Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

FTA:

What changes with the return of Chat Control 1.0—and what stays the same:

*What is coming back:* US tech companies are once again allowed to scan private messages without a warrant or prior suspicion. This affects direct messages on platforms like Instagram, Discord, Snapchat, Skype, and Xbox, as well as emails via Google’s Gmail and Apple’s iCloud.

*What remains unchanged:* Public social media posts and files hosted in cloud storage could already be scanned without this law. Furthermore, private messages can always be reported by users, or monitored by authorities using targeted, court-ordered wiretapping.

*What is still NOT being scanned:* End-to-end encrypted chats, such as those on WhatsApp, have always been exempt from these scans. Additionally, European providers of messaging and email services have never implemented chat control measures.

So, E2E is unaffected?



The Internet Watch Foundation, the group, funded almost entirely by big tech, who pushed for this vote to be held under emergency procedure, is already at work lobbying for the end of E2EE [1].

In a couple years time, Chat Control 2.0 will come about, and the same tyrants will use the EU admission [2] that there is no evidence that suspicionless scanning of private communications has led to an increase in criminal convictions or in rescued children to argue that we need to go further, and break E2EE.

[1]: https://www.iwf.org.uk/resources/end-to-end-encryption-and-k... [2]: https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELE...


Why would big tech be in favor of having to scan message content? It puts more regulatory requirements in place on their activities. Would they not be in favor of _less_ regulation so they can provide services to their users with fewer legal considerations?

If big tech _wanted_ to they could already backdoor their encryption and scan the message content, they don't need regulation to do that. The only thing that changes with regulation is that they now _have_ to, which cannot possibly be in their favor.


> Would they not be in favor of _less_ regulation so they can provide services to their users with fewer legal considerations?

Regulatory capture. If the handling of user messages requires constant scanning and there are enough rules that you need a team of lawyers, then only Google, Meta and Apple will be able to afford it.


Also without chat control they would have to follow much stricter eprivacy directive laws that makes many of their monetisation strategies ilegal.

It's briliant really... instead of trying to dismantle privacy regulations you push for new regulation that overrides them and make data mining users even mandatory.


I get why this might be a thing, but scanning E2EE messages? Big tech invested a lot in making E2EE happen.


Apple is wholly against Chat Control.


Where did you get that impression? The main driver for Chat Control 2.0 is lobby org Internet Watch Foundation where Apple one of the main donors (along with Meta, Google, Microsoft, OpenAI)


because we all can agree child porn is bad and just because a company donates to a charity doesn't mean they get to dictate their policies


In a same way - just because a charity claims they want to solve child porn doesn't mean that their real aim is to help their donors.

In any case the OP claimed "Apple is wholly against Chat Control." i don't think it's so wholly if Apple financially supports biggest pro Chat Control proponents. Even if Apple is aware of it or not.


That is regulatory capture but it really feels like it should be called something else.

If the laws are designed to directly benefit it makes sense like with the FAA allowing Boeing to self regulate to the point of killing a few hundred people. This feels more like bureaucratic capture or some other name, where the entity must be so large to interact.

It has the same effect and you are not wrong, I just wish it was clearer.


I cannot imagine Musk simply submitting to this sort of EU demand, and he has enough hue-and-cry capability on X to maneuver other tech firms into very uncomfortable positions in the same regard.


Dream on. X corp is one of the sponsors of Internet Watch Foundation who are the lobby group behind Chat Control. Musk might play how terrible this is for his audience but in reality they sell all the user data and train their models on it just like every other big tech corp.


You're implying that X is not scanning, or ever planning to scan, private messages without a warrant or prior suspicion?


lol He'll put on a show and then cave-in like he always does: https://people.com/elon-musk-says-he-didnt-do-nazi-salute-at...


Blud thinks musk has any principles, he is literally grifting for maga to stop immigration and then goes and facilitates h1b when there are plenty of talented workers that could be hired.


That guy is outright cheerleading fascists in European countries and wants to put them in power. Why would he want to take away such a powerful tool from them?


He definitely does not want to put this power into the hands of EPP and S+D, which are precisely the two fractions that pushed this through.


Once a law is passed that permits abuse of power, that new toy is available to whoever is in control of the government, which could be the parties he likes. Seen this kind of thing over and over again when one group gains control of a level of government, passes a bunch of authoritarian crap under the belief they have a mandate to rule forever, and then lose power, giving their opponents control over that new authoritarian toy. In the end, the political class gains more power and the public loses. What rarely happens is a change in leadership giving up the power the previous leadership gave itself.


L, and I cannot stress this enough, OL


It's confusing because of the indirection.

The Internet Watch Foundation is one of these NGOs that makes lists of hashed child porn images and URLs. All the big tech companies subscribe so they can coordinate on blocking child porn, as they are legally required to do.

Unfortunately the IWF is also a "charity" and thus engages in political lobbying. Because like all such NGOs they have a single purpose, they lobby for making that purpose easier irregardless of other costs, which they view as out of scope. It's obviously easier to watch the internet if tech firms are forced to watch everything all the time, so that's what they're in favour of.

People actually working at tech firms on messaging systems don't want to do this, however. So they end up funding people who are undermining their own policies. This is very common whenever NGOs get involved e.g. governments funding NGOs that directly undermine the government's own efforts.

The fix would be for tech firms to leave the IWF and set up their own alternative organization that doesn't engage in lobbying activity. However, that would require a lot of cross-org agility that is difficult for big companies to achieve even internally, let alone across the industry, and the leadership is all thinking about AI anyway not EU stuff where they already just assume the EU is going to regulate them all the death anyway. So inertia carries the day.


Because regulation (even well meaning regulation) always favors incumbents and hinders startups.


I think this is basically correct and aligns with Facebook’s massive push toward e2ee in Messenger. They don’t want to be on the hook, and didn’t do e2ee just for the fun of it


Why? To know more to train AI and sell your info to third parties. To spearhead ads to you.

Why an earth would a big tech company say no to gather more info on its users? Show me the first one


Regulation is a good thing for big, established incumbents who can afford expensive lawyers. It keeps them safe from competition.


Do you have source for IWF funding being by big tech?

Haven’t found anything that breaks their funding down by source and the majority on the UK govt site is from “charitable activities” (https://register-of-charities.charitycommission.gov.uk/en/ch...)


https://www.iwf.org.uk/membership/our-members/

The top 25 members (£90k+; big tech are here) contributed between £2.25M and £4.37M. The other 110 members contributed between £2.26M and £4.46M.


Honestly they have a lot of members including the BBC for some reason, Apple is one of them. It seems like it might just be good practice to support them, it signals ‘we are against child abuse’. Dropping support could lead to some bad headlines. Seems like an NGO that is really good at sales, probably putting some pressure on it’s members rather than the other way around.

I get that if you are an ngo that really wants to solve online child abuse you’d want a law like this. It may be mostly the ngo pushing for it, not necessarily big tech. I could be wrong.


This is really strange since the European Commission strongly recommends that staff use Signal[1].

[1]: https://www.documentcloud.org/documents/26073615-c-2025-5430...


Staff is exempted from mass surveillance.


At this point we have no choice but to conclude that the Eu has been subverted by megacorps as badly as the US political system has been.


Any hierarchical system of governance ends up with sociopaths on top. It's just the nature of hierarchy and bureaucracy that is necessary for it.


Guess what's coming next:

> Overview

> End-to-end encryption is a term used to describe blocking or preventing any third-party recipient from viewing, reading or becoming aware of information that one individual has sent to another. In response to growing concerns about online data security, many technology companies are adopting this strategy with potentially dire circumstances.

> The use of end-to-end encryption would prevent the companies or any third-party from detecting illegal activity occurring on their platforms, including the activity of people who use the internet to perpetuate online demand for graphic sexual abuse material of children.

> We believe personal security is extremely important and support efforts to improve online privacy. But, if this solution is implemented with no exceptions for detecting child sexual exploitation, millions of incidents of abuse will remain hidden, leaving these young victims without any help or protection from these horrific crimes.

https://ncmec.org/theissues/end-to-end-encryption


> So, E2E is unaffected?

Because its an extension of an existing bill.

After the whole internet lost its mind about Apple CSAM scanning and being horribly off target, I'd recommend to ignore news reports and go to the sources when making an opinion.

https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A...

https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=COM...

The only issues I can see is the error rate for non-CSAM scanning and how the latest vote was conducted.

Although the scanning part, it is still law enforcement that has to review that information and determine if there is a case. Most of the those are teens sharing naked photos with other teens.


Yes.

Chat Control 2.0 was the big one in those regards.

(Also, LOL @ Skype mention.)


Then I'm not very moved about this. I always assumed that anything unencrypted is scanned one way or another. What I care is not having a backdoor for E2E, i.e. like client-side scanning telling me what I am allowed to talk about like with the LLMs. CSAM excuse is a great excuse to turn every conversation to what we have with AI today.


If reading messages that are not for ones eyes is OK, then it is a much smaller step to the next level, which is to also being able to read encrypted messages. Slowly boiling the frog.


But the next level IS the chat control 2.0 and yes it is the one people should be concerned about. But it's not like this is unprecedented this is literally just an extension of something that existed.


I assume the same, but not because it’s sanctioned. Sanctioning is a slippery slope or a degree change as has been mentioned.


And the temperature of the frog pot rises by one degree.


[flagged]


I disagree. The definition of "bad actor" constantly changes. Something you do legally today can and will become illegal in the future, and if you don't change your ways, you will be a bad actor, too.

The people pushing for this under the guise of protecting children are the same people who went on The Island, or at least protect those who did. They never cared about children's safety.

The biggest criminals of all are the very same people pushing for these laws, this surveillance, this control. Don't be fooled.


Sure, the definition changes but whoever are the bad actors now create the desire to deal with them, which creates a motive or excuse to create or change systems for that. No matter how fair or unfair the treatment is, if you actually manage to stonewall that through technological or other means, those will be destroyed.


I don't think I understand what you're trying to say in this comment, but if by: >if you actually manage to stonewall that through technological or other means, those will be destroyed

You mean some kind of resistance against tyrannical policies, then those "other means", if I understand what you're saying, are often illegal. True resistance that causes true societal change isn't parading the streets with signs or talking to your local representative. It's sabotage, vandalism, and in extreme cases, violence. True activism. The surveillance state's main goal is disrupting such initiatives before they can even get off the ground.


It's a metaphor for a process. Calling people names like "maxxers" is unhelpful and probably against the rules here.


>It's a metaphor for a process. Calling people names like "maxxers" is unhelpful and probably against the rules here.

Yeah we don't mean frogs, that's obvious. Calling people maxxers being offensive is surprising. Maybe you should consider offended for being called cancer instead?


https://en.wikipedia.org/wiki/Argument_to_moderation

The truth is not always somewhere in the middle. If one group wants to serve water and another wants to serve cyanide, the right answer is not to mix the two, it's to serve water and to end the careers of the people who wanted to serve cyanide.


I am not arguing for a middle ground, I argue for addressing the issues directly instead of being maximalist in any way.


You are dismissing things as "maximalist", which is not conducive to treating certain things as sacrosanct.

For example: end-to-end encryption is sacrosanct, and must not be broken, ever. If you want access, your only option should be to serve one of the ends a warrant. That's not "maximalist", that's holding to a principle.


> I always assumed that anything unencrypted is scanned one way or another

By this logic, I should be happy if mail delivered to my address always arrives already open.


Don't downplay Skype, as Teams is still just rebranded Skype for Business (LYNC).


Are my AIM chats safe?! /s


You should be using AIM OTR: https://otr.cypherpunks.ca/


Adding to this there is pidgin-otr and python-potr.

For IRC there is irssi-otr. There was weechat-otr but I think it may have gone unsupported as their script did not work in python3.

There is also ejabberd [0] that has OMEMO [1] preferred over OTR and PGP and supports many to many E2EE.

Someone tried to MitM Jabber, discussion here on HN [2].

[0] - https://ejabberd.im/

[1] - https://en.wikipedia.org/wiki/OMEMO

[2] - https://news.ycombinator.com/item?id=37955264


You kid, but there are still some active AIM users (or at least, a revival of it)


> What is coming back: US tech companies are once again allowed to scan private messages without a warrant or prior suspicion. This affects direct messages on platforms like Instagram, Discord, Snapchat, Skype, and Xbox, as well as emails via Google’s Gmail and Apple’s iCloud.

They are already allowed to do this, and already are doing this. When you provide data to the service provider in a non-e2ee fashion, it's their data as much as it is yours. They can scan it, data mine it, analyze it, whatever.


This is the whole point though. They are allowed to do this because of the original chat control from 2021 which was temporary and expired in march. Without chat control it is very debatable what companies can legally thanks to eprivacy directive.


They aren’t allowed to do whatever they want with your data, there’s strict restrictions on requiring consent for things you want to do with user data.


I assume those 400-page EULAs blast away any 'strict restrictions'.


No, GDPR spells out in much more detail what consent means - and burying things in a EULA doesn’t work.


Yes, and you consent when you enable iCloud.


And your REALLY think E2E is going to "protect" you?

If the "services" want to watch, don't worry they will, "they don't need your password". But I guess they "do" that only for the very baddies, aka child exploitation, human trafficking, terrorists, killers, drug dealers, etc.

We all know here that "information system security" does not exist, this is a fantasy: there is only some "best effort" with a wide spectrum of compromises. If somebody talks to you about "deliverable security", that guy wants to sell you something.

E2E will protect you only against John Doh, "hacker only on Sundays". And we better keep that in mind.


What are you talking about. You think service providers can backdoor aes-gcm? There will always be technology that they cannot get around. The only way to backdoor is to explicitly change the encryption.


Are you misunderstanding on purpose?

This is not specific to 'backdooring aes-gcm implementations' at all. Read again what I wrote, namely this is the general status quo on 'information system security': they don't need your password or aes-gcm key to watch if they really want to. You would be a fool to presume anything else.


Service providers like say Apple and Google can push an update to your phone which will intercept all that data after it has been decrypted.


I understand. So don't use them. There are plenty of OS alternatives


Does this apply only to new messages or also to history?


Are the messages to LLMs scanned (beyond normal collection for future training purposes) or is that just for human-to-human messenging?


Yes. I see no reason to think otherwise.


What's the purpose of this law? Protecting the recipients or punishing the senders?


I don't know what the companies want with it. But they'll try to hide the logs in discovery for a lawsuit. [1]As nyt found out.

https://arstechnica.com/tech-policy/2026/07/openai-faked-ina...


E2E is unaffected... For now


Skype?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: