📣Official statement: the new EU chat controls proposal for mass scanning is the same old surveillance with new branding.

Whether you call it a backdoor, a front door, or “upload moderation” it undermines encryption & creates significant vulnerabilities

https://signal.org/blog/pdfs/upload-moderation.pdf

@Mer__edith I'm willing to bet either Blumenthal, Blackburn, or both keep advising whatever crazies keep proposing this, because every time similar legislation happens here their names are on it.
@Mer__edith Agreed! Keep up the good work 🔒
@stux @Mer__edith I think "No law may force any entity involved in the manufacturing or use of a device to make it function against the will of its user." should be added to constitutions worldwide.
(or a rephrasing thereof)
@Mer__edith Now that more and more countries become right wing extremist safe grounds it is nice to know they now have mass surveillance at their fingertips.
Who would have expected this?
@Mer__edith It’s almost reassuring, in a way, that they keep trotting this out: it acts as a warrant canary letting us know the intelligence agencies haven’t broken encryption yet. Once they stop asking for it we should start asking questions ☺️
@Mer__edith Now THAT is what you call a fantastic press release. Team Signal is fabulous 👏

@Mer__edith

This is a good reminder to download versions of your favorite encryption tools like #Veracrypt while you still can.

https://www.veracrypt.fr/en/Downloads.html

VeraCrypt - Free Open source disk encryption with strong security for the Paranoid

VeraCrypt is free open-source disk encryption software for Windows, Mac OS X and Linux. In case an attacker forces you to reveal the password, VeraCrypt provides plausible deniability. In contrast to file encryption, data encryption performed by VeraCrypt is real-time (on-the-fly), automatic, transparent, needs very little memory, and does not involve temporary unencrypted files.

@Mer__edith
By the way PhantomSecure and EncroChat goes, people can clearly see criminals would opt to buy shady encryption devices in the gray area, instead of using publically-available communication services (no matter the latter is backdoored (like AN0M) or not), and police still has their way to the data they want.

Why all the shitty politicians still vow to backdoor encryption shouldn't be a question that needs to be asked anymore. Clearly it's meant to destroy the privacy provided by strong encryption and control the citizens even more.
@Mer__edith
Thx a lot for this clear statement 😉
@Mer__edith Part of me wonders how long it's going to be before we build AI agents on Ollama that act as client interfaces for our social media and chat platforms, where personal conversations between two people thes agents turn it into normal dull text messages. Part of it will likely include having the agents discussing 'War and Piece' 'Dune' 'The Ring of Life', etc., that provide an overwhelming amount of content for the monitors to try to pick through when invading people's privacy.

@Mer__edith Nobody is going to use the compliant apps. Instead, they will allow installing apps from "untrusted sources," download something like Signal(which will never allow backdoors) from servers not in the EU (since Google Play and Crapple will have to remove it or exit the EU market), and ignore this law. It would take effort on the scale of China's Great Firewall to prevent this and even that would leak, as does China's censorship.

If their ISP blocks the download, they will go to Tor or a VPN and bypass ISP filtering

@LukefromDC @Mer__edith Most people don’t know how to do stuff like this. Regular folks using WhatsApp will get surveiled and have their lives ruined by false positives.

@MisuseCase @Mer__edith Than it will be up to that to make this as accessable as we can and to broadcast information and warnings.

Those the government most wants to surveill will as always be the ones they miss. From organizers to underground direct action crews, from the best freedom fighters to the worst terrorists, they won't be able to read ANY of that traffic.

This will be like trying to prevent drones from delivering guns and drugs into prisons by monitoring the nearest airport.

In other words, the surveillance will hammer the civilian populace while completely missing its intended audience, same way IOF bombs do.

@MisuseCase @Mer__edith First step: In Android permissions you can with one "click" enable installing apps from one existing app. Got to settings->apps->Files (or whatever you have)->advanced/Install Unknown Apps and set to "allowed" and you can then install downloaded apps from the file manager.

In older versions, it was under "security" and would allow installing non-Google Play apps from any program on the device that could open them. This of course had the potential disadvantage of allowing silent installation of malware from the browser.

@LukefromDC @Mer__edith It’s okay I have Signal and I know how to use it

@Mer__edith so will @signalapp stop collecting #PII like #PhoneNumbers and actively work towards making #compliance with such #cyberfacist demands impossible by truly #decentralizing and moving onto @torproject for it's infrastructure...

If not, why?
https://infosec.space/@kkarhan/112636260519554561

Kevin Karhan :verified: (@[email protected])

@[email protected] @[email protected] so will #Signal stop requesting #PII like #PhoneNumbers and refuse to comply with such #cyberfacist demands. - If not, why? - If yes, how?

Infosec.Space

@Mer__edith So what happens if we were to a string of 0s and 1s through text that, when compiled, encodes an image? This whole law is so silly from a technology regulation perspective.

They need to show their code before they can pass the law that forces every provider to use their code... But also: How decentral can you go with Signal node hosting costs?
I understand the law says home-hosted servers are exempted from the law as long as they never touch state money?

@Mer__edith What an embarrassing development. The #EU urgently needs to return to the core values of European societies. /cc @ton

Edward #Snowden reacted:

EU apparatchiks aim to sneak a terrifying mass surveillance measure into law despite UNIVERSAL public opposition (no thinking person wants this) by INVENTING A NEW WORD for it—"upload moderation"—and hoping no one learns what it means until it's too late. Stop them, Europe!

https://x.com/Snowden/status/1803127597158760735

Edward Snowden (@Snowden) on X

EU apparatchiks aim to sneak a terrifying mass surveillance measure into law despite UNIVERSAL public opposition (no thinking person wants this) by INVENTING A NEW WORD for it—"upload moderation"—and hoping no one learns what it means until it's too late. Stop them, Europe!

X (formerly Twitter)

@Mer__edith It honestly stuns me that Europe has forgotten STASI so quickly.

Private communication between individuals is a fundamental requirement for democracy.
Removing that capacity endangers democracy.

@Mer__edith does bigstate in EU try to obtain what has been already obtained by bigstate un US/China via their control of bigtech?
@Mer__edith It's nothing but the same old surveillance tactics wrapped in a shiny new package. Whether they label it a backdoor, a front door, or disguise it as "upload moderation," this proposal is a direct threat to encryption. The audacity to push this under the false pretense of protecting children is beyond belief. The EU council must not let this pass. Our security and freedoms are at stake, and we must stand against this deception!
@Mer__edith They know & are hoping to induce "care fatigue"

@Mer__edith And this shit is not going to go away until the institutional actors determined to enact it have been abolished.

It'd be appropriate to abruptly and comprehensively and completely defund whatever EU agencies keep insisting on authoritarian social controls.

EU Council has withdrawn the vote on Chat Control

The EU Council and its participants have decided to withdraw the vote on the contentious Chat Control plan proposed by Belgium, the current EU President.

Stack Diary

I have many complaints about my country, the USA, but the first amendment and fifth amendments give us some pretty good arguments against the EU's chat control proposal. Not to say we don't have boomers trying to undermine those rights as well and things like the Patriot act among others.

This is utterly embarrassing for the EU for the same country that created the GDPR. I know they have withdrawn the vote, but in my opinion it should have never even been a consideration.

#InfoSec #Privacy

@Mer__edith
How do I know their claims are a bunch of male cow faecal matter?

I found sites on the clear Internet containing CSAM. I attempted to report them to all of the relevant bodies - domain registrars, hosting providers, CDN providers and one notorious DDOS mitigation / CDN company which name rhymes with "loud snare", and government child exploitation organisation at the country the domain was registered at.

Crickets, evasion and pushback.
1/2

@Mer__edith
If the EU politicians were serious about CSAM they would go after the low hanging fruit first, and then turn to the E2EE channels.

The fact that there are CSAM websites reachable on the clear-net and advertised through links in very public telegram groups shows what they really want, and CSAM is just the excuse.
2/2

(Signal)新たなブランド、Same Scanning: “Upload Moderation”がエンド・ツー・エンドの暗号化を蝕む – 反監視情報