upvote
People can also distribute heinous things through snail mail, but we are not yet at the point where the government reads all letters looking for wrongthink.

Just because we technically can make a privacy destroying drag net does not mean we should. Had phones existed 250 years ago, I have no doubt the founders would have thought it obvious that a cellphone’s contents were your personal papers which could not be freely searched.

reply
But that's mostly because it's impractical. They do use dogs to sniff for drugs and explosives, so if CSAM smelled or was visible through X-ray then it would probably be a different story. And let's not forget snail mail is by far a more uncommon way to spread that material than the Internet is. The Internet came into broad use just ~15 years after commercial CSAM was openly being sold by mail order in Europe.

Personally, I am on the side of privacy, just to be clear.

reply
If East Germany can, why can't we? /s
reply
More effort should be done to find real-world equivalents of such actions and "think of the children".

An icloud is like a storage locker or a safety deposit box... the owner should go through all your stuff there, just in case you have some CSAM!

Metadata is just tracking info about who, where and with whom... every bartender should take your IDs and log when you came to the bar, who you sat with and how long you talked there.

EU Chat control is like general eavesdropping... every time you sit down and talk with someone, an EU bureaucrat should sit next to you and listen and write down your conversations, just in case.

etc.

Somehow people think that "it's ok if it's on the internet", even when it's stuff they'd never accept in real life.

reply
Police can absolutely open snail mail with an appropriate warrant when investigating traffickers.
reply
With a signed warrant being the key differentiator vs invading privacy by default.
reply
I agree, so let's make sure that signed warrant is always required for any kind of access to communications, even _if unencrypted_ like snail mail, SMS or plain text chat client. As well as encrypted.

So - political solution, not a tech solution.

reply
Children are often used as a weapon to erode freedoms, like privacy and speech. Those pushing it rarely actually care about the children.
reply
While I’m decidedly pro-encryption, I don’t like this argument. If something is the right thing, it would still be the right thing when promoted for the wrong reasons, and if it’s the wrong thing, it’s still the wrong thing even when at present nobody has ulterior motives.

When arguing against surveillance, the arguments should be on its merits, not on whether the current proponents happen to have ulterior motives.

reply
> not on whether the current proponents happen to have ulterior motives.

Even if the current proponents have no ulterior motive, and in fact live and die having done nothing negative with such power, it does not stop the next group in power from extending and abusing power, don't base laws on temporary trust of politicians.

reply
Calling out the ulterior motives can help clear the deck to focus on what is right or wrong, without as much emotional manipulation in the picture.
reply
One problem with that is that it’s difficult to prove motives. So you’re on shaky and disputable ground. It’s much better to point out how the proposed mechanisms are prone to be misused, which is independent of current motives. Get rid of the shaky ground. Saying “these are disingenuous people proposing this” is exactly an attempt at emotional manipulation, in the sense of an ad hominem fallacy.
reply
So invading the privacy of millions of people, even if it's just automatic scans for some specific thing is a right thing? Does this apply to mandatory drug tests for everyone everywhere? How about drug and weapon seeking drones, doing daily checks in every apartment everywhere? How about mandatory AI powered microphones everywhere that would detect threats, blackmail, any talk about anything illegal, etc.?

If you take a 1000 random people of the street now,how many of them are sharing CSAM via icloud?

If you take a 1000 random politicians, how many of them have corruption scandals? Why not start with them instead, a bodycam and an AI powered microphone that would detect corruption automatically... let them lead as an example, before they apply the laws onto "the rest of us".

reply
You misread what I wrote. My comment is against the argument used, not against what is being argued for. Using the wrong argument diminishes one’s position. I’d prefer the stance against surveillance to not be diminished by such arguments.
reply
Feels like this has gone completely meta and it's now way more common to see people who don't care about children refusing to support that any proposal that might benefit children under the assumption that nobody cares about children so there must be an ulterior motive.
reply
The judge's comments are extremely disturbing, as she seems to want legislation passed that requires companies to violate user privacy.

And client side scanning is just as bad as encryption backdoors. There's a good reason Apple was attacked for even considering it: https://arxiv.org/abs/2110.07450

reply
Truly being honest, I think CSAM scanning of private comms is ineffective in the long term anyways. Pedophiles aren't stupid, you'll drag a bunch at first but the networks will be reestablished and sharing will be done via sneakernet.

The primary focus should always in preventing the creation of CSAM.

- Comprehensive Sex Ed starting young so kids can identify grooming and seek help from a trusted adult, even if abuse comes from a family member.

- Fixing schools in general so homeschooling isn't as attractive for parents. Keep a tab on home schooled children and identify social isolation.

- Bigger resources for actual honest to god on the ground investigations.

To be clear I'm not saying that homeschooling = child abuse, simply there's a lack of the mechanisms to detect it in homeschooling settings.

reply
> Pedophiles aren't stupid

I'm not entirely convinced that's true. Facebook is a leading reporter of CSAM, much of it sent through Messenger, which only recently got E2EE, and Instagram DM, which briefly had E2EE but no longer does. If I was going to transmit something that could get me in trouble, it certainly wouldn't be via Instagram DM.

Facebook's EU CSAM report is here: https://transparency.meta.com/reports/regulatory-transparenc...

reply
Facebook could be catching 99% of those trafficking in CSAM, or 1%, and still be the leading reporter.
reply
I wonder if the judge would be in favor of companies proactively going into people's houses at random to check on their belongings, if they don't have inappropriate photos somewhere, or whatever.

It's harder to do, but conceptually the same. So sad it's not being done. Very disturbing.

They could do it when people are not at home. There'd no problem, nobody would even notice.

reply
Kind of a bad analogy (not service related, no associated liability).

A better one: what about rental property, like a business? Can the landlord randomly check for criminal behavior?

reply
> Can the landlord randomly check for criminal behavior?

Absolutely not.

reply
[flagged]
reply
It is drowning in sarcasm, so I would say yes, it is a joke.
reply
The comment above is illustrating why the judge’s decision would be silly in another circumstance. And if it’s silly in that circumstance, it’s silly in the judge’s circumstance as well.
reply
They are being sarcastic.
reply
> end to end encryption means no CSAM scanning

Not true. There is the option of scanning on the device.

reply
Circumventing encryption with client side scanning is on par with requiring encryption backdoors, and goes against the purpose of having end to end encryption.
reply
> on par with requiring encryption backdoors

There is no back door if nothing leaves your device

> goes against the purpose of having end to end encryption

Most people would consider the "purpose" is to avoid 3rd parties listening in

reply
If nothing leaves the device so why to scan it at all? This is what proves your statement about compatibility of scanning and e2ee to be wrong.
reply
Owning your device (instead of the manufacturer, a set of unlisted governments, big software corporations, etc.) means no scanning.
reply
It also means no banking app will work
reply
Banks are probably the most Orwellian surveillance apparatus of all. Almost every time I read an arrest warrant there is a whole section where banking records are used to damn someone. The equivalent level of banking privacy to graphene is roughly walking in to the teller to withdraw a few thousand cash once a month and then paying literally everything with that (or an anonymized crypto).
reply
-
reply
The judge’s dicta about protecting children in her pro-privacy ruling upholding existing law “tips their hand” that they are somehow part of a global conspiracy to eliminate privacy?

I think your conspiracy theory needs work, to be perfectly honest with you.

reply
deleted
reply
> As sad as this is, end to end encryption means no CSAM scanning.

I think it depends on your definition of e2ee and where the "end"s are.

If the locally running application can decrypt the data, it could always do whatever it wanted. Is that really how you define e2ee?

reply
The locally running application is one of the 'ends' of the end to end encryption.
reply
Then in that case I think the previous statement of "end to end encryption means no CSAM scanning" would be false.
reply