Live data from Hacker News

ChatControl: EU wants to scan all private messages, even in encrypted apps

metalhearf.fr

571–580 of 656 posts

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#571

Earlier quoted context omitted.

I cannot find such an incident.

I was there, and indeed I will never forget it. https://www.nhnieuws.nl/nieuws/212970/om-waarschuwingsschot-...

Getting past the cookie banner was difficult on mobile (Firefox).

Thank you, that was interesting. And impossible to find for those who don't already know the details.

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#572

Earlier quoted context omitted.

Dear citizens of the US: Please stop funding, allying with and protecting the manufacturers of surveillance tools. Stop exporting Palantir products and importing privacy-destroying devices from businesses like Greyshift and Cellebrite. Insist that the US government stop shielding hackers-for-hire like NSO Group who indiscriminately lease their products for discriminatory and illegal purposes. Stop defending "OEM" con…

Collective guilt projection is incredibly unfair. What is the average US citizen expected to do in this? I hereby promise not to buy any weapons systems from Palantir or use Cellebrite if I forget my phone's PIN code. Am I one of the good ones now?

A bunch of people pursuing or considering careers at those companies are hanging out here. Changing their minds should count for something.

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#573
post #240
post #118

Earlier quoted context omitted.

I believe they are referring to using GPG to encrypt data before putting it into Slack, much like using the out of band OTR. In that case all the data shared between those using GPG or OTR would only be accessible to those with the right out of band keys. There are probably not a lot of people doing this, or not enough for governments to care. I do this in IRC using irssi-otr [1]. If that ever became illegal because…

> I believe they are referring to using GPG to encrypt data before putting it into Slack In good approximation, nobody does that. And anyone who is capable of communicating over PGP won't be covered by ChatControl anyway. They can keep using PGP over whatever they want, or just compile Signal from sources. > If that ever became illegal because encryption then groups of people could simply use scripts or addons to pip…

This is some kind of poor encryption.

In fact it is exactly zero encryption both technically and legally. By using encoding I would not be breaking the law at all assuming encryption itself is actually outlawed. Encryption is mathematical obfuscation. This is only useful for text to/from the server of course. Local storage is still being scanned which means one still have to use a device that does not have local scanning if the files are sensitive such as financial documents or those files would also have to be encoded. Encoding may not have value to some people but it has value to me. Obviously if I am trying to hide something that is highly sensitive like a master password database then I would probably do something a tad bit stronger, maybe 64 to 256 chains of encoding. This is still sufficient to break fuzzy scanning.

Here's an easy one:

    MDExMTAxMTEwMDExMDAwMDAwMT
    EwMDAwMDExMTAxMDAwMTExMDEx
    MTAwMTEwMDAwMDAxMTAwMDAw
    MTExMDEwMDAwMTAwMDAwMDEwMA
    oxMDAxMDAxMDAwMDAwMTEwMDAw
    MTAxMTAxMTAxMDAxMDAwMDAw
    MTEwMDAwMTAwMTAwMDAwMDExMT
    AwMTEwMTEwMTAwMTAxMTAxMTAw
    CjAxMTAxMTAwMDExMTEwMDEw
    MDEwMDAwMDAxMTEwMTExMDExMD
    ExMTEwMTEwMTEwMTAxMTAwMDEw
    MDExMDAwMDEwMTExMDEwMAo=
Zero encryption but it might take people a while to figure this out. The commands I used are installed by default to most Linux distributions. If I wanted to get really crazy I would add different levels and types of compression in the middle of the chain.

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#574
post #263
post #118

Earlier quoted context omitted.

I believe they are referring to using GPG to encrypt data before putting it into Slack, much like using the out of band OTR. In that case all the data shared between those using GPG or OTR would only be accessible to those with the right out of band keys. There are probably not a lot of people doing this, or not enough for governments to care. I do this in IRC using irssi-otr [1]. If that ever became illegal because…

If you really want to use encryption under a state where it's forbidden and communication are monitored you rather want to hide your encrypted messages inside cat pictures and tiktok videos. Because blatant obfuscation might trigger warning and draw attention. In the end it's not about making encryption technically impossible but illegal, and if you use it you'll be prosecuted.

Me personally, I will use chained encoding because technically and legally that is not encryption. I am fine with drawing attention. If my adversaries wish to spend a gazillian mega-bucks to try to win the arms race of decoding my chained encoding to see my mid-wit comments and pictures of a moose then I am doing a good job. When they change the laws to prevent encoding then we move on to another technique. There are nearly infinite ways to limit communication to a group of people and evade fuzzy scans.

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#575
post #322

Earlier quoted context omitted.

No, probably not - but those bad guys with all their child porn and terrorist plans won't mind the friction (those will either encrypt or become EU politicians).

You would be surprised. I mean, look at how many technically savvy people use Telegram and think it is "safe". Ever heard of top government officials mistakenly inviting a journalist in a group sharing top secret information?

[dead]

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#576

Dear citizens of the EU: If this gets pushed through, you will gradually lose control of your government much like how the people of the UK already lost control of theirs. What are you going to do when the government's interests inevitably drift out of alignment with yours? Start a political movement? You will have the police knocking on your door for criticizing the establishment. Start a revolution? You have no wea…

[deleted]

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#577

Earlier quoted context omitted.

> Software like PGP is easy to use Criminalize encryption. Oh you're using cryptograhy? Well then clearly you are a child molesting, money laundering, drug trafficking terrorist. No need to actually decrypt anything when cryptography is incriminating evidence unto itself. Computers are subversive. Cryptography alone can defeat police, judges, governments and militaries, and computers have democratized access to crypt…

How do you define cryptography? Let's say my files are written in a format that only my software can read. Is it then illegal to distribute said files?

I define it as anything that even slightly inconveniences the so called "authorities".

I've seen local judges give interviews to television networks about high profile cases where they were nearly foaming at the mouth with rage over end-to-end encryption. Cryptography is whatever causes that.

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#578
post #415

Earlier quoted context omitted.

For the vast majority of people, the purpose of encryption is not to prevent a trusted law enforcement from reading the message. Say the police knocks at my door and asks me nicely to read my messages, I will show them. Doesn't mean I don't care about them being encrypted when I send them over the Internet.

Are we still having to discuss arguments such as "Why are you afraid? You should have nothing to hide!" in 2025 Yeah, safety measures are useless until you face a risky situation. Also I don't care that "the vast majority of people" prefer Facebook chat to discuss online. That they are free to do so doesn't mean I shouldn't be free to preserve the secrecy of my communications.

> That they are free to do so doesn't mean I shouldn't be free to preserve the secrecy of my communications.

My point is that ChatControl does not say that all your communications will be shared. And you will still be able to send encrypted messages with Signal, and your ISP won't be able to read them, and Signal won't be able to read them. So it's not true that it won't preserve the secrecy of your communications. If used correctly, it will preserve the secrecy of almost all your communications. And it would be possible to have a version of ChatControl that would absolutely preserve the secrecy of all your communications (e.g. by only using a list of hashes instead of machine learning).

Maybe you think that you should be free to have illegal material on your phone, but I am not sure the rest of the population agrees. If one could prove that ChatControl never made a mistake (e.g. it's just a hash comparison) and that the list of illegal hashes is never abused, then I'm pretty sure most people would find it okay.

The problem is that we cannot prove that, and in fact it's pretty clear that it is fundamentally difficult to make sure that the list of hashes is not abused. Even more so if instead of a list of hashes it is a machine-learned set of weights.

So ChatControl would be a powerful tool that is difficult to audit, and that therefore could be abused by whoever controls it. This is the risk, this is what we should be talking about.

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#579
post #541
post #539

Earlier quoted context omitted.

In many EU countries neither head of state/government are elected then.

In some (most?) EU countries the head of the state or government is not elected directly, but even then is elected in the parliament and without continuous parliament majority support is unable to effectively govern. This is not the case for the EU institutions, where the EP is the least powerful body by far. While the EP 'elects' the head of the Commission and confirms the members, it does not choose them. It is not…

[dead]

Re: ChatControl: EU wants to scan all private messages, even in encrypted apps

#580
post #573
post #240

Earlier quoted context omitted.

> I believe they are referring to using GPG to encrypt data before putting it into Slack In good approximation, nobody does that. And anyone who is capable of communicating over PGP won't be covered by ChatControl anyway. They can keep using PGP over whatever they want, or just compile Signal from sources. > If that ever became illegal because encryption then groups of people could simply use scripts or addons to pip…

This is some kind of poor encryption. In fact it is exactly zero encryption both technically and legally. By using encoding I would not be breaking the law at all assuming encryption itself is actually outlawed . Encryption is mathematical obfuscation. This is only useful for text to/from the server of course. Local storage is still being scanned which means one still have to use a device that does not have local sca…

> In fact it is exactly zero encryption both technically and legally.

I am not a lawyer (are you?), but technically you're wrong.

"In cryptography, encryption (more specifically, encoding) is the process of transforming information in a way that, ideally, only authorized parties can decode."

A caesar cipher is encryption. I don't see why chaining encodings wouldn't be. Technically and legally.

Post reply on HN