WhatsApp boss says no to AI filters policing encrypted chat
- Reference: 1659425348
- News link: https://www.theregister.co.uk/2022/08/02/encryption_whatsapp_uk/
- Source link:
Will Cathcart, who has been at parent company Meta for more than 12 years and head of WhatsApp since 2019, told the BBC that the popular communications service wouldn't downgrade or bypass its end-to-end encryption (EE2E) just for British snoops, saying it would be "foolish" to do so and that WhatsApp needs to offer a consistent set of standards around the globe.
"If we had to lower security for the world, to accommodate the requirement in one country, that ... would be very foolish for us to accept, making our product less desirable to 98 percent of our users because of the requirements from 2 percent," Cathcart [1]told the broadcaster. "What's being proposed is that we – either directly or indirectly through software – read everyone's messages. I don't think people want that."
[2]
Strong EE2E ensures that only the intended sender and receiver of a message can read it, and not even the provider of the communications channel nor anyone eavesdropping on the encrypted chatter. The UK government is proposing that app builders add an automated AI-powered scanner in the pipeline – ideally in the client app – to detect and report illegal content, in this case child sex abuse material (CSAM).
[3]
[4]
The upside is that at least messages are encrypted as usual when transmitted: the software on your phone, say, studies the material, and continues on as normal if the data is deemed CSAM-free. One downside is that any false positives mean people's private communications get flagged up and potentially analyzed by law enforcement or a government agent.
Another downside is that the definition of what is filtered may gradually change over time, and before you know it: everyone's conversations are being automatically screened for things politicians have decided are verboten. And another downside is that client-side AI models that don't produce a lot of false positives are likely to be easily defeated, and are mainly good for catching well-known, unaltered CSAM examples.
[5]
Messenger services like WhatsApp and others have been at the center of a years-long debate around encryption and public safety. At issue is whether law enforcement agencies should be allowed to dip into the encrypted communications of billions of individuals to hunt down the Four Horsemen of the Infocalypse: terrorists, drug dealers, CSAM, and organized crime, and whoever else comes along.
UK officials have been pushing for such government freedoms to filter, with Ian Levy, technical director of the UK National Cyber Security Center, and Crispin Robinson, technical director for cryptanalysis at British spy agency GCHQ, recently writing a [6]research paper arguing for automated scanners that manage to protect the privacy of individuals.
"We have not identified any techniques that are likely to provide as accurate detection of child sexual abuse material as scanning of content, and whilst the privacy considerations that this type of technology raises must not be disregarded, we have presented arguments that suggest that it should be possible to deploy in configurations that mitigate many of the more serious privacy concerns," Levy and Robinson [7]wrote . Note the "should be" and "many" caveats.
[8]
The European Union in May [9]also proposed legislation that puts much of the responsibility for ferreting out and exposing such material on providers.
[10]Won't somebody please think of the children!!! UK to mount fresh assault on end-to-end encryption in Facebook
[11]UK children's charity: Social media firms rubbish at stopping grooming. Time for a mandatory... AI
[12]Aw, look. The UK is still trying really hard to be the 'safest place to be online in the world'
[13]UK children's charity: Social media firms rubbish at stopping grooming. Time for a mandatory... AI
Some children's rights groups have been vehement that the need to protect children from exploitation should not be compromised by the argument for absolute privacy in communications. Andy Burrows, head of child safety online policy for the National Society for the Prevention of Cruelty to Children (NSPCC) in the UK, told the Beeb that direct messaging is the "front line" of child sexual abuse. The charity has [14]also asked for AI to be deployed in the front line against CSAM by probing private content on people's devices.
He pushed back at the claim by Cathcart that WhatsApp has detected hundreds of thousands of child sex-abuse images through its own techniques – "more than almost any other internet service in the world" – by saying that it has identified a fraction of the abuse that others, include Facebook and Instagram (both Meta businesses) do.
In an online [15]column last week, the Child Rights International Network tried to set the terms of the debate, noting encryption technologies both protect and harm children in such areas as the rights to privacy and protection from abuse.
"Given the complex interplay between encryption and children's rights, it is not surprise that a debate is currently raging on encryption and public safety, in particular regarding the fight against online child sexual abuse," the organization wrote.
However, communications service providers and mobile device vendors are reluctant to weaken encryption policies. Apple last year announced plans to scan photos of users' iPhones for abusive contents before it was uploaded to iCloud. However, the plans were [16]put on hold after complaints from privacy groups and users that doing so compromised security.
"If Apple can't get it right, how can the government?" Monica Horton, policy manager for the Open Rights Group, was quoted as saying. "Client-side scanning is a form of mass surveillance. It is a deep interference with privacy."
Regarding the proposed legislation from the EU, WhatsApp's Cathcart said "what's being proposed is that we – either directly or indirectly through software – read everyone's messages. I don't think people want that." ®
Get our [17]Tech Resources
[1] https://www.bbc.com/news/technology-62291328
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yuj12xwovgk2@iAY8@DXzQAAAI4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yuj12xwovgk2@iAY8@DXzQAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yuj12xwovgk2@iAY8@DXzQAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yuj12xwovgk2@iAY8@DXzQAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://arxiv.org/abs/2207.09506
[7] https://www.theregister.com/2022/07/22/british_encryption_scanning/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yuj12xwovgk2@iAY8@DXzQAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[9] https://ec.europa.eu/commission/presscorner/detail/en/ip_22_2976
[10] https://www.theregister.com/2021/04/19/uk_anti_encryption/
[11] https://www.theregister.com/2019/09/11/nspcc_wants_gov_to_ai_to_crack_down_on_social_media_grooming/
[12] https://www.theregister.com/2020/02/12/online_harms_ofcom/
[13] https://www.theregister.com/2019/09/11/nspcc_wants_gov_to_ai_to_crack_down_on_social_media_grooming/
[14] https://www.theregister.com/2019/09/11/nspcc_wants_gov_to_ai_to_crack_down_on_social_media_grooming/
[15] https://home.crin.org/readlistenwatch/stories/encryption-debate
[16] https://www.theregister.com/2021/12/16/apple_deletes_csam_scanning_plan/
[17] https://whitepapers.theregister.com/
It not true AI
"The UK government is proposing that app builders add an automated AI-powered scanner in the pipeline"
The government as always doesn't know what its talking about. Most AI in business is marketing bullshit, designed to make the company money at the expense of the user, much like Microsoft's "AI" code writer. The the "AI" to scan everyone's chatter and decide what to flag up isn't something the "AI" is aware of, it won't say "That seems like illegal content but hidden to avoid my scans" no, it will be based on what it has been trained on. What's to stop someone training it poorly & how many times will it flag false positives. Too many for a human to then check so people will just be automatically accused by "The AI which is never wrong".
All that will happen is another message app will appear with end2end encryption back in with no scanning.
Other Disadvantages
The government enforced program on your phone will be optimised for thorough scanning, not for conserving your battery. You will have no control over it draining all the power just when you need your phone.
Not only can they expand what is scanned, they can update the program to do other things. "Oh, there's a terrorist threat, so we had to make it send all your messages to us in clear, together with your exact location at all times"
Let's start
By making all MP's phone contents, texts, call logs & browsing history open to public scrutiny by having their data published on a real-time feed on a public website.
This won't end well
Given how far the UK has collectively shoved it's head up it's arse, I would have thought Whatsapp would know what side their bread is buttered. Remember they are overseen by Nadine Dorries which is a testament to the importance the UK places on them.
I suspect this may all be theatre.
Since when have the No Such Agency and friends allowed something properly encrypted to get so big without having a sneaky little backdoor/vulnerability of their own built in? ($NSA_KEY, anyone?) Unless of course it's already in Android binaries and/or the silicon.
We'd never be allowed Internet without all the [1]Black Boxen and fibre taps to keep an eye out for unauthorised democracy.
[1] https://www.channel4.com/news/black-boxes-to-monitor-all-internet-and-phone-data
Re: I suspect this may all be theatre.
I saw something recently (was it a Dave Plummer's Garage video?) that explained that "NSA Key" doesn't mean what people think it means
Of course Child Protection groups are all for this
Think of the children, eh ? How can you disagree with that, you monster ?
Yeah, well think of the journalists in a dictatorship. Think of my access to my bank account.
Sexual abuse, in any form and at any age, is abhorrent and I absolutely disapprove.
But if that means that some dictatorships will be able to find and kill journalists that are just doing their jobs, well I'm sorry, but the police need to up their game before I'll accept murder in exchange for child safety.
Not to mention that I seem to recall having read that actual cases of CSAM represent 0.2% of all reported cases.
The needs of the many is strong, point-to-point encryption. The needs of the few is better police work.
This is meta so a translation
""What's being proposed is that we – either directly or indirectly through software – read everyone's messages. I don't think people want that.""
or more accurately:
"We've tried it because we can make so much money out of your info if it worked, however our AI is shit and we don't have enough headcount to cope with the volume to do it without people noticing and complaining"
Meta never cares about privacy, never has never really will - YOU are the product they are selling.
Levy and Robinson -- Comedians Facing Both Ways At Once!!
Quote: "We do not seek to suggest that anonymity on commodity services is inherently bad....."
Really? It actually looks like the long-term STASI goals are actually:
(1) Make private encryption (and the possession of encryption tools) completely illegal
(2) Make service providers responsible for blocking any message that looks like encryption
(3) Make service providers responsible for reporting anything that looks like encryption to "the authorities"
In the mean time, a "not inherently bad" confection can be whipped up using chacha20, Diffie/Helman, gcc and gmp.....you know....private encryption before private messages enter any public channel.
.....makes E2EE completely moot! ...as well as being under OUR control.....and not available for inspection by anyone in Cheltenham!
Re: Levy and Robinson -- Comedians Facing Both Ways At Once!!
...and there's always steganography!!!!
Time for WhatsApp to put its money where its mouth is
This is a good message from the boss of WhatsApp. However, he knows as well as we do that governments will eventually just impose these requirements on them, despite what he says, and that they will have no choice but to implement the demands.
What we need is for Meta to put its money where its mouth is:
1) Provide an open API which makes it easy for 3rd party apps to send messages using WhatsApp and to handle displaying received messages. Allow a good, integrated user experience to be provided by a 3rd party app with integration with WhatsApp contact lists, etc.
2) Sponsor a standardised way for 3rd party apps to handle encryption - like GPG email - to allow interoperation so we can each choose our own app and publish keys like we do for email.
This would take a tiny amount of effort from them, would enable them to dodge these sorts of requirements, and avoid people moving to smaller, niche messaging systems.
P.S. While they are about it: providing an easy-to-use GPG email app on their platforms, integrated with WhatsApp and Facebook messaging as well as SMTP email, would be useful.
My 2cents
Perhaps if governments of all flavours fostered more trust in the world, we wouldn’t need encryption in the first place
I’m not a religious type, but to know good and evil, comes personal responsibility.
Remember, the WWW started at Cern, within a highly intelligent scientific community where trust and boundaries were, probably largely respected
Genossen, wir müssen alles wissen!
"Another downside is that the definition of what is filtered may gradually change over time, and before you know it: everyone's conversations are being automatically screened for things politicians have decided are verboten."