6 ms·
OK, really hot take here: -ChatControl, as it is currently defined, is not going to happen, because it's absolutely stupid and would make impossible, amongst o
by ZeroConcerns 1y ago
OK, really hot take here:
-ChatControl, as it is currently defined, is not going to happen, because it's absolutely stupid and would make impossible, amongst other things, online banking
-Yet, there is a growing and legitimate demand for lawful interception of 'chat' services. I mean, "sure, your bank account got emptied, but we can't look into that because it happened via Signal" just isn't a good look
-So, something has got to give. Either 'chat' services need to become 'providers of telecoms services' and therefore implement lawful interception laws, or the malware industry will continue to flourish, or something even more stupid will happen
Pick your poison.
- JoshTriplett 1y ago> So, something has got to give. Something does have to give: the constant demands for interception capabilities on end-to-end encrypted protocols. Those demands must be thoroughly destroyed every time they rear their head again.
- _cenw 1y agoIt's interesting that this initiative seems to be mostly driven by influential actors in the "online safety" space that want their flawed scanning tech embedded into every device. Thorn is the most public-facing one, but if you dig into advocacy groups you'll find there's a dozen or so more, and they competed for being the technical solution to the UK online safety act too. But if it involves CSAM it's an even more perfect monopoly - only a very select group of people can train these models because the training data is literally illegal to possess. If you needed any indication for how these pseudo-charities (usually it's a charity front and a commercial "technology partner") are not interested in the public good, SafeToNet, a company that up until last year was trying to sell a CSAM livestream detection system to tech companies to "help become compliant" ("SafeToWatch") now sells a locked down Android phone to overprotective parents that puts an overlay on screen whenever naked skin can be seen (of any kind). It's based on a phone that retails for 150 pounds - but costs almost 500 with this app preinstalled into your system partition. That's exceptionally steep for a company that up until last year was all about moral imperatives to build this tech.
- theelous3 1y agoI haven't seen anything that suggests chat control would do anything to e2e. I am genuinely curious. It seems to be an often parroted point but... ? It's just local image hashing and matching? Or is this only one implementation idea?
- JoshTriplett 1y agoChat Control is in some ways a response to E2E, by saying "let's backdoor the endpoints, then".
- RiverCrochet 1y agoI would rather online banking be impossible, or only available to those that take training and sign waivers, than have all my communications surveiled.
- ZeroConcerns 1y agoOK, you be you, But please note that I did not list "online banking becoming impossible" as a likely outcome. Merely malware continuing to be state-sponsored, or certain communications to be surveilled. Not all of yours, unless you draw an especially vinidicative judge (and yes, I'm assuming a functioning rule of law here -- if that's gone, what's left?)
- RiverCrochet 1y ago> OK, you be you I don't know what you mean by this. > But please note that I did not list "online banking becoming impossible" as a likely outcome. No, but it should be a likely and maybe even desired outcome, especially if a justification for surveillance is the prevention of online banking fraud among other crimes. > Merely malware continuing to be state-sponsored, or certain communications to be surveilled. Norms and mores change over time, so the only conclusion is that "certain communications" will become "all communications" at some point in the future. I'd love to be proven wrong.
- ZeroConcerns 1y ago> Norms and mores change over time Yeah, but laws tend to be more constant, and lawful interception laws are, 100% guaranteed, a thing, right now, in the country where you live. They apply to telegrams, postal mail, telephone conversations, and a whole bunch of other things nobody really does anymore. They don't really apply to the things people do tend to do these days. ChatControl is an incompetent attempt to remediate the lapses in law enforcement that this has caused. I strongly oppose it. But I also strongly oppose the idea that the Internet should be off limits for any kind of law enforcement, unless it is through dubious mechanisms like state-sponsored malware. Your "slippery slope" argument is much more compelling in the absense of extended lawful interception than in the situation where Signal messages would somehow be equated to postcards or SMS messages...
- iamnothere 1y agoI’ll take the malware thanks
- gr__or 1y agowhile this is a link to the malware site x.com, it is shown in a protective trustworthy hull, called xcancel.com
- qwopmaster 1y agoMalware, easily
- PickledJesus 1y agoHow do you propose it's implemented though? The two sides in this debate seem to be talking at cross purposes, which is why it goes round and round. A: "We need to do this, however it's done, it was possible before so it must be possible now" B: "You can't do this because of the implementation details (i.e. you can't break encryption without breaking it for everyone)" ad infinitum. Regardless of my own views on this, it seems to me that A needs to make a concrete proposal
- ZeroConcerns 1y agoLawful intercept laws exist, and they've been sort-of functional for ages. Apps like Signal don't entirely fall within the scope of these, which is the cause of the current manic attempts to grab more powers. My point is that these powers grabs should be resisted, and that new services should be brought into the fold of existing laws. The prevailing opinion here seems to be that, instead, state hacking should be endorsed. Which, well...
- qwopmaster 1y agoThe prevailing opinion here seems to be that we’d really like for there to not be an omnipresent panopticon because protect the children or terrorists or, apparently, malware. If your imagination is particularly lacking on how this might be weaponized just remember that antifa is now designated as an terrorist organization in US, so you better not be a suspected member of it — as in, you best not have sent a buddy a message on signal about how those tiki torch carrying nazi larpers aren’t exactly great guys, or off to a black site you go for supporting terrorism. If you want to prosecute people send physical goons, which are of limited quantity, rather than limitless, cheaper and better by the day pervasive surveillance of everybody and everything.
- ZeroConcerns 1y ago> an omnipresent panopticon OK, sorry to keep repeating myself here, but... I strongly oppose any kind of "panopticon" like ChatControl. What I would like to see, is, say, Signal complying with lawful interception orders in the same way that any EU telecoms provider currently does. So, provide cleartext contents of communications to/from a cleary identified party, for a limited time, by judicial order, for a clearly specified reason. > pervasive surveillance of everybody and everything This is exactly what lawful intercept laws are supposed to prevent. And yeah, of course, abuse, but under a functioning rule of law there are at least ways to remedy that, unlike with mass surveillance and/or malware...
- blurbleblurble 1y agoWithout confidential and private spaces, how in the world can relational trust be cultivated? And how in the world can we have safety if relational trust is suffocated before it can even take root? Please use your imagination! Those aren't the only options if we embrace trust as essential rather than looking at any need for it as a liability.
- dylan604 1y agowhy do you think they want relation trust. unless you mean trusting that if you go against the man, the man will come for you. maybe it would be better for s/trust/fear/
- blurbleblurble 1y ago: _ (
- lukan 1y ago" "sure, your bank account got emptied, but we can't look into that because it happened via Signal" just isn't a good look" Do you want the police to regularily intercept and check your signal chats for fraud and crime so this does not happen, or what is the point here?
- ZeroConcerns 1y ago> You want the police to regularily intercept and check your signal chats for fraud No, that's not how lawful intercept laws work. I want police to be able to obtain a judicial order to intercept, for a limited time, in cleartext, the (Signal chats, or whatever other encrypted communications) of identified parties reasonably suspected to be involved with criminal activity. ChatControl is not that, and it's one of the reasons it's a nonstarter.
- lukan 1y ago"I want police to be able to obtain a judicial order to intercept, for a limited time, in cleartext, the (Signal chats, or whatever other encrypted communications) of identified parties reasonably suspected to be involved with criminal activity." They already have that in most (?) jurisdictions by now. With a warrant, they can install a virus on the device that will then do targeted surveillance. ChatControl is bad, because it is blanket surveillance of everyone without warrant.
- ZeroConcerns 1y ago> With a warrant, they can install a virus on the device that will then do targeted surveillance Yeah, and that sponsors an entire malware industry! I don't really know how I can make my position any clearer, but... -Malware: bad! -ChatControl (encryption backdoors): bad! -Inability to do any kind of law enforcement involving "the Internet": double-plus bad! -Enforcement of existing lawful interception laws in the face of new technology: maybe look at that?
- lukan 1y ago
- mattnewton 1y agoI am having a legitimately hard time wrapping my head around not being able to prosecute bank fraud because signal exists. Was it impossible before when criminals would talk in person instead over a recorded telephone?
- ZeroConcerns 1y agoNo? But lawful intercept laws were never about "criminals [talking] in person". There's a different set of laws for that...
- rstat1 1y agoAnd we all know those laws are never abused and are absolutely only used to target criminals.
- ZeroConcerns 1y agoNo, there is definitely abuse of lawful interception. But, in a jurisdiction with a functioning rule of law, these abuses can be spotted and remedied. Doing the same for mass surveillance (such as ChatControl) or state-sponsored malware is much harder. I'm advocating against ChatControl and malware, and proposing existing lawful interception frameworks as an alternative. But, apparently it's not my day :)
- rstat1 1y agoChatControl is just lawful interception under a different name, but worse.
- awesome_dude 1y agoThere is a famous case of US Mafia meeting in rooms, or out on streets to discuss their "business activities" face to face to prevent authorities from surveilling the phone calls. The reason we know is because authorities were able to place listening devices into the rooms that they were in, or surveil them from other buildings.
- DeepSeaTortoise 1y agoWhy would the malware industry benefit from digital message privacy? If you're the victim, just hand over the relevant chats yourself. Otherwise, just follow the money. And if the attackers are sitting in a country whose banks you can't get to cooperate, intercepting chat messages from within that country won't do you any good either. Also, if someone has malicious intent and is part of a criminal network, the people within that network would hardly feel burdened by all digital messages on all popular apps being listened in on by the government. These people will just use their own private applications. Making one is like 30min of work or starting at $50 on fiverr.
- ZeroConcerns 1y ago> Why would the malware industry benefit from digital message privacy? Because if lawful interception of in-transit messages is not possible or permitted, hacking either the client or the server becomes the only option. You may enjoy reading https://therecord.media/encrochat-police-arrest-6500-suspects https://therecord.media/encrochat-police-arrest-6500-suspect.... Or just downvoting me. Or both.
- retr0rocket 1y ago[dead]
- DeepSeaTortoise 1y agoSure, if you want to read the messages, but the whole point is that that's rarely necessary and the price isn't worth the minimal gain. Of the serious criminals, the only ones you'll be catching are those with low technical knowledge (everyone else will just be using their own applications) and the Venn diagram of those with little tech knowledge and those whose digital privacy practices could deceive law enforcement resembles AA cups against a pane of glass. Regarding Encrochat, it is no surprise that an (unintentional?) watering hole gathered up a bunch of tech-illiterate, the fallacy is that those people wouldn't have been caught if they weren't allowed to flock to a single platform for some time. Would some people have not been caught until much later or even not at all? Sure, but if LE would do its job (and not ignoring, or even covering up, well known problem areas and organizations for years to decades), only those of low priority. Is that little gain worth creating a tool to allow Iran or similar countries to check every families' messages if they suspect some family member might be gay? Hard nope. > Or just downvoting me. Don't worry, I rarely do that and that's not just because I can't...
- Tuna-Fish 1y ago> -Yet, there is a growing and legitimate demand for lawful interception of 'chat' services. I mean, "sure, your bank account got emptied, but we can't look into that because it happened via Signal" just isn't a good look Why on earth would mass intercept be necessary or even help in that? If you got scammed by someone, then you can contact the police and hand over your message history. Why would the cops be interested in someone else's message history for this?
- ZeroConcerns 1y ago> Why on earth would mass intercept be necessary Lawful interception is not "mass intercept." It's the ability to surveil traffic from/to a clearly identified party, upon a judicial order for specific reason, for a limited time. ChatControl, on the other hand, is mass interception. I'm against it. Most people in the EU are against it. But to prevent things like ChatControl coming up over and over again, a basic tool to combat Internet crime is required.
- deleted 1y ago[deleted]
- stephen_g 1y agoThe problem we have is that was OK when someone had to actually listen in or you had to have a tape recorder connected up to every line you want to tap, or physically open individual letters. Now we have found “lawful intercept” can easily just become mass surveillance, and not just by the people who are meant to use it but other parties too. We saw this with CALEA which was used by China (and who knows who else) for espionage and spying for years before anyone realised. You make a system for the “good guys” and it always turns out adversary, criminal groups etc. will gain access, even if the “good guys” don’t start acting like bad guys themselves. Technology made mass surveillance easy, so every lawful intercept becomes mass surveillance as well as vulnerable to scammers, criminals and foreign intelligence. And we don’t have any way of making lawful intercept possible without that unfortunately.
- array_key_first 1y ago
- zwnow 1y agoIm sorry but I know my countries history, there is no good in "lawful interception"
- LudwigNagasena 1y agoA hot take: removing protections guaranteed by constitution should require modification of the constitution. There is already a "temporary" European regulation [1] that is in violation of the German constitution [2]. CSAR would be a further erosion of the legal foundation. Americans were happy when their federal laws that restrict marijuana use were simply ignored by executive fiat without proper processes, well, they aren't so happy now to see that other laws can be freely ignored too. If people speak up and say "take away our rights" at a referendum, let that be their decision, not a political backroom deal. [1] https://eur-lex.europa.eu/eli/reg/2021/1232/oj https://eur-lex.europa.eu/eli/reg/2021/1232/oj [2] Article 10 at https://www.gesetze-im-internet.de/englisch_gg/englisch_gg.html https://www.gesetze-im-internet.de/englisch_gg/englisch_gg.h...
- ZeroConcerns 1y ago> A hot take: removing protections guaranteed by constitution Lawful intercept laws exist in most, if not all, EU countries. It's just that super-national overlay services like Signal don't entirely fall within the framework of those. So, there is now a choice: expand interception powers indefinitely (a.k.a. ChatControl, which, to make things crystal-clear, I'm 100% against), or bring new services into the fold of existing legislation.
- LudwigNagasena 1y agoNo existing legislation requires proactive interception of mail, physical or electronic. Bringing new services into the fold of existing legislation would mean forbidding any proactive scanning by civilians and forbidding such scanning by authorities without a warrant or court order.
- ZeroConcerns 1y ago> proactive interception of mail, physical or electronic Lawful interception is not proactive: it requires a judicial order to collect plaintext communications from/to specifically identified individuals (resident in the country demanding the interception), for a limited time and for a specific purpose. ChatControl, which I strongly argue AGAINST would sort-of be what you describe. But: I. Am. Arguing. AGAINST. That.
- rstat1 1y agoMalware has existed nearly since the dawn of computing. Making the world even less secure under the guise of combating w/e today's latest bogeyman is is not gonna solve that. And having secure private communications is not gonna make it worse. That anyone thinks this blatantly obvious attack on free speech is actually going to be used only for law enforcement is wild to me.
- regularjack 1y agoNothing has to give. Police did their work fine for centuries, they can continue doing it without mass surveillance.
- leshenka 1y agoBut that's not a fair statement. Police did their work for centuries but it was nowhere near "fine" by modern standards and today there's a hundred ways more to commit crime
- pabs3 1y agoLawful intercept equipment is often targeted by criminals and nation states, the entire concept is extremely dangerous. https://en.wikipedia.org/wiki/2024_global_telecommunications_hack https://en.wikipedia.org/wiki/2024_global_telecommunications... https://unshakled.org/salt-typhoon-the-unintended-consequences-of-lawful-intercept/ https://unshakled.org/salt-typhoon-the-unintended-consequenc... https://group2000.com/articles/a-wake-up-call-for-securing-lawful-interception-systems/ https://group2000.com/articles/a-wake-up-call-for-securing-l...