Security

Stop playing games with online security, Signal president warns EU lawmakers

Comment

Signal messaging application President Meredith Whittaker.
Image Credits: PATRICIA DE MELO MOREIRA/AFP / Getty Images

A controversial European Union legislative proposal to scan the private messages of citizens in a bid to detect child sexual abuse material (CSAM) is a risk to the future of web security, Meredith Whittaker warned in a public blog post Monday. She’s the president of the not-for-profit foundation behind the end-to-end encrypted (E2EE) messaging app Signal.

“There is no way to implement such proposals in the context of end-to-end encrypted communications without fundamentally undermining encryption and creating a dangerous vulnerability in core infrastructure that would have global implications well beyond Europe,” she wrote.

The European Commission presented the original proposal for mass scanning of private messaging apps to counter the spread of CSAM online back in May 2022. Since then, Members of the European Parliament have united in rejecting the approach. They also suggested an alternative route last fall, which would have excluded E2EE apps from scanning. However the European Council, the legislative body made up of representatives of Member States governments, continues to push for strongly encrypted platforms to remain in scope of the scanning law.

The most recent Council proposal, which was put forward in May under the Belgian presidency, includes a requirement that “providers of interpersonal communications services” (aka messaging apps) install and operate what the draft text describes as “technologies for upload moderation”, per a text published by Netzpolitik.

Article 10a, which contains the upload moderation plan, states that these technologies would be expected “to detect, prior to transmission, the dissemination of known child sexual abuse material or of new child sexual abuse material.”

Last month, Euractiv reported that the revised proposal would require users of E2EE messaging apps to consent to scanning to detect CSAM. Users who did not consent would be prevented from using features that involve the sending of visual content or URLs it also reported — essentially downgrading their messaging experience to basic text and audio.

Whittaker’s statement skewers the Council’s plan as an attempt to use “rhetorical games” to try to rebrand client-side scanning, the controversial technology which security and privacy experts argue is incompatible with the strong encryption that supports confidential communications.

“[M]andating mass scanning of private communications fundamentally undermines encryption. Full stop,” she emphasized. “Whether this happens via tampering with, for instance, an encryption algorithm’s random number generation, or by implementing a key escrow system, or by forcing communications to pass through a surveillance system before they’re encrypted.”

“We can call it a backdoor, a front door, or ‘upload moderation’. But whatever we call it, each one of these approaches creates a vulnerability that can be exploited by hackers and hostile nation states, removing the protection of unbreakable math and putting in its place a high-value vulnerability.”

Also hitting out at the revised Council proposal in a statement last month, Pirate Party MEP Patrick Breyer — who has opposed the Commission’s controversial message-scanning plan from the start — warned: “The Belgian proposal means that the essence of the EU Commission’s extreme and unprecedented initial chat control proposal would be implemented unchanged. Using messenger services purely for texting is not an option in the 21st century.”

The EU’s own data protection supervisor has also voiced concern. Last year, it warned that the plan poses a direct threat to democratic values in a free and open society.

Pressure on governments to force E2EE apps to scan private messages, meanwhile, is likely coming from law enforcement.

Back in April European police chiefs put out a joint statement calling for platforms to design security systems in such a way that they can still identify illegal activity and send reports on message content to law enforcement. Their call for “technical solutions” to ensure “lawful access” to encrypted data did not specify how platforms should achieve this sleight of hand. But, as we reported at the time, the lobbying was for some form of client-side scanning. It looks no accident, therefore, that just a few weeks later the Council produced its proposal for “upload moderation”.

The draft text does contain a few statements that seek to pop a proverbial fig leaf atop the gigantic security and privacy black hole that “upload moderation” implies — including a line that states “without prejudice to Article 10a, this Regulation shall not prohibit or make impossible end-to-end encryption”; as well as a claim that service providers will not be required to decrypt or provide access to E2EE data; a clause saying they should not introduce cybersecurity risks “for which it is not possible to take any effective measures to mitigate such risk”; and another line stating service providers should not be able to “deduce the substance of the content of the communications”.

“These are all nice sentiments, and they make of the proposal a self negating paradox,” Whittaker told TechCrunch when we sought her response to these provisos. “Because what is proposed — bolting mandatory scanning onto end-to-end encrypted communications — would undermine encryption and create a significant vulnerability.”

The Commission and the Belgian presidency of the Council were contacted for a response to her concerns but at press time neither had provided a response.

EU lawmaking is typically a three-way affair — so it remains to be seen where the bloc will finally end up on CSAM scanning. Once the Council agrees on its position, so-called trilogue talks kick off with the parliament and Commission to seek a final compromise. But it’s also worth noting that the make-up of the parliament has changed since MEPs agreed their negotiating mandate last year following the recent EU elections.

More TechCrunch

Hiya, folks, and welcome to TechCrunch’s regular AI newsletter. This week in AI, music labels accused two startups developing AI-powered song generators, Udio and Suno, of copyright infringement. The RIAA,…

This Week in AI: The fate of generative AI is in the courts’ hands

Like Instagram, Whee also supports the use of photo filters and includes messaging. However, the company’s plans for Whee aren’t clear.

TikTok’s Instagram rival, Whee, has no traction

You can barely go an hour these days without reading about generative AI. While we are still in the embryonic phase of what some have dubbed the “steam engine” of…

Data lakehouse Onehouse nabs $35M to capitalize on GenAI revolution

Four startups will share €1 million in prize money and 8 million GPU hours to train their models on a couple of the bloc’s HPC supercomputers over the next 12…

Unbabel among the first AI startups to win millions of GPU training hours on EU supercomputers

The perfect device is one that never breaks in the first place, while still allowing for easy user repair access when needed.    

Apple stresses device longevity, extends self-service repair to Europe

The Supreme Court on Wednesday rejected a Republican-led challenge to the Biden administration’s communication with social media companies to combat online misinformation on topics related to COVID-19 and the 2020…

Supreme Court rejects claim that Biden administration pressured social media firms into removing misinformation

Starfish Space and aerospace giant Intelsat have signed a new satellite servicing agreement that could permanently change the paradigm for satellite operations. Under the contract, Starfish will use its Otter…

Starfish spacecraft will extend the life of an expensive GEO satellite in 2026 mission

Featured Article

How the Kaspersky ban will hit resellers in the US

“It’s just a lot of time lost for nothing,” a U.S.-based Kaspersky reseller told TechCrunch.

3 hours ago
How the Kaspersky ban will hit resellers in the US

A hacker claims to be selling an extensive database associated with an Indian government portal meant for blue-collar workforce emigrating from the country.

Hacker claims data breach of India’s eMigrate labor portal

Formation builds tech-forward solutions for clinical trials and drug development.

Formation Bio raises $372M to boost drug development with AI

We’re incredibly excited to announce that we’ve added a dedicated Fintech Stage to TechCrunch Disrupt 2024. It joins Space, SaaS and AI as the other industry-focused stages — all under…

Announcing the agenda for the Fintech Stage at TechCrunch Disrupt 2024

When Napster emerged in the late 1990s, it made it easy for people to grab music files without compensating the content owners. The iPod and the iTunes music store changed…

Dappier is building a marketplace for publishers to sell their content to LLM builders

Hyperplane focused on allowing banks to train their own models to power tools across their risk, collections and marketing departments.

Nubank acquires AI-for-banks startup Hyperplane

Retool’s focus is on business apps, not the next social network.

Retool expands its low-code platform for creating internal apps to support external apps, too

Samsara Eco makes and sells fossil-free polymer resins. These resins can be integrated into supply chains and potentially replace plastic packaging and textile products with more sustainable alternatives. The Australian…

Samsara Eco is working to replace plastic packaging with fossil fuel-free alternatives

Video editing app Captions, which is backed by a16z, Kleiner Perkins and Sequoia Capital, has launched a new feature that takes an existing unedited video and adds custom graphics, zooms,…

Video editing app Captions releases AI edit feature that automatically adds effects to your video

Rainforest, a startup that embeds payment processing into other software platforms, has raised $20 million in Series A funding — less than a year after announcing the close of its…

Rainforest lands $20M to challenge Stripe with embedded payments for SaaS providers

CData builds connectors that enterprises can use to stitch together data from different sources – and locations, not just in the cloud – more easily.

CData, which helps orgs use data across apps and build AI models, snaps up $350M

Creatio CEO Katherine Kostereva argues that what sets her company apart is that it was always architected to work at an enterprise scale.

Creatio raises $200M at a $1.2B valuation for its no-code CRM and workflow platform

In a push to bolster profits, more airlines are turning to controversial dynamic pricing tech, which prices fares and amenities variably based on a traveler’s willingness to pay for them.

Fetcherr lands $90M to get airlines on board with dynamic pricing

Activity tracking platform and community Strava is shutting down Fatmap, the Europe-based 3D mapping platform it had acquired last January.

Strava to shutter 3D mapping platform Fatmap 20 months after acquisition

Indian e-commerce giant Flipkart has quietly started rolling out a payments app, dubbed Super.money, as it broadens its fintech ambitions. 

Flipkart Group launches payments app, Super.money, in fintech push

Older adults increasingly want to age in their homes rather than nursing facilities. A study by the American Association of Retired People (AARP) found that nearly 90% of people over…

Sensi.AI grabs $31M Series B from Insight, Zeev to monitor seniors 24/7

Opera said today it is releasing Opera One’s second version in developer beta with features including new multimedia controls, split tabs, and new AI capabilities. The company is introducing new…

Opera’s browser adds AI-powered image generation and better multimedia controls

EasyTranslate is headed in a new direction with a new, generative AI-driven platform that it calls HumanAI.

EasyTranslate thinks augmenting LLMs with humans will give it an edge over pure AI translation services

Apple has finally added support for Rich Communication Services (RCS) to its Messages app.

Apple finally adds support for RCS in latest iOS 18 beta

U.K. startup Climate X has raised $18M to help financial services providers assess the impact of climate change on their physical assets.

Climate X’s founders mortgaged their house to stay afloat — now they’ve raised a $18M Series A

German investment management firm DTCP held the final close of its third growth fund and an initial closing of its new early-stage fund.

Backed by Deutsche Telekom and SoftBank, DTCP raises $450 million for its growth and early stage funds

Accel, India’s most successful e-commerce investor, is making a contrarian move by turning its focus to smaller towns and villages.

Accel turns to rural India in hunt for future unicorns

Microsoft’s AI CEO has a cozy relationship with the man who used to be his rival, he said on Tuesday.

Microsoft’s Mustafa Suleyman says he loves Sam Altman, believes he’s sincere about AI safety