8 ms·
EU Parliament Civil Liberties Committee adopts position on CSAR
- orian 3y agoFrom the source: > Chat control - one of the worst EU plans that is also being described as a surveillance monster - must be stopped. And the EU Parliament has just decided to do so! In a historic agreement on the EU Commission's Child Sexual Abuse Regulation (CSAR) the European Parliament wants to remove chat control requirements and safeguard secure encryption. The decision came after extensive backlash against the original proposal from technology and security experts, to international scientists and to citizens across Europe. This is a great win for our right to privacy and for upholding our democratic values in Europe, but the fight continues! What did the EU Parliament decide? Breyer writes on his website that internet services and apps must be "secure by design and default". The EU Parliament has agreed to: "safeguard the digital secrecy of correspondence and remove the plans for blanket chat control, which violate fundamental rights and stand no chance in court. The current voluntary chat control of private messages (not social networks) by US internet companies is being phased out. Targeted telecommunication surveillance and searches will only be permitted with a judicial warrant and only limited to persons or groups of persons suspected of being linked to child sexual abuse material." A huge win for our privacy rights is also that the EU Parliament has decided to "clearly exclude so-called client-side scanning". In contrast to the original chat control proposal, the version of the EU Parliament wants that a new EU Child Protection Centre proactively searches publicly accessible parts of the internet for child sexual abuse material with automatic crawling, which can also take place in darknet and would be much more efficient than private surveillance measures by providers. Found abuse material must be reported and taken down by the provider. Fight is not over While the EU Parliament's decision is a huge win, the fight is not over. It is expected that the EU Commission will continue to push for general surveillance chat control measures. Now is the time for each and everyone of us to join this fight!
- jdiez17 3y agoWell, that is a big relief. Common sense prevails, which is absolutely not a given these days.
- ta1243 3y agoThe fight is never over. That's why we have strong checks and balances, the commission (made up of appointees of the 26 EU government heads) will push things, the council (made up of those heads) have to agree, and the Parliament (made up from a popular vote) has to agree, then if all that fails the courts step in But the fight isn't as much against the government, it's the hearts and minds of the people to make them care more about their own privacy and security rather than "someone think of the children".
- jliptzin 3y agoI don’t think the average person cares about privacy, sadly. “I have nothing to hide,” etc. The best argument I heard against this crazy policy (only heard recently during these hearings) was that many creators/sharers of this CSAM material is kids themselves! Young teens exploring their sexuality, swapping nudes with each other. So that means that if you’re scanning all messages and you come across one of these chats, instead of that conversation staying between the 2 teens (like it should), it’s getting scanned by the provider, flagged, uploaded upstream to some law enforcement center where god knows how many other people are going to be looking at it, only to realize that there was no abuse happening. And of course that comes with the risk of leaks/hacks/rogue employees spreading it even further. Completely insane!
- nonrandomstring 3y ago> The fight is never over. Checks and balances are working this time hopefully. Regardless our (good) multi-stage processes and multi-chamber structure and even, regardless matters of lobbying and money - in the moment of quiet while smoke is still on the wind - look for the shooter. "Who wants this?" and "What are their fears?" leads to a better leverage point closer to values than parameters. There are a lot of people in the world right now anxious about the digital future. The EU Commission seem to hear too much from Chicken-Licken's gang of sky-repellant gizmo salesmen and not from calmer humane optimists.
- ta1243 3y agoI can't see any specific benefit to this for a corporation, my feeling is it's a political response to a general disquiet with the tech industry abusing people, along the lines of "something must be done, this is something, therefore this must be done" I'm sure some companies would make a fortune, but their lobbying power would be outweighed by other multinational companies like whatsapp and smaller companies like mullvad.
- PoignardAzur 3y agoHuh, they took a pretty holistic approach to the issue.
- gmerc 3y agoThe price of freedom is eternal vigilance wasn’t a platitude
- TacticalCoder 3y ago> ... which violate fundamental rights and stand no chance in court Thankfully the EU still has the European Convention on Human Rights and an associated court which individuals can go to and sue their state: the European Court of Human Rights. This is unlike the European Court of Justice which cannot directly be seized by individuals. That EU Convention on Human Rights contains the "right to privacy" (art. 8). This may be what they meant by saying that this horrible text stood no chance in court: a deluge of individual going to to the EU Court of Human Rights invoking article 8. Now I don't doubt that the sold outs and enemy of the EU states at the European Commission are going to come back with other horrible measures. As a sidenote this whole "good cop (European Parliament) / bad cop (European Commission)" is a bit of a farce played on the EU people too.
- eigenket 3y agoDespite the lobbying from American organisations (Google, Facebook, Microsoft, Amazon, Palantir and others who worked with Thorn on this [1][2]) the EU Parliament did the right thing this time. [1] https://www.thorn.org/partnerships/ https://www.thorn.org/partnerships/ [2]https://web.archive.org/web/20130420162917/http://www.wearethorn.org/aboutus/#techTaskForceExpanded https://web.archive.org/web/20130420162917/http://www.wearet...
- PoignardAzur 3y agoContrary to popular opinion, lobbying isn't as simple as "pay for expensive restaurant, get votes". If legislators feel strongly ideologically about an issue, no amount of lobbying will make them vote the other way.
- eddtries 3y agoHow do you explain big Pharma lobbying to stop reducing drug prices? For example, Democrats who held up drug pricing reforms were the largest beneficiaries of lobbyist money. https://www.reuters.com/business/healthcare-pharmaceuticals/capitol-hill-drug-pricing-reform-opponents-among-biggest-beneficiaries-pharma-2021-10-25/ https://www.reuters.com/business/healthcare-pharmaceuticals/...
- zakary 3y agoEveryone has a price, and drug companies can usually find a way to meet it for even the most steadfast
- eddtries 3y agoYeah I agree, I was responding to > If legislators feel strongly ideologically about an issue, no amount of lobbying will make them vote the other way.
- JoshTriplett 3y ago> Everyone has a price Some people really do have principles they won't violate. We just don't get enough people in politics who don't have a price.
- throwaway2990 3y agoWhatsApp will claim its end to end encryption and can’t scan the messages when they can and do.
- rkangel 3y agoCitation?
- throwaway2990 3y agoNo citation needed. If the statement was false we wouldn’t get advertising based on conversations that happen in what’s app.
- _zoltan_ 3y agowe don't? and meta refuted even planning it.
- rkangel 3y agoI've heard this claim many times, and have yet to see anything to substantiate it. I'm not saying I don't believe it - I have zero trust in Meta, and use Matrix and Signal with everyone that I can. But I would like evidence of foul play before making specific claims.
- contrarian1234 3y agoIsn't this is already a solved problem? This feels like a huge loss for player like Signal that actually ensure privacy by design
- orian 3y agoIt's not that simple. If the country introduces a legislation, every company operating in it's border must comply. If EU would introduce such legislation, it could potentially make software doing end2end encryption illegal. In such case, google would be removing it from EU Play Stores, and this would be more/less end of such messaging apps unless they comply. :-) This is why it's important to have a reasonable legislature and laws.
- ta1243 3y ago> This is why it's important to have a reasonable legislature and laws. And multiple points of control. In the EU the council acts as a check on populism through parliament (even if the nazis took over parliament it wouldn't give them a lot of power), parliament acts as a check on the council (even if the heads of 70% of EU countries decided something, parliament gets its say). Neither of those are the executive so they would be unable to push through laws which favour specific countries or groups of countries (as the commission are supposed to act primarily on behalf of the union, in the same way the US president is supposed to not favour his home state). Then outside of government you have the judiciary who look at the laws passed and interpret them in line with other laws, throwing out ones which are incompatible.
- contrarian1234 3y agoIt'd give people all the more incentive to sideload and get off Google Play Store. That's a win win in my book. And Signal is a non-for-profit. I don't see why they'd care. Designing system that subvert authoritarian regimes.. what's more punk than that If you have to ask governments for permission then that's a bad design and your system will be taken away from you when the next think-of-the-children populists are elected If you work on the assumption all governments are eternally nice and well interventioned .. then E2E chat systems aren't all that necessary in the first place
- yreg 3y agoHopefully, this settles it once and for all in the EU, similar to the Net Neutrality regulation from 2015.
- jacquesm 3y agoUnlikely. What will happen is that instead of one big push to the EU they will try again on the local level. That's how companies abuse the EU all the time. First try to lobby the EU itself for a one-stop-shop approach, and if that fails they go after the member states.
- yreg 3y agoDo you have examples? Ideally related to digital things or privacy. (Thanks)
- jacquesm 3y agoPrivacy is an excellent example. At first it was locally dealt with, and big tech would lobby the individual countries for all kinds of exceptions and ways to effectively get regulatory capture. Then, in 1995 the EU created the DPD. https://en.wikipedia.org/wiki/Data_Protection_Directive https://en.wikipedia.org/wiki/Data_Protection_Directive Big tech and the advertising industry responded by sidestepping the new regulation to make deals with the individual countries to undermine it, and actually managed to get close to getting their way, and possibly to get it repealed completely. https://www.nu.nl/internet/2849758/druk-van-lobby-opstelten-privacyregels-.html https://www.nu.nl/internet/2849758/druk-van-lobby-opstelten-... But the EU responded with the GDPR. And now big tech is again lobbying and pressuring member states for exemptions, for example, Facebook: https://www.theguardian.com/technology/2019/mar/02/facebook-global-lobbying-campaign-against-data-privacy-laws-investment https://www.theguardian.com/technology/2019/mar/02/facebook-... This is just venue shopping, can't get what you want in one place then you just fragment it and try to get multiple smaller deals. So I totally expect a similar thing to happen around this subject, the stakes are just too high for them to ignore the whole EU for their games.
- waihtis 3y agoI've become so jaded by the EU that was expecting the worst from this, so kudos Let's see how quickly it'll resurface again
- sebstefan 3y agoI was jaded by this proposal as well, but jaded by the EU in general? GDPR, forced interoperability from gatekeepers, the 2 year warranty on anything bought online This attempt at breaking encryption completely stood out with the usual things The EU seems like the only governmental organization that's working well to improve my life, in my country. Everything else is either decaying or opposing my values.
- xsdu 3y agoI'm still bitter about their half-baked cookie law that instantly made web browsing a much worse experience, regardless of how well-intentioned it may have been.
- arlcode 3y agoSpecifically in the digital space the DMA and DSA try (and will probably at least partially succeed) to break the plattform feudal rule and move their role more towards that of a public utility by restricting how they can use their market power. That'll have a massive (I think positive) effect on the digital economy.
- waihtis 3y agoJust one example: https://last-chance-for-eidas.org/update-151123 https://last-chance-for-eidas.org/update-151123
- nehal3m 3y agoI was upset at the parliament for even considering this and extremely relieved that they chose not to pursue this draconic instrument. That said, we as citizens will have to remain vigilant and let our voices be heard because the onslaught on our privacy is constant from both commercial interests, spy agencies and state actors. These parties have no issue keeping pressure up over decades whereas we the citizens can become exhausted and exasperated. We need some laws to swing our way; enshrine our rights to privacy in clear terms so implementing laws like chat control become a non-starter.
- eigenket 3y agoThe EU parliament did its job pretty much 100% correctly in my opinion. Their job is to consider the laws the EU commission suggests and thats what they did. They correctly determined it was a shitty law and voted it down. In my opinion you should be upset at the EU commission, and especially commissioner Ylva Johansson from Sweden who seems to be the one pushing this stupid stuff.
- nehal3m 3y agoI have to admit I'm not very knowledgeable about the process, so I thank you for correcting me. :-)
- lock-the-spock 3y agoThe previous commenter is not correct. Parliament votes for its own position on this law, which is then negotiated with the Council ( the 27 national government representatives) which itself has already developed a position. The two institutions negotiate a compromise (wir support from the commission as broker) which then both institutions must vote on in order for it to become EU law. So they can still vote something down later, but generally if it comes to a vote on the final text it is already a position parliament agrees with. In the EU processes laws that are unlikely to be agreed usually don't even get to a vote, rather the commission withdraws it's proposal and provides a new one.
- lost_tourist 3y ago
- pierrelf 3y agoHuge privacy W, I was really worried for a while there. Wonder what effect the emails and protests had!
- asimpletune 3y agoNext step would be OS maintainers to make APIs for providing e2e encryption functionality and then app stores requiring these apis to be used for private messaging.
- bradley13 3y agoBecause you trust closeed-source from Microsoft, Google and Apple? Seriously? Open standards, open-source code. That's really the only option for code people are supposed to trust.
- asimpletune 3y agoAll security is built on trust. If your threat model is trust nothing, then the solution is do nothing. What I’m talking about is called anchoring, where you force a critical flow through a single anchor by design, and thus reduce the places that you have to audit. It’s the same reason they say that all security should be baked in the keys (strength, mgmt, exchange, etc…). Do I trust Apple and Microsoft? I think sort of. I don’t trust them to be perfect, but if your prior is to say that you don’t trust them at all, then it means you basically can’t use them at all bc no amount of security will get around an untrustworthy OS. They control what gets displayed on screen, they control how memory is laid out and accessed for a program. There are already so many more important things we entrust to them. So, yeah, I prefer OS’s (all vendors) to provide APIs, and for app stores to enforce their use. I especially would trust this more than EU laws, and I certainly would trust that more than everyone doing their own thing, regardless if it’s open source. If for no other better reason I trust the OS more, since all of these open solutions will still run on those supposedly untrustworthy os vendors. You basically have to trust your OS, Don’t you think? Otherwise, the answer is you do nothing.
- qwytw 3y agoWhy wouldn't you trust them? To some extent at least? I mean if they are claiming their messaging system is E2E and it turns out it isn't the cost to them (not only financial) would be much higher than whatever they earn from having access to your data.
- rkangel 3y agoThis website is a throwback to a design choice that (thankfully) has mostly died off - choosing a mid-grey for your text, making it much more effort to read. I used to have Stylebot pinned to my extensions to fix it, but haven't had to do it in ages. Designers - please don't do this. (I think it comes from people designing on much higher contrast Apple monitors and not testing on anything else)
- ale42 3y agoIndeed it looks like all the text is grayed out... like "I'm waiting for you to click that damn accept-cookie button before actually showing the page".
- yreg 3y agoIronically, your own (downvoted) comment on this site is even more difficult to read. But you are right, the Tuta article has a contrast ratio of 4.35:1, which doesn't pass even the lower WCAG level (AA = 4.5:1). Accessibility is important. We are all going to depend on it if we live long enough.
- theonlybutlet 3y agoI'd love to know who was in favour of the new better proposal and who was in favour of the old proposal. A clear insight into their values. It's EU parliamentary elections next year, I'd nearly argue those supporting this new better proposal would be a good voting choice next year and to steer clear of those in favour of the old proposal.
- qwytw 3y agoUnfortunately only a tiny proportion of population in the EU keep track of what their MEPs are actually doing and most vote more or less the same way they'd vote in national elections (where I am it's more like an opinion poll preceding the 'real' elections which always happen ~6 months after the European ones).
- layer8 3y agoEU Parliament votes are published, so you'll be able to look it up.
- Ekaros 3y agoMakes lot of sense. In some EU countries like Finland the privacy of communication is a CONSTITUTIONAL right. So you need good reason to break it. And I don't think generic muh terrorism passes the bar.
- eigenket 3y agoEven more than that, its article 7 of the European Charter of Fundamental Rights so its baked into the foundation of the EU itself via the Treaty of Lisbon (which is why its unsurprising this law failed to pass the EU parliament). Even if somehow this law did get passed the parliament the EU's courts should have struck it down.
- deleted 3y ago[deleted]
- AlecSchueler 3y agoThe EU needs to stop it with all this heavy handed regulation. At the end of the day it only hurts businesses. Businesses rely on the data contained within these communications in order to improve their services. This is why US tech companies are growing while EU equivalents are not. It's all well and good to consider user privacy and user safety but not when it stifles the market. [Please note that this is a satirical comment based on some of the arguments I've seen here in the past]
- matt_j 3y agoSure, Satan.
- d3w4s9 3y agoIs that you Zuckerberg?
- zabzonk 3y ago> while EU equivalents are not. doh, ARM? edit: please add "edit" when you edit
- pelorat 3y agoThose comments are not entirely wrong. Regulation does hurt, but the main issue is that even though the EU is a single market in theory, it's made up of nations that each have their own market and speak their own language. Not a lot of new tech companies target the entire EU, they mostly target their domestic market and certainly not the USA. In the USA it's easy for a new tech company to put out a commercial to target the entire US population of more than 300 million people. This is practically impossible in the EU. The market here is actually very fractured. We have "big" tech companies in each EU nation, but they cater only to the domestic market. "Big" as in they are dominant in their field inside their nation. Take online payment systems for instance. While there are global EU companies like Klarna, most EU nations has their own system that everyone uses. So while you usually have a bunch of payment options to chose from, 99% picks the national one (usually no processing fees). This also applies to a bunch of other apps in the EU. If you create an app or a service in the EU and you want it to succeed, you need to target your domestic market first. However chances are there's already an app or service for your idea and you'll have zero chance to compete on the international market, even if you translate your service to as many languages you can think of.
- qxfys 3y agothe fact that this thing needs to be discussed in the parliament in the first place is an absolute waste of time.
- sixhobbits 3y agoWhat's the closest thing to EFF for these kinds of things in Europe? I always feel like there's a huge difference in quality of reporting where EFF produces some of the best content I've ever read on any topic, and stuff about EU privacy is often a lot harder to follow. I know about statewatch and some individuals I follow who do a pretty good job, but feels like there is a gap for an organization to step and replicate what EFF does in the US. I would happily support with money and time.
- schmudde 3y agoYou might try Brave New Europe? They don't look at tech specifically like EFF, but tech touches their stories on economics, regulation, and the media: https://braveneweurope.com/?s=tech https://braveneweurope.com/?s=tech
- skowalak 3y agoMaybe EDRi, which also acts as an umbrella for smaller and local orgs. https://edri.org/about-us/who-we-are/ https://edri.org/about-us/who-we-are/
- schmudde 3y agoPrefect combination with Article 45 (https://www.eff.org/deeplinks/2023/11/article-45-will-roll-back-web-security-12-years https://www.eff.org/deeplinks/2023/11/article-45-will-roll-b...). You can roam around EU versions of websites that rely on government own certificate authorities and allow you to log in with your eIDAS id - which will be a requirement for all "very large online platforms." The EU Parliament giveth and taketh away.
- codeptualize 3y agoThis is exactly as I expected it would end. We'll see this happen again, and again, and again. Some politician gets the genius idea to have backdoors in encryption, initial support, then reality sets in and the plans are abandoned. There is just no sensible way to implement this, therefore it's not going to happen. This iteration did go a bit further than usual.
- TacticalCoder 3y agoPrivate messages won't be scanned for now, but what about the certificates in web browsers that could be swapped at will by any certificate in the control of some EU apparel so that "encrypted" web traffic could be sniffed and MITMed? Which moreover came with a fineprint specifying that it'd be illegal for browsers to warn users about certificate being swapped? Is that out of the window for now too?
- sofixa 3y ago> Private messages won't be scanned for now, but what about the certificates in web browsers that could be swapped at will by any certificate in the control of some EU apparel so that "encrypted" web traffic could be sniffed and MITMed? That was a (probably) unintended consequence of the eIDAS legislation, where specific Certificate Authorities must be trusted by browsers to enable digital certificates and signing to work EU-wide. This has since been corrected and the legislation explicitly states that those CAs and the regular CAs can and should be kept separate, thus MITM won't be possible unless the browser chooses to mix things.
- tasubotadas 3y agoThank you
- Twisell 3y agoMore in depth analysis from a NGO lobbying for online privacy: https://edri.org/our-work/eu-parliament-committee-rejects-mass-scanning-of-private-and-encrypted-communications/ https://edri.org/our-work/eu-parliament-committee-rejects-ma...
- DocTomoe 3y ago... unless it is them who does the scanning. The "Mandatory government-issue SSL certificate" is still on the table.
- zaxomi 3y agoWow, EU Parliament did the right thing this time. When I heard an interview with a Swedish EU politician, I thought it was a lost cause. She was completely blinded by the possibilities and saw no downside whatsoever.
- omgmajk 3y agoI guess you are talking about Ylva Johansson, who is the spearhead of this. Every time she opens her mouth on this subject any person with knowledge on this subject breaks on the inside a little more, she has no idea what she is trying to do. Or maybe she does and it's all a smokescreen, I don't really know.
- kypro 3y agoPerhaps worth noting that the only branch of EU which is directly elected is the parliament.
- NoboruWataya 3y agoSurely not - I only ever hear that the Parliament is toothless body that rubber stamps whatever the Commission proposes.
- mbwgh 3y agoContrary to what this heading suggests, nothing has been "decided" here. This article is not only inaccurate, it is falsely misleading. The Committee on Civil Liberties, Justice and Home Affairs (LIBE) adopted a "draft Parliament position" [0] and that's that. This still needs to go through so-called "tri(a?)logue negotiations", held between the EU parliament, commission and council. [1] Still a tad early for calling this a win! [0] - https://www.europarl.europa.eu/news/en/press-room/20231110IPR10118/child-sexual-abuse-online-effective-measures-no-mass-surveillance https://www.europarl.europa.eu/news/en/press-room/20231110IP... [1] - https://netzpolitik.org/2023/ueberwachung-eu-innenausschuss-stimmt-fuer-die-ablehnung-der-anlasslosen-chatkontrolle/#netzpolitik-pw https://netzpolitik.org/2023/ueberwachung-eu-innenausschuss-... (German)
- latexr 3y ago> tri(a?)logue It’s not a trial-ogue. It’s a tri-logue because it involves three parties.
- yccs27 3y agoIt's also not a dial-ogue, but a di-a-logue because it involves two parties.
- Obscurity4340 3y agoAh, so this is what the whole polylogue has been surrounding
- Obscurity4340 3y agoTripartite might also work
- danaris 3y agoAh, yes: negotiations between the EU Father, the EU Son, and the EU Holy Spirit.
- gnfargbl 3y ago> In contrast to the original chat control proposal, the version of the EU Parliament wants that a new EU Child Protection Centre proactively searches publicly accessible parts of the internet for child sexual abuse material with automatic crawling, which can also take place in darknet and would be much more efficient than private surveillance measures by providers. Found abuse material must be reported and taken down by the provider. This is a good start, if it is sufficiently well-funded and appropriately staffed. I hope that they crawl much more than the public "clearnet" and "darknet", since a lot of media is shared inside the various walled gardens that make up the internet here in the '20s.
- sva_ 3y agoI'm very relieved by this. It is shocking that there was even the possibility of such a law passing, because it would've turned a lot of people, including myself, absolutely against the EU.
- greatgib 3y agoWhat really blow my mind is that now we need so much energy and be that thankful to the EU for something that should be so basic and obvious. When you compare how scandalous and impossibly excessive was looking the story of "1984" a few dozen years ago and that now it is the new normal. In a lot of countries, even democratic ones, we are already far worse than what was described in the book. But very little persons are shocked about that...
- deleted 3y ago[deleted]