News: 1699519392

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

EU lawmakers scolded for concealing identities of privacy-busting content-scanning 'experts'

(2023/11/09)


Europe's government watchdog has found that the European Commission's refusal to disclose which experts it consulted on the proposal to scan encrypted communication for child sexual abuse material amounted to maladministration.

The decision by the European ombudsman, made last month and [1]published this week, stems from a complaint filed in December 2022 by the Irish Council for Civil Liberties (ICCL), an advocacy organization.

The European Commission has been trying to formulate rules for preventing the sharing of online child sexual abuse material, rules known as the [2]Regulation on Child Sexual Abuse (CSA). But critics contend the proposed legislation would have to compromise private encrypted communication.

[3]

"The commission’s legislation would enable member states to compel online platforms, including those offering end-to-end encrypted messaging, to scan users' content and metadata for CSA images or 'grooming' conversations and behavior, and where appropriate report them to public authorities and delete them from their platforms," a coalition of advocacy groups, technology companies, and technical experts explained in [4]an open letter last year.

[5]

[6]

"Such a requirement is fundamentally incompatible with end-to-end encrypted messaging because platforms that offer such service cannot access communications content."

Apple came to a similar conclusion when it [7]abandoned its own [8]proposal to implement a system to scan for CSA material on its devices. The UK, meanwhile, passed its own Online Safety Bill that authorizes telecom regulator Ofcom [9]to demand decryption – even as officials have acknowledged that's not technically feasible at the moment.

[10]Scanning phones to detect child abuse evidence is harmful, 'magical' thinking

[11]EU mandated messaging platform love-in is easier said than done: Cambridge boffins

[12]GCHQ bod tells privacy advocates: Most of our work is making sure we operate within the law

[13]Bad eIDAS: Europe ready to intercept, spy on your encrypted HTTPS connections

Yet the European Commission still appears to believe there's a way to have bypassable strong end-to-end encryption while respecting privacy rights and maintaining operational security, [14]flying in the face of mathematics. And it has evidently persisted in that belief based on consultations with so-called experts.

But the commission refused to identify the experts who helped draft the text related to scanning encrypted communications – which prompted the ICCL complaint.

[15]

"Numerous experts have warned that it is not technically feasible," the ICCL [16]said in response to the Ombudsman's decision.

"Public [17]interest technologists and more than [18]450 academics have warned in public that 'technology to detect CSAM in encrypted content is currently not mature and will not be mature in the next two to five years.' This is in stark contrast to the views put forward by experts relied upon by the Commission, whose names the Commission is refusing to reveal."

The ICCL expressed concern about the commission's lack of transparency because of allegations about ties between the commission and commercial lobbyists.

[19]

In September, [20]a report from Balkan Insight – an investigative non-governmental organization – traced how the European CASM proposal has been supported by organizations that stand to benefit by providing content-scanning software.

On Tuesday, the commission's coyness became less of an obstacle. Member of the European Parliament Patrick Breyer published [21]the list of experts on Mastodon, and Berlin-based advocacy group Netzpolitik [22]also did so .

The list of consultants includes five individuals from an organization providing CSAM scanning tools. It also features academics from the Stanford Internet Observatory; industry technologists from Google and Microsoft; representatives from the National Center for Missing and Exploited Children (NCMEC); and agents of the Australian Federal Police, the Spanish Civil Guard, the UK's National Cyber Security Center (NCSC) and Government Communications Headquarters (GCHQ), and Europol.

Pointing to the findings of the Balkan Insights report, Ross Anderson, professor of security engineering at the UK's University of Cambridge, characterized the European Commission's refusal to publish the names of consulting experts as part of an broad attempt to undermine encryption by businesses that would benefit from content scanning contracts. This was aided by government intelligence services that fear being unable to listen in on important conversations happening through encrypted communications tools, such as Signal.

"We now have crypto war 3.0 coming upon us," Anderson told The Register in an interview, "because His Majesty the King advanced yesterday in his speech from the throne that there's going to be an Investigatory Powers Bill amendments act which, among other things, will give his majesty's ministers the powers to demand that … if you want to sell your wares in Britain and you propose to include any see new security features, [23]you've got to disclose them to His Majesty's government first." ®

Get our [24]Tech Resources



[1] https://www.ombudsman.europa.eu/en/decision/en/176658

[2] https://ec.europa.eu/home-affairs/proposal-regulation-laying-down-rules-prevent-and-combat-child-sexual-abuse_en

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZUy70lVCSkg3zO2C1h4MZgAAAJg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.globalencryption.org/2022/05/joint-statement-on-the-dangers-of-the-eus-proposed-regulation-for-fighting-child-sexual-abuse-online/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZUy70lVCSkg3zO2C1h4MZgAAAJg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZUy70lVCSkg3zO2C1h4MZgAAAJg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/12/08/apple_encryption_icloud/

[8] https://www.theregister.com/2021/10/15/clientside_side_scanning/

[9] https://www.theregister.com/2023/09/20/uk_online_safety_bill_passes/

[10] https://www.theregister.com/2022/10/13/clientside_scanning_csam_anderson/

[11] https://www.theregister.com/2023/03/29/eu_mandated_messaging_interop_paper/

[12] https://www.theregister.com/2018/05/29/crypto_wars_fipr/

[13] https://www.theregister.com/2023/11/08/europe_eidas_browser/

[14] https://www.theregister.com/2015/04/28/us_politicians_complain_that_silicon_valley_cant_create_encryption_unicorn/

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZUy70lVCSkg3zO2C1h4MZgAAAJg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[16] https://www.iccl.ie/news/ombudsman-european-commissions-concealment-of-secret-expert-list-on-csam-regulation-constitutes-maladministration/

[17] https://cdt.org/wp-content/uploads/2023/05/2023-05-16-Letter-from-Public-Interest-Technologists.pdf

[18] https://docs.google.com/document/d/13Aeex72MtFBjKhExRTooVMWN9TC-pbH-5LEaAbMF91Y/edit

[19] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/publicsector&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZUy70lVCSkg3zO2C1h4MZgAAAJg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[20] https://balkaninsight.com/2023/09/25/who-benefits-inside-the-eus-fight-over-scanning-for-child-sex-content/

[21] https://digitalcourage.social/@echo_pbreyer/111364497308411817

[22] https://netzpolitik.org/2023/geheime-liste-wie-der-sicherheitsapparat-die-chatkontrolle-praegt/#dokument

[23] https://www.theregister.com/2023/11/07/ukgov_wants_prior_notice_of/

[24] https://whitepapers.theregister.com/



Stupid see, stupid do

b0llchit

In this country, math will obey the laws of the land!

/s

and the earth is flat too, only 6000 years old and a man-in-the-sky in controlling every our step. Sigh.

Stanford Internet Observatory (limited hangout)

Anonymous Coward

[1]Stanford Internet Observatory: A program of the Cyber Policy Center

“Addressing Viral Medical Rumors and False or Misleading Information”

“Threatening Encryption, Senate Democrats Aid GOP War on Abortion”

“Confronting the evolution and expansion of anti-vaccine activism in the USA in the COVID-19 era”

‘"Hey Beautiful"; Race and Gender on Tinder’

“A Front for Influence: An Analysis of a Pro-Kremlin Network Promoting Narratives on COVID-19 and Ukraine”

“Effectiveness of vaccination mandates in improving uptake of COVID-19 vaccines in the USA”

“Seven tips for spotting disinformation related to the Russia-Ukraine conflict”

[1] https://cyber.fsi.stanford.edu/io/publications

Aston Kutcher's startup Thorn has its finger prints all over this push for client side scanning

Anonymous Coward

From Follow The Money: [1]How Ashton Kutcher’s ‘non-profit start-up’ makes millions from the EU’s fight against child abuse on the net

[1] https://www.ftm.eu/articles/ashton-kutchers-non-profit-start-up-makes-millions-from-fighting-child-abuse-online

Re: Aston Kutcher's startup Thorn has its finger prints all over this push for client side scanning

Anonymous Coward

https://12ft.io/ to remove the paywall

Doctor Syntax

There's a very simple answer to this. Their experts should provide a proof of concept implementation and then let everyone else pick it apart.

The criteria for success would be:

- It should not present a risk to that vast majority of internet users who are going about their lawful business

- It should not present a risk to those living under a repressive regime

- It should not present a risk to those, including but not limited t, children, living in abusive relationships seeking help

- It should not present a risk to whistleblowers seeking to draw attention to some illegal activity

- It should not present a risk to journalists working in hostile environments, including those working undercover

- It should not be open to abuse by unauthorised use or access by authorised users, including, but not limited to, Cheshire police intelligence (sic) analysts

If these experts can provide a robust practice demonstration of this they will have made their point, otherwise they, like the rest of us, should think of the children public at large.

Carson's Consolation:
Nothing is ever a complete failure.
It can always be used as a bad example.