6 ms·
EU parliament agreement to remove chat control and safeguard secure encryption
- hjartats 3y agoI am so extremely happy to see this. Even if the law text all.in all is a disaster, full of holes and inconsistencies the main goal after total rejection was to get rid of the chat control part. Forcing targeted scanning only. I was I Brussels a couple of weeks ago as a volunteer with eDRI and meeting with MEPs and making noise about the issue. As a Swede I feel extra bad about this law and how it has come about since the person driving this is the Swedish commissioner Ylva Johansson. But please keep protesting and explain to.people why the right to private conversations is important. This is a right that I.count on is going to be attacked many many more.times.
- theshrike79 3y agoJust in case people don’t read the article: the European Parliament’s position removes indiscriminate chat control and allows only for a targeted surveillance of specific individuals and groups reasonably suspicious of being linked to child sexual abuse material, with a judicial warrant. End-to-end encrypted messengers are exempted.
- thesnide 3y agoeven more: In detail, our position will protect young people and victims of abuse much more effectively than the EU Commission’s extreme proposal: (...) At the same time, we are pulling the following poisonous teeth out of the EU Commission’s extreme bill:
- SenAnder 3y agoHow does this differ from the status quo? I would assume targeted surveillance, without requiring 3rd parties sabotage the security of their products, is already a legal law enforcement procedure?
- ponderings 3y agoThe EU standardizes a lot of laws that a lot of countries should have had already. I'm sure there must be bad examples but I've really only seen improvements in action. Countries have to part with their idiotic version or give up on their idiotic proposals. NL for example had some issues wanting forced labor for unemployed people with social support but that would be called a job and require minimum wage.
- derefr 3y agoDoesn't have to be different from the status quo. EU law acts upon member countries like the US federal constitution acts upon member states: it prevent individual members from ever changing their own laws to take more extreme positions than the recognized consensus position.
- g-b-r 3y agoTo my knowledge EU Regulations are simply laws that overrule local EU countries' laws, so whether it's possible or not for local laws to be more extreme only depends on such laws being at odds with what the Regulation prescribes (but I'm not a lawyer and only looked into that years ago).
- bmicraft 3y agoFrom what I've been told how it actually works is that eu law doesn't apply directly to member states, but member states are required to amend their laws to be at least as strict as eu laws on all matters.
- g-b-r 3y agoThere's not a single type of EU laws, there are "regulations" and "directives". Regulations are complete laws applicable immediately across the EU as they stand, the states are required to amend any conflicting law but the regulations already automatically prevail on any conflicting local law. Directives instead need to be transposed into local law by each state individually, and can leave many details to the individual implementations.
- Condition1952 3y ago[flagged]
- matthewdgreen 3y agoIt seems like this is a proposal, but it hasn’t been adopted and it’s not clear this coalition will prevail. It’s hard to tell because the language of the article makes it seem like a “done deal”, but I’m less optimistic.
- greatgib 3y agoThe proposal looks equilibrated in my opinion. I think that it is a good example of why voting for Pirate party representative might make a difference with law changes designed to help citizens.
- atoav 3y agoAt least on the EU level, this certainly had its merits. Additionally I think having good informed representatives like that can even have a bigger impact than their seat alone, because they can often influence the opinion of other representatives around them.
- jeroenhd 3y agoThis is great news, I hope this will be the end of the stupid E2EE ban attempts, for a few years at least.
- PeterStuer 3y agoEvil never sleeps.
- ChrisArchitect 3y agoMore discussion a few days ago: EU Chat Control Bill Postponed https://news.ycombinator.com/item?id=37982655 https://news.ycombinator.com/item?id=37982655
- arlort 3y agoTo add context to the link, this isn't a repost, just related. The post linked is about the Council (think US senate or Bundesrat) not having enough votes to pass the text (they're still looking for internal compromises) This post is about the European Parliament's committee examining the draft (well, one of the 5, but LIBE is the lead one)
- ChrisArchitect 3y agoYeah, meant that it was Related, a lot of related discussion in there
- WA 3y ago> We safeguard trust in secure end-to-end encryption. We clearly exclude so-called client-side scanning, i.e. the installation of surveillance functionalities and security vulnerabilities in our smartphones. What does "exclude" mean in this context? Should client-side scanning be allowed or not?
- arlort 3y ago> Should client-side scanning be allowed or not? That's up to you if it "should" (personally, no, horrible most likely illegal idea) Patrick has been a pretty vocal opponent of the draft so if he's content that's good
- andersa 3y agoThey're trying to say it's not going to be required, and also they don't like it.
- attah_ 3y agoOn the one hand this makes me very happy that democracy can actually work things out (and quite well at that)... but on the other hand i'm still horrified people seriously tried to push the original proposal. Not sure what i feel summing up the two.
- SahAssar 3y agoMy takeaway is that the EU as a whole is somewhat responsive to public feedback but it is still too far removed from the people and our will.
- attah_ 3y agoToo far removed or just too technologically inept? Not only was it technologically impossible; but they keep wanting to do things to people's online life that everyone that would never fly in offline life. It's like they think technology is somehow an optional extra, or even a passing fad that doesn't deserve the same rights and safeguards.
- dotandgtfo 3y agoI feel like it's pretty obvious the bill wouldn't pass. It's just so off-base from all other EU tech policy. Banning end to end encryption is both ineffective and practically impossible. And sending "CSAM" (in a lot of cases teenagers/young adult nudes) to a presumably American tech company for manual screening is just so unequivocally wrong on a privacy level. It seems like a lot of money went into making this get to the vote. My impression is that lobbyists have worked for this through the European commission - which is distasteful as it should never have been proposed. But it never stood a chance in the parliament. There seems to be checks and balances. I have to credit the great work of people like Patrick Breyer and everyone who has demonstrated and organized across the EU these last months. Passivity leads to the worst outcomes.
- richarme 3y agoI think you're probably right, but sometimes I wonder if a bit of distance can be a good thing. Perhaps a slight distance can make populism less viable while still being effective at representing the low-pass filtered will of the people in a sense. And perhaps the lower public mindshare might help insulate against people with ambitions but not people's best interest at heart. Or this is crazy talk, not sure which one it is :)
- moogly 3y agoHmm, call me a cynic but this sounds a bit too good to be true. What's the catch?
- bmicraft 3y agoThe "worst" thing about this from my understanding is that for now this is just an agreement. From the bottom of the article: > The EU Parliament’s civil liberties committee is due to confirm the agreement on 13 November. > 20 November 2023: Announcement in plenary (likely no vote on substance) > 4 December 2023: Envisaged Adoption of Partial General Approach by EU Council (tbc) > after 2024 EU elections: Envisaged trilogue negotiations of the final text of the legislation between Commission, Parliament and Council, as well as adoption of the result
- raxxorraxor 3y agoThe bill will probably piggyback a lot of other caveats like age verification or online ID requirements.
- pmontra 3y ago> Security by design: In order to protect young people from grooming, internet services and apps shall be secure by design and default. It must be possible to block and report other users. Only at the request of the user should he or she be publicly addressable and see messages or pictures of other users. Users should be asked for confirmation before sending contact details or nude pictures. Potential perpetrators and victims should be warned where appropriate, for example if they try to search for abuse material using certain search words. Public chats at high risk of grooming are to be moderated. The "publicly addressable" part is feasible and already implemented by many messengers. Asking for "confirmation before sending contact details" is feasible but easily circumvented as is my mail is joe at example dot com. Asking for "confirmation before sending [...] nude pictures" is where it gets interesting. How without scanning every file one is about to share?
- 9dev 3y ago> Asking for "confirmation before sending contact details" is feasible but easily circumvented as is my mail is joe at example dot com. I’m pretty confident this is a task where LLMs will shine.
- raxxorraxor 3y agoNot if you want to scan the image. Locally that would still need quite a lot of processing power.
- besse 3y agoI don't understand. Why would anyone care about circumventing a "Are you sure?" dialog?
- pmontra 3y agoThere are many ways to share contact details. One is to use an app provided mechanism, which can ask confirmation about sending and receiving contacts. Another one is to just type them into a message. The confirmation of the intention to send is implicit but no confirmation is possible at the receiving end: they read the message and get the contact, willing or unwilling. All they can do is delete it before remembering it and report the other party. There is a provision about reporting unwanted interactions. About circumvention, one could think about a way to detect contact details in messages. There are several problems with that. 1. If it warns the sender, the sender will try another way until the obfuscated contact passes unnoticed (text, image, vocal, link, whatever.) 2. If it automatically reports the sender there will be many false positives, some due to copy and paste, keyboard autocompletion, etc. 3. We're back to automatic spying of people.