Live data from Hacker News

EU to greenlight Chat Control tomorrow

patrick-breyer.de

291–300 of 360 posts

Re: EU to greenlight Chat Control tomorrow

#291
post #209
post #203

Earlier quoted context omitted.

You only really answer question 2 of your parent, and they obviously meant for someone operating a Matrix server with regards to their users. It's pretty well summarized in Patrick Breyer's sumary page[0]: > Only non-commercial services that are not ad-funded, such as many open source software, are out of scope > How do you even ensure a client is actually self-reporting? This is an interesting technical question whe…

> However, the provider would need to "create access to end-to-end encrypted data" to report it to the EU Centre. Sorry, I don't follow. Am I misreading something? To me the the quoted text says the opposite. "Providers should remain free to [...] and should not be obliged by this Regulation to [...] create access to end-to-end encrypted data" > prevent against spam reporting, where someone could basically DoS the re…

> Sorry, I don't follow. Am I misreading something? To me the the quoted text says the opposite.

Yeah me too. But how would the provider report CSAM content if they are not obliged to break encryption? I don't really follow the Regulation on that part.

Re: EU to greenlight Chat Control tomorrow

#292
post #291
post #209

Earlier quoted context omitted.

> However, the provider would need to "create access to end-to-end encrypted data" to report it to the EU Centre. Sorry, I don't follow. Am I misreading something? To me the the quoted text says the opposite. "Providers should remain free to [...] and should not be obliged by this Regulation to [...] create access to end-to-end encrypted data" > prevent against spam reporting, where someone could basically DoS the re…

> Sorry, I don't follow. Am I misreading something? To me the the quoted text says the opposite. Yeah me too. But how would the provider report CSAM content if they are not obliged to break encryption? I don't really follow the Regulation on that part.

It wouldn't.

It's a broad framework and - based on my cursory reading:

  - providers have to set up a counter-abuse team and fund it
  - authorities and industry-wide cooperation on trying to come up with guidelines and tech
  - counter-abuse team needs to interpret the guidelines, do "due diligence"
  - provider needs to have monitoring to at least have an idea of abuse risks
  - if there are, work on addressing them if possible without breaking privacy

As far as I understand the point is have more of services like "YouTube for Kids", where you can give your kid an account and they can only see stuff tagged "kid appropriate" (and YT simply said we are going to be sure there are no bad comments, so there's no comment section for these videos - which hurts their engagement, which hurts profitability).

There's a section about penalties and fines, up to 6% of global revenue, if the provider doesn't take abuse seriously. And - again, based on my understanding - this is exactly to prod big services to make these "safer, but less profitable" options.

Re: EU to greenlight Chat Control tomorrow

#293
post #226
post #187

Earlier quoted context omitted.

Based on this proposal the strategy is - providers spend money on having a counter-abuse team - providers and authorities cooperate to identify risks - providers implement proportional controls based on the risks so if Meta/Signal/etc comes up with something they implement it users can continue to run their own private stuff. it seems this has almost nothing do with the organized sex crime stuff, it's about catching…

Okay, so "app", not "device". I was wondering which other app or part of the OS would do that, since obviously Signal won't implement it.

I guess it's stuff like setting up a "kid watcher app"[0] and it helps parents, etc.

[0] yes, amazing name, I know, I know, thank you

Re: EU to greenlight Chat Control tomorrow

#294

How is VPN supposed to work? How are internet banks supposed to operate? All security will go out the window? Backdoors everywhere? Will TLS have to be redone with a third snooping party in the mix? Is that what we're going for here?

The draft specifies (in page 3) that this is only for publicly accessible services: https://cdn.netzpolitik.org/wp-upload/2024/05/2024-05-28_Cou... So regular folks would get scanned, but the bank's private messaging service isn't included. Just like the child pornographer's private messaging service won't be included either.

I want reviewed studies that clearly show how much CSAM is send by those public available services. There are none based arguments for making this regulation. Just spreading a fear and public guilt.

Re: EU to greenlight Chat Control tomorrow

#295
post #210

Earlier quoted context omitted.

To my knowledge, Signal makes a grand total of €0 in profit in Europe, or anywhere else for that matter, being a not-for-profit. It is not the purpose of a not-for-profit to grow exponentially. The Signal Foundation's mission is to ensure the continued existence of a secure messenger app. The people in charge of Signal take that mission very seriously, to their great credit. There are already anti-circumvention mecha…

Doesn't really matter what Signal does. If this goes through then the next push will be to implement the scanning at the OS-level for non-compliant apps. Or just to demand that Android and iOS get the ability to block apps on a government list even if installed outside the app store. Sure, a few hackers (and the criminals) will always have secure communications but you can't win the fight for widespread secure commun…

I think this seems like a fairly extreme and unlikely worst case scenario. I'd be sceptical about the EU's ability to actually implement something like this - there are limits to both what American companies are willing to do (e.g. Google leaving China), and what some of the more historically liberal European states are actually willing to tolerate from the EU level (imagine the blow to business confidence).

That's not to say that the present proposals aren't already bad enough.

Re: EU to greenlight Chat Control tomorrow

#296
post #156

Earlier quoted context omitted.

The question is always about the circumstances. In the "think of the children" scenario the parents are incentivized to consent to some filter. (So they or someone(!!!) gets an alert if the boogeyman is talking to their kids, asking them to send nudes, or sending dick pics.) See recital 13 on top of page 7 for the definition. And see 17 on bottom of page 8 for this: "To allow for innovation and ensure proportionality…

How does something like this avoid false positives? A pretty common example in my circle is parents taking pictures of baby rashes/pimples/blisters etc to send to family doctor or doctor friends. It sounds like a situation where every parent with a toddler will end up on some list.

It doesn't.

One page 17 section 28 says "... constantly assess the performance of the detection technologies and ensure that they are sufficiently reliable, as well as to identify false positives and avoid to the extent erroneous reporting to the EU Centre, providers should ensure human oversight and, where necessary, human intervention, adapted to the type of detection technologies and the type of online child sexual abuse at issue. Such oversight should include regular assessment of the rates of false negatives and positives generated by the technologies, based on an analysis of anonymised representative data sample"

and for the draft law language see page 60 which says that after the user reported something the provider forwards is anonymized to this new EU Centre, where there human verification has to take place.

So supposedly this means our tax will pay for folks to look at a ton of rashes and pimples.

Re: EU to greenlight Chat Control tomorrow

#297

Earlier quoted context omitted.

You can say Boe Jiden is a purple Martian born in Backwaterstan. Boe Jiden will probably sue you for defamation. The courts will very likely give him the win, slamming you with a hefty fine and perhaps more such as prison time depending on the damages your speech incurred. You can say Boe Jiden is a purple Martian born in Backwaterstan again , so long as you're fine going through that rigmarole again though you'll pr…

You have exactly described how freedom of speech works in North Korea. You are allowed to say "I think that Kim is a bad leader", which is guaranteed by the article 67 of The Socialist Constitution of the Democratic People's Republic of Korea. But this doesn't mean you can spread untrue claims and cause societal disrupt, so Kim arrests you for your reckless actions and you go to gulag. Again, freedom of speech exists…

Free speech protects you from prosecution against your speech. The consequences of that speech are a separate matter and not protected by the 1st Amendment.

Again, note precisely what is prosecuted here in the US where free speech is a guaranteed Constitutional right. You can with absolute power say whatever you want, but you will need to own up to it.

If you don't or can't own up to what you say, don't speak. This isn't a violation of free speech because nobody is prohibiting or otherwise compelling you from speaking.

Re: EU to greenlight Chat Control tomorrow

#298
post #167

The current draft would cover every kind of service that allows people to exchange information so that every DM you send on reddit, twitter, discord, steam, ... would be have to be scanned. Not even the most totalitarian governments on this planet have tried to implement something like this. Also it sounds extremely illusory that the people exchanging CSAM wouldn't simply switch to private services knowing their mess…

[dead]

Re: EU to greenlight Chat Control tomorrow

#299

Earlier quoted context omitted.

Free speech doesn't mean you can force anyone to listen. The government should not make any speech illegal on a federal level, but individual private businesses or websites (like HN) can still decide what's tolerated on their property. And the corollary -- I believe in free speech but there are some people I'll never listen to, even though I believe in their right to speak.

What about individual private businesses like Spectrum and Verizon?

Wouldn't the analog counterpart be the postal system? They have no right to poke in your private communications.

Edit: That said postal systems are generally owned by the government. So I suppose ultimately (if nothing else) it would be up to their T&C. But I don't see how they could reasonably justify monitoring the traffic. It's not like it's a PR issue for them what users share through their tubes. I would imagine it'd make sense to have them regulated similarly as the postal system (ensuring private communications).

Re: EU to greenlight Chat Control tomorrow

#300

Earlier quoted context omitted.

Honest question: why would a free speech absolutist start a discussion here, on this site? I have a feeling that plenty of rules here [0] wouldn't be accepted by such a crowd. [0]: https://news.ycombinator.com/newsguidelines.html

Because 15 years ago this was the default point of view everywhere online. Then the unwashed masses came and banned us.

Yup. Using the early internet required a moderate amount of intelligence. The current internet does not. And now when things are being optimized for the lower 50% of the bell curve it results in things looking a lot different.

The early internet was like a race track for experienced drivers. Nowadays even kids are allowed to participate so all cars are heavily speed limited, with soft bumpers and a huge framework of regulations and protections.

That's fine in itself, but more importantly (to the point) it doesn't mean that pure race tracks should be banned. That's where all the interesting stuff happens.

Post reply on HN