16 ms·
The latest EU plan to outlaw encryption and introduce communication surveillance
- d--b 5y agoHonest comment: I thought the UK was pushing these kind of laws to the EU. I am actually surprised that the effort is still there after Brexit.
- foepys 5y agoSadly Germany, a country that should know how bad it is to have the government have access to everything, is pushing for this. Just about 32 years ago the Berlin Wall fell and shortly after the Stasi files were proudly presented as an example of tyranny. Now the German government wants to do the same.
- deleted 5y ago[deleted]
- RealStickman_ 5y agoHistory is the story of how humans never learn from history.
- AnssiH 5y agoThere are lots of people in the various institutions of EU, some are bound to support mandatory CSAM screening. But I very much doubt actual such legislation will get enacted. There is not even an actual proposal yet, only articles like this saying one is coming soon. We do know CSAM screening legislation is coming as the current voluntary rules have a 3-year time limit - but it is, in my opinion, very unlikely there will be mandatory screening, despite some people reportedly pushing for it.
- joconde 5y agoFrench intelligence agencies pushed some domestic legislation to let "black boxes" (the media's word) designed by them have access to telecom networks a few years ago. I think it passed.
- deleted 5y ago[deleted]
- Shadonototra 5y agoit's essential for security to the people who complain, we didn't hear you when the US kept (is still is) massively tracking you and let's not talk about all free apps on your favorite smartphone, they track you to death but who cares, nobody should track me for everyone safety! only for everyone's lack of privacy!
- jacquesm 5y agoIt actually isn't. What is needed for security is better humint, better sigint only increases the stack of hay that the same number of needles has to hide in. Note that in a very large number of terrorist attacks the knowledge was already available, but it either wasn't acted on, communicated improperly, not given enough urgency or lost because too much time was spent looking at spurious signals. Every time the amount of information available goes up that last factor will grow. Signal vs noise is the main contributor in why 9/11 happened, and the same goes for a lot of other terror attacks as well. But that sort of admission requires a complete review of how this is all practiced, would require an end to the security theater and would cut a whole lot of pork. I'm somewhat skeptical that this will happen. But more security theater moves to appease Joe Public and look tough, of course.
- Shadonototra 5y ago> Signal vs noise is the main contributor in why 9/11 happened 9/11 happened because they let it happen Jets would come at you if you flew over cities without permissions Why do we encrypt things in the first place? because lack of trust Maybe let's fix that instead of expecting society should lack "trust" between actors
- deleted 5y ago[deleted]
- jacquesm 5y ago> 9/11 happened because they let it happen Respectfully, you're nuts.
- stavros 5y agoI don't understand how the same institutions can come out with something as good as the GDPR and as bad as this bullshit. It's very tiring to have to fight against these things all the time, and it feels like our concerns aren't being heard.
- turbinerneiter 5y agoThey are just going to try over and over again, until there is Olympic games or a football Worldcup to distract the people.
- brewdad 5y agoGuess what's coming in 2022?
- AlexanderDhoore 5y agoIt feels like that because "our concern" ARE NOT being heard. The privacy concerns voiced on HN are far removed from what the voting population here (Belgium) thinks. Most people don't mind surveillance "because they aren't doing anything wrong". You have to put in a lot of EFFORT to explain it to them. "First they came for the socialists..." and all that.
- stavros 5y agoYeah, unfortunately that is a big problem. People don't care about privacy until it affects them, but then it's too late.
- 1cvmask 5y agoYou think GDPR is good? It entrenches the monopolies of the Googles and makes it harder for a startup in a garage in Berlin. - I am sure there are some people who clearly enjoy pressing on the cookie popups when they travel to Europe like popping zits. Maybe it is the Eurocrats in Brussels.
- jacquesm 5y ago
- 1cvmask 5y agoBig difference between de jure and de facto. We already have de facto surveillance in the US and the 5 eyes jurisdictions. Some of the other EU countries are also in on it. They just want to add a de jure veneer to it. For de facto leadership follow the US example. For de jure leadership follow the Australian/Chinese model.
- GekkePrutser 5y agoThere is a big difference. The secret surveillance can't be used in a normal court of law. Especially here in Europe as we don't have secret courts. But there is another big difference: Currently services they can't tap into will be forced to make arrangements for this to be possible. Not sure how they will do this with the more decentralised platforms like Matrix but they will probably find a way :(
- decebalus1 5y ago> The secret surveillance can't be used in a normal court of law. Especially here in Europe as we don't have secret courts. You don't have secret courts.. yet. Anyway, it doesn't actually matter if you have secret courts or not, for high profile targets. The US has them and the US also has extradition treaties. And if you do have legislation against spying on your own citizens, your allies don't, they can do it for you and then share intelligence. This whole effort is to short-circuit all of that and streamline an existing process.
- GekkePrutser 5y agoI doubt it's really the high-profile targets they're after though. It sounds more like they want to make this the bread & butter of policing. Having an AI looking over our shoulders to see if we're up to anything bad. Of course not just the content of our conversations, but GPS locations etc. Basically like Apple was proposing but here they are already targeting a much wider range than just CSAM. Because if it was only the high-profile cases the intelligence services already have huge permissions in terms of hacking, infiltration etc.
- rrll22 5y agoTo be safer, I would rather have everyone tracked except me, because I know how to use encryption tools. If criminals want unencrypted communications, that's also their choice.
- fsflover 5y agoIf you're the only one using encryption, it should be very easy to target you.
- rrll22 5y agoMany keyboard apps can predict your next word. Download a matrix with 20k English words, showing the probabilities of each word. Arbitrarily choose the first word. Consider the most likely next 8 words for your current word and choose one of them in a way that encodes your 3 bits. Continue until all your data is encoded by groups of 3 bits.
- allyourbase64 5y agoWell, anyone can Base64 anything, and, what's underneath the Base 64 could be binary or ansi or utf-8 or anything. Or encrypted good if you have half a brain. So; Good luck with that. EDIT: Noone types the message-letters on a hooked-up machine. You prepare / encrypt the payload before you paste it onto the sending computer / device. Anything withing the Base 64 you paste into the message-field should be impenetrable.
- bko 5y agoI don't follow this closely but from headlines I've seen it appears as Europe goes after encryption more than the US. They also go pursue what many people consider "good" internet regulations as well, like right to be forgotten, and whatever the hell those cookie warnings are about. I can't help but to think they are two sides of the same coin. Meaning that consumer friendly internet regulations we can all more or less agree on (e.g. let me cancel subscription online), is very correlated to consumer hostile ones (e.g. banning encryption and restricting ISPs). Am I thinking about this wrong?
- Hamuko 5y agoMaybe the US doesn't need to break encryption after seemingly backdooring every major service in the world (PRISM, etc).
- colechristensen 5y agoThey do seem more willing to regulate indeed. Those regulations are to benefit different groups.
- nobodyandproud 5y agoWho benefits the mosts from end-to-end encryption? I feel journalists and in-hostile-nation citizens are a smokescreen for more monied interests.
- jacquesm 5y agoThere are some lawmakers that are a bit delusional in their thinking and they believe that 'if only they could read everybody's email, listen to every conversation and follow everybody's movements' that they could make a serious impact on crime and terrorism. They don't realize yet that Europe is part of the same universe as the rest of the planet and that we don't get to try legislate that Pi is 3 here in the same way that it didn't work in the US. Cryptography, in particular strong cryptography has become essential for business, a good chunk of our economy now has a cryptographic element to it. You can't expect that to survive without giving the baddies the same level of access that the government is demanding, besides that, the amount of noise they will have to deal with far outweighs any possible advantage. At best there will be some drop in crime because of people being more aware of the chance of being caught but in the past such differences did not seem to make much impact. People will do what they will do, irrespective of the chance of getting caught. All of these things are operating as points between two different extremes, the 'good balance' usually lies somewhere in the middle between the protection of rights on the one end and the ability of the authorities to do the jobs we entrust them with. A lot of these technical ideas originate from the perspective that if it can be automated it will be cheap and if it is cheap then they'll be able to fund it. Whereas good intelligence is super expensive, it requires boots on the ground in greater numbers than is currently possible within the budget constraints that there are. Europe is in this sense much more stingy than say the USA and that alone is a big driver behind all these digital tricks. Also: do note that this is a proposal.
- jacquesm 5y agoThis won't work for the same reason it didn't work last time (see: Clipper chip): you can't outlaw math. Phil Zimmermann showed this exhaustively, why the EU wants to ram their head into the same stone I do not know but the end result is quite predictable. Besides that, all they will end up with is more information on how to make chocolate cookies and who is sleeping with who, it won't tell them where the next terror attack is going to take place or who will do it.
- Barrin92 5y agoyou don't need to "outlaw math", you only need to increase the friction to the point where commercial providers can't provide encrypted services and 99.x% of people will comply. Not sure why people always bring this up like some gotcha.
- ChrisKnott 5y agoIt's kind of like thinking "you can't outlaw physics" is a genius retort to speed limits.
- jhkiehna 5y agoyet 99% of people break that speed limit regularly. We all know speed limit laws are less about public safety, and more about generating revenue for the state, at least in the US anyway. and 99.x% of people aren't engaging in sharing child porn anyway, it's the 0.1% of motivated criminals that will share encrypted files anyway, no matter what the law is. They will find ways around the law, they always do. This is a thinly veiled excuse to take basic human rights away from people.
- Sebb767 5y ago> We all know speed limit laws are less about public safety, and more about generating revenue for the state, at least in the US anyway. That's absolutely not true. Sure, some stretches are just to generate revenue, but that you're not allowed to go 200km/h through a city is not for revenue generation. It's also not given by common sense - the fact that you need to set the limit 20 lower than what's save should be plenty of evidence.
- analyte123 5y agoCan someone explain the legal structure under which the EU parliament can (according to this post) dictate laws for service providers inside all of the sovereign nations inside the EU? I would've thought that this was outside the scope of the EU -- is there some kind of "commerce clause" type loophole for this, or was power constitutionally transferred to the EU parliament at some point? If a member nation refused to obey an EU law (or whatever it is), what sort of punishment or sanction could be applied to them?
- ginko 5y agoThis proposed anti-encryption legislation by the European Commission comes from an initiative of the interior ministers of the European Council which is composed of the heads of the individual governments of the member states. It's the member nation's governments that want this, not the European Parliament. The EP has yet to vote on this.
- drumhead 5y agoI dont think the parliament by itself can set laws, it would need to be agreed to by the Councilof Ministers as well. So unless they're happy with it it wont happen. As for sanctions for not applying the law, fines, holding back of funds. If they dont apply the law or dont follow it they can be taken to the European court of justice. I dont think we've ever had a scenario where EU law has not been applied unless there was an opt out. We may see that tested soon, by Poland and Hungary though.
- telmo 5y ago> is there some kind of "commerce clause" type loophole for this The EU is not just a commercial organization. It is an actual political union. The English-speaking press tends to hate mentioning this, but it is the truth. The treaty of Lisbon says that the goal of the European Union is to create an "ever closer" union between the member states. Every member state signed up for this. > I would've thought that this was outside the scope of the EU Few things are outside the scope of the EU. > was power constitutionally transferred to the EU parliament at some point? It is a very complex topic, but the short answer is "yes". Member states agree to translate EU parliament decisions into national law at their own time. They have the ability to veto any initiative through other channels. > If a member nation refused to obey an EU law (or whatever it is), what sort of punishment or sanction could be applied to them? This things are usually dealt with through diplomacy. There is a lot of tolerance. Often nothing happens but many types of sanctions (usually economical) are possible.
- cblconfederate 5y agoAll this fuss just to catch a few terrorists and then release them again as has happened so many times.
- ffhhj 5y agoIf they catch all the Assange's that's worth for them. Terrorists aren't the real terror for the powerful.
- GekkePrutser 5y agoSadly we in Europe haven't had a lot of Assanges or Snowdens. I think this plays into the marketability of these proposals too. People think it's just the US doing it and it isn't so bad here.
- DeathArrow 5y agoMaybe it's time for the EU to end. Peoples of Europe are tired of EU beaurocrats eroding their rights and going against their interest. Or it's time for the EU to be reformed.
- speedgoose 5y agoThese tired people could perhaps start to vote instead of complaining.
- blibble 5y agoquite a few of us in the UK did indeed vote to enact change
- hexxagone 5y agoArguably the EU is enforcing the rights of their citizens more than in many other places (eg. GDPR). Ultimately the EU citizens should vote when there are parliament elections instead of complaining about the bureaucrats afterwards. Only 50% turnout last time.
- GekkePrutser 5y agoThis is true but our votes are so diluted. And there are almost no good choices anymore. Almost all major political parties have an open ear to lobbyists who are much better at influencing them than the public is. I still vote but I don't really see the point anymore either. The game seems rigged.
- heywherelogingo 5y agoThe EU's overbearing character has been visible for a long while. It is the primary reason I supported brexit. It is working towards turning the union into a single country, has bitten off more than it can chew, and is looking increasingly despotic and dystopian.
- telmo 5y agoI am a continental European and I have lived in the UK for some time. I always lived under the impression that the goal of the EU was to increase integration. I think the majority of continental Europeans feel the same and support this idea to some degree. I always felt that this was only news to the British. I also support brexit. I would prefer for the UK to be in the EU because it would make all of us stronger and closer, as I think we should be, but I have to accept that current UK culture is just not compatible with the European project. Good luck to my British friends, who I know see me as "foreigner". I don't see you as foreigner.
- biztos 5y ago> I think the majority of continental Europeans feel the same and support this idea to some degree. I guess that must be true of the political elite in the major (remaining) EU countries, or it wouldn't be the policy, right? But for, say, Hungary, where I have a lot of experience, I'm pretty sure basically nobody thinks "increasing integration" should be the goal. Well maybe some tiny minority who happen to work for the EU itself. The integration everyone cared about already happened, except for the currency integration which will never happen. (IMO good that it won't.) Now you have one side that would like to use the EU as a cudgel for rule-of-law questions but only without interrupting the flow of money; and another, more powerful side that uses the EU as a dog-whistle for nationalists as long as it doesn't interrupt the flow of money. I can't speak for "Europe" (neither can Brussels) but I know a lot of people in Germany who also think there has been quite enough integration already, thank you. Try ordering an espresso in Berlin without speaking English. (I neither supported nor opposed Brexit as I'm just a dirty foreigner in the EU either way, but I have sympathy for those who did so on principle.)
- bruce343434 5y agoAs an EU citizen what can I do about it? Patrick Breyer's last call to action about Chat Control lead to almost nothing: only the Netherlands and Germany voted against, and barely at that.
- AnssiH 5y agoIf an actual proposal comes out that would introduce mandatory screening, convince your representatives to vote against it. There is no such proposal as of yet. In my opinion, the last regulation applied in July 2021 was sound (final text: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32021R1232 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A...), allowing a 3-year extension to the existing practice of voluntary screening until a proper legislation can be finalized. Some would have wanted to completely disallow voluntary screening (which would have been the case had the regulation not been adopted, due to privacy law changes in Dec 2020), too, and I can understand that position. But that is seemingly not shared by European Parliament who voted to allow voluntary screening to continue (they did shorten the time period to 3 years from the original 5, though, by an amendment).
- megous 5y agoBan encryption.... hmm, that's certainly one way to get rid of cryptocurrency and solve those pesky ransomware attacks. Good! I didn't read past the title, so I may be wrong about the actual contents of the article.
- GekkePrutser 5y agoIt has absolutely nothing to do with cryptocurrency. And it's not exactly a ban either. It's about a mandatory backdoor in encrypted communication. Not that makes it any less bad but it's important to clarify. The title is not clear about this.
- jacquesm 5y ago> I didn't read past the title Then maybe you should?
- megous 5y agoIt would be more appealing if the title was not so alarmist. "Outlaw encryption" Really?
- Eithahm5Wi 5y agoI hope you're joking, Megi.
- vmoore 5y agoThis reads like a premature encryption death notice. Encryption isn't going away anytime soon. Ban encryption and you essentially ban using The Internet in any meaningful way. That said I don't trust Whatsapp to NOT read my messages since it's closed source, and there's no way of knowing if your messages are truly private & secure. GCHQ even proposed a 'ghost protocol'[0] so they can play Mallory in your comms. Infact I don't even trust the phone itself, since they /ship/ with Google/Apple-sponsored malware and phones are being hacked all the time. Messenger apps are strange because they all have different caveats to each, and I've tried them all. For example: Signal requires a phone number, which by design, can leak your 'meatspace' identity. Some people don't like that, so they use Matrix (which has its own caveats too). Personally, if the authorities go after messaging apps, it's not a big hit for me, since I don't use them heavily. I can see why businesses would take a hit since they want to protect business secrets, and protestors would take a hit & can't organize etc, but it won't affect me heavily. YMMV. [0] https://www.wsws.org/en/articles/2019/07/06/gchq-j06.html https://www.wsws.org/en/articles/2019/07/06/gchq-j06.html
- johnnyApplePRNG 5y agoIf there is a silver lining to this cryptocurrency madness, it could be that it's educating the public on just how great cryptography really is. These attempts at outlawing encryption of any form should be met with a lot more pushback from now on.
- progforlyfe 5y agoDoes this mean that one day https will not be allowed in the EU and companies will have to go back to supporting http?
- nextlevelwizard 5y agoWhy would it? It just means your cert store will soon have EU signed cert so they can decrypt your TLS connections
- pantulis 5y agoBeware, this comes from the guys that managed to put a freaking cookie layer on almost every website in the world.
- ben_w 5y agoI wish I knew how to make it plain to the politicians and law enforcement officials who ask for this why it must not happen. It would literally be less bad for all display and input devices to have a (password protected, randomly created at time of manufacture) police access mode, than to ban cryptography. I talked to my local MP about the UK’s Investigatory Powers Act when that came up. I still don’t understand why the UK decided to allow the Welsh Ambulance Service in particular to access, without a warrant, the recent “internet connection records” of everyone except sitting MPs and certain protected professions.
- catlikesshrimp 5y agoThen the database is leaked somehow. RIP privacy. Or your ex is a policeman. RIP life
- AnssiH 5y agoThere is no actual legal proposal at all to introduce mandatory screening (yet, anyway). In my opinion, such legislation would be unlikely to pass EU parliament. It is more likely that the current temporary rules allowing voluntary screening get reworked into a permanent legislative proposal. AFAIK the only relevant official procedure here is this initiative that sought feedback from affected parties (and it does not mention mandatory screening - instead it asked for opinions on what should be done): https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/12726-Fighting-child-sexual-abuse-detection-removal-and-reporting-of-illegal-content-online_en https://ec.europa.eu/info/law/better-regulation/have-your-sa...
- bruce343434 5y agoAre you in the know about the whole chat control fiasco? The legislation for non mandatory chat control/decryption is already there...
- AnssiH 5y agoI assume you mean Regulation (EU) 2021/1232 (legal text: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32021R1232 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A... , press release: https://www.europarl.europa.eu/news/en/press-room/20210701IPR07503/parliament-adopts-temporary-rules-to-detect-child-sexual-abuse-online https://www.europarl.europa.eu/news/en/press-room/20210701IP... ) that got approved in July this year. In my opinion it is not a fiasco at all. It simply allows the current pre-Dec-2020 practice of voluntary screening to continue for a limited period of 3 years (so they have time to get a proper permanent legislation in place). Privacy rules changed in Dec-2020 that made voluntary screening effectively illegal, hence the stopgap.
- pimterry 5y agoTo be clear - that previous legislation only legalizes in the EU the CSAM content scanning that online services were already doing (by their own choice) in the EU before GDPR, and which they're also doing everywhere else. It just avoids GDPR unintentionally making it illegal for service providers to scan for CSAM without opt-in user consent from every user involved, and only does so for a temporary period until legislation that formally defines service provider responsibilities is ready. Personally, I'm fine with that. I firmly agree that private E2E messaging should not be banned (the suggestion in this post, which as noted above is not currently a real proposal) but I don't think that means service providers should be forced to blindly host user data that may contain CSAM against their will.
- vegai_ 5y agoI think it's pretty naive to think that digital privacy allowing spreading of child sexual abuse material is going to be accepted in the long run. If we don't figure out a better answer to how we can have one without the other then we're gonna lose digital privacy.
- jonstaab 5y agoBecause the only way to fight slavery is with more slavery, obviously.
- deleted 5y ago[deleted]
- deleted 5y ago[deleted]
- sebow 5y agoPretty sure this was in Brussel's crosshair for years(as in 5+ years, to be precise). And no, the bureaucrats and politicians don't give a rat's ass about your privacy, security, or data.In the vast, vast majority of cases it's the opposite.GDPR was not only useless in protecting customer's data, it was actually used as a tracking mechanism, but don't let me spark your bubble. The EU should either reform or it will die off, and for good reasons.Obviously if the latter is to happen it will take at least a decade or two, but the cracks have begun to show frankly since it stopped being merely an economic union.
- kreeben 5y agoThis is a plan, not a law. It will never become law, because over my dead body. If it turns into law I'll stop going to work. If I do that the project I'm in will fail, followed by my team collapsing, followed by my whole office revolting, followed by my employer crashing, followed by several Swedish cities turning to the streets in anger, followed by the whole of Sweden disintegrating, followed by the whole of Europe proclaiming "our know-it-all moral compass is gone" followed by Europe wide collapse, then American collapse. Don't you worry for once second, peps, I got this. - Very powerful EU citizen
- _-david-_ 5y agoAre you being serious? If you stop working Europe and America will collapse? What happens if you get hit by a bus?
- 93po 5y agosounds like satire to the type of post you see on HN sometimes. people think because they made facebook for dogs and sold out for $50 million that the world revolves around them
- __turbobrew__ 5y agoThank you for your service
- deleted 5y ago[deleted]
- catlikesshrimp 5y agoThat's a very healthy amount of selfsteem. [Grabs needle] POP!!!
- moffkalast 5y agoI take it the whole corona thing happened because you got the flu sometime at the end of 2019?
- 5y ago
- albertopv 5y agoGDPR would be dead for me the instant this should became law.
- e0a74c 5y agoAnd Osama wins again.
- squarefoot 5y agoAny good cartoonists out there? We may soon need the EU equivalent of this: https://i.imgur.com/D93heEo.jpg https://i.imgur.com/D93heEo.jpg
- moffkalast 5y agoWe need it yesterday. Get someone on this, stat.
- motohagiography 5y agoIt clicked for me that the real danger posed by encryption to these governments is that it can guarantee truth. When everything is narrative, even something as simple as a commitment hash for a document removes discretion from the sovereign body because it encapsulates a non-repudiable truth. Irreversible processes (like blockchains) constrain the effect of rule by fiat. The people who write these censorship and anti-encryption regulations aren't worried about secrecy or even crime, violance, and abuse, they just fear being accountable to truth. The real danger of encryption, and in particular blockchains, is that it can subordinate the legitimacy of the state and its policies and actions to a test of truth, and this is why they hate it. The abuse and terrorism arguments are red herrings for this to distract from this fundamental dynamic.
- peter_retief 5y agoWhy does this sound like an unlikely development?
- 29athrowaway 5y agoThere will always be steganography. Hide information in things. Like the red channel of a specific section of a cat picture, in diagonal strides or something. Good luck finding that shit.
- no_wizard 5y agoI feel the EU has both good privacy things (GDPR was a good step forward, not perfect, but arguably good, forcing things like the right to be forgotten), and then they have these widely anti privacy ideas like the ones presented in this article. Why the disconnect? That's my fundamental question.
- detaro 5y agoDifferent political forces with different goals, and GDPR, targeting businesses, isn't fundamentally something the "more state surveillance" group had to prevent, even if they wouldn't have introduced it themselves. And the pro-surveillance push sadly is fairly endless, see also countries trying to introduce general recording of internet metadata despite the EU top court repeatedly having made clear that that's not going to be a thing that survives a legal challenge.
- aborsy 5y agoToo many bureaucrats, proposing too many things.
- dang 5y agoRecent and related: EU interior ministers welcome mandatory chat control for all smartphones - https://news.ycombinator.com/item?id=29200506 https://news.ycombinator.com/item?id=29200506 - Nov 2021 (59 comments) EU Chatcontrol 2.0 [video] - https://news.ycombinator.com/item?id=29066894 https://news.ycombinator.com/item?id=29066894 - Nov 2021 (197 comments) Previously: Messaging and chat control - https://news.ycombinator.com/item?id=28115343 https://news.ycombinator.com/item?id=28115343 - Aug 2021 (317 comments) EU Parliament approves mass surveillance of private communications - https://news.ycombinator.com/item?id=27759814 https://news.ycombinator.com/item?id=27759814 - July 2021 (11 comments) European Parliament approves mass surveillance of private communication - https://news.ycombinator.com/item?id=27753727 https://news.ycombinator.com/item?id=27753727 - July 2021 (415 comments) Indiscriminate messaging and chatcontrol: Last chance to protest - https://news.ycombinator.com/item?id=27736435 https://news.ycombinator.com/item?id=27736435 - July 2021 (104 comments) IT companies warn in open letter: EU wants to ban encryption - https://news.ycombinator.com/item?id=26825653 https://news.ycombinator.com/item?id=26825653 - April 2021 (217 comments) Others?
- zahllos 5y agoI did some digging, because every time I have heard of ChatControl I have seen all this talk about what the EU plans to do and no evidence. https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:52020DC0607&from=EN https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE... is the strategy document. So far, there is a temporary derogation from the ePrivacy Directive (https://www.europarl.europa.eu/RegData/docs_autres_institutions/commission_europeenne/com/2020/0568/COM_COM(2020)0568_EN.pdf https://www.europarl.europa.eu/RegData/docs_autres_instituti...). The ePrivacy directive as part of the EECC forbids (for the sake of discussion) email providers from scanning Maildirs, even if those maildirs are cleartext (as is the case for the majority of providers, s/Maildir/backend storage). The temporary derogation lets them scan for CSE in these sources. I don't see any proposed regulation explicitly targeting end-to-end encryption, but their strategy document does seem to label end-to-end as a problem, citing the NCMEC (US). The project is here: https://ec.europa.eu/info/law/better-regulation/have-your-say/initiatives/12726-Fighting-child-sexual-abuse-detection-removal-and-reporting-of-illegal-content-online_en https://ec.europa.eu/info/law/better-regulation/have-your-sa... .
- BTCOG 5y agoWe are globally quickly slipping down the slope into some disgusting hybrid of Huxley's Brave New World information inundation, and Orwell's 1984. Throw in there that humans are now able to own less and less each passing year. Who can say with certainty what the end goal is, but these things should not be playbooks!
- Nitramp 5y agoHere's a probably truly unpopular opinion: I think it's reasonable policy to enable police, after a judgement by an impartial judge, to surveil suspects, encryption or not. This has worked reasonably well for decades, in Europe's liberal democracies, for pain old telephone, mail, searching apartments, etc. Yes, there have been mistakes and failings, but by and large this system works, and prevents substantial harm. These powers need an actually independent judiciary in a strong legal system (ie. not the us). And they need to be kept out of the hands of secret services (as opposed to genuine police work overseen by judges in the public record).
- jaywalk 5y agoThe point that people are trying to make is not that surveillance itself needs to be banned. I think any reasonable person can see that there are circumstances where it's necessary. The issue is specifically with backdooring encryption to enable surveillance. You're basically describing some magical fantasy land where the ability to utilize the backdoor could be restricted to "genuine police work" by the legal system. Here in reality, we have to acknowledge that it's impossible to do that.
- delusional 5y agoDoes anyone here actually read the resolution before they go claim that the EU is "outlawing math". This is about punching very small and specific holes in the GDPR to allow service providers to scan for CSAM. It does not make it illegal to create technology that can't be intercepted. It removes the excuse that you can't provide the government with data because that would be violating GDPR. Additionally, service providers MUST inform you that you they have scanned your data for CSAM: "Service providers should inform users in a clear, prominent and comprehensible way that they have invoked the exemption provided for in the Regulation"