Tech world may face huge fines if it doesn't scrub CSAM from encrypted chats
- Reference: 1657175227
- News link: https://www.theregister.co.uk/2022/07/07/uk_online_safety_bill_chat_scanning/
- Source link:
The proposed update to the [1]Online Safety bill [PDF], currently [2]working its way through Parliament, states that British and foreign providers of a "regulated user-to-user service" must report child sexual exploitation and abuse (CSEA) content to the country's National Crime Agency. The amendment to the legislation makes it clear that companies must develop software capable of peering into end-to-end encrypted messages to actively detect and report CSEA material to the authorities – or face sanctions.
Truly secure end-to-end encrypted messages can only be read by those participating in the conversation, not network eavesdroppers nor the app's makers. However, it is possible for chat software developers to add a filter that automatically scans for certain illegal material before it's encrypted and sent or after it's received and decrypted.
[3]
How well that computer-vision process would work in practice, and whether the false positive rate causes a significant amount of people's private and lawful chatter to be beamed to the government, remains to be seen. Netizens may also not trust that just CSEA content is being reported.
[4]
[5]
Alternatively, an app maker could engineer their service and code to intercept and inspect the messages as they whiz between a conversation's participants, but that would undermine the whole end-to-end nature. However which way it's implemented, the British government, or [6]what's left of it after a ministerial revolt against Prime Minister Boris Johnson this week, wants encrypted communications to be screened for CSEA material, and has amended its Online Safety bill to that effect.
"Things like end-to-end encryption significantly reduce the ability for platforms to detect child sexual abuse," the UK's Home Secretary Priti Patel – well, Home Secretary at time of writing on Wednesday – [7]argued earlier in the day. "The Online Safety Bill sets a clear legal duty to prevent, identify, and remove child sexual abuse content, irrespective of the technologies they use. Nobody can sensibly deny that this is a moral imperative."
[8]
If the legislation is passed by Parliament, Ofcom – the UK's communications watchdog – will have the power to force tech companies to pay penalties if this inspection system isn't implemented. "The onus is on tech companies to develop or source technology to mitigate the risks, regardless of their design choices. If they fail to do so, Ofcom will be able to impose fines of up to £18 million or [ten percent] of the company's global annual turnover – depending on which is higher," Patel warned.
"We do not want to censor anyone or restrict free speech, but we must do more to combat these foul, hugely destructive crimes," she added.
[9]Twitter sues Indian government over content takedown orders
[10]California's attempt to protect kids online could end adults' internet anonymity
[11]Big Tech silent on data privacy in post-Roe America
[12]Mega's unbreakable encryption proves to be anything but
Building in automatic detection of CSEA content is controversial. Engineers, legal experts, and activists have highlighted the risks of developing such capabilities. It may undermine users' privacy, and potentially gives government officials a foot in the door of people's conversations. For instance, these filters, once implemented, could be expanded beyond child abuse.
Patel, however, believes changes to encryption systems to support this scanning can still preserve users' privacy while combating CSEA: "The UK government wholeheartedly supports the responsible use of encryption technologies … We, and other child safety and tech experts, believe that it is possible to implement end-to-end encryption in a way that preserves users' right to privacy, while ensuring children remain safe online."
"If end-to-end encryption is implemented without the relevant safety mitigations in place, this will become much harder. It will significantly reduce tech companies' and law enforcement's ability to detect child sexual abuse happening online. This is obviously unacceptable," she said.
[13]
Last year, Apple quietly paused plans to scan for CSAM on iPhones. Apple's [14]detection scheme was heavily criticized by academics and advocacy groups.
"Once this capability is built into Apple products, the company and its competitors will face enormous pressure – and potentially legal requirements – from governments around the world to scan photos not just for CSAM, but also for other images a government finds objectionable," [15]declared a letter signed by more than 90 human-rights groups.
The Online Safety bill also [16]attempts to tackle disinformation by getting social networks to filter out state-made interference, and reduce the distribution of stolen information for the purposes of undermining democracy. ®
Get our [17]Tech Resources
[1] https://publications.parliament.uk/pa/bills/cbill/58-03/0121/220121.pdf
[2] https://www.gov.uk/government/news/new-internet-laws-return-to-parliament-for-second-reading-this-week--2
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YsauwyrGNjOKteVOJ83AZQAAAA0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsauwyrGNjOKteVOJ83AZQAAAA0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YsauwyrGNjOKteVOJ83AZQAAAA0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://apnews.com/article/boris-johnson-london-sajid-javid-9b824c051d4524dc0efed20cec309453
[7] https://www.gov.uk/government/news/online-safety-bill-home-secretarys-op-ed-for-the-telegraph
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YsauwyrGNjOKteVOJ83AZQAAAA0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.theregister.com/2022/07/06/india_twitter_it_rules_protest/
[10] https://www.theregister.com/2022/06/28/california_kid_privacy_bill_anonymous/
[11] https://www.theregister.com/2022/06/24/big_tech_post_roe_wade/
[12] https://www.theregister.com/2022/06/22/megas_encryption_broken/
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YsauwyrGNjOKteVOJ83AZQAAAA0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[14] https://www.theregister.com/2021/08/09/apple_csam_faq/
[15] https://www.theregister.com/2021/08/19/apple_csam_condemned/
[16] https://www.independent.co.uk/tech/bill-government-nadine-dorries-damian-hinds-ukraine-b2115698.html
[17] https://whitepapers.theregister.com/
Re: Nobody can sensibly deny that this is a moral imperative
"Moral Imperative" = "of highest importance"
Nobody can deny that preventing child (or indeed, any) sex abuse is a moral imperative.
Nobody can deny that allowing people to communicate privately is a moral imperative.
Home Secs job, like that of many politicians, is to balance dozens of moral imperatives against each other. That's why it's a hard job, and not one that should be assigned to fuckwits.
Incidentally, also...
Nobody can deny that children having a roof over their heads is a moral imperative
Nobody can deny that children having enough to eat is a moral imperative
etc
See if the current government gives a flying f**k about any of that
Re: Nobody can sensibly deny that this is a moral imperative
She's just making a blanket false claim "Brits will share child porn if we cannot spy on everyone" there. There is no moral imperitive for a fiction she created.
She's variously changed the tune from "Terrorists" to "National Security" now to "Pedos" as the reason for backdooring end-to-end encryption.
Re: Nobody can sensibly deny that this is a moral imperative
Another "problem" of minuscule size that requires a nuclear weapon dropped from orbit as if "it's the only way".
Amusing article
There's no mission creep here, we're only interested in dealing with THINK OF THE CHILDREN.
And the article ends with two other potential targets, evidence of creep and how such a scheme could easily be expanded for "subversive" content.
Uh-huh.
Irrelevant really though, isn't it ?
Fucked if I'm letting "approved by Priti Patel" encryption handle anything of mine before I encrypt it myself.
Re: Irrelevant really though, isn't it ?
Exactly how widely that will be adopted is a question, but it will certainly be the MO of kiddie porn flingers.
If they can do why do they not tell us how?
"We, and other child safety and tech experts, believe that it is possible to implement end-to-end encryption in a way that preserves users' right to privacy, while ensuring children remain safe online." They believe this, but refuse to say what leads them to believe this. Open source implementations of E2E encryption have been around for ages, if it was possible then they could easily demonstrate it.
Re: If they can do why do they not tell us how?
Client side scanning prior to encryption is what she's talking about.
Re: If they can do why do they not tell us how?
Indeed, Monitor everything everyone does so that scanning the actual communication being sent becomes moot, they'll already know everything.
You'd think they weren't already tapping all the telemetry sent to the OS mothership.
Edit: someone disagrees with the captains accurate summing up!
Re: If they can do why do they not tell us how?
Actually, she hasn't got a clue what any of it really means at all...
They stopped trying to be rational when they kept getting the "this won't work" response, so now they just want to bully everybody into complience without having to provide a solution... "It's the LAW!"
Given the current debacle in parliament, how she has the cheek to talk about "moral imperative" I cannot fathom.
Re: Client side scanning
OK, lets try this. First I will need to gather collection images including CASM and have it tagged by cheap labour so I can train my AI. Next, to prove that I am forwarding only CASM to Priti Patel I have to publish my dataset.
Is any part of that legal?
Re: If they can do why do they not tell us how?
>They believe this, but refuse to say what leads them to believe this.
Boxed ticked, parents can sleep whilst the children surf the web.
Which immediately identifies the flaw in this statement; the first part ie. end-to-end encryption, has any meaningful impact on children being safe online.
End-to-end encryption won't stop what happened at Disney's Club Penguin.
Re: If they can do why do they not tell us how?
It is trivial, you encrypt one copy of the E3E message with your private key and the recipients public key. And to comply with the law, you encrypt second copy of the E3E message with your private key and a personal GCHQ/CSAM/government public key, sending the a copy of the message (Which they would then get computers to automatically scan using neural networks trained with existing CSAM, and a human would only be allowed to access any messages with an actual court order issued by a judge). Of course this would only work if people had locked down devices that could only execute the government mandated E3E communication application(s) and had no ability to run any unsanctioned applications (no matter how trivial they may be to create - in case someone reading this post does exchange CSAM, I'm not going to explain how). The mentally damaged individuals who own and send CSAM to each other would obviously use the government mandated E3E communication application(s) because they are severely mentally damaged individuals ? Just like these people in the government who created the online safety bill.
Maybe the solution is to start simple, implement the application for governments to test first for say 50 years. If anyone in the government is caught not using the application, they can serve some jail time. And every message sent by everyone in government is decrypted and made publicly available after say 20 years.
Re: If they can do why do they not tell us how?
Ok, i'll bite.
There is already a [1]child abuse image content list available which includes hashes of child porn images. To be compliant, all you'd have to do pn the client end when somebody attaches or receives an encrypted image is to check the image hash against a list of known child porn hashes, and if a match is found then flag it up to the police.
That would be totally compliant with this law, it could only inconvenience people attaching images on the child abuse image content list to encrypted messages and it leaves end to end encryption intact.
In fact the only possible potential this has for scope creep that I can see would be the police asking if they could keep a list of hashes attached to messages so after they've raided a paedophile and got an extra few hundred/thousand images to go on the list that they could retrospectively check to pick up anybody else sharing the same material. Even if this was done, a list of MD5 hashes presents quite a limited threat to privacy, or freedom of expression.
[1] https://en.wikipedia.org/wiki/Child_abuse_image_content_list
The way to attack -
Come up with something so vile that nobody can question it, then destroy privacy in the name of stopping it. Once the capability is developed, it WILL be used to spy on any and all communications. While there is security to be had in anonimity, that only works until the powers that be decide to take an interest in you. All it takes to get someone interested is to cut the wrong person off in traffic.
Testing
I suggest that testing should be done on ministers encrypted chats first.
Seems to be plenty of perverts and sex pests in West Minister.
Re: Testing
If we're lucky, that may lead them to conclude the "false-positive" rate is too high and scrap the whole idea.
Way to go, Priti
In the midst of a complete government melt-down, start to assume that you can legislate world-wide. Just keep believing six impossible things before breakfast...
And don't let the door catch you on the arse on your way out.
Re: Way to go, Priti
The name on the door might change, the attitudes within do not.
When in power 'Think of the children', when in opposition 'Oppose Big Brother'.
Re: Way to go, Priti
Mostly right, but opposition - no matter the colour - have consistently provided sufficient support for a surveillance state.
Another Clipper Chip episode
Of course no dodgy user would ever avoid official implementations of encrypted chat. {S} So eventually an open source coders comes up with multiple client side software. Said coders living in a country that does not support general snooping and remain anonymous for their own safety? Existing chat coders are in what legal position ? Next, support for complete packet analysis looking for the use of unapproved encryption data streams ? Its as if TLAs have plans for big Data retention and real time analytics and bought the right pollies. Regardless, asking Big tech to snoop is another Fox guarding Hen House scenario.
I do rather like the fox guarding henhouse analogy.
So they've finally found another angle
Seems that backdooring encryption has finally been dropped in the hallowed corridors of power.
So now they just make a law to slap a fine on companies that don't subvert encryption. That's not backdooring, right ? So you can't complain anymore.
Gotta hand it to 'em, they're persistent on this issue.
Too bad they couldn't more persistent on some other things, like the economy.
Re: So they've finally found another angle
@Pascal. How right you are.
But there is nothing original in her statement. She is just copying the E.U. and their recent announcement.
However, the answer to all this bollocks is simple. Just use whatever comms app that our "esteemed" M.P.s are using. Currently, Signal after most of them dumped WhatsApp some reason.
I am guessing it is something to do with Signal not making any money in this country so can't be held over a barrel like WhatsApp could be.
Ishy
P.S. Am rather surprised but Patel has also joined the "Stop doing a third rate impression of Trump and just fuck off now" gang.
Yet again...
I have been encrypting mail before I send it for several years now - all automated (meaning no mess, no fuss.) The feds do not think that this will become common? Remember more and more tech savvy kids are born every day.
If crypto is banned, then encryption will be used more than ever - plus that horse already left the barn.
Assumption Alert....Posturing Alert
Quote: " However, it is possible for chat software developers to add a filter that automatically scans for certain illegal material before it's encrypted and sent or after it's received and decrypted."
The assumption is that the encryption/decryption IS BEING DONE ONLY BY THE INTERNET SERVICE PROVIDER.
But there are plenty of people out there who are technically competent to perform a PRIVATE ENCRYPTION BEFORE ANYTHING ENTERS A PUBLIC CHANNEL.
So....per legislation, the service provider decrypts the service provider's own E2EE..............and just finds MORE ENCRYPTION!!!
Do our incompetent law makers know nothing? Surely the answer is a resounding "Actually less than nothing....it's all political posturing!".
Re: Assumption Alert....Posturing Alert
Of course the next step is obvious.............
..................just make the possession and/or use of encryption software completely illegal.
Yup....back to the bad old days before HTTPS, before secure banking, before internet shopping..........
But of course, our incompetent law makers really don't care about the facts.......remember, it's all political posturing!!!
Re: Assumption Alert....Posturing Alert
And then there's the problem if the private encryption utilises Diffie/Helman.....so that there is no persistent key stored anywhere.....the sender and the recipient can calculate the keys as needed, then throw them away. In the example below, the D/H token is a decimal string 2484 digits long -- approximately 8192 bits! Good luck decrypting the
*
0375509608624232715052975752126989428478416991142526807710714335019457280591
9962340451118394054174081568040691878423318442766015830996499358485599984276
6416942844030010522273262747886690515765838051163508193574385648882819367907
0765736182019777289091984705505040015539701846821505819041356272592149537414
5599284837359724402962565307914527390133557356393354680650013067989550170538
8844023274428842491073886088340214971654871549498071612005673727046029380461
4197198724963648359924717087115411424556149394679077598137814370988610539900
6577610357824113268424882198615435707576576078144348343398159341075660487201
7236394225052383884935890642112722875974578374138124307546325610991951959982
4149716163795731729622799589064527968443465478555343484291715625139166532785
8770211248496637981486822038381575518934970873889194016091271371613735110799
9063883603439672118017187716754208004018118491960518013412443885104276858502
1732682152934949671521372709002062241001658276045347419767555875250417368389
4522517081223809749829476130439781246084749139443669575580217965040060452908
7900301682024835789969436611383669069393682558564584600628945641224180853605
6298814830544040466195672925675570448245072528444876119528494293222835045715
2395076889863748761758331732622483885193032634522978144270241411023208159345
0071202817434879747818080206932392810631463566074745762614381333242276269667
3189194090666852659358730217614499883287632679771324319242334326965782411472
1385683937770702350573805682097633617788354233598681485304404689710798046027
0001975294712729317092938112116388977801677701183016342735348445227463527184
8378936807325267031825351032345567193716010607314425325663138174428909705536
5897106540403343924371403706185005130920920237807645181194806824339056415506
2576906937024993068034855390332991654861486631434510106900313224106778946001
3469541756233272083549227147686993355690923162358587402703514667908578295611
0399413602400154994944610204793733803472947657140882492756154905588559959490
4950863647867928811776929592909210119418514207478275576819662446203032801789
8405085637380140402072697270375441624809150996094014412259681921600183325577
8703167635925663587607929917566790997116023453746285061559481816801778181380
9718604360097629155060890990265606559295360347124039629009720153149666608816
8494319564086953263910365821214828843000669301307400289556253182736918658911
23423560052517355190322768101948710
iWk7ri11OsGIwi6m/gr2c8bGdh/apJj0GKV1Mj/7DVVTt1V1vD6z3Q3pg0UvHAXmT+fy4lxL4d9R
TSQPkDJ+u6VXlKkhFhA+y7x0A5S23K3LAF7Qjn5NbdRHrNB+hwTuoNTntjzeW+bNw7Q/Ld42j0KB
oVxhO9D0iuDnShA6zJlSYFPR0Op0o+EDzRklJxShiRMD/vblMrGyyMOzbchoGEWltovy/0OBx3iK
gHMlZhJ65UC2kJ25bIXLaeU6gvsQIg1kVM3O1y3LnyZcvkF6T5PnqO5P9KM5tj0hN2aSO2rDtCOZ
+Wch9h2LI5ipm28OQG3ciFUa7Ey5jb8XpR8MSV+bACKxmPR08EpEkasGAL+xr1iAD7uwoh261RR+
sdM28mTJcy9kUktFE+cQtjKnhoRyk4C7dBmYQA1I+fw0bRIvAOmAlohivkdMpk0fiOO/mKBfv/yA
Ws9DsdrlPK5D4QPKBP6HRhrePpg0/hZ+Pu/gvFWL1eBwrcCTGKVFpLkAAW53aLxEVrtwYM0Bn54o
p6wicdv8JzpIV9oSMIOUklpb2cZ41dtXmyT5r4zPCaiLFw43Od7k9KnoT7rIHLiBeOOva79hNjDr
CBU8nWxtKpUVrP67smrWVJMg7QFbjvqaPSb14nikqaDpWKL0r6H275VVjhsfxRSXbAYXeTMXF/aE
KqRtEZLySA6lyNR+PLJO0MzxskAhLEmB/IoCT/3dmuApoiE4xENrvCJPvFrnMSLRgEu3T0UEXj0m
fq7Xcvo3NMJv2yjQtsL1GBjrRJRnmqB2LjV10EbjUxsrmbgVEz1GJdqwxLQ437A1wah77gfWOiNV
at5/YyD5YtdvBch4wwZrgZPixYHWL4RtmRhHAnOv2nJ6aU0RFGcwQY7lSQDcEySXvU+6IOW/z492
fz4zj47H1ApVTAnOI+Cm//p8KkdpNvtrnrhcm1z1qWy+ayIYNc0BtSju0Ujmq2fKCu5hBewbTJjj
gN9hio2TsJoSfa0GFehFCJjPJuJ0nPK+NZIh6HzvuA6xYw/uTf5LFLa7kNAATboDiA2nFYnQt3d4
9Eb95RQg+pR56PqjVu3Um9D6xagvkXAHBg==
*
Re: Assumption Alert....Posturing Alert
I do DECLARE that YOU ARE Bob POSTING anonymously, and I CLAIM MY 5 pounds.
NOT SAYING how I KNOW.
WTF???
"Things like end-to-end encryption significantly reduce the ability for platforms to detect child sexual abuse,"
""The onus is on tech companies to develop or source technology to mitigate the risks, regardless of their design choices. "
That means one of two things
1) The onus is on tech companies to hold back the tide (these guys must have been sleeping in the King Canute history lesson)
(more probably what they are really after) 2) - All your comms r belong to us
eff off!!
Happy I'm not subject to that jurisdiction, and lets see your economy crash and burn if that ever gets implemented
Intersting addendum
"The Online Safety bill also attempts to tackle disinformation by getting social networks to filter out state-made interference, and reduce the distribution of stolen information for the purposes of undermining democracy"
Presumably to filter out state-made interference from states that "Our state" decides to filter out. Of course any interference from "Our state" or our buddies is A-OK!
Also "reduce the distribution of stolen information for the purposes of undermining democracy"???
One of the pillars of democracy is transparency, and one of the best measures of how good a democracy functions is in how it's freedom of information acts are implemented ie how easily can journalists and citizens find out what the government is REALLY up to. "Stolen" government information that is leaked may very well undermine *the government*, but it doesn't undermine democracy (in fact, usually speaking, if it's uncovering the governments dirty little secrets it's usually strengthening democracy)
Groundhog day
In communist countries, back in the day, when you called someone over the phone, there would be an officer officially listening to the conversation. They would say "this conversation is monitored, carry on". They would make notes who called whom and a brief what it was about.
Of course they didn't have enough agents, so it was at random or if you were a person of interest then almost always.
It's not hard to imagine that government will require providers to install a black box, where government will be performing its own filtering and detection without telling what is being looked for.
In a few years time, they will also develop conversation anomaly detection, where you may be flagged as e.g. potential agent of change and would have your social credit score lowered and people you associate with would get a warning that their score will be reduced if they continue to contact you.
In my opinion, anyone suggesting implementation of these things should be removed from power.
There are plenty out there that have..
Committed actual offences against children. Shall we not start by dealing with them properly first? Something that will make a real impact on people's lives right now.
If I were kiddie porn peddler...
..I would make damn sure that I encrypted my 'product' before I sent it over the public network, thus rendering the whole law completely useless, whilst the rest of us suffer the consequences.
Similarly if I were a terrorist.
Securing comms
2018: "The Five Eyes nations have told the tech industry to help spy agencies by creating lawful access solutions to encrypted services – and warned that governments can always legislate if they don't."
https://www.theregister.com/2018/08/31/five_eyes_2018_meeting_encryption_terrorist_content/
Various people have been put in place to implement it. Pritti Patel in the UK, Peter Dutton in Australia etc:
https://twitter.com/pritipatel/status/1180195336490557442
"Discussing the dangers of end-to-end encryption with close allies AG Barr and @PeterDutton_MP at the US @TheJusticeDept today. We can not let tech firms design platforms that give serious criminals & terrorists the advantage."
Obviously "serious criminals and terrorists" didn't cut the crust, so she's switched to pedos as a way to bypass the privacy right.
2019 we got the Ian Levy/Crispin Robinson proposal to give GCHQ a second key to all encrypted comms. Every time an encrypted session is created, GCHQ would get notified and a key so they can listen in. Oh fook off. You lot are more loyal to 5eyes that Britain. If Barr had told you to spy on Brits for Russia, you lot would have done it.
https://www.securityweek.com/inside-gchqs-proposed-backdoor-end-end-encryption
Any whistleblower care to leak? I think Pritti simply did it anyway and all this lying crap is simply to give a legal basis for it. I bet she already backdoored end-to-end encryption, I bet her foreign "allies" are aware of it, and Brits are not, care to leak?
Re: Nobody can sensibly deny that this is a moral imperative
Nice of the home secretary to openly admit that she thinks I am nobody. I am shocked at her honesty and fully expect her to be pressured by her peers into a prompt resignation.