Live data from Hacker News

Messaging and chat control

patrick-breyer.de

131–140 of 336 posts

Re: Messaging and chat control

#131
post #16
post #10

Assuming this is correct (I only followed a couple of links, but it would be the EU planning to mandate content scan for CSAM on all e-mail and messaging platforms, after making it legal/optional already to do so earlier this year), I guess this answer the question of why Apple released their tech. While it made little sense on iCloud Photos, they can add the exact same client-side scanning to iMessage and keep it (m…

iMessage has an e2e backdoor on by default in the form of plaintext escrow via iCloud Backup (not e2e). iMessage is, in practice today, no longer e2e. Apple knows this and intentionally preserves this backdoor for the FBI: https://mobile.reuters.com/article/amp/idUSKBN1ZK1CT

Meh. Compared to 10 years ago we still live in a bright future where e2ee is available to everyone who needs it. Yeah, you might need to enable some options (like in Telegram) or disable some other options (like iCloud in iMessage), but it's still there.

Even with this on-device CSAM thingy, Apple knows less about you than they did 10 years ago and random staffers at FAANG can't just go and spy on their spouses (the way they could not that long ago).

Re: Messaging and chat control

#132

Earlier quoted context omitted.

I'm wondering the same. I suppose they will have to implement some way to scan the emails, or else they will be forced out of business. That said, I wouldn't bet on it.

Does the EU have some kind of firewall with ISPs to block domains and IP addresses?

No. There are some per-country implementations, but nothing EU-wide.

Re: Messaging and chat control

#133
I voted Remain in the EU referendum here in the UK but, in 2021, a few things have happened that have caused me to question whether that was the right choice and whether, with Brexit, we have the right outcome (albeit for very much the wrong reasons seen through 2016 eyes):

1. Ursula von der Leyen and the EU Commission bullying companies and non-EU countries about vaccine production and provision. A wider point here is that the undemocratic nature of the Commission is something that I have always viewed as a problem.

2. The generally shambolic and inconsistent handling of vaccine procurement and rollout within the EU (which does now at least appear to be running much more smoothly; the UK government did well here but, overall, has handled the pandemic with majestic ineptitude).

3. This[0]. Chatcontrol 2.0 isn't the first ill thought out piece of legislation to get approval in the EU, and it won't be the last, but it is certainly one of the more sinister, and a significant violation of privacy amongst the majority of law-abiding citizens.

Overall I would still probably prefer to be in the EU than not, but I'm simply not as certain about that as I used to be.

[0] This whole assessment is of course contingent on the UK not simply falling into line with this legislation, a la GDPR, anyway. I'm on board with the spirit of GDPR and related legislation but the way every organisation seems to comply has certainly made the web suck more.

Re: Messaging and chat control

#134

Earlier quoted context omitted.

That's fine. My privacy has a price and I'm happy to sell it when I think it's convenient for me. What's happening here is that a state actor is forcing providers to let the state spy on me. That's an authoritarian policy which I strongly oppose.

How much of a rebate on your taxes would you be happy selling it for? What about a discount on your purchases, which was funded by the government, who would then buy the data?

That depends on what are we trading.

I would definitely trade my privacy with the government for any tax discount (and I think I'll have the longer stick, I'm no Indiana Jones) but whether I have an alternative or not is important.

A better question would be: would I move to a country where encryption is illegal if it had 0% tax? No, I would shop for another country. For a similar reason, I don't live in Dubai (0% tax but policies I don't approve of).

Re: Messaging and chat control

#135
post #26

Earlier quoted context omitted.

It's still no and far from a direct democracy.

Can you please be sensible? Direct demoracy is not working with 445 million people.

In my opinion it's impossible for a small group of people/ politicians to determine what's good for 445 million people.

Re: Messaging and chat control

#136
post #38

Does anybody have an idea how big child pornography is on the internet? Are those measures commensurate with the size of the problem? I'm asking seriously.

Hi, you must be new to this game. Here's the deal: none of this is about, or for the children. It's just a bullshit excuse to label anyone who opposes it a pedo. Same goes if "think about the terrorists" is used instead, which might come around soon-ish, since we started this round with "think about the children". OT: if somebody does have some statistics, that might actually be interesting; don't let me discourage y…

Furthermore, it does not matter in the slightest what number it turns out to be. It's going to be nonzero, it's going to continue to be nonzero no matter what legislation you introduce, and so you can always use this argument for more surveillance because people (especially parents, but mostly just everyone, and understandably) get very upset about this topic.

Re: Messaging and chat control

#137
post #6

Privacy is something that people usually only care about on a theoretical level. Practically speaking, they're often happy to not care so much at all if they get something more tangible in return. --- Company: Excuse me, would you mind us profiling you through an accurate survey of most of your everyday purchases? Customer: Heck no! Company: What if we let you collect "points" that will maybe someday safe you a littl…

There's a difference between me _opt-in_ to give private data in exchange for points, and that being unilaterally imposed.

It's also kind of harder to abuse information on my shopping list, whereas there's plenty of ways to abuse having total and complete access to all communication between private parties.

Re: Messaging and chat control

#138
post #16

Earlier quoted context omitted.

iMessage has an e2e backdoor on by default in the form of plaintext escrow via iCloud Backup (not e2e). iMessage is, in practice today, no longer e2e. Apple knows this and intentionally preserves this backdoor for the FBI: https://mobile.reuters.com/article/amp/idUSKBN1ZK1CT

For a little more context, see https://www.howtogeek.com/710509/apples-imessage-is-secure..... For those unfamiliar, as I was, it appears iCloud backup is enabled by default. I think the above statement about iMessage not being e2e in practice is very fair.

This option is transparent to the user and easy to change. Also, anyone who has done IT support will appreciate that yeah regular users actually want / need backups enabled by default, it's often a life saver for them.

Re: Messaging and chat control

#139
post #127

The news are pretty depressing these last couple of days. We're marching towards very dystopian future.

It is astonishing that most liberal democracies are looking at the Chinese system of control on society with envy. In a way, mandatory covid passes to do anything are already a form of social credit system. And with so many people obsessed with virtu signalling, an actual social credit system would likely get some traction.

[flagged]

Re: Messaging and chat control

#140
post #74

As the developer of an E2EE chat system, how could this affect me? Would I be forced to do something? I fall under a non-EU jurisdiction, and my servers are also outside of the EU. Would this apply to me or my users in the least? Thanks

I'm not a lawyer, but I suppose it will apply in the same way GDPR applies to anyone who wants to access the EU market (regardless of where you/your servers are). That is, if you're fine with your system not being accessible from the EU because of non-compliance you should be fine? Don't take my word for it though, I'm just assuming. Maybe somebody with more knowledge chan chime in.

According to https://www.enforcementtracker.com only EU companies get fined for GDPR violations. I assume a private citizen can sue a foreign company for violating their GDPR rights (??), but am I right in thinking that the EU can only prosecute its own entities? Therefore, unless an EU individual sues me for "violating" his right to be spied on, I should be fine? Or would the blame fall on the EU individual for having used a comms channel that doesn't allow the EU to spy on him? I probably am totally wrong, just trying to understand how this works
Post reply on HN