Live data from Hacker News

Mullvad's campaign against EU chat control

mullvad.net

81–90 of 107 posts

Re: Mullvad's campaign against EU chat control

#81

I am currently reading through all of the legislation to try to figure out what the latest version of this actually requires from providers. Early versions talked about scanning for "grooming behavior" in textual conversations, but then also required that there would be no mass-scanning of communications: this seems obviously contradictory. What's frustrating about these laws is how vague everything is: I wish there…

The ambiguity is by design.

It puts the onus on the implementer to be overzealous under fear of being criminally liable. This has the added benefit (to the slimy legislators pushing this garbage) of allowing them to scapegoat any perceived excesses onto corporations and developers.

Re: Mullvad's campaign against EU chat control

#82
post #4

To be honest I'm not very hopeful. The average Joe really is gullible - just drop some terrorism, children and nowadays some "preventing misinformation" bs (which of course has never and will never be twisted to fit government's needs at the time) to the mix and people will accept it. Nevertheless I support these campaigns since I'm more than happy to be proven wrong.

Don't forget "fighting hate speech". If one doesn't support "fighting hate speech", that person is obviously an alt-right neo-Nazi.

I'm not hopeful either. For the first time in literally millennia, we've enjoyed a few golden decades of almost entirely uncontrolled communication. And now a lot of us are (unknowingly) begging for that to be taken away.

Re: Mullvad's campaign against EU chat control

#83
post #24

There are an unusual number of comments from new accounts making disingenuous arguments on this post. I wonder who is behind the astroturfing. The answer to "what else should we do about bad people doing bad things?" is, of course how we usually catch people doing bad things: old-fashioned detective work. It involves taking reports of suspicious or illegal acts, interviewing witnesses and associates, requesting court…

Please remember the HN Guidelines: > Please don't post insinuations about astroturfing, shilling, bots, brigading, foreign agents and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email hn@ycombinator.com and we'll look at the data. https://news.ycombinator.com/newsguidelines.html

I mean yeah, but when there's a bunch of green accounts whose only comments are horrible corpo-speak takes on one single submission they're basically holding a sign that says "I am not a real HN commenter".

Re: Mullvad's campaign against EU chat control

#84
post #50

Earlier quoted context omitted.

It's a tired tale by now but stirring shit (whatever shit wherever it happens) is literally part of the Russian playbook [1] [1] https://en.wikipedia.org/wiki/Foundations_of_Geopolitics

Really? Just the Russian playbook? No other country stirs shit up? No other country meddles in another country's affairs? No other country starts color revolutions to get someone they like to lead the country? No other country bombs another countries pipeline that serves "Allies"?

Yes, russia. And they don't even hide the threats: https://twitter.com/PMSimferopol/status/1634111915596173312

Re: Mullvad's campaign against EU chat control

#85

I am currently reading through all of the legislation to try to figure out what the latest version of this actually requires from providers. Early versions talked about scanning for "grooming behavior" in textual conversations, but then also required that there would be no mass-scanning of communications: this seems obviously contradictory. What's frustrating about these laws is how vague everything is: I wish there…

The legislation [1] is amazingly vague about the impact on end-to-end encrypted systems. In fact the string "encryption" appears twice, and only once in the body of the text (in Paragraph 26 on page 27.) This paragraph basically says "it's ok to use end-to-end encryption" but does not actually stipulate an exemption for scanning technologies. Presumably this means you would need to somehow implement an effective scanner into your end-to-end encryption. The legislation gives no other guidance about how to do this, how secure it will be, or even a mild discussion of the tradeoffs.

This is alarming because the bill also makes clear that the goal is to detect not only known and unknown CSAM using some technological measure, but also to detect textual content that represents "grooming behavior." Only the "known" CSAM detection approach has ever even been attempted in a production system (with significant limitations) and that system was not ultimately deployed due to technical and customer concerns. But as much as CSAM media scanning worries me, the idea of automated ML-based text analysis for something as vague as "grooming behavior" is frankly terrifying. And I haven't even considered the slippery slope that becomes visible the second you build text-analysis and reporting systems into encrypted communications.

What is much more concerning than the legislation is the Impact Assessment [2], which is cited in the legislation to justify its reasoning. Specifically, the Impact Assessment recommends Option E, which is "mandatory scanning of all known and unknown CSAM, as well as textual detection of 'grooming behavior'" even in systems that deploy E2E encryption.

Where the legislation is vague about E2E encryption, the impact assessment [2] leaves no scrap of unambiguity: it makes clear that the need for these mandatory scanning mechanisms is almost entirely a response to the increasing deployment of E2EE, and specifically cites Facebook's (still un-deployed) 2019 encryption announcement to support its argument for a mandatory scanning requirement. It uncritically cites Apple's (since withdrawn) CSAM scanner (p. 39) as an example of a balanced privacy solution. It cites vaguely to the existence of scanners capable of detecting unknown CSAM, barely acknowledging that such techniques are entirely at the hypothetical/research stage and may not be safe at all. Finally it provides a privacy analysis that somehow concludes that the privacy benefits "in protecting victims" naturally outweigh all other concerns that might pop up around the deployment of what will be the world's most powerful ML-based text and media mass-surveillance system for encrypted and unencrypted private messages.

Because take note: while the authors don't use that terminology, readers should have no doubt: that is what the EU is proposing to build with this legislation.

[1] https://eur-lex.europa.eu/resource.html?uri=cellar:13e33abf-...

[2] https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE...

Re: Mullvad's campaign against EU chat control

#86
post #83

Earlier quoted context omitted.

Please remember the HN Guidelines: > Please don't post insinuations about astroturfing, shilling, bots, brigading, foreign agents and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email hn@ycombinator.com and we'll look at the data. https://news.ycombinator.com/newsguidelines.html

I mean yeah, but when there's a bunch of green accounts whose only comments are horrible corpo-speak takes on one single submission they're basically holding a sign that says "I am not a real HN commenter".

This might be the one guideline that makes me uneasy. I get why it's in place - some people will call anybody that disagrees with them a shill or whatever - but to pretend it isn't happening while it so obviously is feels a bit immoral. At the very least, it's certainly complacent.

Re: Mullvad's campaign against EU chat control

#87
post #50

Earlier quoted context omitted.

Really? Just the Russian playbook? No other country stirs shit up? No other country meddles in another country's affairs? No other country starts color revolutions to get someone they like to lead the country? No other country bombs another countries pipeline that serves "Allies"?

Yes, russia. And they don't even hide the threats: https://twitter.com/PMSimferopol/status/1634111915596173312

Neither does the US.

https://www.bloomberg.com/news/articles/2022-02-07/biden-sai...

Re: Mullvad's campaign against EU chat control

#88

I am really worried about this. I feel completely helpless though, I am almost a 100% convinced this legislation will make it through. It will be the worst day in the history of the EU. Great to see this campaign though.

We will then go and use GPG and Tor, where's the problem

Re: Mullvad's campaign against EU chat control

#89
post #15

Earlier quoted context omitted.

This is what Microsoft and Google are doing already. This is why I don't backup my photos to a cloud any more.

And if you are worried, don't upload to a some smaller provider either because some of them might have fun looking at the backups of the things that people find to to sensitive to upload to Google.

There's nothing sensitive - I just don't like being treated as a potential criminal.

Re: Mullvad's campaign against EU chat control

#90
post #87

Earlier quoted context omitted.

Yes, russia. And they don't even hide the threats: https://twitter.com/PMSimferopol/status/1634111915596173312

Neither does the US. https://www.bloomberg.com/news/articles/2022-02-07/biden-sai...

Turns out he did not even have to do anything. Russians did it themselves.
Post reply on HN