• 0 Posts
  • 10 Comments
Joined 3 years ago
cake
Cake day: June 12th, 2023

help-circle
  • So they say “no, let’s not do Chat Control 2.0! Let’s do Chat Control 2.0 but let’s also ignore part of the problem we don’t know how to solve”.

    Well, the idea is that if the creation is prevented, the spreading will solve itself. Chat Control 2.0 also isn’t judicially targeted. And to be clear, that summary is based on what the EP is advocating for (and is, I believe, part of the basis for amendments in the earlier document you linked).

    Btw, there are 2 links in my post. The 1st one is more interesting in my opinion.

    Why do people claim they are looking to introduce mass surveillance when they clearly don’t?

    Because the initial proposals from the Council and Commission more or less were mass surveillance. Only after a couple of years has it done away with the mandatory scanning (for now anyway) after it became clear the EP wouldn’t be in favour (again). People are understandably suspicious. Unfortunately, people tend to conflate the entire EU into one thing, in large part because reporting tends to just say “EU”. The EP certainly isn’t looking to introduce mass surveillance, that much should be clear by now.

    Why no one is doing this?

    Why do you say no one is doing this? Big Tech isn’t advocating for the continuation of (the temporary) CC1.0 because they’re not using it.


  • we can argue if grooming and CSAM is a real problem

    I don’t think we need to argue that. It is a real problem. It’s more that measures like this, aren’t likely to be particularly effective in combatting CSA. It’s not for nothing that many digital rights organizations like the EDRi and EFF are advocating against this. Even child protection services aren’t necessarily in favour of this. This proposal does little to actually help the victims of CSA (even more so because of the exclusions of software that isn’t publically available).

    That leaves the question, who does it benefit?

    parents should be monitoring their kids, not EU and police has tools to fight CSAM without client side scanning

    Agreed!

    it’s definitely not an attempt to break e2e encryption and monitor all communications.

    Maybe not explicitly, but it sure makes it easier.

    If EU is trying to introduce mass surveillance like that then they are doing shit job

    Thanks to the EP. I agree that CC2.0 has lost a lot of its teeth due to the exclusion of explicit mandatory scanning (though it’s still problematic). Before those changes, it was absolutely mass surveillance imo. Currently, I’d say it’s more of a stepping stone.

    Most people would be completely fine with WhatsApp scanning their media, they already post everything on Instagram

    Most people don’t seem to care about privacy in general unfortunately, though posts on instagram are not the same as WhatsApp messages and the like.

    WhatpsApp actually doesn’t want to scan anything because it’s extra work for them with no gains

    I kinda doubt that. Meta already has those tools.


  • You said:

    I did not. I responded to the comment that said that. I said that they kept bringing CC2.0 back.

    I did also say that it’s specifically about scanning, but that’s indeed not entirely accurate. That’s part of it, but it’s broader than that.

    but it’s still just client side scanning, not breaking encryption

    Not sure what you mean by “still just”. Client side scanning just sidesteps encryption, making the encryption useless. It’s like saying “we’ll never open your posted letters in transit, but we’ll look over your shoulder while you write/read it”.

    Services that are not likely to be used to share CSAM will not be forced to mitigate anything.

    Sure, but chat apps are pretty likely, no? And authorities are allowed to adjust the risk assessments.

    Another mitigation could simply be disabling sharing of media - text messages will not have to scanned

    I mean, sure, but that doesn’t seem like a feasible solution. People’d just leave that platform. Imagine if WhatsApp blocked sending images or files.

    So we’re basically talking about checking hashes of shared media against some database in some of the services

    This wouldn’t catch new CSAM though (thus not protecting children).



  • You’re right, it doesn’t use the word “scan”, it uses “detect”. It doesn’t say “chat”, it says “interpersonal communication”. There are 335 mentions of “child sexual abuse”, I wouldn’t call that “barely mentions”. All of it is mentioned in the opening paragraph as background info.

    Detection obligations have indeed been removed since the linked document (it wasn’t before that, as you can see in that same document, page 3), thanks to the EP, but it still provides the legal framework for companies to do so anyway, without any reasonable suspicion. That’s already bad enough.

    Moreover, there are mitigation obligations:

    Certain providers of high-risk services will have the obligation to take measures to develop relevant technologies to mitigate the risk of child sexual abuse identified on their services

    In order to prevent and combat online child sexual abuse effectively, providers of hosting services and providers of publicly available interpersonal communications services should take all reasonable measures to mitigate the risk of their services being misused for such abuse, as identified through the risk assessment

    Mitigation is very hard to do without identifying it. For that you’ll have to detect it in some way, f.e. by scanning chats, which you are allowed to do through this. Scanning might not be the only way (though I can’t think of another way), but it is the easiest way.

    In particular, given the importance of ensuring that all possible risk mitigation measures have been taken in accordance with this Regulation, the competent authorities should be granted specific powers to require providers to adjust their risk assessment or mitigation measures so as to ensure compliance with the relevant requirements of this Regulation

    Authorities can adjust the risk assessment themselves.

    Accordingly, this Regulation should not apply to interpersonal communications services that are not available to the general public and the use of which is instead restricted to persons involved in the activities of a particular company, organisation, body or authority.

    Very ironic. The ruling class and elites are excluded.

    E2EE protection is nice, but pretty irrelevant. With clientside scanning, the E2EE is not broken, because your device has already decrypted it. It simply negates E2EE

    This EU explainer, puts the document in simpler language: https://www.consilium.europa.eu/en/press/press-releases/2025/11/26/child-sexual-abuse-council-reaches-position-on-law-protecting-children-from-online-abuse/

    The new law, once adopted, comes with obligations for digital companies to prevent the dissemination of child sexual abuse material and the solicitation of children.

    How would a chat company do such a thing without scanning chats?

    But, even if all of it was fully voluntary (what chat control 1 more or less is), it’s still really bad. Why do we want to give companies the legal right to scan everything we do on their platforms?

    I recommend taking a look at Patrick Breyer’s site (ex-MEP for the Pirate Party) and the EDRi.