EU: Users who refuse scanning to be prevented from sharing photos and links
patrick-breyer.de
patrick-breyer.de
So the two major fields where you really want to snoop their private chats to see if they are up to no good, are excempted?
https://european-pirateparty.eu/chatcontrol-eu-ministers-wan...
- "Julia uttered a tiny sound, a sort of squeak of surprise. Even in the midst of his panic, Winston was too much taken aback to be able to hold his tongue."
- "'You can turn it off!' he said."
- "'Yes,' said O'Brien, 'we can turn it off. We have that privilege.'"
They're not stupid, and they're NOT example-setters (very few exceptions) - for myself.
#never voted, and very proud of it.
The bad is obviously that they’re immune to their own legislation.
The good is that it prevents incumbents from using this data as part of their campaign. It would be Watergate all over again.
There is also data that probably shouldn’t be public. Locations and status of missile silos, troop locations, etc. In an ideal world, all of that would be on secured channels that are managed by appropriate entities. In the real world, it seems like a struggle to get troops to stop posting selfies with sensitive data on Facebook; I don’t doubt much more exists in private messages.
I’m also about 95% sure our politicians (globally) are incapable of managing the OpSec of having 2 devices, one secured and one not, and using them appropriately. They’ll forget one or the other exists.
I just also think that it's worth considering that there are some communications where the cost of leaking data is higher than the cost of a very low chance of catching CSAM. These exclusions are overly broad in my opinion (the cost of most of these comms leaking is low to non-existent), but there are good reasons for some limited communications to either be excluded or have an alternative system.
A Watergate scenario weakens shared belief in the government/democracy. Leaking nuclear secrets is obviously bad. Leaking troop locations/movements is also very bad. A prosecutor getting access to communications between a defendant and their lawyer would be very bad.
My preferred solution would be to not have the scanning, for various reasons including that exclusions would either be so broad that practically nothing gets scanned or too narrow and we'd eventually have some kind of crisis.
Their tower dumps contain enough metadata to determine all the people who spend most workdays at office buildings in McLean Virginia. And then, of course, where those people sleep (i.e. charge their phones) at night. It takes positive effort to erase that data, and believe me, it's being erased. The powerful people don't want it to exist.
So yeah, there is already a system for doing this kind of thing. It will be extended. Plebs like you and me don't get to use it.
Good on those powerful people then, because this data should not exist.
Not saying it’s a perfect solution, but they might consider it a “95% good enough” solution.
Unless by 'feature' you mean the mandatory scanning?
So, if you self-host [1], you don't need to adhere to the legislation.
But, wait… Are you telling me that security officials are allowed to use not their self-hosted infrastructure, but use public one to send (I assume, based on their exemption) confidential data?
And, as @WA proposed, will be a list of contacts of these officials given to all for-profit organisations?
What a stupid joke it is!
[1]: See third row at https://www.patrick-breyer.de/en/posts/chat-control/#current... .
As far as I can tell from the article, the justification for the proposed rules is "won't someone think of the children".
Those two major fields you mention might do well with more oversight in general. But I doubt they are especially prone to dealing with children?
And if the discussion is concerned with what one does outside of work, well, presumably those exempted industries also have time outside of work.
I was merely arguing against this remark:
> So the two major fields where you really want to snoop their private chats to see if they are up to no good, are excempted?
Those two major fields aren't especially prone to dealing with children. (They probably aren't any less prone than eg software development, sure. But that wasn't the point.)
> Those two major fields aren't especially prone to dealing with children.
Neither are software developers, so why aren't we exempt?It is not about arguing that only they should be exempt.
> all fields should be exempt
Except perhaps teachers, and pediatricians, and social workers, as per the logic given.Assuming those claims are true(I know, that is a big ask, but they claim it) what function do exceptions provide unless they are purposely giving those exceptions for the production and distribution of csam by those groups?
More likely their claims of the privacy and/or purpose are false.
They may even be true today. The problem is that if true, it won't stay true.
Interested parties find ways to tap into stuff like this once it exists. Given enough time, they create a legal framework to justify it.
If I'm sharing nasty stuff through one of these platforms and I can send text, I can send a link. In any platform "that doesn't allow links" you see people sharing them anyway through normal text, even if they have to create some new conventions. And you can also just use different platforms anyway, so where is the deterrent?
This is just annoying based on people legislating for technologies they don't understand.
That's the most positive take you can have on this.
Outside public content can be scanned as part of "defense in depth" too.
Of course it won't catch 100% of it, but very few laws or measure do that (and those that do almost always come with very high amounts of false positives). Also links are not hard to scan for either, and you can't "just" upload CSAM to anywhere either and not expect troubles sooner or later (unless you know what you're doing, in which case we're back to the previous paragraph).
I think it's very hard to deny that of course it will catch a non-zero number of people, although it's hard to determine exactly how many beforehand. That doesn't mean it's a good law, it just means that all these type of "it won't even catch anyone!" argument are just bad arguments.
I don't think anyone really thinks that.
After a while the second, third and fourth won't be required.
Jeeze...we learned obfuscation fucking years ago (torrenting was punishable then, probably is still, and a few people may be made examples of, by ip tracking etc as subscribing becomes more disliked).
Sure, but it is still completely valid to argue that it won't quantitatively be effective enough to justify its cost, either in money or in creating-the-infrastructure-for-a-fucking-police-state. "Non-zero" isn't necessarily an acceptable level of effectiveness.
They don't, or they don't care. Measures like these have two purposes:
1. To make it seem like someone is doing something. Constituents don't accept the idea that their representatives are powerless to fix certain hot-button issues. Even if a new law or regulation will have minimal or no effect on a problem, as long as legislators (or whomever) can pay some "experts" to say good things about it, many constituents -- most of whom don't understand the issues involved -- will be (somewhat) satisfied.
2. Continuing to establish and normalize surveillance technology and make it a part of normal life. The more that government types can mandate that people can't do in private, the easier it is for them to do... well... whatever they want to do.
It would be better instead to empower and educate parents with tools to protect their children rather than outsourcing to government or public companies.
Do we think that CSAM comes from poor parenting? That the parent's didn't do enough?
Of course, a lot of it comes from major organized crime networks that parents are powerless against. But that then falls under the incidence of more regular police investigations to stop and curtail. You don't need to monitor everyone's chat history to be able to find and dismantle a crime ring.
1947: commies
2001: terrorists
2021: pedosOfficials supportive here are either naive, extensively lobbied or have an authoritarian streak. Nothing really redeeming about their plans.
In other words, the problem is these peoples' insatiable power addiction.
https://mjtsai.com/blog/2022/08/22/google-account-deleted-du...
Google support is notoriously non-existent and/or obtuse, and that's the real problem here. Combined with that it's a "ban for life" black/white type thing, that it's not really possibly to appeal anywhere reasonably independent, and that type of stuff. There's tons of innocent reasons your account can get banned, and this is just one o them.
Doing anything that allows random people to upload or send stuff is being flypaper for the worst of the worst of dickheads. You really do need some kind of protection.
I'll go a step further and say that providing such a large platform which ties in to so many aspects of life (whether you want to or not) means accepting some responsibility. This means having at least vaguely helpful support. And also means not being a massive host for CSAM.
I remember a time when I worked as a repair tech and randomly clicked something on the frontpage of Google Video just to test if Flash Player was working without really looking what it was, and it was some guy blowing his brains out. And "young 12-year old Alice proudly shows her small tits" type stuff being quite common to just come across without looking for it on Kazaa, "warez" sites, and the like.
Where do you strike the balance on all of that? Good question. But pretending the balance doesn't exist is not helpful.
If it ever gets promoted to law, my predictions is: ASCII art is back.
Actually 99.99% of users won't give a single fuck and will just allow scanning. People don't care at all in case you didn't notice.
If the detector has a false positive rate of 0.01% that still means ~50000 false hits every day, if every one sends one image daily. And my guess is it's WAY more than that in volume and false positive rate.
It's hard to have time to think about these issues when you have zero free time, barely manage to make ends meet, don't have techie friends and are bombarded with propaganda. It's possible, but it's hard, especially when that very propaganda uses the main thing you work your ass off to scare you into submission.
I'm not talking about sharing vacation photos with your friends, but stuff like:
- here is a link that explains how to do taxes for your nonprofit
- here is our new school logo
- this is a link to the soccer tournament schedule
and so on.
I actually bother to decline those things.
So, not everybody. Your statistics are off by at least one.
I had a person who was having a printer problem close a dialog box telling exactly what was wrong with the printer. It came up every single time they tried to print. This is not abnormal behavior.
People regularly just click on the default boxes, and you know it's true otherwise there wouldn't be so many dark patterns on the internet. Dark patterns work because people don't read what's on their screen.
Any other market and any developed country will have us beat.
Though you seldom get deregulation by just deleting laws. Most of the time deregulation means replacing one regulation with a different set (that is hopefully simpler, but not always).
Eh, I disagree, in general. I see little benefit.
Perhaps I'm missing something.
I never need to think about import/export restrictions, immigration law, visas, exchange rates, phone contracts or medical insurance contracts.
It certainly deregulated my life. I feel less regulated on what I can do. It removed barriers. And that's really the only thing that matters.
I think it is extremely hard to argue that this was a case of the EU deregulating anything. What happened was the EU started to regulate more, which invalidated the regulations of states.
The EU is specifically the mechanism by which the countries streamline their legislative differences.
For me, I found the way EU handles food safety as opposed to the US to be a great summary of their philosophies: in EU a food needs to be proven to be safe to be allowed, while in the US the food needs to be proved unsafe to be banned.
See e.g. how Germany handles milk compared to the US.
Eg in Germany minced pork has to be safe to eat raw, because that's what Germans do. Not because they are necessarily any stricter in general.
In the US eggs have to refrigerated. In Germany they are typically sold at room temperature. (I'm not sure whether refrigeration of eggs would be legal for shops in Germany?)
Especially when to comes to the dichotomy of proven safe vs. not proven unsafe.
On the other hand, EU allows cheese made from raw milk while most of the US states disallow it.
On both issues and as a cheese lover I'm glad to live on the right side of the Atlantic.
My comment also includes many additives, pesticides and other lots of food-related components which are allowed in the US but not in the EU.
Also, if you say something that sounds like "free speech" their heads explode. It's quite spectacular to watch.
EU economies have benefited greatly from the removal of barriers between countries. The EU officials didn't see that as a sign that the strength of the EU lies in their members freedom, but as a sign that now every single issue should be regulated by EU officials.
That is why you have laughable things like the recent AI regulations. An entire continent with barely a single AI company wants to tell the rest of the world what to do. The cause is pretty clearly in the delusional minds of EU officials who genuinely believe that their regulation are worth more than the paper they are written on.
It tells "the rest of the world" what to do when they operate in the EU.
Which is exactly what governments are made for. AI companies do whatever they like outside the EU, and it's not the EU's concern.
They don't want to create laws which only effect how AI companies handle operating in the EU, they see European contribution to AI as offering a legal framework of how it should be operated and legislated worldwide.
Alas, the EU isn't special in this regard.
Deregulation isn't really popular these days. But it has happened from time to time here and there.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32...
A summary is here: http://publications.europa.eu/resource/cellar/c56fbf1c-97bd-...
It abrogated the various national laws concerning product quantities, ie. in France you could sell shampoo in 250ml or 500ml bottles, but not 295ml. Or you could sell mushrooms in 250g and 500g boxes, but not 230g or 490g.
This is now allowed, which made this in effect a deregulation enabling shrinkflation.
> CHARTER OF FUNDAMENTAL RIGHTS OF THE EUROPEAN UNION
> (2012/C 326/02)
> Article 7
> Respect for private and family life
> Everyone has the right to respect for his or her private and family life, home and communications.
All data shared by politicians, public servants and all of their family members within the EU has to be shared, analysed for corruption + stored forever.
If we are all considered pedophiles, then all politicians are criminals.
Yes, a few people will be wrongly accused and we all loose our freedom.
HOWEVER, with every election we will get a small chance that the previous administration will get audited and corruption and other crimes will get uncovered.
Seems to be worth it.
Well you could do the latter without doing the former. Except that - of course - politicians would never do anything against themselves.
The more you tighten your grip, the more star systems will slip through your fingers.Now we have Windows Arm PCs with UEFI and upstream Linux support, "close enough" to Apple Silicon perf/watt. PC OEM price competition and enterprise volume buys will yield affordable Arm laptops in a few years. Framework has proven that laptops can be modular. Did they inspire Lenovo to make a more repairable Thinkpad? If Framework releases a modular Arm laptop based on Qualcomm/Mediatek/Nvidia, watch out.
On the software front, the sold-out "Local First" conference recently wrapped in Berlin, https://www.localfirstconf.com/. If HTTP can be extended to support synchronization, it could dramatically lower the cost of cooperative infrastructure, including offline (think Cuba sneakernet) sync, https://stateb.us/what & https://news.ycombinator.com/item?id=40480016, tearing down big walls of tech and lobbyists.
Some conflicts are won by making them irrelevant.
Of course, it's pretty messed up that the rationale to continue voting Republican is apparently, "well, I don't like Trump and dictators and the erosion of democratic values, but... man, that Biden guy annoys me".
Today I'm in a very clear minority today and I think for now that trend will only continue.
Whether by accident or design, the "smartphone" (package of sensors) manufacturing revolution made surveillance cheap and pervasive. Those atop a wealthy hill of deregulated inequality may be attracted to a mirage of tech-enabled control, powered by harvested signals and McKinsey dashboards. But all observations affect the observer, so observe.. wisely.
These proposals keep returning because there are legitimate concerns that are being left unadressed by industry self-regulation.
When nobody wants to have a conversation about good measures, politicians are going to try again, even the new ones.
It is sincerely horrifying what the reckless deployment of generative AI is doing in this space. And it's all dismissed as "Well you can't stop math anyway so we're not going to do anything" and (implicitly) "The ends justify the means, sacrificing a few children is worth it to get AGI". These are terrible optics.
If tech does not hold itself accountable, privacy is going to die sooner or later. The politicians need only win once.
If privacy dies, it ends creativity, civil society and funding for politicians. That scenario would be painful, but self-correcting. On the other side, something new can be born.
Note: "privacy" is not a car that can be stolen once. Like freedom, it is infinitely divisible, and even those who have lost 99% will keep fighting for what little remains. There are countless examples in history, independent of temporal technology minutiae.
I'm not talking about "all of privacy" being lost in one go, I had assumed this would be obvious to all readers.
I'm talking about the specific matter at hand; Message scanning, with the point of how this failure mode poses a threat for further and further infringements of privacy down the line.
> If privacy dies, it ends creativity, civil society and funding for politicians.
Cute poetry, but the aftermath of 9/11 clearly shows otherwise.
Consider for a moment how even these "anti-terrorism" measures are seeing shockingly little pushback. Despite al-Qaeda being an ocean and continent away.
You're a fool if you think any politician would risk their career to revoke message scanning once implemented. The attack-ads write themselves, "[POLITICIAN] wants to let pedophiles sextort your children".
This is a bit silly. Apple tried to do this and it was deemed overwhelmingly anti-consumer. This is like wanting private phone calls, but also blaming phone companies for sex lines. This isn't a fine line for companies to walk. It's a line of negative width.
What are you on about? This is precisely the kind of situation where a best-effort can be done.
Though let us swap your example of "sex lines" for something legitimately harmful. Scamming callcenters.
Should they stop all scams? No, they can't. Inspecting phone call traffic to monitor for scams would be extremely invasive. Should they disconnect the firm they and everyone else knows are scammers? Yes.
Thus the point. When these companies don't make a best-effort, the government gets involved.
The only added complexity here is that the chat apps themselves can't do anything. But the big tech giants could stop making the problem infinitely worse, big platform holders who already monitor publicly-posted content could work to ensure their reports are actioned upon.
On what basis? There's no "everyone knows". If police in a jurisdiction report something, it can get taken down. That's not a matter of "self-regulation". That's you thinking unelected tech company middle managers should do what the police are paid to do, and many countries are structured to only allow the police to do.
But still, I feel like this property only slows down the march toward authoritarianism. It won't stop it.
Most of what I've seen of "a new generation" leads me that, on average, they're disturbingly willing to comply with any kind of authority on any kind of pretext. And some of the rebellious outliers are kind of Naz-ish.
Not wildly different from any previous age groups, of course, but definitely not some giant anti-authoritarian wave.
... and people of any age will only reliably "backlash" if they're actually inconvenienced. Most people will just accept the spying and go back to sharing stupid memes. Until it's too late, anyhow.
Fortunately for human civilization, our options are not limited to "authoritarian" and "anti-authoritarian".
Societal change may conclude with mass movement of followers, but it begins with individuals who create new choices and incentives.
[1] https://www.reddit.com/r/privacy/comments/voaicx/10_error_ra...
Anyway, most people will just set external pages under international hosts anonymously, or under i2pd and yggdrasil.
Also, any German can just use SDF with a validated account and call the US law on hosting (and maybe content) instead of the German one.
I think that is what I said.
>Anyway, most people will just set external pages under international hosts anonymously, or under i2pd and yggdrasil.
"Make yourself a criminal" is not good advice.
I don't know what you are trying to tell me. I know that there are technical means to circumvent this, just like there will be technical means to circumvent chat filters. That isn't the issue, the issue is that it is criminal to do so.
Again, this is criminal. Again, I am aware that there are numerous technical means to circumvent this, yet all of these are criminal.
I still don't get what your point is.
Also I think it is extremely unlikely that the court will agree. There are many, many more egregious laws in existence in the EU, this effects very few people and is a big sovereignity issue.
Effective but terrible Shannon's Limit though.
The last attempts of this have been stopped by European Parliament so we need to make sure the new one stops it as well.
Any idea where we can find that information (those who proposed and voted on it)?
Hopefully other EU countries has similar sites. If you have a local Pirate Party, that might be a good place to start. I'm guessing they would link such a site.
This measure is still being developed by the European Council, which is a non-legislative body.
https://en.wikipedia.org/wiki/European_Council
It would have to be submitted to and taken up by the Parliament for the information you want to exist in a meaningful form.
Parliament is not keen:
https://en.wikipedia.org/wiki/Regulation_to_Prevent_and_Comb...
The might be a list of votes there somewhere.
[1]: https://www.patrick-breyer.de/en/chatcontrol-1-0-pirates-con...
[2]: https://www.patrick-breyer.de/en/european-parliament-o-exten...
https://news.ycombinator.com/item?id=40523902
tl;dr the title is misleading. This comes from the European council (which consists of representatives of member countries) and is not a fact until the European Parliament has voted on it. It is likely that the EP will reject this proposal like earlier attempts.
Yes, we should fight this , but it’s not the ‘EU’ who says this.
Once accepted, it's almost impossible to repeal the law by the EP because they will need the approval of the EC and Council of the EU, both of which have members that are not directly elected by the people. EC and Council of the EU is also that body which so far has proven to be far more authoritarian in it's approach.
So, the parent is largely correct.
Which is the relevant part here, not muddying the water by bloviating about something else, right? Having a body that can only vote on/debate on proposals is absolutely not rare across western democracies.
Democracy can be slightly more complex than direct democracy without being a sham like "elections in the USSR".
See my comment here: https://news.ycombinator.com/item?id=40560873
Ultimatly the popular Parliament and the government council can block it, and the leaders of each member government can of course nominate commissioners who do not wish such laws passed
The reality is that democracy if governments want this type of law - hell large numbers of the people do. It’s the problem with democracy.
Certain interests dont like the EU as it’s harder to manipulate than a typical national government and people.
But you will stop what you are doing to spread awareness, write articles, send letters to your representatives and raise hell doing activism so you can stop it. You might be able to stop this authoritarian proposal.
And then they will just push it again with a different name and rewording. But while you need to devote your time and effort they are being paid for this and with your tax money (ha!) plus whatever those AI companies lobbying are putting into the table. And they just need to get it approved once before they move to the next thing-of-young-sebastian draconian law.
Different organisations have different goals and those into "security" just want to delegate their jobs to computers when they chill, get paid and prized for their success. Some more cynical ones are also plotting for political control, I'm sure.
I'm very annoyed by this trend of government organisations really really desire to look into our stuff all the so they don't have to do their jobs the hard way like finding suspects and investigating them. Bunch of wankers and nothing more, aren't they?
If aligned government bodies is desired then a dictator is needed. EU isn’t suited for this.
Remember that GDPR has carveouts for governement as well.
Everyone speaks like "privacy" has a common, shared meaning across all people and it couldn't be farther from truth. And we need to keep that in mind - for governments, online posters and even organizations like Signal.
Do they actually need anything to accuse you? Who is to check the false positives and who checks the checking?
Possibly worse than loss of privacy is that this would require computers to be entirely controlled by someone other than their owner. It rules out the pc like open ecosystem for phones.
But people don’t seem to understand, if you cheer when governments use their power to “protect” you, they don’t suddenly decide to stop doing it.
Just because phase 1 was friendly to your pet interests, doesn’t mean phase 2 will be.
I wish folks would look at all regulation with a much more critical lens, and be much more humble about implementing it.
Decentralization brought on by the internet is messy, complicated, and scary. But it’s a direct transfer of power from central authorities to individuals. So whenever you bypass the messy, decentralized way of solving problems in favor of the easy centralized way (regulation), you have given up your power. You reap what you sow.
In particular, the csam detector could false-positive on anything involving the currently ruling party’s political platform and on the face of any elected official.
What a stupid implementation, also one could harm others by sending them things anonymously.
Can't see any way this could go wrong at all, none whatsoever.
As everybody knows this is not about the children but concerns how to snoop on the public in not so obvious ways.
Europe has no obvious path for staying relevant in the near future since colonialism is long gone.
EU prides itself on its institutions and their control over international trade and relations such as banking and insurance etc.
This is the only way they can assert some kind of authority over primarily US internet businesses.
https://arxiv.org/pdf/2401.15817
Quite long paper, but rich in examples that speak for themselves, like AI mistaking a Starbucks logo for a Ferrari one, or an airplane for a baby stroller, etc. CSAM producers will always find a way to poison images or use other tricks to conceal them. There was one in fact years ago that involved appending a .rar archive to a .jpg image without renaming the image (including the .jpg suffix): an image viewer would correctly show the image ignoring the following data, while a .rar unpacker would ignore anything preceding the .rar header, thus the image, and would extract the archived file anyway without errors. One wonders if the capability was intentional and how many times this trick has been used to exfiltrate from somewhere sensitive data disguised as kitten pictures.
Absolutely insane orwellian legislation being written by, at best, some of the least introspective forward-thinking EU drones... What the actual fuck.
It seems like all it takes is to point to a credible external threat and sane people are pushed down by 'lurker' insane people in a heartbeat.
They can't destroy tor pedo sites, or stop them from sending data in archive with passwords? These people are willingy inserting spyware into phones while constantly harrasing big tech for this. Clown world.
At the end of the day Europe is not even the place where most apps are created, just a bureaucratic nonsense.
If you though the cookies law were bad just wait.
Even though, it's far easier to change peoples opinion in one country than in 28.
They are a horrible, horrible party that desires power over all else.
I suggest voting with your feet. The only vote that actually makes a difference.
EDIT: Weird to downvote for this, I suppose that people here are in favour of removing privacy
Basically you must have your identity fully checked by a third party whenever you do something that can be used for terrorist reasons, which currently includes having a bank account and using a phone. Adding instant messaging in general to that list would not be surprising.
There is an entire industry in Germany and Europe in general built around supplying this service of checking people's identities.
At this point they really just qualify as enemy of the people
> But if they aren't doing anything wrong, why are they so afraid?
I would be afraid of eg a would-be assassin, even if I never did anything wrong in my life. So this is a weird argument to make.
I'm all for discussing the issue, but at some repetition exhaustion is a thing, updates without anything significant are not really updates and maybe Patrick should be aware of crying wolf (and it's also a campaign issue)
At what point can we say HN is just going round and round? Or is it just pleasure with suffering?
If I take pictures and never share them, no scanning is done. If I copy private pictures to my wife's phone when we are meeting in person, no scanning is done. Similarly, I can archive pictures to my PC or print them out and all of that respects my privacy.
Only if I use a public service, like Facebook, WhatsApp, TikTok, is there the possibility of my pictures being sent to authorities if (and hopefully only if) the local scanning was inconclusive. But in that case, Facebook, WhatsApp, TikTok can (and probably do) already spy on me and my pictures. I don't think it's all that draconian for authorities to take a look, too, after you have already voluntarily !!! sent them to a for-profit corp with questionable morals.
And I feel like the proposed law design also matches with the real risk profile. Pretty much all of the blackmailing scams that drove teenagers to suicide were being perpetuated from outside the country that the victim was living in, e.g. [1]. So it makes a lot of sense to more tightly control cross-country online messaging on almost anonymous platforms than in-person photo sharing.
[1] https://www.bbc.com/news/world-australia-68720247 "Two arrested in Nigeria after Australian boy's suicide"
EDIT: In case anyone wonders, here's the 100+ page EU report that presents their opinion of the facts and then makes suggestions, some of which are now being discussed: https://www.europarl.europa.eu/RegData/etudes/STUD/2020/6527...
Section 3.5.1. is about the scanning of your private pictures that Facebook is already doing, meaning regardless of how the EU decides in this case.
TSA for example is one of the most invasive security screenings most people endure on a quasi-regular basis and it's been the source of overreach and still does not catch much of anything whatsoever.
Criminals are incentivized to get around this scanning, regular users are not. Who really bears the burden here?
You don't have to send the photos to a for-profit corp though. E2E encryption is entirely possible. What the law should be enabling is for people to sue companies that claim to do E2E encryption then compromise it by independently sending things to law enforcement.
But the problem with your example is:
-criminals CP-sharing etc use end-to-end encryption -> politicians: encryption must be weakened, but that doesn't work...damn opensource
-Now we need local scanners on every phone, but damn those Linux laptops the criminals use still have no scanner.
-And now we need an authorized operating system ...., but damn those open source guys.
-So now there is a full file system scanner chip in every router, laptop and phone. If you get caught using a device without this chip -> straight to jail.
It goes on and on, and next we have to leave the laptop on so gov can always inform us about important stuff ;)
> Pretty much all of the blackmailing scams that drove teenagers to suicide were being perpetuated from outside the country that the victim was living in
The recent cases in the Netherlands (where I live) were all Dutch perpetrators.
Anyway, this technology won't catch that -- sending nude pictures is, after all, both perfectly legal and very common. The scanning software can't know that the picture is sent to somebody only acting as a boyfriend rather than an actual boyfriend.
I can see the point of a database of known child porn pictures. The phone app could keep a database of hashes of those exact files, and check for them.
Other than that, I don't see what good automatic scanning can possibly do, and there is a HUGE potential for abuse.
I'm not saying this is happening. In Meta's case, I simply assume that they at least collect meta information on your photos, such as GPS coordinates to build a better ad profile of you. I might be wrong, but maybe not. That's why I don't give WhatsApp access to my photo library.
It’s absurd to suggest that users of an e2ee chat service can reasonably expect the service provider to “take a look” at the pictures they share.
But sadly, that's already happening. It's probably best to avoid sharing any private pictures on Facebook, WhatsApp, TikTok or any public cloud. Because you never know who might have access or gain access in the future. And isn't Google actively scanning their Drive user's files and removing presumed adult content, too? And didn't Dropbox one tweet about the X-th file uploaded being a cat photo? How did they know?
"We'll only beat you on Tuesdays" is not balanced.
The control over the scanning of your device remains with them, and the likelihood of this power being exploited is almost guaranteed.
This is not an issue where there can be much of a compromise. My chats are private and not to be surveilled by a central authority. This isn't a policy that faces the challenges of new technology, this is something that should have stayed in the last century.
The internet did raze down quite a few borders and despite some risks, it is very much worth it to keep it in this form.
If the EU wanted to be constructive in strengthening and protecting users, it would have created legislation that big tech cannot screen user content with impunity. Instead it now forces them to do so and report "wrongdoings" to something that isn't even a real police force.