To be clear, this is a
really serious situation.
The current Online Safety Bill wording from https://bills.parliament.uk/publications/49376/documents/282... (https://bills.parliament.uk/bills/3137) is as follows: clause 124(3) declares that OFCOM (the telco industry regulator) can impose "proactive technology" to comply with or remediate illegal content, child safety or fraudulent advertising(!):
(3) A proactive technology requirement may be imposed in a confirmation decision only for the purpose of complying with, or remedying the failure to comply with, any of the duties set out in—
(a) section 9(2) or (3) (illegal content),
(b) section 11(2) or (3) (children’s online safety),
(c) section 23(2) or (3) (illegal content),
(d) section 25(2) or (3) (children’s online safety), or
(e) section 33(1) or 34(1) (fraudulent advertising).
and clause 202(1)(a) then defines "Proactive technology" to mean:
202 “Proactive technology”
(1) In this Act “proactive technology” means—
(a) content moderation technology,
(b) user profiling technology, or
(c) behaviour identification technology,
In other words, the Bill gives the industry regulator the ability to impose a requirement that communication apps implement content moderation technology - which for an end-to-end encrypted system, obviously means the ability to scan and exfiltrate encrypted content to moderators (as how else can you moderate content). As a result, anything that whatever scanning technology deems illegal would have to end up in an unencrypted moderation queue (presumably provided by the app vendor?!), thus completely violating the encryption privacy guarantees. For instance, folks in Ukraine using Signal/Element/etc to discuss being bombed might end up with their messages exfiltrated by the scanning software to a moderation queue because they include the word 'bomb', which is then a sitting target which bad actors would use to gather intelligence and entirely sidestep encryption.
The penalty for not complying is still being determined, but could mean jail time for those building the apps: https://www.telegraph.co.uk/politics/2023/01/16/rishi-sunak-...
This is LITERALLY the online equivalent of putting a CCTV camera in everyone's bedroom, hooking it up to an machine learning classifier to detect 'illegal activity', and then sending unencrypted recordings to a moderation queue run by the CCTV vendor.
It's terrifying, and we have to stop it, before it sets a precedent that the EU follows with ChatControl, or that the US follows (or uses it as an excuse to remove E2EE entirely).
The way to stop it is to yell about it loud on social media, talk go the press, and if you're in the UK, write to your MP (they do actually read these letters).
Signal & others, if you're reading this: we need to coordinate on an open letter to UK Parliament (probably the House of Lords Committee) to present a united front against this; please ping me at matthew[at]matrix.org to sync.
The OSB is alarmingly advanced through the legislative process, and we are running out of time to stop it.