9 ms·
EU proposal to scan all private messages gains momentum
- philipallstar 1y agoThank goodness the EU is regulating dangerous communication.
- baal80spam 1y agoDitto, I feel safer already!
- philipallstar 1y agoI also feel safer. Thank you regulators for my safe and happy life.
- Cartoxy 1y agoThis seam like a hopeless endeavor. If circumvention takes little to no effort the people that are already committed to CSAM are going to CSAM. And everyone else will just hate the burdensome bloat, etc. If you know your not a theif having your bags checked after paying is an annoyance
- philipallstar 1y agoHaving your shoes checked before a flight is also an annoyance!
- Cartoxy 1y agoWell. It is if you don't have a bomb isn't it? You trade it for your safety but since you don't die in a firey crash if the person 3 streets over is CSAMing its kinda unfair comparison
- philipallstar 1y agoWell it's not if you're the child feeding the CSAM addictions.
- 9rx 1y ago> people that are already committed to CSAM are going to CSAM. Does its prevention even help anyway? The adult porn industry is regularly criticized for seeing people choose it over real sexual relationships. Conceivably the same could hold true for CSAM. As in, if you can't access it, you're going to go get the real thing instead. The narrative that it prevents child abuse sounds good in theory, but what does the data actually tell us?
- gjsman-1000 1y ago> what does the data actually tell us? The anecdotal evidence is that most child abusers started with CSAM and continued escalation from there; not that they would have been abusers except for CSAM. While it has never been proven to be a casual link, Ted Bundy, Brian Mitchell, Mark Bridger, Jeffrey Dahmer, and now Bryan Kohberger all accessed violent pornography before taking their actions. Dahmer stated it was his ritual - consume violent pornography before finding the next victim. Bundy meanwhile stated it was the tipping point for him psychologically, more than any other known factor, even describing it as his "fuel."
- 9rx 1y agoHowever, the anecdotal evidence around the regular adult porn industry is that users go in the opposite direction. The data is abundantly clear that people, especially young people, are having less sex, all while porn consumption has increased substantially. Likewise, causality hasn't been proven, but it is likely the most compelling answer. Why it is it different? At what rate have child abuses declined?
- 10298373 1y ago> Likewise, causality hasn't been proven, but it is likely the most compelling answer. That's a massive stretch—there are many things that have been declining along with the rate at which people have been having sex. Porn is in no way "the most compelling answer". It certainly could be a factor, sure, but by no means the only one.
- JimDabell 1y ago> If circumvention takes little to no effort the people that are already committed to CSAM are going to CSAM. Meta made 1.8M CSAM reports to authorities in 2024 Q4 alone. An awful lot of these people aren’t taking any steps at all to avoid detection – they are posting it to social media. You can argue the ethics of this scanning all you want, but if you’re arguing that it won’t be effective then you’re wrong.
- potato3732842 1y agoYou're acting like those 1.8m reports are actually legit. I'd wager it's 99% baby pictures, gore, normal porn and dank memes, in that order and that the other 1% was parties a) already on the radar of law enforcement b) hacked accounts being utilized for that purpose by parties unknown. If it were of real value they'd be touting arrests, not reports.
- Faark 1y agoYou forgot c) real but won't be looked at by understaffed police agencies
- deleted 1y ago[deleted]
- deleted 1y ago[deleted]
- nickslaughter02 1y agoHave 1.8 million people been arrested? If not it's clear the detection got it wrong.
- olgeni 1y agoEvery message will be scanned, except for von der Leyen's contract negotiations via SMS :D
- derelicta 1y agoYou are laughing, but last time they had added a built-in exception for politicians and members of law enforcement. Interesting, don't you think? :D
- superkuh 1y agoSeems like all regions of the world all falling into their own particular flavors of authoritarian fascism. EU's better than most but this is absolutely draconian. We all know this won't actually be feasible to implement but the end result of of this infeasibility will be a status quo where everyone is guilty of a crime by default when needed.
- evoseven 1y agoFascism is an ideology very different from the controlled liberal-capitalism of the EU. There is absolutely no push to reduce individualism so it's very wrong to use "fascism".
- nickslaughter02 1y agoPolicing what you can or cannot send in private even if illegal is not reducing individualism?
- echelon_musk 1y ago> won't actually be feasible to implement Why wouldn't it be feasible to implement? Sadly, I don't share your optimism.
- integralid 1y agoAs an EU citizen I don't believe chat control will ever happen. We already had mass protests in my country during the last 20 years against internet and population control, and we will again if this becomes close to reality. Maybe I'm delusional and I'll be severely disappointed I'm my country and the EU, but I don't think so. Who knows, time will tell.
- bigbacaloa 1y ago[dead]
- addandsubtract 1y agoI think it's at least time to write your representative. I know I will.
- Havoc 1y agoThank god AI never makes mistakes… I pity whoever is going to be the first false positive guinea pig for this csam process. Functionally a guilty (as decided by algo) until proven innocent logic
- lelandfe 1y ago2022, Google refuses to reinstate man’s account after he took medical images of son’s groin https://www.theguardian.com/technology/2022/aug/22/google-csam-account-blocked https://www.theguardian.com/technology/2022/aug/22/google-cs... > The man... took pictures of his son’s groin to send to a doctor after realizing it was inflamed. The doctor used that image to diagnose Mark’s son and prescribe antibiotics. When the photos were automatically uploaded to the cloud, Google’s system identified them as CSAM. Two days later, Mark’s Gmail and other Google accounts, including Google Fi, which provides his phone service, were disabled over “harmful content” that was “a severe violation of the company’s policies and might be illegal”... He later found out that Google had flagged another video he had on his phone and that the San Francisco police department opened an investigation into him. > Mark was cleared of any criminal wrongdoing, but Google has said it will stand by its decision. Less "guilty until" and more "guilty despite innocence."
- deleted 1y ago[deleted]
- izzydata 1y agoI assume this is just a police state overreach rather than genuine intent to stop crime. They must know that anyone actually engaging in criminal activity is going to not be caught by this because they use other forms of encrypted communication.
- philipallstar 1y agoContinent-wide police overreach.
- bccdee 1y agoIt'd be extremely easy to circumvent, too. Since the scanning runs client-side on images uploaded into the messenger, you just need an app to mangle and unmangle images. XOR the pixels in your payload with a picture of static, then do it again on the other side. It does not need to be particularly secure—the messages are still E2E encrypted so long as nothing trips the client-side scanner.
- k7sune 1y agoI suppose by XOR the payload the image size will multiply many times because no compression, whether lossy or lossless, will be possible.
- bccdee 1y agoOr transform the bytes of the compressed image file into pixels and send that. That'll be incompressible, but the file size should be similar.
- myrmidon 1y agoI'm not saying that this is NOT police state overreach, but the assumption that all (or even most) criminals practice good operational security still seems laughable to me. I think you are letting your ideological alignment (against surveillance state) push you into irrational standpoints ("more surveillance would not catch additional criminals"). I'm 100% with you on opposing legislation like this, but it is very important to not delude oneself about its likely effects, and to pick the right hills to die on, figuratively speaking.
- formerly_proven 1y agoThe overall policymaking direction of the EU can be summarized aptly: Pride cometh before the fall.
- domq 1y agoThe US being the one that showeth us the way of the fall that cometh huh?
- nickslaughter02 1y agoFingers crossed. The EU has outlived its usefulness and is a net negative to Europe of today.
- andrepd 1y agoThe ridiculously _opaque_ and un-democratic EU wants your messages to be _transparent_. It's almost too on the nose to be satire.
- integralid 1y agoI'm against any kind of censorship, chat scanning and privacy violations. Nevertheless: >Telegram founder Pavel Durov warned that France risks societal collapse if it continues down a path of political censorship and regulatory overreach. Durov was arrested in France in August 2024 after being accused of failing to moderate his app to reduce criminality Telegram is the messenger of choice for cybercriminals (not signal, interestingly). Most stealers and many other malware families use telegram to exfiltrate data and stolen credentials. It's also used as public announcement channels for criminal groups. Telegram ignores all reports about known malicious chats, despite it being easily provable, not to mention it's not e2e encrypted. At this point this is not resisting censorship but knowingly profiting from crime. Continuing the analogy, it's like post office was sending mails for terrorists, despite police staying in the hallway and begging them to stop that. (my job is related to anti-malware and cybercrime prevention)
- aaomidi 1y agoThen ban the app.
- integralid 1y agoI don't want to ban a chat app loved by many people, and I think that would be an overreaction. I just want them to actually respect abuse reports and the letter of the law.
- nemomarx 1y agoI think the post office screening letters to be sure terrorists aren't sending them would also be pretty bad
- graemep 1y agoThe UK recently introduced machine readable codes on postage stamps so they can now collect metadata on letters.
- CJefferson 1y agoWhile the post office didn't screen all letters, it was possible to get a warrant to read all the mail going to a certain address, and police often did that.
- deleted 1y ago[deleted]
- sackfield 1y agoThis pops up every few years, and I bet once it gets in it never goes away. It seems asymmetric that one side only has to win once to win permanently while the other side has to win constantly. Is there any mechanism to stop this in the EU and make this kind of legislation explicitly barred?
- azmodeus 1y agoVote them out and never vote for their parties in your general elections If your Member of European Parliament supports chat control stop voting for their parties and politically support their opposition
- progbits 1y agoNot good enough. They can get in again next election.
- vaylian 1y agoI agree. But also: I've been doing that for a long time already. The problem is that these surveillance laws don't get enough attention by the general public until they come into effect. For example: The UK's online safety act.
- izacus 1y agoSo make general public aware of them. Campaign. Inform. That's how democracies work. Don't expect others do to the legwork for your pet case.
- kurthr 1y agoVote for an opposition which promises mass deportations? Certainly, they will never go back on their word to create a surveillance state?!? Asking your politicians to lie to you is not a substitute for changing their incentives. The key point to make is that once you're spying on your own people, you've created the single weakest point of entry for your geopolitical opponents spying on you and manipulating the population as well. It's such a dumb political move, it seems like it could only come from extreme fear, greed, or manipulation. Switch it around and make them afraid of the alternative.
- orwin 1y agoIf this pass: the EUCJ will likely kill most of the proposal, once again we will hear 'judges are against democracy and for pedocriminals', once again the EUCJ will have to justify itself and spend political power and allow a sliver of the law to pass (my bet on age verification). The issue is that the EU courts are easy to predict. I'm not afraid of this law for itself because I know how the EU works and this will be challenged. I'm afraid of this because once again the 'center right' (i.e liberals) and the traditional right manage to move power away from courts. 'Les irresponsables' should be translated asap in German, English and any other language in the EU, and hopefully politicians will find a mirror in this book and stop worsening everything.
- efitz 1y agoDo citizens in the EU actually want this? If not, how are EU politicians so disconnected from their citizens? How did this state of affairs come to be? Is it reversible? In the US, our politicians don’t diverge quite as much, but when they do, the reason is money, and when it gets bad, we throw the bums out and elect populists. It’s not pretty and it’s messy but it self corrects with the next election if it doesn’t work out how people wanted.
- deafpolygon 1y agono, many of the citizens are just like any other country: some of them aren’t aware this is happening.
- amarcheschi 1y agoMost of the people I know - and I live in eu - are not knowledgeable about these topics. Furthermore, I've never heard about this in one of the main news channels, so I guess that most people don't even know about it
- p0w3n3d 1y agoThere's this "I have nothing to hide" sentiment followed by blind trusts into officials, their intentions and their alleged protection. I.e. people are scares of terrorism and would like it to stop, so they hope the terrorists will be found by spying. At least in countries where the terrorism emerged recently, I'd say...
- potato3732842 1y agoBeing "scared of terrorism" is perfectly legitimate even if not underpinned by statistics. The conversion from that to "so therefore the .gov ought to have powers that amount turnkey ability to violate human rights on a whim" is the problem. Any "well actually terrorists aren't that big a deal" discussion only serves to bog things down in the weeds and direct blame away from bad people who believe bad things. Replace terrorism with whatever the cause of the day is, drugs, satanic cults, tax evasion, etc, etc all you want, doesn't change anything. There are people who believe (though they'll rarely admit it when you lay it so bare) that you can take something that is flagrantly bad in its base or default form (like for example letting the government just read everyone's personal communication by default) and think that the fact that because it can be applied toward noble ends then it is a power the .gov ought to have access to by default.
- hsuduebc2 1y agoEven though it goes against all my beliefs and values, I still see it primarily as a desperate attempt to gain at least some means of control over encrypted tools — which are, in fact, constantly used for criminal activity. The endlessly recycled “think of the children” argument is laughably pathetic. I don't understand why they don't present the real and much more reasonable justifications — such as terrorism in Europe or the spread of propaganda, which is a genuine issue here. But those reasons likely don’t sell as well with populists. That said, I wouldn’t be surprised if this turned into a European version of the Patriot Act — where the state takes advantage of the fact that people have become desensitized, and everyone ends up being monitored 24/7. In the end, every citizen would be under surveillance, while criminals would simply download an app that doesn’t comply with this absurd requirement.
- wqaatwt 1y agoNot incompetent criminals will just workaround, there is no way to avoid that besides 1984 style universal surveillance.
- hsuduebc2 1y agoExactly. Only outcome is more surveillance for others with zero effect on the problem itself.
- nickslaughter02 1y ago> the spread of propaganda, which is a genuine issue here Now we are policing speech?
- hsuduebc2 1y agoBecause I perceive someone spreading lies with a clear malicious intent as a problem I'm policing a speech? Ok.
- nickslaughter02 1y agoLies according to whom? Are you the judge? You fight lies by presenting clear evidence to the contrary, not by censorship.
- Bender 1y agoThe first mitigation steps that come to mind: - Keep casual conversations on mainstream crap to be reachable by the masses and give the appearance of being monitored. - Send friends to a tiny URL that redirects to a tiny ephemeral private anonymous chat instance running entirely in RAM with an IP certificate [0] once available to remove domain name ownership from the picture. When done with that chat edit redirect to be something benign and wipe the chat instance. Block most crawlers using Anubis [1] and some other tricks. Chat crawlers that validate URL's are usually very obvious. I would wager HN could come up with 1000% more clever ideas. [0] - https://letsencrypt.org/2025/07/01/issuing-our-first-ip-address-certificate https://letsencrypt.org/2025/07/01/issuing-our-first-ip-addr... [1] - https://github.com/TecharoHQ/anubis https://github.com/TecharoHQ/anubis
- morkalork 1y agoNeat idea, a link that the first two people to open it get websockets and a chat, every subsequent connection gets a redirect. If pages are being crawled preemptively, the chat will be broken and if they're crawled afterwards there's nothing to see.
- amarcheschi 1y agoI've done an essay as my exam for an ethics course in uni, and choose to talk about chat control. I came up with very funny ways to circumvent scanning images. The easiest one would be to just encrypt an image and send the key and the encrypted message on different platforms to the recipient, I highly doubt they will be tied to the single user. Another - funnier way - would be to send the image as a file, and the recipient should convert it back to an image. Of course this could be automated as well on the scanning side, but if the regulation only talks about images, it should be safe. Not that I would do this if chat control happened and I would need some way to secure the content
- johndhi 1y agoCan someone explain how the same group of countries can simultaneously issue book-long regulations about how everyone needs to respect privacy to the nth degree, and run around the world trying to force others to do the same, yet also propose these kinds of things?
- attila-lendvai 1y agopretty simple: hypocrisy and lying from pathological personalities to gain more power, with a population fool enough to take them at face value.
- thmsths 1y agoThis is government 101. We tend to see governments as one big singular entity, this is rarely the case (and this especially true for a supra national organization like the EU with no real head of state). Instead you have different institutions with different goals that sometimes contradict each other. Then you have to account for multiple factions in those some institutions and you end up with what we currently have. The idea is that on the long run, if you average out the decisions/rules/regulation it is somewhat cohesive and leads to "good" governance.
- SoftTalker 1y agoSame reason US Congress usually exempts itself from the laws it passes. Rules for thee but not for me. You can bet the MPs private messages will not be included.
- nickslaughter02 1y agoEU ministers want to exempt themselves https://european-pirateparty.eu/chatcontrol-eu-ministers-want-to-exempt-themselves/ https://european-pirateparty.eu/chatcontrol-eu-ministers-wan...
- FredPret 1y ago"Four legs good, two legs better" is how
- 1y ago
- captain_coffee 1y agoAnd this, ladies and gentlemen, is how tech-savvy people will go out of their way to make sure they communicate with as many people as possible exclusively using End-to-End-Encrypted services exclusively. (that do not scan your messages even locally / on device before sending / after receiving them) In the UK a massive surge in using VPNs happened in the last 2 weeks and the adoption only keeps rising. Call me Nostradamus but if this legislation gets passed I can see how a lot of people will become familiar with the Privacy and Security aspects of the tech world (comms in particular).
- p0w3n3d 1y agoThe problem is it will be to late. We must not allow politicians pass laws that will be irrevocable and later find our workarounds, because (1) of complications (making our lives hell) and (2) allowing politicians to go further, e.g. forbid us from using phones where you can install arbitrary software, or another example - putting people to jail for encrypting their messages
- amarcheschi 1y ago[dead]
- sunshine-o 1y ago> Instead of weakening encryption, the plan seeks to implement client-side scanning, meaning software embedded in users’ devices that inspects content before it is encrypted. That sounds worst to me. That would make illegal any non official Signal client for example. Or worst does that mean it will be outside of the messaging app in the OS itself? In the end, we need to take a step back and look at the situation: - We know since at least Snowden the US listen to whatever they want - China and Russia probably have advanced capabilities like this but maybe more limited geographically - The EU is so incompetent they haven't figured it out. So now they are gonna force us to have some back channeling malware that is gonna slow and crash my phone every hour? How low can we go?
- WhyNotHugo 1y ago> Instead of weakening encryption, the plan seeks to implement client-side scanning, meaning software embedded in users’ devices that inspects content before it is encrypted. And there's really no way to enforce this unless you mandate locked-down devices with attestation. Then again, that's likely the long-term plan here.
- koonsolo 1y agoYou think this is some genius scheme? These politicians have no clue what encryption, client-side scanning, embedded software, and how these would all work together to scan messages means.
- bccdee 1y agoThey don't need to know what any of those things are. The people in the intelligence service know plenty. All the politicians need to do is give the spooks what they're asking for, in the name of national security.
- WhyNotHugo 1y ago> These politicians have no clue what encryption, client-side scanning, […] I agree. Puppets can’t fathom what the puppeteer envisions.
- jjani 1y agoNowadays the biggest EU parties are ones that are effectively against the EU, so they're using the most effective way to kill it: make their citizens hate it by passing such laws. If you create a diagram of "pro-EU" and "pro-Chat scanning" EU parliament parties, 90% will be in the two quadrants: "pro-anti" and "anti-pro". Yes, this proposal has been around since long before those parties got as big as they are now, but even back then the quadrants were roughly similar, and as such the level of support (including now looking to pass, unlike before) has also roughly been in step with the growth of those parties.
- Gud 1y agoThis is not just being championed by anti EU parties. I don’t think this is a fair explanation of what’s going on.
- pmg101 1y agoSomething the HN discussion on this topic just like the UK online safety act seems to ignore is that this kind of legislation has broad support among voters. I'd say in general people are more concerned about The Bad People than about privacy. Probably because they mostly trust their governments, certainly more than they trust Big Tech.
- wqaatwt 1y agoMost voters (in EU’s case anyway) are neither aware nor understand what is this all about. If you told are random person that the government will be able to freely access and read all of your private comment I bet they wouldn’t be too excited about it. Unfortunately only a tiny minority are even aware this is happening..
- lII1lIlI11ll 1y ago> Probably because they mostly trust their governments, certainly more than they trust Big Tech. Then why would they want big-tech employees to look at their nudes flagged by automated dumb scanning and unbeknown to them sent for human verification?
- raxxorraxor 1y agoBig tech and government is a false dichotomy though and these people are idiots. That is why we have right enshrined, for example that surveillance is prohibited. And gladly Telegram does not cooperate. That is a feature.
- ajb 1y agoThis is at least partly because the people opposing it don't know how to make a mainstream political case. The case for is "catch child abusers". People opposing it are talking in abstractions like privacy and right to use encryption. Which are important but you need to identify concrete harms that ordinary people identify with. You can't oppose a harm people can visualise and feel emotional about with an abstraction. Opponents need to say "if this passes your kids might be taken away because of a bot looking at your photos" . "Even if you send a picture of your own kid to your own mum, you will have to think about whether it could be mistaken for child abuse by some minimum wage worker at G4S from a completely different culture, who has to process 20 pictures a minute" The opposition mostly sounds butthurt that politicians are making tech decisions. And I say that as someone who genuinely thinks chat control is a terrible idea.
- betaby 1y agoThe same EU which says what you Airtag/Findmy is not a valid reason to suspect your stolen IPhone is at the location the tracking shows.
- Copenjin 1y agoIs this a reputable source guys? Why this stuff is not getting flagged instantly anymore?
- koonsolo 1y agoI remember a unix command back in the 90's that would list random words that NSA would intercept. You could then feed it to email footers. ChatGPT thinks it was 'spook', but can't find any references. Anyway, it seems we need such things again for messages, to overload any system the EU would have.
- throwaway89201 1y agoOn a slightly different subject (and it seems to be massively under reported): the European Parliament has already voted in favor of a law that mandates age verification for pornography with a one year prison sentence. It was included at the last minute as an amendment into this bill [1]. Search for "Amendment 186". The full accepted amendment reads: "Disseminating pornographic content online without putting in place robust and effective age verification tools to effectively prevent children from accessing pornographic content online shall be punishable by a maximum term of imprisonment of at least 1 year." [1] https://www.europarl.europa.eu/doceo/document/TA-10-2025-0116_EN.html https://www.europarl.europa.eu/doceo/document/TA-10-2025-011...
- tamimio 1y ago> the plan seeks to implement client-side scanning, meaning software embedded in users’ devices that inspects content before it is encrypted So, a literal malware?
- ryanstanley0147 1y ago[dead]
- mrsupreme005 1y ago[dead]
- mrsupreme005 1y ago[dead]
- angelina1470 1y ago[dead]