name and address and potentially put me with 1 foot in jail because I have viewed the images and have them in my browser's cache.
If they really wanted to protect children from sexual abuse, they would've created easy to report online services. But it's not and never was about pedophilia.
Oh no, I wish there was a way to obfuscate links
//news .ycombinator .com/item?id=40551260
They try to surveil people. You can post all the links you want, but you can't be sure that they will only be seen by your intended recipient.
Ohh, wait…
The EU election is important though to ensure that the EU Parliament doesn't enact such a horrid proposal into law.
https://www.svt.se/nyheter/ylva-johansson-ifragasatts-om-lob...
I don't like mass-surveillance or "dragnets" which are actually considered unconstitutional in the US (see https://en.wikipedia.org/wiki/Dragnet_(policing) ), where you make an extraordinary amount of people suspects in order to catch a single suspect.
In medicine there is a number called NNT (Number Needed to Treat) which is a really good comparision to this. It's how many you have to treat with a medicine or procedure in order to help one patient. If that number goes up too large it's a bad sign, like if you would have to feed 1 million people a pill every day to avoid 1 heart attack per year.
Here you have mass surveillance and an incredible breach of privacy of 500M citizens, in order to catch how many pedos? If they would even be caught by this at all to start with.
Meanwhile, Canada lets me vote by mail, no fuss, and they even send the ballot to my home address automatically every election.
Would that really be so hard to do for EU or national elections?
This is far too forgiving a representation, they are surveillance wolves disingenuously wearing the sheeps' wool of protecting children to further their eventual thought-policing goals of "total information awareness."
Doing anything to protect children is difficult to object to. Using the children as their pretense for monitoring dissidents is really the heart of the matter. It's important to differentiate between the two.
I get that this difference could be subtly implicit in that comment, but let's please make it explicit.
Moreover the EU Parliament is controlled by social democrat (left) parties. There currently a bunch of stories in the press freaking out over the possibility that the EU Parliament might actually become majority right wing for the first time ever, example:
https://www.google.com/amp/s/ecfr.eu/publication/a-sharp-rig...
So it's very unclear how you reached your conclusions about who people should stop electing and what effect that would have.
Both the commission and the parliament are controlled by socialists (of various kinds).
This is ridiculous.
I told you then, that end-to-end encryption is far more worrying for politicians, than mere cryptographic signatures. And that they’ll be coming for it next. Because it can hide billion-dollar transfers, or CSAM, or gasp seditious material against the king.
Well, it’s not just Europe, it’s all over the world:
https://community.qbix.com/t/the-global-war-on-end-to-end-en...
The above chronicles many cases even in your own country!
Today regular people are just as clueless about end-to-end encryption as many on HN are about web3 and decentralized network innovations. Think of the children!
And then they will come for the regular person, and by then there will be no one left making tools that could have helped them.
As for me and my views, I have come to believe that end-to-end encryption vs state actors is a band-aid, that if you are reduced to sneaking around then your government and agencies need fixing. Whereas digital signatures and smart contracts and decentralized networks are useful as they allow everyone to be in control of their own identity, voting, balances etc. without relying on a third party. It’s done in the open. But the difference is that it can be limited to “benign” things and enforces the rules, while everyone gets to make their own decisions and one party can’t corrupt the system.
To me, the transparency and resilience to corruption is the main thing. The sneaking around, I can see how governments can declare war on that.
Crypto has probably done more to undermine privacy than Hoover’s FBI. Its proponents are ambitiously unlikeable, relishing their distastefulness to burnish outsider credentials. Its damage is easy to quantify in a way troublesome speech is not. And because a broad set of the population either doesn’t like it or, much more prominently, doesn’t care, it serves as a stalking horse for advancing general anti-privacy laws.
Signal is a great example. They should be a unifier for the notoriously-apathetic privacy crowd. But it isn’t. In part due to its crypto crossover. I genuinely can’t seriously take Signal as a canary of anything, because it’s unclear what motivates its leadership.
If the states aren't the bigger fish, the bad actors would be.
They can ban that as well.
The only way anything can continue working in practice is if it’s decentralized, and served by different websites secured bu https rather than one app in one app store. Hard to take them all down.
Perhaps Moxie Marlinspike now better appreciates decentralization behind messengers. I have written here years ago as a response to him exactly this scenario: https://community.intercoin.app/t/web3-moxie-signal-telegram...
The thing with https of course is that the governments can insist that browsers include their backdoored certificates. But the browsers are large enough that it’s difficult to get them to do it. China’s Great Firewall probably can. But in order for that to happen they have to prevent packets encrypted with the non-backdoored certificate chain from being routed. That requires serious control over all the networks.
This is partly why I started Qbix. So people can host whatever they want on computers of their choice. Without this decentralization, the governments are two steps away from mandating ALL your voice conversations are scanned, transcribed and analyzed by AI at the edge. Microsoft Recall + message and voice scanning = 1 step away from total panopticon of everyone everywhere. And with superintelligent AIs doing precrime based on everyone’s conversations!