Live data from Hacker News

EU proposal to scan all private messages gains momentum

cointelegraph.com

61–70 of 230 posts

Re: EU proposal to scan all private messages gains momentum

#61
post #51

Can someone explain how the same group of countries can simultaneously issue book-long regulations about how everyone needs to respect privacy to the nth degree, and run around the world trying to force others to do the same, yet also propose these kinds of things?

pretty simple: hypocrisy and lying from pathological personalities to gain more power, with a population fool enough to take them at face value.

Re: EU proposal to scan all private messages gains momentum

#62
post #44

Do citizens in the EU actually want this? If not, how are EU politicians so disconnected from their citizens? How did this state of affairs come to be? Is it reversible? In the US, our politicians don’t diverge quite as much, but when they do, the reason is money, and when it gets bad, we throw the bums out and elect populists. It’s not pretty and it’s messy but it self corrects with the next election if it doesn’t w…

Most of the people I know - and I live in eu - are not knowledgeable about these topics. Furthermore, I've never heard about this in one of the main news channels, so I guess that most people don't even know about it

There's this "I have nothing to hide" sentiment followed by blind trusts into officials, their intentions and their alleged protection. I.e. people are scares of terrorism and would like it to stop, so they hope the terrorists will be found by spying.

At least in countries where the terrorism emerged recently, I'd say...

Re: EU proposal to scan all private messages gains momentum

#63
post #53

Earlier quoted context omitted.

The data tells us that many child abusers are caught with CSAM as well, so it does jack shit to keep them from abusing kids, Take your CSAM apologia somewhere else.

> The data tells us that many child abusers are caught with CSAM as well How much CSAM? A PornHub's worth of content, or a couple of pictures? The data suggests that in the adult porn world, people aren't satisfied by a single Playboy magazine. Which, too, is the logic behind CSAM laws — that the insatiable search for more content incentives production of more content. But at some point there will be more content tha…

> But at some point there will be more content that can be consumed, and given how often CSAM producers are caught (not even counting those who never are) we've no doubt far exceeded that threshold

No, we haven't "no doubt far exceeded that threshold". Some CSAM producers getting caught does not make it so. I could say it's unlikely that CSAM production even approaches 1% of the magnitude of adult pornography production—but I too would be pulling numbers out of my ass. Without hard data on this, all we have is meaningless assumptions—and I'm not sure this sort of data is available to anyone.

> Ad hominem is a logical fallacy.

Logical fallacies apply only to arguments.

Re: EU proposal to scan all private messages gains momentum

#64
post #49

The first mitigation steps that come to mind: - Keep casual conversations on mainstream crap to be reachable by the masses and give the appearance of being monitored . - Send friends to a tiny URL that redirects to a tiny ephemeral private anonymous chat instance running entirely in RAM with an IP certificate [0] once available to remove domain name ownership from the picture. When done with that chat edit redirect t…

I've done an essay as my exam for an ethics course in uni, and choose to talk about chat control. I came up with very funny ways to circumvent scanning images. The easiest one would be to just encrypt an image and send the key and the encrypted message on different platforms to the recipient, I highly doubt they will be tied to the single user.

Another - funnier way - would be to send the image as a file, and the recipient should convert it back to an image. Of course this could be automated as well on the scanning side, but if the regulation only talks about images, it should be safe. Not that I would do this if chat control happened and I would need some way to secure the content

Re: EU proposal to scan all private messages gains momentum

#65
post #3

This seam like a hopeless endeavor. If circumvention takes little to no effort the people that are already committed to CSAM are going to CSAM. And everyone else will just hate the burdensome bloat, etc. If you know your not a theif having your bags checked after paying is an annoyance

> If circumvention takes little to no effort the people that are already committed to CSAM are going to CSAM.

Meta made 1.8M CSAM reports to authorities in 2024 Q4 alone. An awful lot of these people aren’t taking any steps at all to avoid detection – they are posting it to social media.

You can argue the ethics of this scanning all you want, but if you’re arguing that it won’t be effective then you’re wrong.

Re: EU proposal to scan all private messages gains momentum

#66
post #49

The first mitigation steps that come to mind: - Keep casual conversations on mainstream crap to be reachable by the masses and give the appearance of being monitored . - Send friends to a tiny URL that redirects to a tiny ephemeral private anonymous chat instance running entirely in RAM with an IP certificate [0] once available to remove domain name ownership from the picture. When done with that chat edit redirect t…

Neat idea, a link that the first two people to open it get websockets and a chat, every subsequent connection gets a redirect. If pages are being crawled preemptively, the chat will be broken and if they're crawled afterwards there's nothing to see.

The first two people would open this link would be you and the police's LLM

Re: EU proposal to scan all private messages gains momentum

#67

I assume this is just a police state overreach rather than genuine intent to stop crime. They must know that anyone actually engaging in criminal activity is going to not be caught by this because they use other forms of encrypted communication.

I'm not saying that this is NOT police state overreach, but the assumption that all (or even most) criminals practice good operational security still seems laughable to me. I think you are letting your ideological alignment (against surveillance state) push you into irrational standpoints ("more surveillance would not catch additional criminals"). I'm 100% with you on opposing legislation like this, but it is very im…

We in infosec are often trained to imagine the ideal "adverse actor" who could do the most possible damage to our systems to test their vulnerability.

It's a good model for identifying and closing gaps (especially if one is not, oneself, prone to think like a criminal), but like all other human population groups, half of all criminals are below average.

Re: EU proposal to scan all private messages gains momentum

#68
post #49

The first mitigation steps that come to mind: - Keep casual conversations on mainstream crap to be reachable by the masses and give the appearance of being monitored . - Send friends to a tiny URL that redirects to a tiny ephemeral private anonymous chat instance running entirely in RAM with an IP certificate [0] once available to remove domain name ownership from the picture. When done with that chat edit redirect t…

Technology has been there for decades. The real problem is convincing people you want to chat with that this it's important and worth all inconveniences (no chat history, no multi-device sync, no group chats, etc.) and the network effect is working against it.

Would be great if regulators understood that serious criminals will have a way of communication that is not traceable with this regulations.

Re: EU proposal to scan all private messages gains momentum

#69

Earlier quoted context omitted.

I'm not saying that this is NOT police state overreach, but the assumption that all (or even most) criminals practice good operational security still seems laughable to me. I think you are letting your ideological alignment (against surveillance state) push you into irrational standpoints ("more surveillance would not catch additional criminals"). I'm 100% with you on opposing legislation like this, but it is very im…

I've always thought we're actually very lucky that terrorists tend to be idiots.

I'm reminded of the story of the bombing attempt that failed because two cells miscommunicated on timezone.

The bomb was handed off across a political boundary and detonated at some arbitrary point on the way to its target, an hour earlier than expected.

(And then there was the one in France, where a cellphone-triggered bomb detonated prematurely and eliminated its builders because the mobile carrier they were using sent a "HAPPY NEW YEAR" SMS to every customer).

Re: EU proposal to scan all private messages gains momentum

#70

Earlier quoted context omitted.

I'm not saying that this is NOT police state overreach, but the assumption that all (or even most) criminals practice good operational security still seems laughable to me. I think you are letting your ideological alignment (against surveillance state) push you into irrational standpoints ("more surveillance would not catch additional criminals"). I'm 100% with you on opposing legislation like this, but it is very im…

I think the slightly more sophisticated position is that, regardless of the operational security that is currently employed, if you were to implement something like this, then criminals would quickly adapt to improve their operational security accordingly. Especially because "operational security" in this case is doing a lot of heavy lifting to obscure how easy it would be: just use a good E2E messenger. This is not…

> you were to implement something like this, then criminals would quickly adapt to improve their operational security accordingly

This just isn't the case. Many criminals use non-encrypted phone calls, leave voice mails, etc. all the time. For example this recent theft of a gold toilet:

https://www.bbc.co.uk/news/articles/cgeg39vr3j3o

> A photograph found by police on his phone showed a carrier bag stuffed with cash, which was sent on WhatsApp with the message "520,000 ha ha ha".

The only reason that was E2E encrypted is because everyone in the UK uses WhatsApp and they enable E2E encryption by default.

> I think the assumption that criminals would not learn how to use one of the many free E2E encrypted messengers is the deluded and naive position.

It absolutely isn't. Some would, but the vast majority of criminals are not security experts.

It's still a dumb law. Also the criminals that it claims to target (paedophiles) are probably the least likely to get caught because they're already used to lots of electronic scanning things. Though even there it's not like they're all criminal masterminds. I can't find it now but there was recently a story about a someone who tried to hide child porn just in a deep folder structure like .../secret/do_not_open/i_warned_you/...

Dumb law, but lets use real reasons to argue that.

Post reply on HN