News: 1682072923

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

International cops urge Meta not to implement secure encryption for all

(2023/04/21)


An international group of law enforcement agencies are urging Meta not to standardize end-to-end encryption on Facebook Messenger and Instagram, which they say will harm their ability to fight child sexual abuse material (CSAM) online.

The Virtual Global Taskforce was formed in 2003 and is currently chaired by Britain's National Crime Agency. The VGT consists of 15 law enforcement bodies, including Interpol, the FBI, the Australian Federal Police and other law enforcement agencies from around the world. In its [1]letter [PDF], the VGT said reports from tech industry partners play a key role in fighting CSAM content, with Meta being its leading reporter of abuse material.

But the taskforce thinks that will end if Meta continues its encryption push. "The VGT has not yet seen any indication from META that any new safety systems implemented post-E2EE will effectively match or improve their current detection methods," the taskforce said.

[2]

Meta's WhatsApp platform has long used E2EE by default, and the company has long said it planned to implement E2EE on Facebook Messenger and Instagram, with most recent estimates indicating E2EE would become the default [3]sometime this year.

[4]

[5]

As Reg readers know, End-to-end encryption theoretically makes it impossible for an intermediary to read the contents of messages - even if served with a subpoena the contents of an end-to-end encrypted message would be encoded.

"The announced implementation of E2EE on META platforms Instagram and Facebook is an example of a purposeful design choice that degrades safety systems and weakens the ability to keep child users safe," the VGT said.

[6]

The organization cited the [7]arrest and conviction of David Wilson in the UK as one example it claimed wouldn't have been possible with E2EE in place. Wilson, a Facebook user who groomed hundreds of children using fake Facebook and Instagram profiles, was sentenced to 25 years in prison in 2021. Of his conviction, the VGT said "it is highly unlikely this case would have been detected" if E2EE had already been implemented.

"The VGT calls for all industry partners to fully appreciate the impact of implementing system design decisions that result in blindfolding themselves to CSA occurring on their platforms, or reduces their capacity to identify CSA and keep children safe," the taskforce said.

In an email to The Register, Meta disputed the VGT's claims that Wilson's arrest wouldn't have happened with E2EE in place, telling us it submits CSAM tips using both public and private information.

[8]

"We have developed detection systems using behavioral signals and other account activity that are not reliant on the content of private messages to identify malicious actors," Meta said, adding that "It's misleading and inaccurate to say that encryption would have prevented us from identifying and reporting accounts like David Wilson's to the authorities."

Without going into any details, Meta told us it's committed to continuing to work with law enforcement as it rolls out E2EE. "We don't think people want us reading their private messages, so have developed safety measures that prevent, detect and allow us to take action against this heinous abuse, while maintaining online privacy and security," a Meta spokesperson told The Register.

Earlier this week, the UK's professional computing body the BCS wrote its own statement urging the exact opposite of VGT's: It wants parliament to shoot down the Online Safety Bill, a proposed piece of legislation that would require tech platforms to identify and remove CSAM or face fines.

[9]Google backs Bard to generate ads, which apparently improves creativity

[10]Facebook puts a price on privacy for US users and it's not enough to buy a cup of coffee

[11]Meta has nothing to say about politicians making deepfaked ads

[12]Ex-politico turned Meta hype man brands Metaverse 'new heart of computing'

Under the bill, companies would be required to remove content "whether communicated publicly or privately," which, as The Register [13]previously pointed out, would mean messages either wouldn't be able to be encrypted, or scanning for CSAM would have to occur prior to encryption. Critics argue this would be tantamount to adding a government-sanctioned back door on encrypted communications, which BCS chief executive Rashik Parmar told us "is exactly what many bad actors want."

"Building confidence in technology is a global priority in 2023. A bill aimed at keeping us safe online should protect encrypted messaging," Parmar said.

The VGT said that it wants industry partners "only to implement platform design choices, including E2EE, at scale alongside robust safety systems that maintain or increase child safety."

How that could be accomplished without also weakening encryption is something the law enforcement agencies are yet to answer. We've asked the VGT if it supports the Online Safety Bill, or whether it would support a different approach, but the taskforce has yet to respond to our email. ®

Get our [14]Tech Resources



[1] https://nationalcrimeagency.gov.uk/who-we-are/publications/646-vgt-end-to-end-encryption-statement-april-2023/file

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZEKzIag8JChjewQ@u6-@GQAAAFc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.theregister.com/2022/09/20/encryption_abortion_data/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZEKzIag8JChjewQ@u6-@GQAAAFc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZEKzIag8JChjewQ@u6-@GQAAAFc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZEKzIag8JChjewQ@u6-@GQAAAFc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.bbc.com/news/uk-england-norfolk-56009383

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZEKzIag8JChjewQ@u6-@GQAAAFc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2023/04/21/google_bard_ai/

[10] https://www.theregister.com/2023/04/19/us_facebook_users_class_action/

[11] https://www.theregister.com/2023/04/11/in-brief-ai/

[12] https://www.theregister.com/2023/03/31/metas_clegg_goes_nuts_metavere/

[13] https://www.theregister.com/2023/04/18/wrong_time_to_weaken_encryption/

[14] https://whitepapers.theregister.com/



Doesn't make sense

Flocke Kroes

First up, clearly most people involved in CSAM already apply excellent opsec or they would get caught promptly. Also, if criminals are communicating with children then the child's end point is the weak link for monitoring communication - preferably by the parents. This stinks of an excuse for restricting access to end to end encryption to silence [1]legitimate uses .

[1] https://en.wikipedia.org/wiki/United_Kingdom_parliamentary_expenses_scandal

Man on the end, not in the middle

Anonymous Coward

They're obsessed with the impossibility of secure encryption where they can somehow eavesdrop on the conversation unbeknownst to Alice or Bob. This is only ever going to be a pointless, noisy stalemate.

But Bob's parents can look over his shoulder, physically or metaphorically, without infringing his rights, as a child's right to privacy is not fully developed. The social media companies can treat logins from junior accounts differently, and nothing stops them providing parents with pre-compromised "junior" clients with built-in eavesdropping key(s), for themselves, and/or the provider.

Nobody has a problem with parents being able to forbid, monitor or control the internet consumption of their children. But it's not my job (my three are grown and flown), and I'm not having my privacy compromised because they can't do theirs.

Man on the end, not in the middle

Bebu

Reminds me of a (probably apocryphal) story concerning the six month delay in the introduction of the GSM mobile(cell) phone system in AU (replacing the analogue AMPS service.)

The story went that the cops and spooks were concerned that unlike AMPS, GSM traffic was encrypted and that they wouldn't be able to intercept (tap) the phone conversations between criminals etc and prevailed on the government of the day to delay the introduction presumably so they could try to introduce a back door into the already piss poor crypto. Presumably some telco engineer wielding the cluestick managed to convince the few polyneuronal members of these institutions that the telco decrypted the traffic within network where their wiretap requests would normally be serviced.

Even today I don't think end to end encrypted phone(voice) calls are yet really a thing.

This whole excercise is not what it looks like

Pascal Monett

Look, we know what's going on now. You're not thinking of the children. Child abuse is a terrible thing and should rightly be stamped down as soon as it appears, but you do not need the power to invade everyone's privacy to safeguard the children, and that's not what you're fighting for.

You're fighting for the power to invade anyone's privacy on whatever pretext suits the meal of the day. In itself, if only the government institutions could do that, it might eventually be acceptable, but the NSA has amply demonstrated that it will abuse whatever the hell it wants with or without permission, so by "eventually acceptable" we need to read "absolutely not acceptable".

And then there's the whole problem of if the encryption can be intercepted, it will end up being intercepted by the "wrong" people (and any value of wrong can suffice here).

Finally, I'll accept this possible invasion of my private life and correspondance if and only if all government officials use the same technology for their top-secret communications.

Hey, if it's good enough, then it's good enough for everyone.

Re: This whole excercise is not what it looks like

Missing Semicolon

Especially if the snooping is subcontracted to Crapita, who then lose the lot.

Re: This whole excercise is not what it looks like

Arthur the cat

Especially if the snooping is subcontracted to Crapita, who then lose the lot.

Worse, they'd mix up data so completely innocent people would get hammered by the law and the criminals would get off free.

mark l 2

Breaking E2E encryption is not what the police should be striving for to stop grooming and child abuse. The focus should instead being on educating children to realise when its occurring and report it. As it doesn't matter if the message were E2E encrypted in transit or not if they can get the messages from the childs device after its been decrypted and then use that as evidence to go after the perpetrator.

Although we know that CSA is just the attention grabbing headline the authorities use for their argument, as then anyone who doesn't agree with back dooring E2E they can accuse of siding with the abusers.

But the real reason they want to put an stop to E2E encryption is that the authorities have got used to having access to all your data, freely available to tap into whenever they wanted and now they don't like that more and more of it is getting closed off to them with encryption.

Old Confused Person Here

Anonymous Coward

Any group with a gcc or clang compiler can implement their own private encryption.

Their encrypted messages can be carried by Gmail, Signal, Telegram, Whatsapp, or any other service.

The end points used by members of this group can be fabricated (i.e. anonymous).

How does breaking E2EE make any difference?

Old, confused person here!

It was kinda like stuffing the wrong card in a computer, when you're
stickin' those artificial stimulants in your arm.
-- Dion, noted computer scientist