Skip to content

Comment on EU "Chat Control" and Mandatory Client Side Scanning

Comments

What's the point? Criminals will just use linux/custom devices, while normal people will have to face all of the false-positives of the scanning..

The point is to create a totalitarian EU. Obviously.

... create?

The point is that the EU parliamentary members should vote no on this.

I'm almost 100% positive they will, there's a broad consensus among left and right that this proposal is bonkers.

What I've heard is that the only this is a proposal that child rights NGOs has been lobbying for, which I think we can both agree, are not expert in anything tech.

Many children's rights NGOs also think that the proposal is a terrible idea. This article gives an overview (German) https://netzpolitik.org/2022/massenueberwachung-das-sagen-ki...

I am deeply sceptical of lobbying and special interest groups, and that includes the "think of the children" variety.

Sometimes I wonder if criminals aren't as lazy and prone to just using what's popular as the rest of us.

How often do communications done through a wide variety of channels that wouldn't satisfy a cypherpunk from email to Whatsapp show up on evidence before court, even if the people involved knew that they could end up in court? Weren't a bunch of criminals fooled by a literal FBI phone?

It depends on the level of criminal. The larger criminal organizations had their own phone networks. But even then, it's still suffers the same issues as any other organization in that at some point some of its members are going to be top notch and great at what they do, others will be the types to do the least possible or even ignore procedures.

If i open kik in my location there's whole bunch of people openly dealing drugs. Maybe some are lazy. But it's a two way street. They probably are capable of using more secure means but that means far less customers.

To paraphrase a criminal mastermind and philosopher: "Are fucking taking notes on a fucking conapiracy?"

I am often dumbfound by the exsessive paper trail people leave for all kind of things...

Criminals will just use linux

It's far more difficult than that.

Most Linux contributions are made by multi-billions companies like IBM/Redhat. They would not risk to contravene to law. For example that it conforms to the law, look at WiFi drivers. There are many requirement by local laws on which band to use, what kind of traffic is authorized, etc. The WiFi drivers (most of them opaque binaries) conform to each country law.

To make Linux not lawful, you would have to create your own kernel with your own altered drivers, except you can't modify binaries.

Even then how could you make you system unidentifiable? How would you have control over booting your modified Linux in a commercial computer that uses UEFI? How would you know that the commercial CPU is not phoning home through the Intel Management Engine?

You would have use a FPGA CPU, your own designed hardware and a trusted OS but at the end you will always rely on the work of thousands people and hundred companies.

Mainline WiFi drivers will easily let you break the law by just pretending to be in a place with different regulations. Assuming this ever gets implemented in Linux, there's no reason to believe you won't be able to just pretend to be in Uzbekistan or whatever where this EU law doesn't apply.

If literally every jurisdiction on Earth makes it a crime, then I guess this option would go away, but that seems unlikely to me.

Most Linux contributions are made by multi-billions companies like IBM/Redhat.

The source code is published on the internet under the GPL. Anyone who doesn't like any of their contributions can take that one out and keep any of the others. Do you expect the Kali Linux people to include a backdoor?

To make Linux not lawful, you would have to create your own kernel with your own altered drivers, except you can't modify binaries.

You can in fact modify binaries, it's just more work. For one person, once. Although that's fairly irrelevant because there exists hardware that doesn't require binary-only drivers.

How would you know that the commercial CPU is not phoning home through the Intel Management Engine?

You install a firewall in front of it to detect or prevent this. Also, because it can be so easily detected and would be a scandal, it's very likely to be public knowledge if any commercial hardware in widespread use actually did this.

Are you sure the hardware you are going to use for firewall purposes is not biased towards letting the traffic from/to Intel ME to be unnoticed? What filters are you going to set?

You can install open source software on a PC from the early 2000s that predates the Intel Management Engine and use it as a firewall.

Then you use default deny and allow only e.g. a VPN connection.

What if your computer is still accessible for Intel ME surveillance because the VPN server is also Intel ME and they would negotiate somehow to keep having your Intel ME instance an ability to phone home? Is in possible to have a VPN provider which guarantees not having any Intel machines on the network?

What if your computer is still accessible for Intel ME surveillance because the VPN server is also Intel ME and they would negotiate somehow to keep having your Intel ME instance an ability to phone home?

This would require the hardware backdoor to be aware of and integrate with the specific VPN that you used, which could be a version of the code published after the hardware shipped.

Is in possible to have a VPN provider which guarantees not having any Intel machines on the network?

Irrelevant unless the code on your side could hook the VPN, though of course you could.

The better attack would be to have the compromised firmware send its packets using the addresses and ports of some existing connection regardless of its contents, and then have a compromised ISP read them. But even that could be detected by logging the packets at the clean firewall. If it records any that aren't a part of the VPN connection then you've got yourself a rat and a scandal.

In that case they'd just make linux and other dangerous unregulated software illegal. Much like in RMS's old and predictive, https://www.gnu.org/philosophy/right-to-read.en.html

Remember, these are politicians. What they do doesn't have to make sense or be possible. All they have to do is pass laws. If it makes everyone a criminal that's good. The law just won't be enforced unless you rock the boat. Much like with the CFAA in the USA or GDPR in Europe.

but you are missing out that the solution is to keep making it inconvenient to let people use linux and other kinds of custom devices

eventually either nobody will use that, or they'll just jump the shark and outlaw such things

I know that for example in Canada, because taxes, ALL restaurants are (were?) FORCED to use a specific sets of devices else they're branded as tax-avoiders and dealt with accordingly

I've already had trouble using banking stuff under linux, I have had to cancel some cards because they became useless without a smartphone app (the real punchline is that I got a new card that's only works on a smartphone. but at least it was like this when I signed up; they didn't change how it works under my feet)

99% of criminals use regular phones with apps from the app store. 1% are using backdoored crimephones like Anom.

The ANOM service was widely used by criminals, but instead of providing secure communication, it was actually a trojan horse covertly distributed by the United States Federal Bureau of Investigation (FBI) and the Australian Federal Police (AFP), enabling them to monitor all communications.

https://en.m.wikipedia.org/wiki/ANOM

To be honest I wouldn't expect Linux nor custom devices to even be necessary. It's not dark magic to host a private, e2ee chat service.

Either a Matrix Server or even NextCloud chat will do the job just fine. Then just sideload an APK which is rather trivial

Assuming the OS has privileged access to everything that runs on it, the EU just has to tell the vendor to implement scanning and reporting at ring(app-1) and let the vendors scramble to figure out how to make that fever dream a reality, no? Hell, put it into the Intel Management Engine/analogue and compromise every device subsequently manufactured. The pervs (or the freedom fighters, or the tentacle hentai underground, or whatever) will just have to go back to passing hardcopy in dank backrooms of no-longer-smoky-because-they-banned-smoking-in-pubs...pubs

It's not dark magic to host a private, e2ee chat service.

But it might be a good way to attract the attention of law enforcement. People running PGP phone services have been arrested and prosecuted because their networks were primarily used by criminals. If you run a encrypted chat service to circumvent the law you might be held accountable for what users use your encrypted chat service for.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.