16 ms·
EU's concealment of secret 'expert list' on CSAM regulation is maladministration
- miohtama 3y agoThe secret expert list is now published https://news.ycombinator.com/item?id=38205743#38205787 https://news.ycombinator.com/item?id=38205743#38205787
- belter 3y agoI had it with these people. The next time there are elections for the Commission I will...hey...wait a minute!...
- bad_alloc 3y agoWell, the Commission is elected by the elected governments of the member states. In a similar fashion, many heads of state are voted in by the elected government and not directly. Both procedures can be seen as iffy, but for the EU this was a deliberate compromise to get potential members on board.
- Vinnl 3y agoWhich is to say: in your next national elections (Dutch ones are in two weeks!), vote for someone who'll use their influence to get a Commission you approve of.
- sgift 3y agoAnd in the EU parliament elections.
- jokethrowaway 3y agoThat's hilarious This is never a talking point because it's so detached from normal people life and it's actionable - it's not a good empty promise they can taper cities with and then never fulfill. The ideal empty promise is something that will take more than 5y to evaluate and people care about.
- Gud 3y agoOr even better, vote for someone who will dismantle this nominally democratic system and implement something better. We can do better. https://www.eda.admin.ch/aboutswitzerland/en/home/politik-geschichte/politisches-system.html https://www.eda.admin.ch/aboutswitzerland/en/home/politik-ge...
- josefx 3y agoIt is one thing to have that structure and hold to it, it is another matter to hold sham elections to select possible candidates and then pick people that weren't even on the list. Every time I hear of it it seems to go out of its way to shit on the very core concepts of democracy, maybe not because it is that way by design, but simply because it can.
- belter 3y agoYour comment ignores the well known fact, that within party factions, election for the golden salaries of Brussels and the European parliament are a compensation mechanism. For the losers within the power plays of internal Party politics in Europe. The winners run the Government and run Ministries. The losers are sent to Brussels.
- denton-scratch 3y ago> Well, the Commission is elected by the elected governments of the member states. Nope. Commissioners are appointed by the member governments. Each government has an allocation of commissioners to appoint. They are usually failed politicians of the party of government (all political careers end in failure). They have to be signed off by the EU parliament (I think), but nobody in Europe knows the background of every political has-been in other EU countries.
- matthewdgreen 3y agoI believe that the EU Council (elected heads of state) gets to appoint the EU Commission President, with an approval required from the Parliament. The remaining 26 Commissioners are selected by the Council of Ministers (appointed ministers for each EU member state, and hence an additional layer of indirection away from the actual electorate.) Then Parliament has some substantially more limited ability to review these appointments, but I don't think they get an outright veto.
- realityking 3y agoThe European Parliament does get an outright veto or rather the opposite, without explicit approval from the EP commissioners can‘t be appointed. The catch, they can only approve (or not approve) them as a group. Usually the parliament will indicate which nominated members they find unacceptable and those respective countries nominate new candidates. Reference: https://www.europeactive.eu/news/european-parliament-gearing-confirmation-new-european-commissioners https://www.europeactive.eu/news/european-parliament-gearing... Arguably this is more democratic than how we appoint government ministers in Germany. The chancellor gets elected by parliament and then appoints (and fires) ministers on their own authority without any check by parliament.
- denton-scratch 3y ago> The catch, they can only approve (or not approve) them as a group. OK, that's what I thought, but I had doubts, because I read something contrary recently. Thanks for clarifying. Can German chancellors appoint anyone they like as ministers, or do they have to appoint someone who has been elected to the Bundestag? Because commissioners are not elected. So, as I recall, there's been exactly one instance in which the EU Parliament has rejected all the Commissioners; they sacked the lot, because it was evident that they were mostly corrupt. Plus ça change, plus c'est la même chose.
- nvm0n2 3y agoThe Commission President has a de facto (not de jure) veto power over who the member states nominate so in reality the Commission is selected by its President. The President is in theory selected by the Council (leaders of the member states), but in practice the whole process is secret so nobody knows how it happens. Certainly the Commission often ends up with extremely dubious Presidents where nobody can explain on what merits they gained that position. And then the selection of both President and Commissioners is supposed to be ratified by the Parliament but last time they were given a vote with a single option on it. You could either support vdL or abstain. And it's not a real Parliament anyway so nobody with any political ambition actually runs for it, it's a joke chamber made up of yes-men and people who think their countries should leave the EU entirely. Even Juncker didn't take it seriously. So nothing about the Commission relies on elections.
- snowpid 3y agowhere do you live? And can you vote directly for your government?
- deleted 3y ago[deleted]
- deleted 3y ago[deleted]
- denton-scratch 3y agoMost people don't get to vote directly for their government. They vote for a local representative, or MP. In the EU, most countries don't even have a government party, because most governments are coalitions, which may not have even existed before the elections. So you don't even get to vote for the party of government, nor its leader. It's all very indirect.
- Closi 3y agoIt's simple! You just vote for someone who then votes for the person who decides who will vote for the person that is the European president. It's like democracy except so indirect that it's total shit. Can't trust the people to actually choose who to put in charge - have to leave that decision to the leaders selected by the other leaders who were voted by the other leaders.
- Kenji 3y ago> I had it with these people. You've had it with the EU bureaucrats? What a shame, CSAM has been detected on your phone. Prepare to be apprehended.
- pembrook 3y agoAhhhh yes. A fun case study in how democracy can devolve into byzantine bureaucracy.
- cool_dude85 3y agoEU was designed to be run by technocrats and, as much as possible, totally insulated from any kind of democracy. There's no "devolution" going on here.
- matthewdgreen 3y agoA technocratic government might produce good outcomes sometimes, but the main problem here is that the "technocrats" seem to be relatively inexperienced with information technology.
- omginternets 3y agoThe 'techno' prefix in 'technocrat' does not refer to information technology, or even science. It instead refers to a technical specialist in the exercising of governmental or managerial authority. I can't think of a single instance in which a technocracy has produced a good outcome.
- bojan 3y agoThe proposed European Constitution went a long way to fix this, but was unfortunately rejected in French and Dutch referendums. The people didn't want the EU to reform.
- omginternets 3y ago>The proposed European Constitution went a long way to fix this Uhh... what? Firstly, it was rejected by more than just the French and the Dutch. Secondly, the reason it was rejected is precisely because, for lack of democratic process, it structurally favors this kind of authoritarian opacity. The proposed constitution doesn't even begin to fix this; it is instead the very cause.
- deleted 3y ago[deleted]
- baz00 3y agoI suggest people read the full decision from the ombudsman: https://www.ombudsman.europa.eu/en/decision/en/176658 https://www.ombudsman.europa.eu/en/decision/en/176658 It shows what an absolute bureaucratic mess it all is.
- seanw444 3y agoThe bureaucratic evolution and its consequences have been a disaster for the human race.
- deleted 3y ago[deleted]
- pphysch 3y agoWe would never reach 8B population and successful space programs without huge bureaucracies. Unless of course by "human race" you or Uncle Ted mean "my personal fulfillment".
- nonrandomstring 3y ago> would never reach 8B population You make it sound like that's a positive achievement. There are "Limits To Growth" [0] [0] https://en.wikipedia.org/wiki/The_Limits_to_Growth https://en.wikipedia.org/wiki/The_Limits_to_Growth
- TeMPOraL 3y agoWhich we won't overcome without huge bureaucracies either. Also, while the population growth itself may not be a positive achievement directly, it's kind of necessary for all the scientific, technological and cultural achievements. Unless you don't see those as positive either - in which case I don't think there's anything left to discuss.
- naasking 3y agoThat's just more of what the OP was pointing out: why are you assuming overcoming those limits is good? This is just natural selection in action: only people who are good at slotting into bureaucracy and being well-behaved cogs in the wheel will thrive in this environment, and other types of humans will die out. This exact same argument suggests we should not tolerate indigenous people who live separate from civilization. Adapt or die right? But this conclusion is typically quite abhorrent to the same type of people who advocate for your position. Can't have it both ways.
- miohtama 3y ago> 17. The Commission representatives noted that many companies, which participate in the EUIF, are concerned about their security and public image. In addition, the topics discussed in the EUIF are often of a sensitive, operational nature and disclosure could be exploited by malicious actors to circumvent detection mechanisms and moderation efforts by companies. Revealing some of the strategies and tactics of companies, or specific technical approaches also carries a risk of informing offenders on ways to avoid detection. The Commission representatives provided additional confidential information during the meeting with the Ombudsman inquiry team on why the list of experts could not be disclosed. If the goal of your company is to promote and get a wiretap on every single device and messenger app, IN SECRET, you should be concerned about your public image. I also suggest you should be also concerned human rights and your personal moral compass. Time to drag out these bastards to the light.
- baz00 3y agoI suspect the bastards are already well known and accepted bastards. What is going on here is the EU doesn't want to look like it consulted bastards and is coming up with arbitrary reasons to hide that.
- marcosdumay 3y agoWell, they are now. But honestly, it was surprising for me to discover that the people pushing for the wiretrap were actually only the ones selling wiretraps. I really expected some larger conspiracy.
- amluto 3y agoMaybe you should try Occam’s Razor for conspiracies: the most straightforward conspiracy is likely to be the right one :) For example, one might imagine that eIDAS 2 isn’t backed by a consortium of would-be spies but is more likely backed by a small consortium of crappy CAs that are sick of being forced to comply with CA/B Forum rules and want regulation to override the rules. (The CA/B rules are very specific and extremely aggressively enforced. It’s not like the GDPR where you can apparently get away with messing around for quite a while. Multiple fairly large companies have had their CA operations effectively shut down by the CA/B Forum for noncompliance.)
- cwoolfe 3y agoIt is possible to detect CSAM in end-to-end encrypted messaging by doing it on-device on the client side before it is encrypted and/or on the receiving client side after it is decrypted. iMessage already does this in the latest release. Most smart phones have AI-enabled chips that would be able to run images/videos against classification algorithms. The tricky part would be enforcing that users use clients which do this, so the task becomes regulating allowed messaging clients, which might be impossible. That being said, one could probably knock out 80% of the problem by legally forcing the hand of all the major platforms to do client-side scanning. At that point, only the truly dedicated would move their comms to another platform. Mobile users are very susceptible to nudges.
- andersa 3y agoIf the app is processing data in a way you do not want before sending it, especially one that will no doubt be constantly argued to scan for more and more things they find objectionable, then it defeats whole point of end to end encryption, and you might as well just not do it at all.
- aaomidi 3y agoPlease don’t AI detect CSAM. That is a disaster waiting to happen.
- vacuity 3y agoIt works great! Until it doesn't, and then someone gets put into jail and the court doesn't bother reviewing the AI's verdict because how could it go wrong?
- Freak_NL 3y agoIt's not that you would end up in jail (although granted, that level of fuck-uppery is possible), it's just that anyone flagged would go through hell with real-world consequences before everything is cleared up.
- figglestar 3y ago
- Phil_Latio 3y ago25000 lobbyists. If they don't deliver, what are they good for?!
- deleted 3y ago[deleted]
- sproketboy 3y ago[dead]
- cwoolfe 3y ago[flagged]
- scanny 3y agoI wonder why it is that the Netherlands hosts 77% of urls for child exploitation Netherlands 77% US – 5% France 4% Russia 2% Lativia 2 % Luxembourg 2% (Internet Watch Foundation Annual Report, 2020) - from OPs link https://enough.org/stats_exploitation
- krageon 3y agoLarge internet exchange would be my guess
- LinuxBender 3y agoI wonder why it is that the Netherlands hosts 77% of urls for child exploitation I'm not sure if this anecdotal point is applicable but I have run into many shady server resellers in the Netherlands. Oddly a couple of them are just down the street from The Hague. It was so prevalent for so long that I used one of them to do all my port scanning from a long while back. Pretty much anything goes. They would just forward abuse@ reports to the server renter so they were aware. I was expecting them to drain my throw-away bank but it turned out there is still some honor among thieves. Either that or some of them are honeypots. Other clients were the only issues I ran into. They would steal my IP addresses so I had to steel them back. no L2 port protection. I don't know much of this is still true so it's just a data point.
- Jigsy 3y agoI wouldn't trust stats from the IWF... or the UK in general since they classify drawings as CSAM/CSEM.
- logifail 3y ago> It is technically possible to do client side scanning; and since we don't trust the government to do it, we can do it on localhost only, and report AI-flagged results to parents I'm afraid I don't understand the last bit - to whom is a device going to report flagged content?
- Despegar 3y agoThe only way for this system to work would be if the database of CSAM were managed by consensus by geopolitical rivals. That is, it would have to include Russia and China. This is the only way to ensure that Western governments don't abuse their access in the future to surveil dissident groups. Trusting that NCMEC can't be compromised is a nonstarter. I would trust a system where Chinese, Russian, American, British, etc police agreed that the database only includes CSAM.
- 4ugSWklu 3y agoThis does already exist somewhat as the INTERPOL Baseline list - https://www.interpol.int/Crimes/Crimes-against-children/Blocking-and-categorizing-content https://www.interpol.int/Crimes/Crimes-against-children/Bloc... Does this meet your threshold?
- Despegar 3y agoIf national legislation by Western governments provided that only signatures from this org could be included, then I'd support it. But I don't know anything about this INTERPOL list, does it actually require consensus by all of these countries? Or can one country influence what's included in practice? There has to be an effective veto by all the countries involved for anything to be included.
- 4ugSWklu 3y ago“To be included in the Baseline list, child abuse images and videos must be recognized as such by our specialist network of investigators, and meet specific criteria in terms of the severity of the image content, for example those believed to feature children aged 13 and under. The strict criteria ensure that the Baseline list refers only to images and videos which would be considered as illegal in any country.” INTERPOL has a very large membership, including Russia and China. The baseline list is reviewed so only media that is illegal in every country INTERPOL operates in is included. I’m not sure how a veto system as you’re suggesting would work practically, but this might be the closest thing.
- ritzaco 3y ago> Suggestion for improvement > 26. Given the Commission’s failure to identify the list of experts despite the complainant’s clear interest in it, the Commission should register this now as a new request for public access to documents and handle it in accordance with Regulation 1049/2001. I know the ombudsman doesn't really have power and can only provide recommendations but surely "and the people who initially denied the request should be fined/fired/imprisoned" or some such language would have been OK to add? Seems like 'we can ignore the law until someone jumps over the substantial hurdles to complain about us ignoring the law and then we can follow the law' is not good for democracy.
- gpvos 3y agoCSAM = child sexual abuse material
- deleted 3y ago[deleted]
- GuB-42 3y agoAlso called "child pornography". The term had me confused at first because I though it consisted of evidence of child sexual abuse, including things like medical records showing traces of abuse. But no, it is just child porn, stuff that gets pedophiles excited, which may include stuff where no real child abuse has taken place (ex: lolicon).
- jmyeet 3y agoSadly, this sort of thing isn't new. Governments around the world are trying to avoid any kind of public scrutiny for what they're doing. I'm reminded of the Trans-Pacific Partnership ("TPP") from ~8 years ago. Very few people were even allowed to see the text of the treat [1] yet the people's represntatives had to ratify this when their own constituents weren't allowed to see it? Wikileaks and others leaked drafts and it was as bad as people thought it was going to be. Defenders argue that trade negotiations need to happen in secret so as to not worsen our negotiating position. This really translates to "we don't want to afford the public the opportunity to oppose it". The EU now is finding some BS rationale for operating in the shadows. [1]: https://www.npr.org/sections/itsallpolitics/2015/05/14/406675625/a-trade-deal-read-in-secret-by-only-few-or-maybe-none https://www.npr.org/sections/itsallpolitics/2015/05/14/40667...
- cultureswitch 3y agoDid we ever stop to consider the theory of harm of CSAM circulating in private communications? Because I don't see how bytes being copied around in secret actually hurts children in any meaningful way. Obviously it is wrong to create child porn intentionally. But that's already illegal and people who do this are laughably bad at ITSEC. Like seriously, read the stories of CSAM making "studios" who got caught. Either law enforcement is so bad that any remotely shrewd criminal defeats them, either the criminals are just not all that technically savvy. Either way, the tools to catch actual child molesters are effective and adequate.
- omginternets 3y agoI think you're right that we should be able to debate this question, but I also have a hard time believing that circulating CSAM has no detrimental effect whatsoever. I find it quite credible that the production and distribution of original child-abuse content can earn a social reward for pedophiles, and in so doing, encourage them to continue or expand their practice. I also find it credible that it can form the basis of a "street cred" system that binds online communities of child abusers together. On car forums, you're cool if you're the first to do a particular mod. In pedo communities, I'd expect you to be "cool" if you violate a new, hitherto-unseen kid, or violate one in a new and creative way. >But that's already illegal and people who do this are laughably bad at ITSEC. Like seriously, read the stories of CSAM making "studios" who got caught. Separately, this doesn't follow. Catching criminals with laughably bad OPSEC doesn't exclude the existence of successful criminals with very good OPSEC.
- falserum 3y agoRhetorical, but relevent, question: Will new measures help catch people with good opsec capabilities? I have doubts, that new measures will move the needle much.
- naasking 3y ago> but I also have a hard time believing that circulating CSAM has no detrimental effect whatsoever Some studies have shown that availability of animated CSAM reduced recidivism among child molesters. That we treat these two categories of CSAM the same, along with the assumption that it encourages more harm, are some of those conversations that need to happen.
- Footnote7341 3y agoIsn't it illegal to save, view, or post, the new zealand shooting in NZ and Australia. Add those hashes to the list too why not... the exact same twisted logic that we use in this crusade surely it would apply to videos of people getting killed not just raped right? or is there a unique puritanical weirdness that allows CSAM to get a pass to where states should be violating all of our devices
- gunapologist99 3y agoCan you imagine if holocaust museums didn't exist? If Auschwitz was paved over and it was illegal to talk about it?
- lakomen 3y agohttps://netzpolitik.org/2023/geheime-liste-wie-der-sicherheitsapparat-die-chatkontrolle-praegt/ https://netzpolitik.org/2023/geheime-liste-wie-der-sicherhei...
- hulitu 3y ago> EU's concealment of secret 'expert list' on CSAM regulation is maladministration What is more disturbing is that there are very few European institutions and companies on this list.