The only good thing is that end-to-end encrypted messaging services such as Signal are temporarily safe. However, this law fundamentally threatens encryption and citizen safety. There is something you can do about that:

https://fightchatcontrol.eu/

  • ExLisper@lemmy.curiana.net
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    7
    ·
    edit-2
    6 hours ago

    They are actively working on Chat Control 2.0, the permanent, mandatory scanning of everything including encrypted stuff.

    Chat Control 2.0 specifically protects e2e encryption. It’s not about scanning of encrypted messages in any way. It’s mostly about age verification. Where do people take this false info from and why they keep spreading it? Is it on purpose or are people simply confused?

    • thanksforallthefish@literature.cafe
      link
      fedilink
      English
      arrow-up
      8
      ·
      edit-2
      5 hours ago

      CC 2 does NOT specifically protect e2e encryption because it hasn’t passed yet, and in order to achieve the articulated primary aims it cannot protect it. Supposedly protecting it is one of the variants that has been tabled to try and get it through (and that proposal has truck sized holes in it).

      As per the link above

      "Does it touch encrypted messages? Potentially yes — inclusion of end-to-end encrypted messengers remains contentious between Parliament and the Council. "

      Timeline June 2026 "Chat Control 2.0 “Final” trilogue fails

      The fifth trilogue, billed as the last with adoption targeted for July, produces no deal. Negotiators cannot agree on making suspicionless scanning permanent, as requested by Council. Progress is reported on excluding mandatory age verification, but agreement is postponed and talks continue under the incoming Irish presidency. "

      Suspicionless scanning REQUIRES a bypass to e2e - you can’t routinely scan all messages if they are encrypted.

      It is not a coincidence that IT security and tech literate people are the ones fighting the hardest on this -we understand what this breaks

      https://8bitsecurity.com/posts/chat-control-2-0-–-how-the-european-union-wants-to-get-rid-of-privacy-and-what-we-can-do-to-stop-it/

      "the proposed technological solution is completely inappropriate and would lead to the establishment of a mass surveillance system that would completely eliminate the privacy of all European citizens.

      According to this proposal, every European citizen’s online activity should be automatically scanned and categorized by Artificial Intelligence (AI) algorithms."

      https://informatecdigital.com/en/chat-control-what-is-it/

      “There are two distinct frameworks: 1.0 (voluntary and in place) and 2.0 (proposed with mandates for detection and debate on encryption). Chat Control 2.0 is not approved: the Council must establish a position, and then a trilogue and final vote will follow. Pre-encryption scanning poses technical and legal risks; legal experts warn of incompatibilities with fundamental rights.”

      https://www.brusselsreport.eu/2025/10/01/chat-control-2-0-the-end-of-our-private-communications/

      https://rvntos.io/blog/eu-chat-control-explained/

      “This post explains what Chat Control actually proposes, why cryptographers say “client-side scanning” breaks end-to-end encryption even when the encryption technically stays in place, how the political fight unfolded through 2025 and 2026, and where it stands now.”

      Edit, formatting for readability

    • ReluctantZen@feddit.nl
      link
      fedilink
      English
      arrow-up
      3
      ·
      5 hours ago

      Chat control is specifically about scanning chats to see if there’s no CSAM. That’s mass surveillance (one that child protection services and such don’t think’ll work).

      E2E-protection means nothing when the scanning is done on the client.

      • ExLisper@lemmy.curiana.net
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        4 hours ago

        That’s what Chat Control 1.0 is about and the scanning is voluntary. Here is the text of Chat Control 2.0: https://data.consilium.europa.eu/doc/document/ST-15318-2025-INIT/en/pdf

        Can you point me to the part about scanning chats? Because the entire text doesn’t even contain the word ‘scan’. It barely mentions CSAM or chats. It does say:

        nothing in this Regulation should be interpreted as prohibiting, weakening or circumventing, requiring to disable, or making end-to-end encryption impossible. Providers should remain free to offer services using end-to-end encryption and should not be obliged by this Regulation to decrypt data or create access to end-to-end encrypted data

        In order to facilitate the providers’ voluntary activities under Regulation (EU) 2021/1232 the EU Centre should make available to providers detection technologies that they may choose to use, on a free-of-charge basis, for the sole purpose of carrying out voluntary activities in line with Regulation (EU) 2021/1232

        So detection is still specifically voluntary and e2e encryption protected. Which part of this document introduces mandatory chat scanning? But please, point me parts of the document, not some vague blog posts. I’m not saying it’s not there, just that I read it and didn’t find it. If you’re claiming it’s there I’m sure you will be able to show it.

        • ReluctantZen@feddit.nl
          link
          fedilink
          English
          arrow-up
          2
          ·
          edit-2
          2 hours ago

          You’re right, it doesn’t use the word “scan”, it uses “detect”. It doesn’t say “chat”, it says “interpersonal communication”. There are 335 mentions of “child sexual abuse”, I wouldn’t call that “barely mentions”. All of it is mentioned in the opening paragraph as background info.

          Detection obligations have indeed been removed since the linked document (it wasn’t before that, as you can see in that same document, page 3), thanks to the EP, but it still provides the legal framework for companies to do so anyway, without any reasonable suspicion. That’s already bad enough.

          Moreover, there are mitigation obligations:

          Certain providers of high-risk services will have the obligation to take measures to develop relevant technologies to mitigate the risk of child sexual abuse identified on their services

          In order to prevent and combat online child sexual abuse effectively, providers of hosting services and providers of publicly available interpersonal communications services should take all reasonable measures to mitigate the risk of their services being misused for such abuse, as identified through the risk assessment

          Mitigation is very hard to do without identifying it. For that you’ll have to detect it in some way, f.e. by scanning chats, which you are allowed to do through this. Scanning might not be the only way (though I can’t think of another way), but it is the easiest way.

          In particular, given the importance of ensuring that all possible risk mitigation measures have been taken in accordance with this Regulation, the competent authorities should be granted specific powers to require providers to adjust their risk assessment or mitigation measures so as to ensure compliance with the relevant requirements of this Regulation

          Authorities can adjust the risk assessment themselves.

          Accordingly, this Regulation should not apply to interpersonal communications services that are not available to the general public and the use of which is instead restricted to persons involved in the activities of a particular company, organisation, body or authority.

          Very ironic. The ruling class and elites are excluded.

          E2EE protection is nice, but pretty irrelevant. With clientside scanning, the E2EE is not broken, because your device has already decrypted it. It simply negates E2EE

          This EU explainer, puts the document in simpler language: https://www.consilium.europa.eu/en/press/press-releases/2025/11/26/child-sexual-abuse-council-reaches-position-on-law-protecting-children-from-online-abuse/

          The new law, once adopted, comes with obligations for digital companies to prevent the dissemination of child sexual abuse material and the solicitation of children.

          How would a chat company do such a thing without scanning chats?

          But, even if all of it was fully voluntary (what chat control 1 more or less is), it’s still really bad. Why do we want to give companies the legal right to scan everything we do on their platforms?

          I recommend taking a look at Patrick Breyer’s site (ex-MEP for the Pirate Party) and the EDRi.

          • ExLisper@lemmy.curiana.net
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            2 hours ago

            Detection obligations have indeed been removed

            Ok, thanks. So hopefully you will stop spreading misinformation that in introduces mandatory scanning now.

            • ReluctantZen@feddit.nl
              link
              fedilink
              English
              arrow-up
              2
              ·
              edit-2
              1 hour ago

              Did you read the rest of my comment?

              Voluntary scanning is bad enough, but it still introduces mandatory mitigation, which may as well be the same thing as mandatory scanning in all but name.

              That’s why people are still up in arms about it.

              • ExLisper@lemmy.curiana.net
                link
                fedilink
                English
                arrow-up
                1
                ·
                44 minutes ago

                You said:

                They are actively working on Chat Control 2.0, the permanent, mandatory scanning of everything including encrypted stuff.

                You’re right, Chat Control 2.0 will make client side scanning more difficult to avoid but it’s still just client side scanning, not breaking encryption and it’s still only specific mitigation for sharing CSAM and part of broader evaluation. Services that are not likely to be used to share CSAM will not be forced to mitigate anything. Another mitigation could simply be disabling sharing of media - text messages will not have to scanned. So we’re basically talking about checking hashes of shared media against some database in some of the services and not “permanent, mandatory scanning of everything including encrypted stuff”.

                I’m not saying you have to like and support Chat Control 2.0. I’m not even saying it’s harmless legislation. Just admit it’s not about “permanent, mandatory scanning of everything including encrypted stuff”.

                • ReluctantZen@feddit.nl
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  edit-2
                  14 minutes ago

                  You said:

                  I did not. I responded to the comment that said that. I said that they kept bringing CC2.0 back.

                  I did also say that it’s specifically about scanning, but that’s indeed not entirely accurate. That’s part of it, but it’s broader than that.

                  but it’s still just client side scanning, not breaking encryption

                  Not sure what you mean by “still just”. Client side scanning just sidesteps encryption, making the encryption useless. It’s like saying “we’ll never open your posted letters in transit, but we’ll look over your shoulder while you write/read it”.

                  Services that are not likely to be used to share CSAM will not be forced to mitigate anything.

                  Sure, but chat apps are pretty likely, no? And authorities are allowed to adjust the risk assessments.

                  Another mitigation could simply be disabling sharing of media - text messages will not have to scanned

                  I mean, sure, but that doesn’t seem like a feasible solution. People’d just leave that platform. Imagine if WhatsApp blocked sending images or files.

                  So we’re basically talking about checking hashes of shared media against some database in some of the services

                  This wouldn’t catch new CSAM though (thus not protecting children).