Live data from Hacker News

EU to greenlight Chat Control tomorrow

patrick-breyer.de

201–210 of 360 posts

Re: EU to greenlight Chat Control tomorrow

#201
post #173
post #162

Earlier quoted context omitted.

see https://news.ycombinator.com/item?id=40712506 for my argument that making child porn illegal protects abusers more than abuse victims. i guess that makes me a free speech absolutist?

I think it is fundamentally dishonest to point to a Pulitzer Prize winning photograph as any sort of representative example of "child porn". Neither of the photos you specifically call out would meet the "I know it when I see it" standard cited by the US Supreme Court and the photos that do would never be published by reputable news sources regardless of their actual legal status. Therefore, your argument isn't even…

it sounds like you didn't read very much of my comment, because you didn't understand what my argument was about, even as a vague outline

separately, you say, 'I think it is fundamentally dishonest to point to a Pulitzer Prize winning photograph as any sort of representative example of "child porn".' however, the thing you think is dishonest is something you made up, not something i said, suggested, implied, or agree with

Re: EU to greenlight Chat Control tomorrow

#202

Earlier quoted context omitted.

EU was established to provide mutual economic and military security in Europe on a federal model following WW2, and it's done very well in that aim. Of course it's not perfect, but shallow takes like the one above provide nothing of value.

> military security Wasn't that NATO (aka mostly the US)?

Kinda, but NATO is (imho) more about external threats. I think part of the EU's founding vision was to prevent further intra-European wars, in which it has been largely successful.

Re: EU to greenlight Chat Control tomorrow

#203
post #193
post #154

I can see how that would be implemented for WhatsApp and other apps from large companies. But how would that work in practice for applications like Matrix where clients are not controlled by the server operator nor the server developer? Some questions I have from reading Patrick's website: - How do you even ensure a client is actually self-reporting? On-device attestation doesn't really work. - As a provider of E2EE…

Matrix is a software, it's not a provider. It's out of scope. (see 1. on page 37 for scope) see page 39 "5. Without prejudice to Article 10a, this Regulation shall not prohibit or make impossible end-to-end encryption, implemented by the relevant information society services or by the users" https://cdn.netzpolitik.org/wp-upload/2024/05/2024-05-28_Cou... see also page 46 "... measures shall be ... targeted and propor…

You only really answer question 2 of your parent, and they obviously meant for someone operating a Matrix server with regards to their users. It's pretty well summarized in Patrick Breyer's sumary page[0]:

> Only non-commercial services that are not ad-funded, such as many open source software, are out of scope

> How do you even ensure a client is actually self-reporting?

This is an interesting technical question whether or not it's covered by the actual proposal. How do you ensure that Messenger for instance is

1. actually doing the reporting, and not someone simply bypassing the app to keep sending e2ee chats without them being client-side scanned. That would most likely be against ToS and accounts would maybe get banned if doing so

2. prevent against spam reporting, where someone could basically DoS the reporting service with false positives

> If a photo are flagged, will it appear in a GDPR access request?

There are a bunch of dispositions in the draft concerning personal data protection (ctrl+f personal data to find the relevant articles). It also states pretty much everywhere that processing should be done in accordance with Regulation (EU) 2016/679, more commonly known as GDPR.

[0] https://www.patrick-breyer.de/en/posts/chat-control/

What really bugs me though, is this:

> Having regard to the availability of technologies that can be used to meet the requirements of this Regulation whilst still allowing for end-to-end encryption, nothing in this Regulation should be interpreted as prohibiting, requiring to disable, or making end-to-end encryption impossible. Providers should remain free to offer services using end-to-end encryption and should not be obliged by this Regulation to decrypt data or create access to end-to-end encrypted data

I believe this was added as a request from France, which didn't want E2EE to be undermined by this proposal. However, the provider would need to "create access to end-to-end encrypted data" to report it to the EU Centre. Although the following article states that E2EE can still be used if you don't send images, videos and URLs, so I guess that's the compromise?

Re: EU to greenlight Chat Control tomorrow

#204

Earlier quoted context omitted.

Would Signal allow an app to be side loaded? Would it be possible for an Signal-like app to be loaded that would ruin everything for everybody?

Android does. Apple doesn't, obviously. Even in the EU where they have to.

yes yes, we all know this is the obvious answer. so thanks for that and ignoring the actual point of the question

Re: EU to greenlight Chat Control tomorrow

#205
post #159

Earlier quoted context omitted.

The issue is when "free speech absolutists" often aren't actually that. They'll stand up to defend folks like the ones from the case you cited because "Free Speech". Yet, they'll also defend laws like the ones passed earlier in the year by the US House about codifying the IHRA's definition of anti-Semitism. > spectrum The spectrum is far too often simply colored by the politics one's interested in, i.e. Free Speech i…

>they'll also defend laws like the ones passed earlier in the year by the US House about codifying the IHRA's definition of anti-Semitism. Anyone who defended that isn't even close to a free-speech absolutist. >I don't believe anyone truly has a Free Speech Absolutist position I do. It's what makes America great. Erosions like that jewish law are slowly weakening that. You should be allowed to say whatever you want a…

Should I be able to make wild claims about my product to trick you into buying it? False claims about my buisness performance to pump the stock? Lies about your character? Your kids? made up stuff that whips up entire segments of your city to commit violence or vandalism against you?

Because absolute free speech is allowing all that without consequence

Re: EU to greenlight Chat Control tomorrow

#206
post #147
post #145

Earlier quoted context omitted.

>> Unfortunately outside the US and a handful of other places free speech doesn't seem to be valued that much, often it's even viewed as a threat >Can you convince me of this? Because it's not my impression. In my country (Macedonia), our then-Prime Minister a few years ago during the height of the pandemic, spoke (broken) English and funnily pronounced vaccines, something like "vac-signs" (or "vaksajns" in Macedonia…

Mmm, yes. America is the only country that has true freedom of speech. I suppose that's why a silly Canadian like me wouldn't know much about other countries. We just don't have free speech.

America does not have true freedom of speech as it places all sorts of limits on it

Nowhere does

Re: EU to greenlight Chat Control tomorrow

#207
post #185
post #179

Earlier quoted context omitted.

They decisively said “this was a bad idea” and disavowed the effort.

Things change, especially when the Gov says they must. It’s already been a few years. Given the “Apple in China” precedent I wouldn’t be so optimistic.

My understanding is that Apple openly declares they have the same encryption standards in China, and that iCloud Advanced Data Protection was one of the things that started getting them on China’s “naughty list” again.

Re: EU to greenlight Chat Control tomorrow

#208
post #159

Earlier quoted context omitted.

The issue is when "free speech absolutists" often aren't actually that. They'll stand up to defend folks like the ones from the case you cited because "Free Speech". Yet, they'll also defend laws like the ones passed earlier in the year by the US House about codifying the IHRA's definition of anti-Semitism. > spectrum The spectrum is far too often simply colored by the politics one's interested in, i.e. Free Speech i…

>they'll also defend laws like the ones passed earlier in the year by the US House about codifying the IHRA's definition of anti-Semitism. Anyone who defended that isn't even close to a free-speech absolutist. >I don't believe anyone truly has a Free Speech Absolutist position I do. It's what makes America great. Erosions like that jewish law are slowly weakening that. You should be allowed to say whatever you want a…

> Anyone who defended that isn't even close to a free-speech absolutist.

No True Scotsman.

> You just don't want to acknowledge such a stance is possible because the people you agree with are in power, allow the speech you agree with, and censor the speech you don't disagree with, so you stand with nothing to gain by supporting free speech. That's a personal choice to have no integrity.

... I am not American, neither do I have anyone in power who supports the speech I agree with. There's no need to attack me specifically. I am talking about the wider pattern. Free Speech Absolutists exist as long as the speech they support is being oppressed. Do you support Free Speech of the person screaming obscenities at your young child? False claims about you? Whipping up entire communities to attack you physically? Do you support speech that incites genocide?

Yes, some of those are crimes but I am not sure you'd care if you'd been attacked already. The damage is done.

Re: EU to greenlight Chat Control tomorrow

#209
post #203
post #193

Earlier quoted context omitted.

Matrix is a software, it's not a provider. It's out of scope. (see 1. on page 37 for scope) see page 39 "5. Without prejudice to Article 10a, this Regulation shall not prohibit or make impossible end-to-end encryption, implemented by the relevant information society services or by the users" https://cdn.netzpolitik.org/wp-upload/2024/05/2024-05-28_Cou... see also page 46 "... measures shall be ... targeted and propor…

You only really answer question 2 of your parent, and they obviously meant for someone operating a Matrix server with regards to their users. It's pretty well summarized in Patrick Breyer's sumary page[0]: > Only non-commercial services that are not ad-funded, such as many open source software, are out of scope > How do you even ensure a client is actually self-reporting? This is an interesting technical question whe…

> However, the provider would need to "create access to end-to-end encrypted data" to report it to the EU Centre.

Sorry, I don't follow. Am I misreading something? To me the the quoted text says the opposite.

"Providers should remain free to [...] and should not be obliged by this Regulation to [...] create access to end-to-end encrypted data"

> prevent against spam reporting, where someone could basically DoS the reporting service with false positives

Yep, probably there's no way to do this. (Likely this whole thing will be a lot of money spent to realize this.)

Re: EU to greenlight Chat Control tomorrow

#210

Signal Foundation has already said they would leave the EU if Chat Control goes ahead. https://mastodon.world/@Mer__edith/112535616774247450

Signal isn't big enough to play that game. They'll just be blocked from the app store for EU users and their user base in the EU will drop to near zero within a year.

To my knowledge, Signal makes a grand total of €0 in profit in Europe, or anywhere else for that matter, being a not-for-profit. It is not the purpose of a not-for-profit to grow exponentially. The Signal Foundation's mission is to ensure the continued existence of a secure messenger app. The people in charge of Signal take that mission very seriously, to their great credit.

There are already anti-circumvention mechanisms built into Signal to facilitate use in places like China and Iran, so they've shown no interest in compliance where that goes directly contrary to their mission. Should they be removed from the App Store in Europe, I imagine they'll work on making use of the EU's own push to open iOS up for alternative app stores / PWAs. (It's clear that the EU is unhappy with Apple's current take on compliance, so we can expect that to open up further.)

Post reply on HN