24 ms·
The EU Commission accepts high error rates when checking chats
- Neil44 4y agoI think what makes false positives scary in this context is that accusation is guilt for most practical purposes. There needs to be a tremendous ammount of openness around systems like this so that people understand the meaning of it's outputs.
- ho_schi 4y agoThe commission does not seek to break encryption Okay. Encryption is not only important to protect private communication, but would also help perpetrators/criminals No. It is there to protect us from perpetrators, criminals and all the people which think they are on the good side. The road to hell is paved with good intentions. Authoritarian regimes on our planet always thought they were the "good guys". Encryption is actually there to protect us from you! The mothers and fathers of the German Grundgesetz (~ constitution) learned that the hard way. https://www.gesetze-im-internet.de/gg/art_10.html https://www.gesetze-im-internet.de/gg/art_10.html
- medv 4y agoWell. Nothing is just white or black.
- mayoi 4y agoThat's right, everything is gray and black instead.
- moffkalast 4y agoSome of it is a weird shade of red.
- 7373737373 4y agoThey are traitors against the spirit of the constitution. Article 10 of the Basic Law: (1) The privacy of correspondence, posts and telecommunications shall be inviolable.
- pantalaimon 4y agoWell there is also (2) Restriction to this are only permitted if required by law. Which is used to force postal operators to report and investigate suspicious letters that might contain drugs.
- djbebs 4y agoYeah I always laugh at those clauses that totally override all that came before
- ho_schi 4y agoBefore I miss it. Here are the "good guys" at work (paywall): https://www.nytimes.com/2022/08/21/technology/google-surveillance-toddler-photo.html https://www.nytimes.com/2022/08/21/technology/google-surveil... We can see "AI" at work. And even if a human checks it you are doomed, because you don't fit in the business plan. Therefore never upload private data on a strangers computer. The cloud is by definition a strangers computer! It is nice that you can find your lost phone with their website but you shall not store any private data on the computer of someone else. If you want keep data in sync across multiple devices multiple providers providers and tools allow for that: * https://syncthing.net/ (recommend: everyone) * https://git-scm.com/ (recommend: it-professionals) * https://mailbox.org (recommend: everyone, including mail, calendar, contacts, notes) * https://posteo.de/ (see above) * https://nextcloud.com (recommend: hobby and it-professionals) The situation changes somewhat if you pay with money for service instead with data. Now you are the customer and not the people working with your data. Shared-Hosting usually comes with readily usable E-Mail and other stuff, sometimes with automatic setup of nextcloud or similiar. Does someone have recommendations for US based E-Mail providers which are reliable and "not free"?
- mayoi 4y ago> Does someone have recommendations for US based E-Mail providers which are reliable and "not free"? Buy a refurbished server rack and mount it anywhere in US, install and configure email software with everything else that you need. > The situation changes somewhat if you pay with money for service instead with data Yeah, now company is profiting not only from your data, but from your bank account aswell, that's the difference.
- jaywalk 4y ago> > Does someone have recommendations for US based E-Mail providers which are reliable and "not free"? > Buy a refurbished server rack and mount it anywhere in US Not anywhere. You won't get very far trying to host an email server on a residential Internet connection.
- 4y ago
- capableweb 4y agoI'm for E2E encryption wherever it's applicable, and for individuals having the ability to be fully anonymous online, but it's not useful to claim it doesn't have drawbacks as well. Yes, it's true that it might it harder to arrest criminals because of encryption, but the alternative that nothing can be 100% private is so much worse.
- Aeolun 4y agoIt was hard to arrest criminals before digital communication as well, I’m sure we’ll deal.
- sofixa 4y agoBut each improvement in communications tech (landlines, mobile phones, internet) have enabled new, faster, easier, better communication methods. Medieval criminals would have to physically meet to coordinate a coach robbery; nowadays a terrorist attack can be coordinated fully remotely and anonymously. There is no point in denying the facts - that encryption and the ease of use of the Internet enable criminals to coordinate more easily. Sweeping it under the rug won't change it, and it will be a part in the reasoning for limiting encryption. It should be fought with numbers and the gravity and the tradeoffs, not "people used to be able to communicate with pidgeons so there is no issue here".
- nix23 4y agoEncrytion was used since forever and birds as a fast transportation too. Nothing changed. And btw if i where a terrorist i would use birds to communicate. What do we learn? Criminals will always find a way, instantly.
- tetris11 4y agoCan't the authorities do what they've always done since time immemorial: monitor these activities from afar (without needing to know specifically what was said), and plant people in these organizations. Compromising everyone's security to target a few seems backwards.
- mrtksn 4y agoWell, encryption is in fact used by offensive military forces too so it definitely can be a part of the "bad guys" arsenal but I don't think this is the real motivation behind the push for breaking encryption. It's not just EU but UK, USA, China and every single entity that collects intelligence for their goals. They all would love to have encryption braked in their favor because we created vast communication networks with enormous data stored that can be reached at instant but they can't reach those due to encryption. Consider that you are in charge of defending your community against straight out criminals and foreign influence or actors who have other goals than you do. How amazing would be for you to be able to check out each and every citizen or each and every device relevant to you at click of a button, right? It's the ultimate society debugger, you will be able to do your job so much more easily. The problem with that is, we as a society, don't have a definitive good or bad or truth or allies or enemies and we constantly change our minds on all these things and this is not a bug but a feature. Let's say some kind of anomaly happens and the encryption is removed and government officials have total access and none of them are corrupt and they do their jobs perfectly. Instantly you removed progress in the society and everything will stay the way it is, good luck if you are on the wrong side of things because the only way anything changes from now on will be possible only through discussion from within the community of those who happened to be in control when the encryption no longer worked. I don't want this to happen because I don't live in country where the mainstream policies are aligned with my ideas on how the world should work. What about criminals you say? Well, catch them through police work and other means - it doesn't have to be completely effortless for you to do your job.
- HeckFeck 4y agohttps://www.youtube.com/watch?v=zgsQNNYurWo https://www.youtube.com/watch?v=zgsQNNYurWo Demolition Man called this. How did the police catch criminals before bio-engineered trackers were attached to every citizen? "We worked for a living, this fascist crap makes me want to puke".
- hn_throwaway_69 4y ago>No. Assume for sake of argument that it were possible to develop an encryption regime which protected bona fide users, but did not protect criminals. That would be a good thing. As a matter of public policy, criminals shouldn't be given the right to communicate for the sake of furthering criminal activity without the possibility of lawful interception. It's here that some technologists lose sight of the real world. In the real world, society expects that authorities be able to fight crime using proportionate means. The real issue is that you can't separate the two from each other - weakening encryption for criminals means weakening it for everyone.
- etherael 4y agoYou sure you want to deprive anybody who has ever been allocated the tag "criminal" the right to private communications? You might want to think long and hard about the members of that class, and what fate they are subject to when they are laid bound at the feet of their prosecutors in the state, who were also the party responsible for defining who they are, sometimes for no offense more complex or voluntary than being born. And then if that still doesn't dissuade you, you want to think again even from a position of pure self interest, because you are very likely technically a criminal yourself. (https://www.amazon.com/Three-Felonies-Day-Target-Innocent/dp/1594032556/ref=sr_1_1?ie=UTF8&s=books&qid=1279295536&sr=8-1 https://www.amazon.com/Three-Felonies-Day-Target-Innocent/dp...) Be very, very careful about handing power to the state, there's a reason they're the largest cause of non natural death in the past century, and it's not their innate benevolence.
- nix23 4y agoExellent idea. We make a socialscore-system and just people above a certain score can buy stuff with working encrytion.
- megous 4y agoThere is a possibility of lawful interception at the endpoints of the end-to-end encryption. Does it mean the problem is solved?
- Mordisquitos 4y ago> Assume for sake of argument that it were possible to develop an encryption regime which protected bona fide users, but did not protect criminals. That would be a good thing. [...] The real issue is that you can't separate the two from each other - weakening encryption for criminals means weakening it for everyone. Even if such a hypothetical encryption scheme was not intrinsically weaker, it still requires two very strong assumptions: 1. Not a single individual with legal access to the interception system will ever abuse it for their own purposes, or in exchange for a significant bribe or under the threat of blackmail from a powerful and wealthy malignant actor. 2. A future government (democratically elected or not) will never decide that currently legal behaviour is now a crime which warrants interception—say possession of drugs for personal use, "deviant" sex, unpatriotic discourse, etc.
- pelasaco 4y ago> The mothers and fathers of the German Grundgesetz (~ constitution) learned that the hard way. > https://www.gesetze-im-internet.de/gg/art_10.html https://www.gesetze-im-internet.de/gg/art_10.html Weren't we Germans calling out Poland, because they decided that national law can take precedence over EU law? So I guess our GG < EU Law.
- Joker_vD 4y agoThat's different, you got to understand. /s
- pelasaco 4y agoThe kids must be protected /s
- rndgermandude 4y agoNo
- pelasaco 4y agoYes https://www.reuters.com/world/europe/france-germany-say-poland-must-abide-by-eu-rules-2021-10-08/ https://www.reuters.com/world/europe/france-germany-say-pola...
- fnord123 4y ago>The mothers and fathers of the German Grundgesetz (~ constitution) learned that the hard way. Well, now we can counter "Think of the children" with "Think of the Ukrainians"
- rjzzleep 4y ago
- leodriesch 4y ago> It specifically prohibits discrimination and welcomes people from other nations, both of which the average German does not actually like That’s an absolutely wild claim and I’d like to know where you got this impression from.
- jeofken 4y agoHave you ever seen a poll of a European country where people wanted more immigration (from the 3rd world)?
- mercy_dude 4y agoI am as sympathetic to the Germans who dont want racial diversity and as anti globalist as it gets. But here is the counter argument. Europe (if you don’t take the Slavs and the albenians into account) has a negative birth rate. There is no way to sustain current standard of living without immigration. The politicians in Bundestag who control the EU knows that. And if there is one thing that they are afraid of is to encounter the shortage of labour and have to increase wages that comes from that. As the crisis from Covid has shown us. I think the root cause of the decline of the national and cultural identity of Europe is not because of immigration but because of a local population that has mostly no interest in family formation.
- davidro80 4y ago
- FpUser 4y ago>"but because of a local population that has mostly no interest in family formation" I am in Canada so do not know what the trends are in Europe but I can clearly see that having kids here is quickly becoming a financial burden many people can not afford. Part of it because people want higher living standard while the other is our fucking politicians creating such conditions.
- peoplefromibiza 4y ago> The mothers and fathers of the German Grundgesetz (~ constitution) learned that the hard way repetita iuvant: secrecy is not privacy. encryption makes conversation private but not totally secret, WhatsApp knows if I write to the person named "dentist" on my address book only when the phone number connected to "wife" is out of town. Or if I dial the number of a tow truck service at 4 am after my phone has been for hours inside a club and my CC was used to pay for half a dozen alcoholic drinks. that's more than enough to imply what everyone is implying by reading this. no need to know the content. on that matter cheating was easier and safer before encryption was a common thing, nobody actually listened to our calls, and we did not leave around clues strong enough to rebuild our entire life in exchange for a messaging platform. Secondly, that article clearly states, as any other deliberation of the EU, that the law can override the right to secrecy and that's what happens all the time: the authorities ask the permission to a judge that can grant it or deny it. It's not like the CIA that breaks your SSL certs and wiretaps on your communications without asking anyone if they can or cannot.
- jaywalk 4y ago> It's not like the CIA that breaks your SSL certs and wiretaps on your communications without asking anyone if they can or cannot. It's absolutely hilarious that you believe America is the only country that does this.
- peoplefromibiza 4y ago> It's absolutely hilarious that you believe America is the only country that does this. where did I say it's the only one? But would you deny that its the one spending more on it and with the most advanced technologies to do it? I don't know many other "free" countries that spied the political leaders of allied Nations.
- Amezarak 4y agoEvery country spies on their nominal allies. That part is not unusual or unexpected and has a long historical tradition. You can find story after story on this. “Allies” are only allies for reasons of national interest, not because they are genuinely friends, whatever that would mean between countries. Of course, there’s still outrage when they get caught. Here, for example, is Germany being outraged that the US spied on them. [1] And here’s Germany spying on France [2]. But they all know it’s going on. And here’s a good quote from French intelligence: > “If Hollande was genuinely shocked by these allegations, that would mean he wasn’t aware that this kind of thing is normal,” he said. “But of course he is aware. Hollande has to satisfy the feelings of the general public by expressing some indignation, but the truth is all countries spy on their friends and the only limitation is the means at their disposal. [1] https://www.cnn.com/2021/05/31/europe/denmark-us-nsa-merkel-spying-intl/index.html https://www.cnn.com/2021/05/31/europe/denmark-us-nsa-merkel-... [2] https://www.france24.com/en/20151113-germany-spying-france-hollande-merkel-no-surprise https://www.france24.com/en/20151113-germany-spying-france-h...
- ben_w 4y ago> > Encryption is not only important to protect private communication, but would also help perpetrators/criminals > No. Without going into whatever context the original quote has: doch — encryption does both. There is no technology so pure it only helps the "good guys", from fire to firearms[0] there are things we can't possibly survive without, and yet criminals can use them for crimes. I don't know the best way to handle this with crypto, mainly because the problem is much deeper than the crypto itself: even if absolutely everyone without exception or equivocation agrees everyone gets unbreakable cryptography, it is getting ever easier to just spy directly — laser microphones on drones, using software to repurpose a WiFi antenna as a wall-penetrating radar, IR cameras, using AI for gaze detection and 3D scene reconstruction to figure out who (or what) you were looking at when you blushed — that's all coming to a blackmailer near you. (Caveat: fake images and potentially at some point 3D bioprinted fake bodies will make the evidence invalid in courts of law, but that's a whole different discussion). The only thing I can even think to suggest is a radical liberalisation of almost every law and punishment such that we can as a society survive when everyone's crimes, misdemeanours, and administrative infractions/regulatory offences are cataloged and dealt with in real time. The only thing I am sure of is that the future can't look anything like the examples from history — while it might be much better or much worse, it won't be even close to the same. [0] I don't mean in the American 2nd amendment sense though, I mean an army with no firearms will loose to one that has them.
- coldtea 4y ago>Without going into whatever context the original quote has: doch — encryption does both. There is no technology so pure it only helps the "good guys", from fire to firearms[0] there are things we can't possibly survive without, and yet criminals can use them for crimes. So? Cars also help the bad guys escape from robberies faster, but we don't seem to ban those... Not to mention knives... those can be deadly if somebody stubs you with one. And what about clothes? Naked criminals would be much less effective... The thing is anything can assist criminals. Why single out encryption (besides the government wanting to snoop at will)?
- ccvannorman 4y ago
- PurpleRamen 4y agoPretty hard joke to point at the German constitution, after it displayed it hard failing in the last years. Protection from bad state-actors is necessary, but not for the price to also expose the citizens to non-state bad actors. Protecting the citizens is also a state's job, and somewhere they need to find balance between the different protections.
- deleted 4y ago[deleted]
- seper8 4y agoDisgusting. Wonder if people working on these commissions ever consider the thought that they are "the baddies". In any case, the gestapo would have _loved_ this service.
- mayoi 4y agoI know a few, and these people genuinely and completely unironically without a doubt in their mind consider that they're doing the right thing for the greater good of humanity.
- bruce343434 4y agoThat's scary. Where to even begin to convince them?
- mayoi 4y agoYou cannot. If you need proof to convince you, really look into any revolution that ever happened in human history. It was always the <10%, both on the bad and the good side who did them, while everyone else watched and did nothing - the same people you'd try to convince. The reality is that most people will go wherever life sends them, if their country turns into utopia, they'll think "that's cool I guess", and if it turns into dystopia, they'll only think "that sucks but what can I do anyway", but in neither scenario will they ever do anything themselves. If nothing more, there's a few words for people who are aware of this and actually do something about it, you can read all about them by looking up news articles containing words like "Terrorist", "Public enemy", "Anarchist". In some cases it is thinly veiled in unrelated words like "Nazi" even though if you really think about it, the problem with "Nazis", whatever that even means today, was fascism, same fascism that you're dealing with right now, but it's totally not fascism however because fascism requires Hitler, and trains, and uh, public shootings or something.
- pushkine 4y agoThere's actually a way (though it won't happen). Setting up a system that invades privacy to catch crimes is bad because once you have that system, all you need is for your government to criminalize good things to reach a dystopia. In order to avoid that, you'd have to actually run that dystopia, but dramatically and at a small scale. A great example could be a US state where abortion is illegal and gives actual jail time (I think that's a thing, not sure). You have one of those states put into law that online services must scan for the word "abort" then actually find and put women that had illegal abortions to jail over this. If you did that, you might get the congress to make digital privacy a protected right at the national level.
- altacc 4y agoDue to the volume of messages and the endless need to maximise profits, companies will accept 10% flagged content may be false positives but act against all 100% of flagged content, meaning that the default will be innocent people having action taken against them but with no real recourse to clear their name. I also didn't find anything in there about expectations for reducing numbers of false negatives (where automation fails to flag suspicious activity). Content control is basically just PR if it ignores the majority of activity it is designed to police.
- mayoi 4y agoNot just will have action taken against them, they already are: https://archive.ph/W41mf https://archive.ph/W41mf
- coffeeling 4y agoAnd in typical Google fashion, you get flatlined and there will be no recourse. > “You have to talk to Google,” Mr. Hillard said One of the most impossible feats in the modern world.
- MonkeyMalarky 4y agoDoesn't the system eat itself in the end? False flag 10%, remove those users, falsely flag some more, remove them, and so on until all that's left are people who don't use it or just send pictures of their food?
- llampx 4y agoWhere will those flagged users go? The point of FAANG is that they are monopolies.
- MonkeyMalarky 4y agoOffline? If the system is as automated and un-appealable as the doom posters are saying, their lives are ruined and they're banned from those platforms forever.
- seper8 4y agoIf this ever gets into production I hope the tech community can come together and work on a system to generate false positives until this system is no longer viable. Let's hope its a typical EU project and will take at least a decade to complete, or better, let's just hope it will outright fail.
- jand 4y agoWhile i get the sentiment, you should check the mentioned penalties for abusing the system (once known) before jumping to action.
- mayoi 4y agoI guess everyone should just check the penalties for committing crimes before assuming that crime is real...
- LeeroyWasHere 4y agoThat works so well with DMCA, no one ever abused it and it hasn't negatively impacted the lively hood of anyone.
- immibis 4y agoAnd in particular, Google totally doesn't have a special business relationship with RT to allow RT to ignore the DMCA on their disinfo.
- prlmer 4y ago
- mayoi 4y ago
- 4y ago
- sparsely 4y agoNo comment on the policy etc, but I think the presentation of the numbers is a bit misleading. That 10% is the percent of flagged images which are actually OK. Whether this represents a large fraction of all legal content depends on how much illegal content there is. It would be better if they quoted the false positive rate and false negative rate as a fraction of legal/illegal images respectively. e.g. if 1/100,000,000 legal images are flagged incorrectly, and 100% of illegal images are flagged correctly, then a corpus of 100,000,000 legal images + 9 illegal images would result in the stats in the headline. That seems like a pretty good system (ignoring any principled objections to the scanning in the first place).
- Retr0id 4y ago10% of all OK images may be falsely flagged, but what about specific categories of images? What would the error rate be for an album of legal pornography? What would the error rate be for an album of a family spending the day at a beach?
- sparsely 4y ago> 10% of all OK images may be falsely flagged, but what about specific categories of images? The article doesn't say what % of OK images are falsely flagged, only what percent of flagged images are OK. Agree that subsets might have different stats, but there's 0 information in the featured article about any of that!
- Retr0id 4y agoAh, I see what you mean.
- kmeisthax 4y agoThe (false negative) error rate on a parent taking pictures of an unusual growth on their child's naughty bits and texting it to their doctor is 0% - as in, the algorithm correctly identifies this as CSAM every time. Nevertheless, nobody[0] would consider this CSAM, based purely on context that... absolutely will not be available to any of the intermediaries charged with scanning for it. What system does the scanning won't matter, because it's not a question of accuracy; it's a question of missing information. This isn't even a hypothetical. The case I mentioned above actually happened. Google narc'd on someone who did exactly the thing I mentioned, and they got a police investigation for their trouble. And while the police - armed with exhonorating context - did eventually drop charges, they are still banned from Google for life. Yes, Google was contacted by journalists about this guy and they said they stand by their initial decision to permaban him. The core danger with any automated scanning system is not the false positive or false negative rate - that is an engineering problem. It will get better. The danger is the amount of legal-but-crime-adjacent activities that will be effectively prosecuted as crimes. I mentioned child telehealth above, but there's other instances of automated prosecution expanding far beyond the letter or spirit of the law. YouTube Content ID is top-of-mind for me; though that has two problems. It both kills fair use, and correctly prosecutes copyright infringements that people expect to fly under the radar. [0] Child anti-explotation agencies still caution against this because they don't want your kid to get used to getting photographed down there. However, they wouldn't consider this sexual abuse.
- isaacfrond 4y agoWith 90% accuracy, and assuming the incidence of true grooming in random conversation is way smaller, they are setting themselves up for the base rate fallacy. https://en.wikipedia.org/wiki/Base_rate_fallacy https://en.wikipedia.org/wiki/Base_rate_fallacy
- contravariant 4y agoAt this point I wonder if that's by design, they ask for a random 10% of conversations in order to spy on people, it's the only sensible interpretation of these policies.
- hdkrgr 4y agoIn the linked Netzpolitik article (in German) it's pretty clear that the 90% refers to Precision (i.e. 90% of flagged instances are True Positives), not accuracy. Still, the article (and probably the primary documents as well) do a horrible job of differentiating such concepts. [For clarification: Don't understand as my post as an argument for Chat Control, please :)]
- snovv_crash 4y agoSo does this mean that if nobody produces illegal material somehow the models will need to get better?
- n4r9 4y agoGood to know there's a name for this. It's pernicious. I came across it recently when someone said "if vaccines are effective then how come 60% of COVID patients in hospital have had one?".
- rob_c 4y agoNo in this case there is an abuse of language which has led to the poisoning of the conversation somewhat. There, the reason being the broad change in the correct definition of the word "vaccine". In former years this would be a preventative treatment that was probably 90%+ effective for multiple years for most people for almost all symptoms and almost all ability for infection to spread. The key being stopping the spread as this is why vaccines are adopted in the first place historically. For some reason this particular treatment is given this grandiose title despite unfortunately not really working at reducing spread, and only demonstrably reduces severe symptoms for those who are clinically at risk. It's a preventative treatment which works very well and should be applauded but the problem is people are now calling it what it's not which causes problems.
- throwaway22032 4y agoWhich messenger do we switch to if this goes in? I don't think I'd have an issue convincing people. Is Signal subject to this? Telegram? Do we need something "less mainstream"?
- contravariant 4y agoYou could use your own Matrix server as far as I know. It's annoying you need to go that far just to prevent the EU from snooping on your communication.
- mayoi 4y agoYou have to keep in mind that to do this you'd have to blacklist every other server from federating, keep all rooms private and disable public room discovery completely. And it still wouldn't really be all that private, because matrix is public oriented protocol and nowhere on the main website do you see the word "privacy" in context of user privacy. You also cannot really delete users, nor force deletion of their messages from servers that you're federating with once the user uses the disable endpoint. Also, matrix server specification is garbage, synapse is the only implementation that at least pretends to work reliably because of that, and it's maintained by a for-profit organization.
- Arathorn 4y ago> You have to keep in mind that to do this you'd have to blacklist every other server from federating, keep all rooms private and disable public room discovery completely. Yup, if you want to run a Matrix server which doesn’t share data with any other server you just turn off federation; same as email. It’s trivial to do so. > And it still wouldn't really be all that private, because matrix is public oriented protocol and nowhere on the main website do you see the word "privacy" in context of user privacy. Nope. Matrix is for both private and public comms. For instance, right now the matrix.org homepage includes clips from the Synapse 1.65 blog post which celebrates hooking up private read receipts so you can disable read receipts from being seen by other users. > You also cannot really delete users, nor force deletion of their messages from servers that you're federating with once the user uses the disable endpoint. Obviously there is no guaranteed way to obligate a server you don’t control to delete your data. Prior to deactivating your account, you can ask servers to delete your messages. After account deletion, you don’t have a way to delete your messages… because you deleted the evidence that you created them when you deactivated your account. > Also, matrix server specification is garbage, synapse is the only implementation that at least pretends to work reliably because of that, and it's maintained by a for-profit organization. sigh. The spec is not garbage; Dendrite is perfectly usable (despite being beta), and I hear Conduit is usable too. Synapse is maintained by the Matrix.org Foundation C.I.C, which is a UK non-profit: https://matrix.org/foundation https://matrix.org/foundation. Contributions come from all over the shop, including for-profits like Element.
- charlieyu1 4y agoAnything that violates privacy to such an extent shouldn’t be legal.
- dathinab 4y agoIt isn't. It is equivalent to an automatized search of all peoples conversations all the time, just because it's automatized and done local on the phone doesn't make it not a search. Which means it's pretty much unconstitutional. It's also probably not very useful as when it is people knowingly committing crime with YT access will know about it and will know how to work around it. And outside of cases of people which know they are doing illegal things and therefore take precautions it's unlikely to make a relevant difference I think.
- denton-scratch 4y ago> Which means it's pretty much unconstitutional. In the USA, I guess. But this is an EU proposal; the EU doesn't have a constitution.
- Bogdanp 4y agoBut individual countries within the EU can and do have constitutions. Here's title 2, chapter 2, article 28[1] of Romania's constitution: > Secretul scrisorilor, al telegramelor, al altor trimiteri poştale, al convorbirilor telefonice şi al celorlalte mijloace legale de comunicare este inviolabil. > Secrecy of the letters, telegrams and other postal communications, of telephone conversations, and of any other legal means of communication is inviolable. [1]: http://www.cdep.ro/pls/dic/site2015.page?den=act2_1&par1=2&idl=2 http://www.cdep.ro/pls/dic/site2015.page?den=act2_1&par1=2&i...
- denton-scratch 4y agoA number of Eastern European countries joined the EU without first bringing their domestic legislation into line with the European treaties. Unsurprisingly, some of those countries have dragged their feet about coming into compliance after the fact. This is one reason I was in favour of Brexit. That "title 2 chapter 2" seems reasonable enough to me; but it's a problem if an EU Regulation comes into conflict with the constitution of a member state. If a member state's constitution can override EU legislation, then there's no EU to speak of any more. Any state could then sidestep EU Regulation by simply passing a constitutional clause that declares it unconstitutional. What I'm saying is that EU Regulations override the legislation of member states, which are required to be in compliance with Regulations. If Romania has a constitutional clause that is overridden by a new Regulation, that Regulation isn't unconstitutional; rather, the clause ceases to be law (or Romania leaves the EU).
- dylkil 4y agoIs there any estimate for what percentage of chat communication happening within the EU is done by "perpetrators/criminals"? The average crime rate is 40 incidences per 100000 people per year, which would mean 0.0004% of the population is considered a criminal every year. What % of that tiny margin are going to be using online chat to commit their crimes? is it really worth abandoning the privacy of 450mil other people in the hopes that you might stop a criminal?
- Proven 4y ago
- mnd999 4y agoIt’s hard to escape the conclusion that they do not have any idea what they’re doing.
- tut-urut-utut 4y agoOf course they do and they do it on purpose. They are not some good but stupid people. They are clever and evil. Or led by their own interest. Which makes them do evil even if they are not. And that’s the worst kind of evil.
- immibis 4y agoWhy don't you specify what they are doing?
- diziet 4y agoThe fact that type I and type II error rates are not mentioned is an interesting point by itself.
- gloppers 4y agoThat old adage "if you've nothing to hide, then you've nothing to fear" is oft berated in these sort of discussions, but it really does apply here. This regulation is for the purposes of criminal investigation into serious harms against children, not for spying on whatever innocuous messages you happen to be sharing with friends and family. The privacy fears are being way overblown for us ordinary people. Paedophiles, on the other hand, do not deserve privacy. They need to be scrutinised their entire lives to keep children - the targets of their vile depravity - from harm. I support this regulation; every parent should.
- mayoi 4y ago
- gloppers 4y agoNo need to be so rude. From the law enforcement side, that is the system working as it should - the police investigated and cleared him of any wrongdoing. That Google can close someone's account for any reason and without any recourse is a wider issue, and one separate to this EU regulation.
- dathinab 4y ago> and one separate to this EU regulation. no, not separated at all laws have to take the implicit effects they have into account they could have added a clause to require providers to not close the account until the police investigation finishes. They didn't. Which means they are implicitly partial responsible for such abuse.
- gloppers 4y agoThat is a broader consumer rights issue which, I agree, the EU should do something about too. But adding a clause to this regulation would not solve that wider problem.
- 4y ago
- 752963e64 4y ago
- DangerousPie 4y agoImportant to note that this is not 10% of all messages being falsely flagged (= 10% false positive rate), but 10% of flagged messages being false positives (= 90% precision). As someone who works with these types of classification problems in a different context, 90% precision is actually quite good - especially assuming there is some sort of manual review process to take care of the 10%. Whether that makes this whole plan a good idea or not is obviously a very different question, but I think it's important to be clear about what this number actually means.
- mayoi 4y agoFor a moment, consider that you're running a company that supports some form of user communication. How much time and money are you willing to risk in a gray area considering all the legalese? Google doesn't seem to be willing whatsoever: https://archive.ph/W41mf https://archive.ph/W41mf
- nullc 4y agoIt's easy to achieve high precision when you just define a hit very broadly. See also the political flap about teachers factually describing the existence of alternative sexuality as 'grooming'. If you want to see the lie behind any of these child protection surveillance initiatives when they talk about things like 90% precision or millions of hits per year ask them how many of those detection of vile child predators resulted in an arrest warrant -- not even an actual arrest, or an actual conviction, but just an attempt. The answers is extraordinarily few and that tells you everything that you need to know.
- thr923400230 4y ago> It's easy to achieve high precision when you just define a hit very broadly. No, it's easy to achieve high recall when you define a hit very broadly. Precision will come down starkly.
- imtringued 4y agoCode is law the algorithm is always right 90% of the time.
- tomekn 4y agoThis whole debacle reeks of stupidity. The only thing that will happen is that the criminals they are (allegedly) trying to catch will simply move their comms to different channels. What's stopping a sophisticated crime syndicate form simply creating their own app which will have a small enough footprint such that it will fly under the radar? From the perspective of tech companies, they are being put between a rock and a hard place by simultaneously being asked for more privacy, and also less privacy.
- vidarh 4y agoVPN + using services in a country that doesn't care is enough. This will be a sales point for VPN providers.
- dane-pgp 4y agoHow long until the bureaucrats start saying "These unregulated foreign VPNs are a danger to our private data / economy / national security / children"? I mean, if a jurisdiction is making people's phones spy on them, then it's not much of a stretch to also make those phones not connect to unapproved VPNs, or even to prevent them installing unapproved apps (despite the recent win of the EU supporting sideloading on mobile OSes).
- vidarh 4y agoUnless they try to aggressively regulate the sale, import and manufacture (at this point, many hobbyist level homebrew retrocomputers are powerful enough to run a VPN) of general purpose computer devices or aggressively firewall all of the EU and punish anyone using to obscure encrypted data flows through approved protocols, this will of course only stop the people who actually don't have anything to hide. It'll be trivial to work around for anyone actually up to no good
- dane-pgp 4y ago> It'll be trivial to work around for anyone actually up to no good I never claimed they were motivated to actually stop these crimes. If the real ultimate goal is to prevent the spreading of "state secrets" (i.e. journalists exposing government malfeasance), or reduce copyright infringement, or limiting the spread of "disinformation", or banning memes that insult public figures, then the government needn't worry about "hobbyist level homebrew retrocomputers". Most people will continue to use mainstream platforms, and most governments mostly care about controlling most people. Besides, the next step will be to make ISPs deny service to any machine which doesn't have Secure Boot enabled, and which isn't running an "approved" OS, which checks every executable you run. Suddenly your general purpose computing device isn't very useful any more.
- hnhg 4y agoI have such a strong reaction to news like this, it's hard for me to not think that it's appropriate for every member state to consider leaving the EU now. They've succeeded in shifting me to a very anti-EU stance in one proposed measure - brilliant! It wouldn't surprise me if the leaders of most states are quite keen on such surveillance though.
- cuteboy19 4y agoThe issue is that they might end up breaking encryption anyways as exited states.
- wyager 4y agoBetter to have a patchwork of occasional shitty laws from weak, small states than consistent and unified shitty laws with widespread enforcement.
- gnomewascool 4y agoThe counter-argument is that nothing prevents governments coordinating on this in a supranational manner, anyway (cf. the planned, but fortunately rejected ACTA). In the EU enforcement is mostly decentralised, anyway.
- delusional 4y agoI kinda get it, but it doesn't make sense to blame it on the EU when you own government would likely impose the exact same (if not harsher) rules. Thats at least what I tell myself. I'm under no illusion that my own government is any better.
- jetbooster 4y agoSee: The UK, doggedly pursuing similar legislation
- deleted 4y ago
- uvesten 4y agoHow many EU beaureaucrats got their training in East Germany, I wonder? Or is it rather that they are too young and do not know about/remember what constant surveillance does to trust in a society?
- peoplefromibiza 4y ago[flagged]
- mantas 4y agoSilly fear of communism/socialism? :) Why would we be afraid of the thing that messed up with us for 50 years? :) It's funny when Westerners who have no practical experience talk down to us how we should throw away our practical experience...
- peoplefromibiza 4y ago[flagged]
- mantas 4y ago[flagged]
- peoplefromibiza 4y ago[flagged]
- DubiousPusher 4y ago[flagged]
- mantas 4y agoI know that part. But in this case another user, who seems to be european, calls my experience in Eastern europe „American paranoia“. It feels like some people have such a strong irrational love for certain political system that they can't accept that some people dislike it for valid reasons. Maybe actual American paranoia is when people blame US of A for whatever when their arguments run out.
- pelasaco 4y agoSo the TL;DR is the EU Commission wants to implement surveillance in Chat applications to "protect and combat sexual abuse of minors", because nobody is against "combating sexual abuse of minors", right? Probably later they extend that to "protect and combat right wing opinion", because nobody is against "combating the right wing opinion", or even "protect and combat the climate changes", because "Who are against it", right? Sounds like the a lot of "paranoid people" were just right, i guess?
- rvz 4y ago> EU Commission wants to implement surveillance in Chat applications to "protect and combat sexual abuse of minors", because nobody is against "combating sexual abuse of minors", right? > Sounds like the a lot of "paranoid people" were just right, i guess? Yes they were. The privacy activists are yet to realise that they have lost the battle decades ago. It is that dire that you have companies and governments pretending to care about privacy but it is always about mass surveillance in the end.
- pelasaco 4y agoIn the flip side of the same coin, almost the same group demand a stronger presence of the police in the internet[1] [1] https://www.youtube.com/watch?v=Xdm8SG8_v0I https://www.youtube.com/watch?v=Xdm8SG8_v0I
- Joeri 4y agoIt’s sort of how blocking of websites was introduced in some of the countries of the EU to combat sexual abuse of minors (CIRCAMP), and then the infrastructure set up to do it was reused to block torrent sites, fake goods sites, phishing sites and a whole host of other web content deemed illegal. The slippery slope is real, and I have zero doubt this chat control system will be used to detect other illegal activities within the year. Private correspondence should be private until a judge orders it unsealed in a specific case. Blanket surveillance is worse than the crimes it purports to combat, and there are always better ways to combat those crimes.
- perryizgr8 4y agoHow ironic. On one hand EU forces legitimate businesses to spend billions of dollars to satisfy GDPR in the name of privacy. On the other, they are planning to stream teenagers' private pics directly to designated "investigators".
- ginko 4y agoIt's almost as if the EU were composed of many different people with different viewpoints.
- perryizgr8 4y agoI get that, but it is still ironic. And it makes me sad looking at the utter wastage of money and human effort.
- noodles_nomore 4y agoIt's not ironic at all. Both decisions benefit the government which considers itself the sole proprietor of your privacy rights. Slave owners don't like it either if you mess with their 'property' without their consent.
- GuB-42 4y agoActually 10% false positive rate is not that bad if the system really has a 90% chance of detecting child abuse. Keep in mind that it only raises a flag, it doesn't automatically results in a false conviction. I don't have the numbers but I think that during an investigation, way more than 10% of suspects did nothing wrong. In fact, some people estimate that 10% of convictions are wrong (though I think that's an overestimate). A 90% effective system may actually end up preventing false arrests, search warrants, etc... a win for privacy! The real concern is the potential for abuse, not that 90% bar that is, I think, completely reasonable.
- joelhaasnoot 4y agoSo 10% of Google accounts are now banned? https://nypost.com/2022/08/22/google-bans-dad-for-sending-pics-of-toddlers-swollen-genitals-to-doctor/ https://nypost.com/2022/08/22/google-bans-dad-for-sending-pi...
- deleted 4y ago[deleted]
- goodpoint 4y agoEven 1% false positive rate would be beyond ridiculous and completely unusable.
- deleted 4y ago[deleted]
- mnw21cam 4y agoMake sure you get the correct meaning of the 90%. This article isn't talking about a 10% false positive rate, which would mean that 10% of OK pictures are falsely flagged as bad. That would be awful. The article is actually talking about 90% precision, AKA 10% false discovery rate, which means that 10% of the pictures flagged as bad are actually OK. That's a fairly good precision - however it is only half the picture, as the false positive rate definitely needs to be specified (and be very low).
- deleted 4y ago[deleted]
- vaylian 4y agoIt doesn't matter how low the error rate is. The fact that the European Commission wants to have a third (robotic) participant listening in on every digital communication is absolutely ridiculous. Saying that this is about child protection is a blatant lie. This serves only as a stepping stone to introduce other screening criteria later. And with opaque ML models it will be very tedious to determine what the model is supposed to find.
- kurupt213 4y agoI agree, child protection isn’t what’s driving this. It’s the deflection
- ChrisKnott 4y agoWhat evidence do you have to support this? Everything I can see suggests that they sincerely believe this will help protect children.
- Spivak 4y agoEspecially because in the US we already do this and the sky hasn’t fallen. Storage providers and hosting services already scan for it and popular chat apps block sending matching images client side. Like everyone saying this is the spiral to dystopia has to contend with the fact that we’re already apparently living in one.
- WillPostForFood 4y agoThe alarm here is because the EU is proposing mandating it, that’s not happened yet in the US.
- qubex 4y agoThe sky hasn’t fallen?? Have you read https://www.nytimes.com/2022/08/21/technology/google-surveillance-toddler-photo.html https://www.nytimes.com/2022/08/21/technology/google-surveil... ?
- chucklenorris 4y agoI think there are some important questions that need to be answered before such a dangerous decision should be made. How big is the risk of a child being groomed through these electronic means? Is it comparable to being struck by lightning? What is worse weighted by probability: being sexually assaulted as a child or being suspected and having your life turned upside down for years by these algorithms. We already see these things happen with relatively minor things like having your google account closed by an algorithmic mishap. How was this 10% number of false positives determined? Is this only an expectation of false positives or an actual statistic. What does 10% mean in the context of mass surveillance? It might well be that millions of children are groomed and assaulted every year through chats. I don't have the data so i cannot say. I was under the impression that most sexual assault cases happen in the family and not by strangers. What's worrying though is that these decisions are taken behind closed doors without any oversight, on the hope that they might save a child and possibly putting our lives in the hands of algorithmic justice.
- dylkil 4y agoThese are the type of questions that need to be presented to the public. This type of attack on encryption hasnt changed in 30 years, except now governments are going hard on the CSAM aspect as opposed to the other 3 horsemen[1]. It makes sense too since its the type of argument which invokes the most emotion in people, how could anyone be against protecting the children. [1]https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalypse https://en.wikipedia.org/wiki/Four_Horsemen_of_the_Infocalyp...
- wyager 4y ago99% of people are simply not capable of making or even comprehending the relevance of probability-weighted utility calculations. This has predictable and deeply unfortunate effects on the political process.
- llampx 4y ago"If even one child is protected, then it was all worth it"
- idrathernot 4y agoWhat is to stop criminals from using any specific form of encryption (ie. math)? Meanwhile the average person who follows the law will be at a much greater risk of identity theft, ransom-ware, etc…
- npteljes 4y agoIt will apply in the same way the unskippable anti-piracy segment on DVDs applied to pirates. In no way at all. Honest people who bought or rented legally, were subjected to the bullshit, while pirates enjoyed the superior unaltered movie experience.
- shakaijin 4y agoIt is so tiring to see the constant efforts to erode our rights. Even if they succeed in creating a surveillance state, do they think that it will not blow up in their face one day? It will make violence and revolutions against the surveilling institutions innevitable, or maybe it is just wishful thinking...
- kahrl 4y agoNot while the average person is content. It won't matter until it personally affects them. And by then it will be WAAAAAY too late.
- Am4TIfIsER0ppos 4y agoAh just in time to monitor fledgling revolts due to their own policies. Can't rebel against the deliberate reductions in wealth if you start black-bagging anyone who wonders about the current state of the continent.
- Tainnor 4y agoThe only "good" thing is that the current German government is very skeptical about this and two of the current governing parties (the Greens and the liberal party) have also long been opposed to more surveillance. This was different with the previous government where the "law & order" mentality was much more entrenched, and which did nothing to prevent e.g. upload filters (despite promising to do so). So I try to maintain some hope that at least Germany as a member state could tank this awful bill. edit: Here's the list of 61 questions that the German government sent to the EU concerning the bill (at the end of the article, in English): https://netzpolitik.org/2022/chatkontrolle-bundesregierung-loechert-eu-kommission-mit-kritischen-fragen/ https://netzpolitik.org/2022/chatkontrolle-bundesregierung-l... From a cursory reading, it reads to me like the diplomatic equivalent of "what you're proposing doesn't make any sense".
- norswap 4y agoAre you sure they're ideologically against it, or where they against it because they were in the opposition and it was convenient for them to be?
- imtringued 4y agoThe Greens in Germany are basically a more serious/realistic Pirate party when the topic is related to the internet. Honestly I vote Greens because of that alone. The fact that the rest of their program is sane is a cherry on top.
- rjzzleep 4y agoOh my god, not at all. The Greens, are more ideologically driven than any other party and not in a good way(and that ideology does not line up with their campaign promises at all). They have been the single most destructive force in German politics and they have not kept a single campaign promise. This is the supposed "Green" party that campaigned on anti-war and not sending weapons to war zones and closing coal that has been actively lobbying on reopening coal plants and has been the most vocal in its request to send weapons to Ukraine. If Greens were in favour of anything they campaigned on it would be the perfect political party, but it's not. It's actually the FDP and AfD that has been most actively against these things. The AfD has been labelled far right and racist conveniently ignoring all the massively racist statement and actions by past CDU/CSU and SPD leadership.
- choeger 4y ago> The EU Commission is apparently aware of the problem and is consciously accepting it. So they're fine to read 10% of all messages? Probably more, because of context? Besides this obviously being a massive DDOS on whatever dystopian spy center of sanitary thoughts they want to build, I wonder how the big EU honchos get their free pass on that? Or didn't they simply not consider that they're going to get monitored as well?
- kahrl 4y agoNo. The article explains that it is 90% accuracy on already flagged messages.
- paganel 4y agoAs an EU citizen I didn't know exactly what that Chat Control thing was, so I web searched it: > The EU wants to oblige providers to search all private chats, messages, and emails automatically for suspicious content – generally and indiscriminately. The stated aim: To prosecute child pornography. [1] Yeah, that will go down well, a central government checking our private conversations for "suspicious content". Of course they would use the "think of the children" trope, they could also have gone with the "think of the bad terrorists" trope, but that would have been too American, too cowboy-ish, we need to feel special, we're Europeans, after all. Minus some street protests I don't think we can actually stop this, and, even then, I have my very big doubts. It so happens that I live in the EU periphery (I still need to present my ID card if I want to travel to Budapest or West from there), and it sickens me to see that my privacy depends on countries and electorates on which I have no say (like Germany, with all due respect to the Germans who still care about their privacy). Why should my privacy be made fun of because of decisions taken by some people from half way around the continent with which I have no direct connection and no shared past? Did they have a Securitate-like thing? Many of them didn't, and even those that did (like the same Germans), it looks like it doesn't matter at this point, they're all too happy to see their private political conversations be scrutinised 24/7. F. that, the only viable solution I see for my country is an exit from the EU, but the money (still) coming in from Bruxelles is too good to leave aside for pesky political principles, so of course that no serious politician from around these parts puts the problem that way. [1] https://www.patrick-breyer.de/en/posts/messaging-and-chat-control/ https://www.patrick-breyer.de/en/posts/messaging-and-chat-co...
- easytiger 4y ago
- yccs27 4y agoSorry, sarcastic remarks with no discussion don't get upvotes. That is standard here, unlike on Reddit.
- the_only_law 4y ago
- jernejzen 4y agoIt kinda gets me into the stance: every member of EU parliament and EU commission should make their bank accounts fully transparent so populi can check whether they are committing some act of corruption.
- erdos4d 4y agoThis will never fly in Germany. Those people still have internet cafes without surveillance cameras so they can do their computing anonymously. Paranoia is a way of life there, for good reason.
- RektBoy 4y ago
- hammyhavoc 4y agoCan someone give me the tl;dr regarding where Matrix protocol stands in regards to this and people running their own server for family?
- DubiousPusher 4y agoMaybe I'm missing something here but it seems to me there is a basic question here. Do two or more people have a right to privately communicate via a third party? If the answer is yes, then regardless of the accuracy of the system or the mass nature of the communication network this is objectionable law making. IMO, it is a fundamental human right to communicate privately. The only real question is what is the responsibility of a third party. If I give a shipper illicit material are they responsible to inspect it and report it? I'm personally unaware of the law regarding this but I assume your shipper is not required by law to open every package it ships and report upon it. Are they required to do a percentage? If not than what the state is claiming here is a right by convenience. It happens that digital communication is easier to inspect than crates. Therefore, the state can create an expectation of one third party it does not of another.
- therealmarv 4y agoThere is a fundamental problem to making everyone a suspect. I'm no criminal... why do I need to prove it to the state(s) and companies with EVERY message sent? Not even when driving a car I'm tracked all the time. And I think driving a car can be also dangerous.
- lakomen 4y agoI can only repeat myself, the EU is not a democracy. Also I thought chat control was off the table? Did that change?