Live data from Hacker News

The EU could be scanning your chats by October 2025

techradar.com

251–259 of 259 posts

Re: The EU could be scanning your chats by October 2025

#251
post #152

Earlier quoted context omitted.

> CSAM is also a list of hashes for some of the worst CP video/images out there. It doesn't read anything, just hash matching. The list presumably contains CSAM hashes. However, it could also include hashes for other types of content. AFAIK the specific scope at any point in time is not something that can be fully evaluated by independent third parties, and there is no obvious reason why this list could not be extend…

CSAM scanning has been around for at least 15 years. All service providers are required to do it by law. You are absolutely correct with your "what-ifs" and this underlines the need for more oversight and transparency. The process (my knowledge is a few years old) is that service providers or Law enforcement from countries can submit files to the CSAM database. The database is owned by National Center for Missing & E…

> CSAM scanning has been around for at least 15 years. All service providers are required to do it by law.

That is true for scanning in the cloud, but it's important not to conflate this with client-side scanning. The distinction between cloud and local processing is foundational. Collapsing that boundary would mark a serious shift in how surveillance infrastructure operates.

> Once they receive the files they review them and confirm that the files meet the standard for the database, document its entry, create a hash and add that to the database. After that the file is destroyed.

That is already a structural problem: If the original is destroyed, how can independent parties verify that database entries still correspond to the intended legal and ethical scope? This makes meaningful oversight functionally impossible.

Even if centralizing control in a state-funded NGO were considered acceptable (which is already questionable), locating that NGO in the US (subject to US law and politics!) is a serious issue. Why should, say, the local devices of German citizens be scanned against a hash list maintained under US jurisdiction?

> So it's possible to submit an image that is not what CSAM is intended for, but the chances of it even remotely getting into the database is next to nothing. To add to this service providers can be sued for submitting invalid files.

Procedural safeguards are good, but they don't solve the underlying problem: the entire system hinges on policy decisions that can change. A single legislative change is all it takes to expand the list’s scope. The current process may seem narrow today, but it offers no guarantees about tomorrow.

We’ve seen this pattern countless times: surveillance powers are introduced under the pretext of targeting only the most heinous crimes, but once established, they’re gradually repurposed for a wide range of far less serious offenses. It is the default playbook.

Re: The EU could be scanning your chats by October 2025

#252

Earlier quoted context omitted.

If you don't mind me asking, are you autistic? You are conflating the de jure (winning the popular vote wins you the state's electors) with the de facto (the electors are a pro forma/rubber stamp).

I am not. And they aren't. You are trying to brush over a significant point to avoid admitting my comparison made sense. https://en.wikipedia.org/wiki/Faithless_electors_in_the_2016...

The comparison does NOT make sense. One is a body pledged, often legally, to vote for the state's winning candidate, with only extremely rare deviations by faithless electors (which never once came even close to putting the popular electoral results in question). The other is a body who is explicitly tasked with making the decision from scratch. Is it possible that you acknowledge that these are not in the slightest the same?

Re: The EU could be scanning your chats by October 2025

#253
post #132

Earlier quoted context omitted.

> Fuck, I don't want to live in a China with a blue flag instead of red. This is absolutely dystopian. I think it's too late. People already showed they'd loudly support this if propagandized enough like during COVID times where the most draconian and anti constitutional of policies were enacted, literally following and lobbied by China. Unless people recognize that they did a terrible thing in supporting covid polic…

I don't think this kind of discourse helps and I don't agree with the point. I am vehemently against chat control, but at least in my country (Netherlands) I saw nothing beyond the pale re: covid measures given the situation. I also don't see how those measures, regardless of whether you agree with them, reflect on chat control, as I'm not aware of any covid measures targeting encryption, nor of any EU-level measures…

> I don't think this kind of discourse helps and I don't agree with the point.

Helps who? It absolutely helps to call out the hypocrisy and consequences. This is what you wanted. Enjoy it.

> I am vehemently against chat control, but at least in my country (Netherlands) I saw nothing beyond the pale re: covid measures given the situation. I also don't see how those measures, regardless of whether you agree with them, reflect on chat control, as I'm not aware of any covid measures targeting encryption, nor of any EU-level measures you might be referring to here.

You're willfully ignorant of the authoritarianism perpetrated, then.

- They imprisoned you in your home. - They disallowed movement beyond certain ranges. - They censored free speech and sometimes even legally punished or imprisoned people for speech. You would refer to it as "dangerous misinformation" but that is what every authoritarian government says when they're oppressing their populace. - they blamed different political or ethnic groups of the "spread of the disease". - they destroyed the concept of informed consent from the Nuremberg trials and coerced people under threat of job loss/house loss/family separation to get new vaccines (extremely questionable ones, to add insult to injury). - Questioning the vaccines in any way was censored and equated with the worst of offenses. - invasion of privacy and constitutional rights of all kinds were justified in the name of "stopping the crisis". - there was no perceived end and many legal frameworks stayed.

> you care to elucidate?

Hope you hace fun with the above. I could go for ages.

> Regardless by equating the two I think you alienate people

Oh my sweet summer child. You think I care about alienating people who wanted to send the "evil spreaders of disease" and "fredumb" lovers to camps?

I'm absolutely over you and the likes of you. You either come to the side of anti authoritarianism fully and do a full mea culpa or I'll just laugh while loudly saying "this is what you wanted".

> because as far as I can tell most people are still brodly understanding of COVID measures taken and the core demographic that's not is also generally in favor of Chat Control

I don't quite parse the last part but I can assure you that people who were manipulated to give away their rights during COVID can be coerced or manipulated to give whatever next right they're asked. You'll scream about terrorism, the evil right, the evil foreign country, the evil criminal or whatever and that's that.

Get shocked and push for freedom for all or just take it because it's what you asked for. Nanny government. No dissent.

Re: The EU could be scanning your chats by October 2025

#254
post #251

Earlier quoted context omitted.

CSAM scanning has been around for at least 15 years. All service providers are required to do it by law. You are absolutely correct with your "what-ifs" and this underlines the need for more oversight and transparency. The process (my knowledge is a few years old) is that service providers or Law enforcement from countries can submit files to the CSAM database. The database is owned by National Center for Missing & E…

> CSAM scanning has been around for at least 15 years. All service providers are required to do it by law. That is true for scanning in the cloud, but it's important not to conflate this with client-side scanning. The distinction between cloud and local processing is foundational. Collapsing that boundary would mark a serious shift in how surveillance infrastructure operates. > Once they receive the files they review…

> That is true for scanning in the cloud, but it's important not to conflate this with client-side scanning.

From what you say it's clear you never read Apples paper on this.

The client puts a flag on a match. It is only verified on the server both by another scan and a law enforcement.

If the client doesn't flag a file, it can never be decrypted on the server by anyone except the device owner.

The current system just checks everything. If your device never talks to the cloud in both scenarios nothing happens.

> That is already a structural problem:

You seem to have an over simplified view of how it all works. They don't just throw hashes in.

They can verify it by the chain of custody and documentation that is stored about that hash.

> the local devices of German citizens be scanned against a hash list maintained under US jurisdiction?

CSAM is a UN protocol that has 176 countries signed onto it. Including Germany.

Many countries also have their own independent department that works with CSAM. Germany has their Federal police (BKA) that work that role. They work with NCMEC on ensuring the CSAM hashes are correct. Germany is also one of the strictest countries in relation to CSAM.

> the entire system hinges on policy decisions that can change.

Again it's an over simplification. If the US government did do that.

- It would first be challenged in the courts.

- They would not be able to hide the fact they have changed it.

- This would lead to service providers not assisting with the corrupted CSAM.

- As this is a worldwide initiative the rest of the world can just disconnect the US from the CSAM until what is put in is confirmed.

> It is the default playbook.

If they wanted to do that, the CSAM database is the worst way to do it.

I'd recommend you read up on all of it a bit more. Most of your claims are unfounded in relation to the CSAM.

Re: The EU could be scanning your chats by October 2025

#255
post #251

Earlier quoted context omitted.

> CSAM scanning has been around for at least 15 years. All service providers are required to do it by law. That is true for scanning in the cloud, but it's important not to conflate this with client-side scanning. The distinction between cloud and local processing is foundational. Collapsing that boundary would mark a serious shift in how surveillance infrastructure operates. > Once they receive the files they review…

> That is true for scanning in the cloud, but it's important not to conflate this with client-side scanning. From what you say it's clear you never read Apples paper on this. The client puts a flag on a match. It is only verified on the server both by another scan and a law enforcement. If the client doesn't flag a file, it can never be decrypted on the server by anyone except the device owner. The current system jus…

> From what you say it's clear you never read Apples paper on this. ... You seem to have an over simplified view of how it all works. They don't just throw hashes in. ... Again it's an over simplification. If the US government did do that. ... I'd recommend you read up on all of it a bit more. Most of your claims are unfounded in relation to the CSAM.

The posturing about supposed expertise adds nothing. If you want to make an argument, make it. Vague appeals to technical depth are just noise.

> The client puts a flag on a match. It is [...] verified on the server [...] The current system just checks everything.

Sure, that’s how the flagging process works. It’s also beside the point. Listing technical details doesn’t change the core issue: this system performs scanning on the user device, which is what makes it problematic.

> If the client doesn't flag a file, it can never be decrypted on the server by anyone except the device owner. [...] If your device never talks to the cloud in both scenarios nothing happens.

Correct, but not relevant here. No one is arguing that airgapped devices leak information. The issue is what happens when devices are online.

> [On the structural problem of inability of independent oversight] They can verify it by the chain of custody and documentation that is stored about that hash.

What specific documentation would allow actual evaluation? And who can access it? The process is opaque by design: The list of neural hashes is private, matching and flagging happen silently, and escalation logic like threshold levels or safety voucher generation is not open to inspection. Whatever theoretical accountability might exist, it’s irrelevant in a system of systematic secrecy that cannot be independently observed or audited.

> CSAM is a UN protocol [...] countries [...] work with NCMEC on ensuring the CSAM hashes are correct. Germany is also one of the strictest countries in relation to CSAM.

Yes, Germany has police and ofc works to fight CSAM. That doesn’t change the concern: the system design is extensible and unverifiable. If a U.S. administration wanted to expand the scope (say, for terrorism, extremism, drugs, or IP enforcement), who exactly stops them? Not a German agency. Certainly not NCMEC.

> [On the obvious loophole of policy change] If the US government did do that. - It would first be challenged in the courts.

That is... optimistic. What legal mechanism exactly would allow a challenge to a (as an example) classified National Security Letter expanding the hash set? What court has even the standing to hear that? What precedent makes you believe such a challenge would surface in time?

> - They would not be able to hide the fact they have changed it.

Why not? The hashes are not reversible. The list is not public. The matches are not auditable. Gag orders are legal. What in this system ensures visibility or accountability?

> - This would lead to service providers not assisting with the corrupted CSAM. - As this is a worldwide initiative the rest of the world can just disconnect the US from the CSAM until what is put in is confirmed.

The Apple proposal is not a worldwide initiative, but a US-driven proposal involving a handful of US orgs. EU involvement in the whole issue has been comparatively lacking and is often dependent on US lobbying and funding. The idea that the world could or would opt out assumes a degree of transparency and technical independence that simply does not exist on this planet right now.

If you want to argue that the system is technically robust against political misuse, then please do. If there are decent guardrails in place, I'd really truly do like to know about them. But so far, it mostly reads like a wish list.

Re: The EU could be scanning your chats by October 2025

#256

I was reflecting on the whole chat apps and protocols the other day and felt we might just have trapped ourselves artificially. If I want to casually keep in touch with a friend, I am supposed to have the following options: - SMS/RCS: no need for an app but is controlled - WhatsApp: no good to many reasons - Signal: how can you believe it is not controlled once it becomes the mandatory app in the US Gov. - Matrix: gr…

A few corrections: - Matrix does not require you to host a server, even if I'd prefer it - there are multiple public ones in various jurisdictions. - There is XMPP - like Matrix, but older, jankier, much lighter and kind of freer. - Weird to call Simplex "centralized" if you did acknowledge that it's selfhostable... But it's indeed weird that last I've seen, there's not some directory with the public servers like there is for Matrix/XMPP. They seem to be going with adding other servers to defaults instead, like they did with Flux recently.

Re: The EU could be scanning your chats by October 2025

#257
post #174

Earlier quoted context omitted.

Sure. That's a very generous interpretation. But I am quite certain OP does not mean "priviliged white dudes" as the issue with "multiculturalism". May OP can expand on what they mean exactly.

No it isn't a "generous interpretation". You seem to be taking very uncharitable interpretation while insinuating they are some sort of unrepentant racist. I am not sure why you are doing that. I find it extremely tiresome. I deliberately gave examples where both groups were White Europeans so to avoid any conflation with racism. Otherwise the conversation is guaranteed to go nowhere as it ends up in accusations of p…

i think in this case they used multicultural people to refer to me saying the government was afraid of immigrants.
Post reply on HN