What’s the endgame here, with porn, chat control and age verification occurring globally, when will this end and where will we end up? What are the realistic outcomes?
I lost count how many times the "lets get rid of encryption" plans have been tried and failed. It's truly ridiculous how these people don't understand anything about encryption and somehow still think this is a good idea.
How is it possible that after years of discussing plans like this, they still managed to not listen to anyone who knows anything about encryption and online safety?
Makes me really worried about the future. There is a lot going on in the world, and somehow they feel the need to focus on making our communications unsafe and basically getting rid of online privacy.
The goal they are trying to achieve is good, but the execution is just stupid and will make everyone, including and maybe especially the people they want to protect, less safe online.
The age verification thing is another example. All it does is send a lot of sensitive traffic over cheap or free VPN's (that might be controlled by foreign states). Great job, great win for safety!
What they should be doing is giving us the ability to use public apps without the apple store or google play. What they are doing is letting Palantir get our data, despite it being from a country that thas repeatedly threantened Greenland.
What exactly is the plan? To mandate some client side checking so that transfer encryption backdoors won't be needed?
At what level would you need to do that? E.g. for iOS and then iOS need to comply with every app store app having it or else they can't operate in the EU? Is that the plan?
In the past, we could have made a version of Signal without this spyware, to be installed as an APK (as I would expect the EU to force Google to ban the non-spying version from the app store). With the upcoming Android developer verification, this will no longer be a possibility.
>as I would expect the EU to force Google to ban the non-spying version from the app store
If you expect hostile action by Google you should also expect the rootkit that is google play services to also do that. Which means in both cases the solution would be to use a actual open source mobile OS based on AOSP.
This thread is going to be 400 comments of people talking about how stupid this is, how it won't work and never will, how no sane person could possibly want this. And you know what, I agree with all of that.
But there are a few people asking who is pushing for this legislation so hard. That's mostly police forces who are pointing out that they're unable to track the activities of criminal organisations. For example, in the UK sophisticated gangs steal cars and phones and ship them around the world where they're resold. They locate a buyer anywhere in the world who requests a specific car, find that car, steal it and have it in a shipping container within 24 hours. It's impossible to know who's done it, or track any of the communications involved.
In previous eras it wasn't possible to create international criminal organisations of this level of sophistication because it was harder to communicate securely. Now it's possible and we all pay the price of increased criminal activity. Everyone's insurance premiums go up, making everyone poorer. UK car insurance premiums are up 82% between 2021 and 2024 and insurance providers are still making a loss.
Just to drive this point home - watch/rewatch The Wire (2002-08), except make it impossible to tap the communications of the drug gangs because they're all using encrypted messengers with disappearing messages. Immediately the people running the organisation become untouchable. The police likely can't even figure out who the lieutenants are, let alone the kingpin. At best you can arrest a few street level dealers and that hardly disrupts the criminals at all.
On HN everyone is going to say "everyone has a right to private communication, even criminal empires". And sure, I'm not going to disagree. I'm merely pointing out that private communication allows criminal networks to be much larger, more effective and harder to disrupt. And all of society pays the price when we're victimised by criminals.
Edit: I'm not saying breaking encryption is a good thing or that it will work, I'm only pointing out why police forces want access to communication records. They're unable to do their jobs and are being blamed for the rise in crime. To prove that you've actually read my comment till the end, please mention banana in your comment.
Name and shame the clearly corrupt politicians that are being paid by someone who wants to benefit from all the compliance bullshit that will come from it.
No one has really pointed forward a convincing explanation of who is behind this movement.
The idea that this is the police is ludicrous to me, I don't know every european country but my overall opinion is that they have very little sway over anything.
I am in a group of high civil servants for digital services in France and strangely no one seems to have heard about the project despite these people drafting most of France's position on numeric policies.
My view is it is probably more about mass control (avoiding a movement like Gilets Jaunes and the like) than anything else.
If this could possibly work it would have already been implemented for DRM. It doesn't even really work if you have complete control over content distribution. I get that politicians want to be seen as being active in combating crime. But the only proven way to prevent creating and proliferation of CSAM is to educate the masses.
They could just ask Meta, most europeans use WhatsApp anyway. Or we know where WhatsApp sends back ups to, totally unencrypted.
So what do we have. TG chats not encrypted by default, Signal works fine to the best of my knowledge. But with physical access to devices MAC with file vault off and most windows machines, its lights out right away.
18 comments
[ 1.9 ms ] story [ 35.5 ms ] threadWho proposes it and drives it and lobbies for it? It doesn't come from nowhere.
How is it possible that after years of discussing plans like this, they still managed to not listen to anyone who knows anything about encryption and online safety?
Makes me really worried about the future. There is a lot going on in the world, and somehow they feel the need to focus on making our communications unsafe and basically getting rid of online privacy.
The goal they are trying to achieve is good, but the execution is just stupid and will make everyone, including and maybe especially the people they want to protect, less safe online.
The age verification thing is another example. All it does is send a lot of sensitive traffic over cheap or free VPN's (that might be controlled by foreign states). Great job, great win for safety!
> "We must break with the totally erroneous perception that it is everyone's civil liberty to communicate on encrypted messaging services."
> Share your thoughts via https://fightchatcontrol.eu/, or to jm@jm.dk directly.
https://mastodon.social/@chatcontrol/115204439983078498
At what level would you need to do that? E.g. for iOS and then iOS need to comply with every app store app having it or else they can't operate in the EU? Is that the plan?
If you expect hostile action by Google you should also expect the rootkit that is google play services to also do that. Which means in both cases the solution would be to use a actual open source mobile OS based on AOSP.
But there are a few people asking who is pushing for this legislation so hard. That's mostly police forces who are pointing out that they're unable to track the activities of criminal organisations. For example, in the UK sophisticated gangs steal cars and phones and ship them around the world where they're resold. They locate a buyer anywhere in the world who requests a specific car, find that car, steal it and have it in a shipping container within 24 hours. It's impossible to know who's done it, or track any of the communications involved.
In previous eras it wasn't possible to create international criminal organisations of this level of sophistication because it was harder to communicate securely. Now it's possible and we all pay the price of increased criminal activity. Everyone's insurance premiums go up, making everyone poorer. UK car insurance premiums are up 82% between 2021 and 2024 and insurance providers are still making a loss.
Just to drive this point home - watch/rewatch The Wire (2002-08), except make it impossible to tap the communications of the drug gangs because they're all using encrypted messengers with disappearing messages. Immediately the people running the organisation become untouchable. The police likely can't even figure out who the lieutenants are, let alone the kingpin. At best you can arrest a few street level dealers and that hardly disrupts the criminals at all.
On HN everyone is going to say "everyone has a right to private communication, even criminal empires". And sure, I'm not going to disagree. I'm merely pointing out that private communication allows criminal networks to be much larger, more effective and harder to disrupt. And all of society pays the price when we're victimised by criminals.
Edit: I'm not saying breaking encryption is a good thing or that it will work, I'm only pointing out why police forces want access to communication records. They're unable to do their jobs and are being blamed for the rise in crime. To prove that you've actually read my comment till the end, please mention banana in your comment.
Disgusting pigs.
I am in a group of high civil servants for digital services in France and strangely no one seems to have heard about the project despite these people drafting most of France's position on numeric policies.
My view is it is probably more about mass control (avoiding a movement like Gilets Jaunes and the like) than anything else.
Tic, tac, tic, tac, tic, tac...
Mark my words.
https://youtube.com/shorts/33Cm88Dazoo?si=Eb1CfOZB6Ri34Dov
They could just ask Meta, most europeans use WhatsApp anyway. Or we know where WhatsApp sends back ups to, totally unencrypted.
So what do we have. TG chats not encrypted by default, Signal works fine to the best of my knowledge. But with physical access to devices MAC with file vault off and most windows machines, its lights out right away.