11 ms·
EU to greenlight Chat Control tomorrow
- Lichtso 2y agoAlready was somewhat degraded by the EU parliament: https://proton.me/blog/eu-parliament-chat-control https://proton.me/blog/eu-parliament-chat-control
- Macha 2y agoNote the concern is based on historical precedent, that the commission can browbeat the parliament into passing it, especially considering the recent changing of the guard and relatively limited information that many national voters get of their MEP's activities in the european parliament because of the tendency for EU elections to be decided on domestic issues.
- qwtree 2y ago[flagged]
- shortsunblack 2y agoThe parliament can block legislation indefinitely.
- pantalaimon 2y agoSure it’s now opt-in. But if you don’t opt in, you can no longer send photos or videos.
- treyd 2y agoThat seems so arbitrary, where does ascii art fall?
- Almondsetat 2y agoProbably under the umbrella of "you're not going to transmit anything meaningful with an extremely limited amount of horizontal space due to the automatic formatting of chat bubbles"
- rolph 2y agoyou would shatter it and send the shards off in a stream of messages. the recvng client would capture, and append to a file until complete.
- nine_k 2y agoASCII art porn vs CSAM pictures and videos: what do you think has a higher chance to involve e.g. child abuse? Preventing the spreading of CSAM is one of the key ideas behind the regulation. I wonder what happens with pictures sent as base64 text blobs though.
- walterbell 2y agoEU Poetry Party Welcome all ye bards!
- rolph 2y agobefore bittorrent such primal tools like uuencode, or mpeg2ascii were the way to move media thru a domain that filtered it.
- linuxandrew 2y agoSignal Foundation has already said they would leave the EU if Chat Control goes ahead. https://mastodon.world/@Mer__edith/112535616774247450 https://mastodon.world/@Mer__edith/112535616774247450
- wafflemaker 2y agoThanks to hn crowd, who explained it's not super difficult (and not going to lie, summer $500 discount), a Google pixel phone, soon running GrapheneOS, is on it's way. Can GrapheneOS prevent detection of somebody sideloading Signal?
- Wytwwww 2y agoProbably not but you still need to have someone to someone to communicate with even if you manage to install it. If you can't get it on the mainstream app stores it will just be a niche app for "privacy nerds" and drug dealers (in the EU at least..)
- pantalaimon 2y agoAll the drug dealers are on Telegram already, they need a hassle free way to communicate with their customers.
- dirigableuser 2y agoCustomers as a voluminous body of users can't be underestimated as a solid block of shade for the whistleblowers and journalists
- amelius 2y agoWill you convince all your friends and family to start running GrapheneOS?
- elric 2y agoThat's an interesting thread ... they claim they won't be compliant, which I applaud, but what will happen is that unwitting Signal users will end up being targeted by law enforcement. There are already precedents of people with "secure" phones or encrypted messaging apps being targeted, such as the Sky ECC case.
- FredPret 2y agoThis is why the roles of the major players in society (government, monopolies) need to be circumscribed. Large organizations will always try to grow in size and power. We need some sort of human right for digital privacy to make this sort of thing illegal.
- delichon 2y ago> This is why the roles of the major players in society (government, monopolies) need to be circumscribed ... We need some sort of human right for digital privacy to make this sort of thing illegal The entities that need to be circumscribed need to enforce a law that circumscribes themselves? Those incentives do not seem to align to form a stable structure.
- FredPret 2y agoThe only way is to have a broad-based idea among the people about exactly what is allowed for a government and a big business. There's a strong and widespread expectation among many that it's morally imperative for them to be able to elect their own government. So any moves by the government to limit this will be met by fierce resistance. If a similar idea existed about privacy, these sneaky moves wouldn't be feasible and would leave a bad taste in the mouths even of the perpetrators. Unfortunately, many among us are of the "But I've got nothing to hide" persuasion.
- Wytwwww 2y ago> widespread expectation among many that it's morally imperative for them to be able to elect their own government. So any moves by the government to limit this will be met by fierce resistance. That's not really true as far as it comes to the EU though? The EU parliament has always been a joke with limited power (both because of structural reasons and because most of it's members are clueless and extremely easy to influence) and besides that the EU population has no way to exert any direct influence on EU policies (they could do that through the council but they'd have prioritize the EU over domestic issues when voting in national elections which will never happen)
- belter 2y agoEU is, and always was, a compensation job for failed national politicians at their respective national levels. It's the trade horse for allowing your party buddies to take over the government jobs. EU politicians should keep their over inflated salaries, and stick to what they are good at. Meeting with Google and Microsoft lobbyists at the best Brussels luxury restaurants.
- seydor 2y ago> and stick to what they are good at. No they should be kept accountable for their actions and the money they waste. Currently there is no mechanism for that, but i m sure hordes of them would quit if we made one
- lxgr 2y ago> Meeting with Google and Microsoft lobbyists at the best Brussels luxury restaurants. Are you talking about the same EU that just passed the DMA? That must have been some really nasty food poisoning then!
- Wytwwww 2y agoAt least far as it comes to privacy Apple and even FB, MS and Google to an extent share the same interests as their users, unlike the EU bureaucrats who just seem to be salty because they are unable to exert control over society and justify their existence (they might pass some decent policies while they are it that's just mostly a coincident..). If Chat Control goes ahead long-term that will outweigh any benefits DMA might have.
- shortsunblack 2y agoDMA, like any other regulation that preceded it, was severely lobbied down. It happened in spite of EU. There is too great of a democratic consensus for it to be completely ignored. Do not get this wrong.
- matricaria 2y agoAre they even enforcing DMA? My WhatsApp still doesn’t have Third Party Chats.
- xmalrhk 2y ago[flagged]
- moffkalast 2y ago> Only Germany, Luxembourg, the Netherlands, Austria and Poland are relatively clear that they will not support the proposal, but this is not sufficient for a “blocking minority”. Ahem what? Last I checked any EU country can veto anything on its own. > Belgian EU Council presidency It's Council of the EU, not EU Council, that's the heads of state who don't have any legislative role. But the Council only does inter-country treaties, how is this even their thing?
- Macha 2y ago> Ahem what? Last I checked any EU country can veto anything on its own. Only on certain topics, which have been narrowed down over time. For most areas (including something like chat control), it comes down to Qualified Majority Voting, which needs at least 55% of countries representing at least 65% of EU population. https://en.wikipedia.org/wiki/Voting_in_the_Council_of_the_European_Union https://en.wikipedia.org/wiki/Voting_in_the_Council_of_the_E...
- moffkalast 2y agoHmm if they are passing this as a "treaty" of some sort then the head of state Council might still need to confirm it even if it passes. At least I hope so. Feels like they did this shit deliberately though, as it would never pass the Parliament for sure.
- ricardobeat 2y ago55%? That’s a pretty low bar for laws that will become written in stone for decades.
- timeon 2y agoBrexit was even lower.
- zirror 2y agoThere are some matters at the council that just need a qualified majority to move forward. Other matters, notably foreign policy, require unanimity.
- zx10rse 2y ago[flagged]
- seydor 2y agoGood, our children can now sleep safe. Emphasis on sleep
- mistercheph 2y agoWon't someone think of our childrens' rights to eternal slumber?
- radicalbyte 2y agoI already kicked up a shit here in NL together with a few other well connected people (with success) but it's a little frustrating that there's little more to do other than hope that nerds in other EU countries can make a difference.
- contravariant 2y agoLooks like the Netherlands is already opposed, for what good that will do. Any useful links to share with people?
- margana 2y agoFor any regulation or directive to pass, it needs to pass both the Parliament and the Council. Passing the Council means it needs unanimous approval from every member country. I don't see what "blocking majority" the article refers to, one country should be enough. Unless they mean stop it even before it reaches a Council vote, in which case that might be true.
- KoolKat23 2y agoIt's a council of the EU vote (as apposed to an EU council vote, different council). Within certain treaties (in this case the Lisbon treaty), certain matters only need a qualified majority (>55% of countries, 15 approximately, and to represent>65% of EU population).
- Kim_Bruning 2y agoWould it help if more Netherlanders made some noise, or is there really no further action possible?
- radicalbyte 2y agoThankfully some key people in the civil service understand the dangers extremely well & listen to the advice of the same voices we listen to :) It's really disappointing that Sweden are behind this as they have some extremely talented people only they aren't being listened to.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- worldsayshi 2y agoHow is VPN supposed to work? How are internet banks supposed to operate? All security will go out the window? Backdoors everywhere? Will TLS have to be redone with a third snooping party in the mix? Is that what we're going for here?
- Dig1t 2y agoClient side scanning is going to be required, it doesn’t matter if you’re on a VPN if your device is self-reporting.
- gpvos 2y agoHow would my device be (self-)reporting?
- worldsayshi 2y agoAll legal apps have to be self reporting I guess... So whenever you send anything to example.com you also send it to government-snooping-service.org?domain=example.com. And if you refuse to adjust your app you will get fined I guess. Will curl have to self report every request? Lol... Every client? Like will axios need to self report?
- pas 2y agoProviders, not individual apps. For actual details in the draft see page 45 and 46 ... https://cdn.netzpolitik.org/wp-upload/2024/05/2024-05-28_Council_Presidency_LEWP_CSAR_Compromise-texts_9093.pdf https://cdn.netzpolitik.org/wp-upload/2024/05/2024-05-28_Cou... ... "... measures shall be ... targeted and proportionate in relation to that risk, taking into account, in particular, the seriousness of the risk as well as the provider’s financial and technological capabilities and the number of users; ..."
- pantalaimon 2y ago> So whenever you send anything to example.com you also send it to government-snooping-service.org?domain=example.com. No, it's client side scanning - you have a database with bad material / a neural network trained to detect such material. Only when it detects a positive match, it will contact the government server.
- pera 2y agoThe proposal leaked a few weeks ago[1] is extremely vague on this matter and does not clarify how providers should detect CSAM "prior to transmission". Is anyone aware of any sort of scanning technology that can be implemented purely on the client side? Note that the leaked text says that it should be able to detect known and new abuse material. [1] https://cdn.netzpolitik.org/wp-upload/2024/05/2024-05-28_Council_Presidency_LEWP_CSAR_Compromise-texts_9093.pdf https://cdn.netzpolitik.org/wp-upload/2024/05/2024-05-28_Cou...
- godelski 2y agoMicrosoft: Replay Apple: Their CSAM detection system that was lambasted not too long ago[0] [0] https://www.apple.com/child-safety/pdf/Expanded_Protections_for_Children_Frequently_Asked_Questions.pdf https://www.apple.com/child-safety/pdf/Expanded_Protections_...
- theshrike79 2y agoAhh, the Misunderstanding Olympics of 2021 The Apple system was pretty much the best way this could be done short of having a 100% reliable "AI" system on-device detecting bad stuff.
- jonaharagon 2y ago> The Apple system was pretty much the best way this could be done This may be true, and yet it's also true that it was still a terrible plan. This is exactly why it simply shouldn't be done at all.
- godelski 2y ago> 100% reliable "AI" system It wasn't 100% reliable and in fact people quickly found collisions. Which you should expect to be able to with an even more advanced system. > Ahh, the Misunderstanding Olympics of 2021 There's much nicer ways to say this that is congruent with community standards[0]. If you believe I have misunderstood then try pointing out specifically what I have misunderstood instead of just making an assertion. But the question was if anyone was aware of any client side scanning technology that could in fact check for stuff such as CSAM. In fact, the Apple system was developed explicitly for this purpose, so yes, this does exist. While Replay doesn't have this explicitly feature stated (that I'm aware of), it is not a big step to think that you can just smash the two things together. As Apple shows a system detecting based on images and Replay is taking images of one's computer. [0] https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- throwawayfear 2y agoEU continues its descent into an authoritarian surveillance state. I hope all the EU netizens wake up and realize how much more control the EU has been exerting over its citizens since the pandemic.
- gpvos 2y agoIt hasn't, apart from this Chat Control.
- throwawayfear 2y agoCovid restrictions were significantly worse in the EU than USA, your government locked you all down and made it clear that they decide who works and who doesn’t. To be clear, the USA has some awful cities with those types of ideas too but it was far more rare. EU, Canada, and Australia showed they are teetering towards authoritarian surveillance states more than they are democracy. The more people put their head in the sand and justify these actions with the talking points they receive from the overlords, the more the water starts to boil.
- kalleboo 2y agoSweden is in the EU and didn't really lock down?
- gpvos 2y agoYou're entitled to your opinion, but I think those were basic public health measures, fully justified. They ended when no longer needed.
- zx10rse 2y agoNext time you want to stay home destroy economics and life of millions of people please don't drag us with you -[1] "lockdowns have had little to no effect on COVID-19 mortality" "The price tag of lockdowns in terms of public health is high: by using the known connection between health and wealth, we estimate that lockdowns may claim 20 times more life years than they save." "Numerous deaths can be attributed to the interruption of normal social life and routine regular social interactions. The direct factors are [25,26]: increased mortality due to postponement of diagnoses and routine treatments increase in mortality due to non-arrival at hospitals increase in mortality due to a decrease in the level of income and as a result—use of less safe cars, reduction in the scope of physical activity, etc. “deaths of despair” caused by drugs, alcohol, and suicide following loss of social-economic status increase in violence, including domestic violence; dismantling of families severe health damage to the elderly in particular—physical and mental deterioration (usually irreversible) due to loneliness, lack of movement, and routine supportive care." [1] - Are Lockdowns Effective in Managing Pandemics? - https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9368251/#:~:text=Later%20research%20(January%202022)%20performed,side%20effect%20of%20increasing%20mortality https://www.ncbi.nlm.nih.gov/pmc/articles/PMC9368251/#:~:tex....
- ls612 2y agoIt will be very interesting to see the responses of WhatsApp and Apple if this moves forward. Do their commitments to E2EE mean anything or not. Will iMessage and WhatsApp leave the EU or not. That would be extremely telling as to the actual quality of the security guarantees they purport to provide.
- dankai 2y agoWouldn't client side scanning prior to E2EE circumvent this issue? If WhatsApp or iMessage scan your messages on device it doesn't really matter if they are then encrypted during transmission.
- nicce 2y agoThe end-result is the same. There is no security if someone is snooping over your shoulder.
- pavon 2y agoApple is easy - they had already implemented this voluntarily until they got pushback, and decided against rolling it out.
- ls612 2y agoThey decisively said “this was a bad idea” and disavowed the effort.
- sureIy 2y agoThings change, especially when the Gov says they must. It’s already been a few years. Given the “Apple in China” precedent I wouldn’t be so optimistic.
- nicce 2y agoTheir argument was that ”with this you don’t need to ban encryption”, and they tried to prevent that regulation. Look what we got… I am sure that no single implementation is as sophisticated as Apple had.
- mellosouls 2y agoHeadline is clickbait nonsense. Nothing is being greenlighted. Here's the only relevant section, which links to an article [1] that says only that discussion will continue on the 19th June: According to documents leaked by netzpolitik.org, the COREPER 2 meeting in which they will put it [compromise proposal] to a vote will already take place on Wednesday, 19 June. [1] https://netzpolitik.org/2024/anlasslose-massenueberwachung-frankreich-wackelt-in-der-ablehnung-der-chatkontrolle https://netzpolitik.org/2024/anlasslose-massenueberwachung-f...
- mariusor 2y agoAlso, I expect "green light" in this context means that it will make it on the EU Parliament's agenda, nothing more. That's still perilously close, but it's not done and dusted yet.
- xinayder 2y agoI'm pretty sure the "greenlight" on the title means they are meeting to confirm that the countries will vote in favor of the law so it can be quickly approved once it makes to the parliament: > If Chat Control is endorsed by Council now, experience shows there is a great risk it will be adopted at the end of the political process. meaning: there will be little opposition to the proposal once it reaches the MEPs.
- mariusor 2y ago> meaning: there will be little opposition to the proposal once it reaches the MEPs. meaning: because the dust hasn't settled on the EU parliamentary elections, MEPs could vote without giving full attention to the law. Call me an optimist, but I still hold hope that that's not the case.
- Sayrus 2y agoI can see how that would be implemented for WhatsApp and other apps from large companies. But how would that work in practice for applications like Matrix where clients are not controlled by the server operator nor the server developer? Some questions I have from reading Patrick's website: - How do you even ensure a client is actually self-reporting? On-device attestation doesn't really work. - As a provider of E2EE chats, should the client report to you or to a third-party (Who?)? If the client reports to you, you are now possessing CSAM. Since even possession of CSAM is illegal, how does that work? - If a photo are flagged, will it appear in a GDPR access request?
- pas 2y agoMatrix is a software, it's not a provider. It's out of scope. (see 1. on page 37 for scope) see page 39 "5. Without prejudice to Article 10a, this Regulation shall not prohibit or make impossible end-to-end encryption, implemented by the relevant information society services or by the users" https://cdn.netzpolitik.org/wp-upload/2024/05/2024-05-28_Council_Presidency_LEWP_CSAR_Compromise-texts_9093.pdf https://cdn.netzpolitik.org/wp-upload/2024/05/2024-05-28_Cou... see also page 46 "... measures shall be ... targeted and proportionate in relation to that risk, taking into account, in particular, the seriousness of the risk as well as the provider’s financial and technological capabilities and the number of users; ..." also, it's a big framework without any tech requirements (see page 8 recital 17)
- risson 2y agoYou only really answer question 2 of your parent, and they obviously meant for someone operating a Matrix server with regards to their users. It's pretty well summarized in Patrick Breyer's sumary page[0]: > Only non-commercial services that are not ad-funded, such as many open source software, are out of scope > How do you even ensure a client is actually self-reporting? This is an interesting technical question whether or not it's covered by the actual proposal. How do you ensure that Messenger for instance is 1. actually doing the reporting, and not someone simply bypassing the app to keep sending e2ee chats without them being client-side scanned. That would most likely be against ToS and accounts would maybe get banned if doing so 2. prevent against spam reporting, where someone could basically DoS the reporting service with false positives > If a photo are flagged, will it appear in a GDPR access request? There are a bunch of dispositions in the draft concerning personal data protection (ctrl+f personal data to find the relevant articles). It also states pretty much everywhere that processing should be done in accordance with Regulation (EU) 2016/679, more commonly known as GDPR. [0] https://www.patrick-breyer.de/en/posts/chat-control/ https://www.patrick-breyer.de/en/posts/chat-control/ What really bugs me though, is this: > Having regard to the availability of technologies that can be used to meet the requirements of this Regulation whilst still allowing for end-to-end encryption, nothing in this Regulation should be interpreted as prohibiting, requiring to disable, or making end-to-end encryption impossible. Providers should remain free to offer services using end-to-end encryption and should not be obliged by this Regulation to decrypt data or create access to end-to-end encrypted data I believe this was added as a request from France, which didn't want E2EE to be undermined by this proposal. However, the provider would need to "create access to end-to-end encrypted data" to report it to the EU Centre. Although the following article states that E2EE can still be used if you don't send images, videos and URLs, so I guess that's the compromise?
- jauntywundrkind 2y agoPatrick's & a number of other Pirate Party seats were lost in the last EU elections. https://stackdiary.com/patrick-breyer-and-pirate-party-lose-eu-parliament-seats/ https://stackdiary.com/patrick-breyer-and-pirate-party-lose-... https://news.ycombinator.com/item?id=40631517 https://news.ycombinator.com/item?id=40631517 It's going to be awful not having Patrick Breyer reporting these activities.
- account42 2y agoPerhaps the German pirate party should have sticked to focusing on privacy and digital rights instead of becoming a second Green party with a far left bend. Really his snide at the right gaining traction in his post shows that he still doesn't get it.
- dankai 2y agoThe current draft would cover every kind of service that allows people to exchange information so that every DM you send on reddit, twitter, discord, steam, ... would be have to be scanned. Not even the most totalitarian governments on this planet have tried to implement something like this. Also it sounds extremely illusory that the people exchanging CSAM wouldn't simply switch to private services knowing their messages on public services are scanned. "... As services which enable direct interpersonal and interactive exchange of information merely as a minor ancillary feature that is intrinsically linked to another service, such as chat and similar functions as part of gaming, image-sharing and video-hosting are equally at risk of misuse, they should also be covered by this Regulation. " https://cdn.netzpolitik.org/wp-upload/2024/05/2024-05-28_Council_Presidency_LEWP_CSAR_Compromise-texts_9093.pdf https://cdn.netzpolitik.org/wp-upload/2024/05/2024-05-28_Cou...
- pas 2y agopage 46. "... measures shall be ... targeted and proportionate in relation to that risk, taking into account, in particular, the seriousness of the risk as well as the provider’s financial and technological capabilities and the number of users; ..." . . It's a big framework to push the industry to have more "parental controls". Everything is covered, but there the actual requirements make sense. See page 45. It's still bad, because it's extremely tone-deaf (and playing with fire is bad), but it's written by and for policy idiots, who live in Word documents, and (un)fortunately rarely have contact with the outside world.
- xela79 2y agohttps://www.synology.com/en-eu/dsm/packages/Chat https://www.synology.com/en-eu/dsm/packages/Chat self hosted chats included? ;)
- quantum_state 2y agoAre these guys so unimaginative that they ended up taking a page from the playbook of authoritarian regimes?
- nikolay 2y agoI think the government is more reasonable than the private corporations. As an example, I got suspended by Facebook yesterday with nobody to contact. All my friends from school, relatives, and former coworkers are gone - with most of them I was connected only via Facebook. All my messages in Facebook Messenger groups have been deleted! Everything that I ever posted, shared, or reacted to - gone! With no recourse - all at the mercy of some 20-year-old reviewer. Yeah, the government sucks, but private corporations suck much more! At least I can complain to the government and talk to real people! I know there are alternatives to Facebook - I've pitched all of them to my friends, but people my age are still only on Facebook.
- 7373737373 2y agoIt's time for humanity to move on, to social/messaging platforms not controlled by (for-profit) entities. Or ideally by themselves. Have you seen https://lurk-lang.org https://lurk-lang.org? Now it's even possible for anyone to provably compute a specific algorithm on your encrypted data!
- Kim_Bruning 2y agowasn't there a specific lobbying group pushing for this kind of legislation in some places (connected to the makers of software for this type of scanning)?
- BitPirate 2y agoAshton Kutcher and his Thorn organisation?
- KoolKat23 2y agoThis whole thing stinks. The relentless push, I feel may mean some American contractors are demanding their pound of flesh. https://mullvad.net/en/why-privacy-matters/going-dark https://mullvad.net/en/why-privacy-matters/going-dark They should be checking the bank statements of those on the EU payroll, and who are relentlessly pushing this. Make sure everything is above board.
- bfelbo 2y agoThat’s an incredible article, thanks for sharing! Really recommend others to read this.
- 7373737373 2y agoI'd like to hear from actual law enforcement personnel why/if violating my constitutional rights this way is actually necessary, specifically.
- orasiscore 2y agoIt will really happen. And it will happen fast
- butz 2y agoIn addition to usual communication, everyone should just start spamming as much as possible of "content" generated with GenAI. Good luck sorting through all that nonsense.
- sharpshadow 2y agoOnce implemented it would be just a matter of time until they advance the features of this with image scanning and of course active actions like taking control over your device with a warrant obtained digitally.
- Benjaminkleine 2y agoDo you think that Discord will leave the european union if chatcontrol pass ?