Europe proposes tackling child abuse by killing privacy, strong encryption
- Reference: 1652337310
- News link: https://www.theregister.co.uk/2022/05/12/eu_encryption_csam/
- Source link:
A number of options [1]have been put forward for lawmakers to mull that aim to encourage or ensure online service providers and messaging apps tackle the "detection, removal, and reporting of previously-known and new child sexual abuse material and grooming."
These options range from voluntary detection and reporting of child sexual abuse material (CSAM) and grooming, to legally mandating that service providers find and report such material using whatever detection technology they wish — essentially scanning all private communications and, if necessary, breaking end-to-end (E2E) encryption for everyone.
[2]
If rubber-stamped, the rules will apply to online hosting services and interpersonal communication services, such as messaging apps, app stores, and internet access providers.
[3]Privacy is for paedophiles, UK government seems to be saying while spending £500k demonising online chat encryption
[4]UK.gov is launching an anti-Facebook encryption push. Don't think of the children: Think of the nuances and edge cases instead
[5]Apple quietly deletes details of derided CSAM scanning tech from its Child Safety page without explanation
[6]WhatsApp's got your back(ups) with encryption for stored messages
"If this proposal were to come to pass, it could result in countries banning true end-to-end encryption," EFF Senior Policy Analyst Joe Mullin told The Register , noting that requiring service providers to detect suspected child grooming requires them to analyze all private messages.
"The EU proposal is incompatible with end-to-end encryption and with basic privacy rights," Mullin continued. "There's no way to do what the EU proposal seeks to do, other than for governments to read and scan user messages on a massive scale. If it becomes law, the proposal would be a disaster for user privacy not just in the EU but throughout the world."
[7]
[8]
Here's what the proposal says service providers would need to do after receiving a "detection order" to scan for, report and remove any CSAM or grooming activity:
This regulation leaves to the provider concerned the choice of the technologies to be operated to comply effectively with detection orders … That includes the use of end-to-end encryption technology, which is an important tool to guarantee the security and confidentiality of the communications of users, including those of children. When executing the detection order, providers should take all available safeguard measures to ensure that the technologies employed by them cannot be used by them or their employees for purposes other than compliance with this Regulation, nor by third parties, and thus to avoid undermining the security and confidentiality of the communications of users.
It's worth noting that this finding-and-stopping-pedophiles argument is frequently used to [9]oppose E2E encryption and drum up support for mass-surveillance proposals — like [10]Apple's plan to scan photos on iPhones and iPads for CSAM, which it subsequently and [11]quietly walked back late last year.
EU 'war on E2E encryption'
"In case you missed it, today is the day that the European Union declares war upon end-to-end encryption, and demands access to every persons private messages on any platform in the name of protecting children," [12]tweeted Alec Muffet, who architected and led Facebook Messenger's end-to-end encryption effort.
He has first-hand experience with this. The UK government's ongoing rumblings against end-to-end encryption also relies heavily on similar [13]think-of-the-children and [14]Facebook-harbors pedophiles rhetoric.
Matthew Green, a cryptography professor at Johns Hopkins University, [15]called the Euro proposal "the most terrifying thing I've ever seen."
[16]
If signed into law, this regulation would likely require service providers to use AI to read entire text messages to figure out if a user is "grooming" children for sexual abuse, he [17]added .
"It is potentially going to do this on encrypted messages that should be private. It won't be good, and it won't be smart, and it will make mistakes," he said. "But what's terrifying is that once you open up 'machines reading your text messages' for any purpose, there are no limits." ®
Get our [18]Tech Resources
[1] https://ec.europa.eu/home-affairs/proposal-regulation-laying-down-rules-prevent-and-combat-child-sexual-abuse_en
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Ynzaxhd8cwxfsXPBug2u0AAAAIU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://www.theregister.com/2022/01/20/no_place_hide_campaign_anti_e2ee_ukgov/
[4] https://www.theregister.com/2021/09/08/uk_anti_encryption_facebook_e2ee_push_begins/
[5] https://www.theregister.com/2021/12/16/apple_deletes_csam_scanning_plan/
[6] https://www.theregister.com/2021/10/14/whatsapps_backups_encryption/
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ynzaxhd8cwxfsXPBug2u0AAAAIU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ynzaxhd8cwxfsXPBug2u0AAAAIU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2021/04/19/uk_anti_encryption/
[10] https://www.theregister.com/2021/08/09/apple_csam_faq/
[11] https://www.theregister.com/2021/12/16/apple_deletes_csam_scanning_plan/
[12] https://twitter.com/AlecMuffett/status/1524315613421879297
[13] https://www.theregister.com/2021/09/08/uk_anti_encryption_facebook_e2ee_push_begins/
[14] https://www.theregister.com/2022/01/20/no_place_hide_campaign_anti_e2ee_ukgov/
[15] https://twitter.com/matthew_d_green/status/1524094474187644933
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ynzaxhd8cwxfsXPBug2u0AAAAIU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[17] https://twitter.com/matthew_d_green/status/1524094474187644933?s=20&t=qnF6xEuqHN-ikWrmoaLE5Q
[18] https://whitepapers.theregister.com/
Re: Scunthorpe
Those encrochat users thought they where safe too…..
https://www.bbc.co.uk/news/uk-england-manchester-61400174
Ultimately whomever you chat with has to unencrypt your filthy messages so they either get you or they get them, either way they already know who your talking with.
Who’s to say your encrypted messages don’t contain the filth the authorities say they do? After all it’s in an unnecessarily secret code etc etc etc.
Ultimately, given the end to end nature of comms, governments know historically who connected to who.
its incredibly difficult to convince a jury, without the shadow of doubt, that something scrambled contains the nasties the authorities think it does even when they can prove connectivity took place and nasties are present on 1 side.
Removing encryption is all about removing that doubt.
Of course what they will find is that crims will use different tactics or use customised encryption.
Customised encryption will stick out and draw attention as only those peddling csam would use unauthorised encryption.
This incessant nudging needs to be stopped before other harms are introduced.
Re: Scunthorpe
Very clever! I bet when they spot something they can't decrypt they'll ignore it and carry on looking at the stuff they can decrypt.
There's absolutely no way that they would think that your PGP message contained child porn, singling you out for extra attention. Not a chance.
Re: Scunthorpe
Hmmm... if you use the World Wide Web, you should perhaps be aware that the vast majority of sites now use HTTPS, which provides End-to-End Encryption between you and the server. Most internet traffic is encrypted already.
Re: Scunthorpe
I'm quite sure that TLS is no problem for most of the Five Eyes to decrypt already, given the key harvesting that they have been engaged in for the last decade at least. Add the fact that most FE countries also hoover up the vast majority of data flowing on the Internet already, regardless of whether they can currently decrypt it or not and you begin to get an idea of the scale of the mass surveillance system which is already in place.
Given that they also have willing allies in even non FE countries like Sweden who happily provide data collection facilities to feed the data mines with raw feeds from links which are not located in FE countries, the penetration of the existing mass surveillance system is pretty much total.
The existence of these informal data sharing alliances also gives these countries the ability to spy on their own citizens, even when that is specifically illegal, by asking one of the other allies to do it for them. Add all the data which private companies collect about people through their pervasive surveillance systems to the pot and you end up with the ability to build a comprehensive profile of anyone's daily life and social network already.
The fact that the FE countries and their allies are attempting to remove the last vestiges of privacy from the day-to-day lives of the population will make anyone who uses illegal encryption systems (as they will become) stick out like a sore thumb in the data flows that are absorbed into the data mines.
We are already screwed. This proposal is just further proof (as if any was needed) of the contempt with which the ruling class treats the plebs these days.
Re: Scunthorpe
In that case write a software robot that writes random data to a file, encrypts it, then emails it randomly to an address from a large list. Have this timed so that they are sent out randomly. Then publish the source so that other like minded geeks can also get into poisoning their system.
Re: Scunthorpe
then emails it randomly to an address from a large list of legislators and other supporters of banning E2E encryption. And then tells the police about it.
FTFY
What was the proportion of kiddie fiddlers again ?
If I'm not mistaken, I seem to recall recently reading in these hallowed pages ( [1]this article ) someone stating that kiddie porn was 0.2% of all cases, the proportion being relatively stable for the past decade.
Now, far be it from me to declare that the children being abused is negligeable, it is a horrible thing, but I don't see why I should give up my privacy for this.
Get the police to do their jobs and that will solve the problem.
[1] https://www.theregister.com/2022/01/28/internet_society_calls_out_uk_encryption_war/
Re: What was the proportion of kiddie fiddlers again ?
Whilst I understand your sentiment, just stating "Get the police to do their jobs and that will solve the problem." when part of the problem is that so much is digital now, if they cannot read it, how can they do their job?
There is no easy answer but as encryption in transit and at rest combined with increased end-point security increase and becomes more complex, exactly how can they improve what they are doing?
Re: how can they do their job?
How about listening to children? Giving children clear opportunities to speak? Explaining that is not their fault?
They can take away https, ssh and gnupg when:
Using their own personal money they research and implement defective encryption. They use this defective encryption to protect all their money. When the money is taken they have no legal come-back on the thief and their the defective encryption is not mandated.
Re: how can they do their job?
I'd go further than that. Any legislator planning to vote for this should publish all their online credentials, banking, email, trading etc. and then postpone the vote for a year.
How to kill the proposal...
Intercept, decode, print out, & publish in a global media outlet all the communications from all the politicians proposing the law. If they don't like it, tough shite, because that's the reality of what they're trying to make into law. Don't want your stuff open for everyone to read? Then don't pass the fekkin' law.
Re: How to kill the proposal...
Intercept, decode, print out, & publish in a global media outlet all the communications from all the politicians proposing the law.
Do let us know a global media outlet that will be willing to and support the publication of these politicians communications….
Now Musk is buying Twitter that might be the only place that would publish such things, I doubt other outlets would be inclined to do so especially once they are convinced it’s all a good thing and thinking of the kids will increase sales or keep them on the good side of their regulators.
Re: How to kill the proposal...
Russia Today would probably be happy to publish private communications of UK government ministers. Or perhaps Al Jazeera. Or WikiLeaks (is that still a Thing?). Or any one of millions of anti-UK internet forums. Or somewhere on the Dark Web, leaked to "baddies" around the world.
Russia Today
Then maybe it would be simpler just to label the proposal as an attempt to "give Russia access to ..." at this time when EU member states are all feeling awkward about needing to prove they're not in Vladimir's boudoir?
Re: How to kill the proposal...
Distributed Denial of Secrets
https://en.wikipedia.org/wiki/Distributed_Denial_of_Secrets
Re: How to kill the proposal...
I don't think the proposals are about publishing everything into the public domain.
Just going from one extreme to the other invariably makes things worse.
Re: How to kill the proposal...
I feel like maybe you missed ShadowSystems point.
Re: How to kill the proposal...
"I don't think the proposals are about publishing everything into the public domain."
Not intentionally. OTOH how would you feel about your online banking becoming insecure? They don't intend it but nevertheless it's what the proposals are about. You can facilitate surveillance or you can have secure online business: choose one.
So what they're really asking for ....
.... is for every communication service to implement a MITM attack on every comminucation.
I think that we'd see a sudden explosion of the internet's version of book cyphers. It's the one where there is a large library of files that appear to contain random bits. You XOR your document with one (or more) of the documents in this library, then send it out. And only those that know which document(s) to use can get back to the original document ..... which (of course) is encrypted as well.
Or you just publish your XORed document to the library (making the library even bigger) and let whomever know which documents need to be used.
Re: So what they're really asking for ....
Except for their own communication, which must be and stay private and secure. There are two sets of rules: Us and the rest. The rest is subject to Us.
Sounds familiar?
Re: So what they're really asking for ....
How do you let the other side know which docs to use?
Over that government approved encrypted connection?
Re: So what they're really asking for ....
Ideas:
a) Send them a plain-text email containing your Book Club's latest reading list?
b) Send them a plain-text email containing the first book, phone them and tell them the second book by voice, send an SMS with the name of the third book, send a letter in the post with the fourth book, etc.
c) Communicate via a non-government approved connection, tunnelled over SSH or HTTPS. Are they going to try to make TLS illegal?
Re: So what they're really asking for ....
"Are they going to try to make TLS illegal?"
Yes, they'd need to if they are to achieve what they want.
the way we're going...
so politicians are (again) pushing for full access to everyone else'e commuication.... while in th emeantime there is a growing tendency for some government officials to use private email/messaging instead of their official government ones because they don't want the public to ever know what they're up to and FOI requests can't get at their private comms
Are Elected Politicians going to be exposed to the same level of Scrutiny?
Or will they claim 'Parliamentary Privilege' ?
Re: Are Elected Politicians going to be exposed to the same level of Scrutiny?
Note to self:
“... a rhetorical question. It has a question mark at the end, but you are not meant to answer it because the person who is asking it already knows the answer.” ― Mark Haddon, The Curious Incident of the Dog in the Night-Time
Impossible
It's impossible to prevent people from encrypting messages to each other. Even if you make mathematics illegal.
Yes, you can force the most popular private messaging apps to remove their privacy, but that just forces people to a wider variety of privacy solutions. Much harder to track baddies, then.
What about internet banking? Online shopping?
Don't shoot the messenger!
1 in 5?
"At least one in five children falls victim to sexual violence during childhood"
I wonder where that 1 in 5 comes from. I see the citation is the EU own campaign, "1 in 5 Campaign", so I click that link and read that page:
"About 1 in 5 children falls vicitim to violence including sexual abuse. "
Wait, its gone from AT LEAST 1 in 5 fall victim to *SEXUAL* VIOLENCE, and now in one click its changed to "*about* 1 in 5" and "violence *including* sexual abuse".
Again no supporting evidence.
Next paragraph is "Raise your hand against smacking"... "Corporal punishment is the MOST WIDESPREAD form of violence against children. It is any punishment in which physical force is used and intended to cause some degree of pain or discomfort. It is a violation of children‘s rights to respect for human dignity and physical integrity. The Council of Europe calls for a legal prohibition of corporal punishment of children in law and in practice. Corporal punishment conveys the wrong message to children and can cause serious physical and psychological harm to a child. "
OK, now we're two paragraphs down, and its 1 in 5 kids get smacked for being naughty. The EU is declaring punishment like smacking as the violence which is then redefines as sexual violence, which it then redefines as "sexual exploitation" of kids, or sexual abuse.
How do you *cyber* smack children BTW? Is there some sort of Apple "iSmack" I don't know about?
Oh FFS. Are you literally saying that 1 in 5 kids get smacked as punishment, and that therefore 1 in 5 are sexually abused because smacking = sexual abuse and offering no supporting evidence for any of that.
Such a game of misdirection and lying.
All to open a giant can of worms, and break end to end encryption, the thing protecting us from Russian hackers. Remember Russia? The soldiers that slit the throats of children in front of their mothers for shock value? Those hackers working to break end to end encryption and you trying to break end to end encryption, and you cannot see any danger in your lies?
What about terrorism? You could scan for extremism and flag that too, again since you're scanning it, those potential fiddlers might also be terrorists. It's no more of a privacy violation since they're already being scanned.
What about insighting speech like Holocaust denial? I assume everyone is one board, nobody likes Nazis, better scan for that too.
Why not copyright infringement, you're scanning it anyway, so why not also for copyright infringment?
What about plotting crimes, all crimes, any crimes, anything that might indicate pre-crime. Think of all the crimes you could prevent by watching everyone all the time.
"Roe vs Wade"... think of all those poor Republican victims you see on Fox News, don't they deserve protection from that hateful speech? I see they're saying protesting is a federal crime, and you do have that US EU cooperation treaty.
Basically, you're saying "there is no privacy right", attempting to justify it with "for the children" lies and offering options, none of which are "we have no justification for this therefore we assert something we know to be a lie, that 1 in 5 kids are victims of sexual abuse, and it is genuinely a very bad idea that undermines our core security".
Re: 1 in 5?
Reminds me of a similar mis-use of statistics I came across a while ago. Apparently some very high proportion of women (1 in 2? 1 in 3? or thereabouts) claims to have suffered sexual abuse according to the report highlight. Then you read the details:
Sexual abuse includes sexual harassment. Sexual harassment includes being looked at, while in public, by somebody who you don't want to look at you.
I am certainly not defending real abuse, but if the publishers of these kinds of reports were honest then something might be done to protect the 0.5% that really do suffer instead of everything being dismissed because 50% 'obviously' are not suffering.
Re: 1 in 5?
I think its 0.00004% suspected.
i.e. 12k reports of suspected molestation a year in 2020. I assume that's US focussed reports, so lets say 100 unique photos a year taken each by 300 million people, 12k/30 billion. suspected.
Re: 1 in 5?
It's the same sort of statistic fudging that the road safety mob use in the "killed or seriously injured" stats they use in thier apparent quest to restore the red flag act for cars - or at least reduce our progress to that of an arthritic snail.
As ever, " There are lies, dammed lies and statistics"
Re: 1 in 5?
Thank you, some sense here. Someone who actually reads the BS that the EU dishes out to manipulate parliamentarians, journalists and citizens.
The calculated nudging of EU parliamentarians
I would advise anyone to download the relevant PDF. The main, not so long PDF mentions *nothing* of encryption, but mentions the word 'children' hundreds of times. In note '32' there is a reference to the relevant addendum. That, however, is the one text not directly linked. In that very long addendum, in basically one place only, the actual decryption is mentioned, and that a 'EU Centre' for whatever will offer the necessary software for free, i.e. basically server spyware.
It's COM (2022) 209 final 2022/0155 (COD) and COM (2022) 212 final.
Kids are most at risk from their own family members. Putting cameras in every parent and every child's bedroom would be more effective to actually protect kids.
Please stop giving them more ideas.
Book Ciphers
The trouble with book ciphers is that the interceptor can look at your encrypted text and come up with a custom 'book' as the key to claim that you sent whatever it is they want to pin on you.
Steg
I can see a boom in live video streams being used as carriers for steganography or similar, by those with sufficient motivation. What's to say that live streamed trading rodent last year wasn't hiding something disgusting, like D Trump's tax returns ?
Great Reset
“You Will Own Nothing and You Will Be Happy” – WEF The Great Reset / Agenda 2030.
What they didn’t mention is that in owning nothing, it will include our data and privacy.
I’ve given you 7+ years warning. You’re welcome.
Slowly the EU slides into a CCP like dictatorship
Obligatory tracking boxes in new cars.
Proposed "internet off" buttons.
Proposed prohibition of encryption.
Censorship on Russian news sites to prevent "misinformation".
EU funds get allocated to support EU friendly candidates during elections in member states.
There are no checks and balances in place to limit EU commission overreach.
The EU applauding machine (parliament) is not accountable to its voters.
Non-elected EU central commitee apparatchiks attack, with the support of Big-Tech to implement censorship and suppression of alternative views, the freedom our (great) grandparents gave their lives for in WW2.
I m feeling optimistic this morning (a dreadful feeling by the way) and chose to go with Mr. Hanlon on this one:
"never attribute to malice that which is adequately explained by stupidity."
With the corollary: "Incompetence is a valid substitute of stupidity".
I might be wrong, but if you look at the background (see below), it looks like they know they are somehow part of the problem but also have no clue what they are talking about. Which is extremely dangerous, as the path to hell is indeed paved with good intentions.
On the other hand, I do read things like these: https://en.wikipedia.org/wiki/Catholic_Church_sexual_abuse_cases_in_Europe
Try to Ctrl+F "five years" to have a taste of how many times an actual child rapist got away with just 5 years in prison. If you are still feeling like having lunch, take a look at this (from way back in 2021): https://www.euronews.com/my-europe/2021/03/18/german-church-faces-moment-of-truth-with-abuse-report-due-for-release
So, if they actually wanted to DO something, they'd have their hands full with things that _might_ be closer to their comfort zone.
__
This is from April 28th 2020, European Commission:
https://ec.europa.eu/home-affairs/news/increased-amount-child-sexual-abuse-material-detected-europe-2020-04-28_en
The Internet Watch Foundation 2019 report highlights concerning trends around the increase of child sexual abuse imagery hosted in Europe.
The Internet Watch Foundation (IWF) has just released its 2019 Annual Report. Unfortunately, the report shows some alarming trends:
In 2019, almost 9 in 10 (89%) known URLs containing child sexual abuse material were hosted in Europe. This compares to 8 in 10 (79%) in 2018.
This is followed by North America, which hosted 9% of all known child sexual abuse URLs in 2019, a fall from 18% in 2018.
The Netherlands hosts 71% of the child sexual abuse content found by the IWF. This equates to 93,962 URLs. This is an increase from 2018 when the Netherlands was found to be hosting 47% of all known child sexual abuse material.
The relative amount of Child Sexual Abuse Material that detected in the Netherlands has almost doubled, from 47% of the total that they detected globally in 2018, to 71% in 2019.
This is due to a pervasive business model of “bulletproof hosting”, which takes advantage of the more permissive legal system and excellent technical infrastructure that The Netherlands provide.
Scunthorpe
but more importantly how will they read my messages without my keys ? Becuase (obviously) I ain't using no "EU" approved service. I will PGP anything before it goes anywhere.