The Chat Control 1.0 rule is simply that organisations like Meta are allowed to scan messages if they want to. In other words your Facebook messages are not private from Facebook. Surely we already knew and expected that.
Chat Control 2.0 is the worrying one because it mandates scanning and bans E2EE.
These two things should not have both been given the same branding.
> The Chat Control 1.0 rule is simply that organisations like Meta are allowed to scan messages if they want to. In other words your Facebook messages are not private from Facebook. Surely we already knew and expected that.
Actually, I would expect the EU to limit the ways in which these platforms can access private messages as much as technically possible. That's the only thing that would be in line with recent privacy legislation.
The Internet Watch Foundation, an organisation funded by almost all of big tech, is already at work pushing for client side scanning next [1], for the children, of course.
lol, say someone publishes an E2E distributed extension to an existing chat protocol.
Are you going to arrest someone for writing code? Are you going to arrest people who use private communications? Sounds like a legislator carve out hot and ready to happen.
I get the point, ban E2E, OK sure, but what if some software is designed in such a way that the company doesn't provide it, but it just happens to be compatible with the protocol extension? Are you going to arrest the authors if they don't explicitly ban it?
This is about 1.0, which sounds ok - it basically allows providers a legitimate exception from data privacy laws to scan for CSAM in not E2EE communications. I reckon gmail, iCloud mail and the like already scan attachments for malware and emails for phishing scams, now they can also scan for child abuse.
Can anyone explain something? Since there are so many open source chat applications, what keeps anyone from "just" exchanging a key with someone else out of band, and then modifying the client so that it uses that key to encrypt all communication? I understand that this does not scale to big groups, but surely whoever is pushing this crap must have thought about this? Or is the idea that we will have completely locked down PCs as well ala android and ios so you can't run anything unapproved?
What is the US legislation on this - I thought providers were already mandated to take action against distribution of CSAM, or is that only for public-facing posts?
They won't scan my messages since I run my own XMPP server and clients using only free software - prosody for the server, Conversations/dino/gajim/converse.js for the clients. OMEMO (the encryption scheme used by 'modern' XMPP systems) uses the same double-ratchet encryption as Signal without the dependency on a central Signal server.
Prosody can run on just about anything and is mostly maintenance-free, give it a try I'd say. You'll want to get a domain for it but that's easy and cheap.
Of course they are. They will boil the frogs slowly until they get the frog soup they so desire. Each time the water gets a little bit too hot (public outrage) they will turn it back down for a bit.
Every major global region has this problem. I would tell you the slope is slippery, but I already fell down and cracked my head open.
Joking aside, this privacy invasion will keep happening until there are laws passed (a foundational constitution perhaps?) that make it impossible to attempt to even create such laws/rules.
23 comments
[ 2.9 ms ] story [ 146 ms ] threadChat Control 2.0 is the worrying one because it mandates scanning and bans E2EE.
These two things should not have both been given the same branding.
Actually, I would expect the EU to limit the ways in which these platforms can access private messages as much as technically possible. That's the only thing that would be in line with recent privacy legislation.
On the other, they need access to all of your data.
[1] https://www.iwf.org.uk/policy-work/preventing-the-upload-of-...
Are you going to arrest someone for writing code? Are you going to arrest people who use private communications? Sounds like a legislator carve out hot and ready to happen.
I get the point, ban E2E, OK sure, but what if some software is designed in such a way that the company doesn't provide it, but it just happens to be compatible with the protocol extension? Are you going to arrest the authors if they don't explicitly ban it?
Yeah, right.
cc 2.0 is a different beast.
Prosody can run on just about anything and is mostly maintenance-free, give it a try I'd say. You'll want to get a domain for it but that's easy and cheap.
Every major global region has this problem. I would tell you the slope is slippery, but I already fell down and cracked my head open.
Joking aside, this privacy invasion will keep happening until there are laws passed (a foundational constitution perhaps?) that make it impossible to attempt to even create such laws/rules.