4 ms·
FTA: What changes with the return of Chat Control 1.0—and what stays the same: *What is coming back:* US tech companies are once again allowed to scan privat
by mrtksn 3mo ago
FTA:
What changes with the return of Chat Control 1.0—and what stays the same:
*What is coming back:*
US tech companies are once again allowed to scan private messages without a warrant or prior suspicion. This affects direct messages on platforms like Instagram, Discord, Snapchat, Skype, and Xbox, as well as emails via Google’s Gmail and Apple’s iCloud.
*What remains unchanged:*
Public social media posts and files hosted in cloud storage could already be scanned without this law. Furthermore, private messages can always be reported by users, or monitored by authorities using targeted, court-ordered wiretapping.
*What is still NOT being scanned:*
End-to-end encrypted chats, such as those on WhatsApp, have always been exempt from these scans. Additionally, European providers of messaging and email services have never implemented chat control measures.
So, E2E is unaffected?
- lrae 3mo agoYes. Chat Control 2.0 was the big one in those regards. (Also, LOL @ Skype mention.)
- mrtksn 3mo agoThen I'm not very moved about this. I always assumed that anything unencrypted is scanned one way or another. What I care is not having a backdoor for E2E, i.e. like client-side scanning telling me what I am allowed to talk about like with the LLMs. CSAM excuse is a great excuse to turn every conversation to what we have with AI today.
- stavros 3mo agoAnd the temperature of the frog pot rises by one degree.
- mrtksn 3mo ago[flagged]
- hnhg 3mo agoIt's a metaphor for a process. Calling people names like "maxxers" is unhelpful and probably against the rules here.
- mrtksn 3mo ago>It's a metaphor for a process. Calling people names like "maxxers" is unhelpful and probably against the rules here. Yeah we don't mean frogs, that's obvious. Calling people maxxers being offensive is surprising. Maybe you should consider offended for being called cancer instead?
- JoshTriplett 3mo agohttps://en.wikipedia.org/wiki/Argument_to_moderation https://en.wikipedia.org/wiki/Argument_to_moderation The truth is not always somewhere in the middle. If one group wants to serve water and another wants to serve cyanide, the right answer is not to mix the two, it's to serve water and to end the careers of the people who wanted to serve cyanide.
- mrtksn 3mo agoI am not arguing for a middle ground, I argue for addressing the issues directly instead of being maximalist in any way.
- JoshTriplett 3mo agoYou are dismissing things as "maximalist", which is not conducive to treating certain things as sacrosanct. For example: end-to-end encryption is sacrosanct, and must not be broken, ever. If you want access, your only option should be to serve one of the ends a warrant. That's not "maximalist", that's holding to a principle.
- kode-targz 3mo agoI disagree. The definition of "bad actor" constantly changes. Something you do legally today can and will become illegal in the future, and if you don't change your ways, you will be a bad actor, too. The people pushing for this under the guise of protecting children are the same people who went on The Island, or at least protect those who did. They never cared about children's safety. The biggest criminals of all are the very same people pushing for these laws, this surveillance, this control. Don't be fooled.
- alanwreath 3mo agoI assume the same, but not because it’s sanctioned. Sanctioning is a slippery slope or a degree change as has been mentioned.
- zelphirkalt 3mo agoIf reading messages that are not for ones eyes is OK, then it is a much smaller step to the next level, which is to also being able to read encrypted messages. Slowly boiling the frog.
- shangofox 3mo agoBut the next level IS the chat control 2.0 and yes it is the one people should be concerned about. But it's not like this is unprecedented this is literally just an extension of something that existed.
- Idesmi 3mo ago> I always assumed that anything unencrypted is scanned one way or another By this logic, I should be happy if mail delivered to my address always arrives already open.
- raverbashing 3mo agoAre my AIM chats safe?! /s
- mghackerlady 3mo agoYou kid, but there are still some active AIM users (or at least, a revival of it)
- ibejoeb 3mo agoYou should be using AIM OTR: https://otr.cypherpunks.ca/ https://otr.cypherpunks.ca/
- Bender 3mo agoAdding to this there is pidgin-otr and python-potr. For IRC there is irssi-otr. There was weechat-otr but I think it may have gone unsupported as their script did not work in python3. There is also ejabberd [0] that has OMEMO [1] preferred over OTR and PGP and supports many to many E2EE. Someone tried to MitM Jabber, discussion here on HN [2]. [0] - https://ejabberd.im/ https://ejabberd.im/ [1] - https://en.wikipedia.org/wiki/OMEMO https://en.wikipedia.org/wiki/OMEMO [2] - https://news.ycombinator.com/item?id=37955264 https://news.ycombinator.com/item?id=37955264
- bombcar 3mo agoDon't downplay Skype, as Teams is still just rebranded Skype for Business (LYNC).
- scotty79 3mo agoAre the messages to LLMs scanned (beyond normal collection for future training purposes) or is that just for human-to-human messenging?
- KETHERCORTEX 3mo agoYes. I see no reason to think otherwise.
- scotty79 3mo agoWhat's the purpose of this law? Protecting the recipients or punishing the senders?
- ganzsz 3mo agoI don't know what the companies want with it. But they'll try to hide the logs in discovery for a lawsuit. [1]As nyt found out. https://arstechnica.com/tech-policy/2026/07/openai-faked-inability-to-search-training-data-hid-billions-of-logs-nyt-says/ https://arstechnica.com/tech-policy/2026/07/openai-faked-ina...
- budududuroiu 3mo agoThe Internet Watch Foundation, the group, funded almost entirely by big tech, who pushed for this vote to be held under emergency procedure, is already at work lobbying for the end of E2EE [1]. In a couple years time, Chat Control 2.0 will come about, and the same tyrants will use the EU admission [2] that there is no evidence that suspicionless scanning of private communications has led to an increase in criminal convictions or in rescued children to argue that we need to go further, and break E2EE. [1]: https://www.iwf.org.uk/resources/end-to-end-encryption-and-keeping-your-child-safe-online/ https://www.iwf.org.uk/resources/end-to-end-encryption-and-k... [2]: https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:52025DC0740 https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE...
- ratorx 3mo agoDo you have source for IWF funding being by big tech? Haven’t found anything that breaks their funding down by source and the majority on the UK govt site is from “charitable activities” (https://register-of-charities.charitycommission.gov.uk/en/charity-search/-/charity-details/4013804/charity-overview https://register-of-charities.charitycommission.gov.uk/en/ch...)
- NopIdoN 3mo agohttps://www.iwf.org.uk/membership/our-members/ https://www.iwf.org.uk/membership/our-members/ The top 25 members (£90k+; big tech are here) contributed between £2.25M and £4.37M. The other 110 members contributed between £2.26M and £4.46M.
- throwaway_5633 3mo agoHonestly they have a lot of members including the BBC for some reason, Apple is one of them. It seems like it might just be good practice to support them, it signals ‘we are against child abuse’. Dropping support could lead to some bad headlines. Seems like an NGO that is really good at sales, probably putting some pressure on it’s members rather than the other way around. I get that if you are an ngo that really wants to solve online child abuse you’d want a law like this. It may be mostly the ngo pushing for it, not necessarily big tech. I could be wrong.
- phito 3mo agoDoes this apply only to new messages or also to history?
- armchairhacker 3mo ago[dead]
- nonethewiser 3mo agoSkype?
- sneak 3mo ago> What is coming back: US tech companies are once again allowed to scan private messages without a warrant or prior suspicion. This affects direct messages on platforms like Instagram, Discord, Snapchat, Skype, and Xbox, as well as emails via Google’s Gmail and Apple’s iCloud. They are already allowed to do this, and already are doing this. When you provide data to the service provider in a non-e2ee fashion, it's their data as much as it is yours. They can scan it, data mine it, analyze it, whatever.
- omnimus 3mo agoThis is the whole point though. They are allowed to do this because of the original chat control from 2021 which was temporary and expired in march. Without chat control it is very debatable what companies can legally thanks to eprivacy directive.
- IanCal 3mo agoThey aren’t allowed to do whatever they want with your data, there’s strict restrictions on requiring consent for things you want to do with user data.
- sneak 3mo agoYes, and you consent when you enable iCloud.
- flumpcakes 3mo agoI assume those 400-page EULAs blast away any 'strict restrictions'.
- IanCal 3mo agoNo, GDPR spells out in much more detail what consent means - and burying things in a EULA doesn’t work.
- EagnaIonat 3mo ago> So, E2E is unaffected? Because its an extension of an existing bill. After the whole internet lost its mind about Apple CSAM scanning and being horribly off target, I'd recommend to ignore news reports and go to the sources when making an opinion. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A52022PC0209 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A... https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=COM:2025:797:FIN https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=COM... The only issues I can see is the error rate for non-CSAM scanning and how the latest vote was conducted. Although the scanning part, it is still law enforcement that has to review that information and determine if there is a case. Most of the those are teens sharing naked photos with other teens.
- miohtama 3mo agoGuess what's coming next: > Overview > End-to-end encryption is a term used to describe blocking or preventing any third-party recipient from viewing, reading or becoming aware of information that one individual has sent to another. In response to growing concerns about online data security, many technology companies are adopting this strategy with potentially dire circumstances. > The use of end-to-end encryption would prevent the companies or any third-party from detecting illegal activity occurring on their platforms, including the activity of people who use the internet to perpetuate online demand for graphic sexual abuse material of children. > We believe personal security is extremely important and support efforts to improve online privacy. But, if this solution is implemented with no exceptions for detecting child sexual exploitation, millions of incidents of abuse will remain hidden, leaving these young victims without any help or protection from these horrific crimes. https://ncmec.org/theissues/end-to-end-encryption https://ncmec.org/theissues/end-to-end-encryption
- throwwwll 3mo ago[dead]
- deleted 3mo ago[deleted]
- tomerlir 3mo agoE2E is unaffected... For now
- sylware 3mo agoAnd your REALLY think E2E is going to "protect" you? If the "services" want to watch, don't worry they will, "they don't need your password". But I guess they "do" that only for the very baddies, aka child exploitation, human trafficking, terrorists, killers, drug dealers, etc. We all know here that "information system security" does not exist, this is a fantasy: there is only some "best effort" with a wide spectrum of compromises. If somebody talks to you about "deliverable security", that guy wants to sell you something. E2E will protect you only against John Doh, "hacker only on Sundays". And we better keep that in mind.
- exfalso 3mo agoWhat are you talking about. You think service providers can backdoor aes-gcm? There will always be technology that they cannot get around. The only way to backdoor is to explicitly change the encryption.
- sylware 3mo agoAre you misunderstanding on purpose? This is not specific to 'backdooring aes-gcm implementations' at all. Read again what I wrote, namely this is the general status quo on 'information system security': they don't need your password or aes-gcm key to watch if they really want to. You would be a fool to presume anything else.
- int_19h 3mo agoService providers like say Apple and Google can push an update to your phone which will intercept all that data after it has been decrypted.
- exfalso 3mo agoI understand. So don't use them. There are plenty of OS alternatives