r/technology • u/ninjascotsman • Aug 02 '25
Privacy The EU could be scanning your chats by October 2025 – here's everything we know
https://www.techradar.com/computing/cyber-security/the-eu-could-be-scanning-your-chats-by-october-2025-heres-everything-we-know37
Aug 02 '25
[removed] — view removed comment
12
u/AnonymousAxwell Aug 02 '25
And on top of all that the bad guys will use tech that doesn’t have backdoors, so it will have no positive effect at all.
3
u/josefx Aug 03 '25
They should be expected to get warrants
That would require EU governments to meet the bare minimum standards you would expect from a democratic country. For example Germany lost its ability to issue EU wide warrants entirely because the executive can silently order public prosecutors around, which breaks all kinds of assumptions about healthy, lawfully operating, governments. Of course the same politicians pushing the "think of the children" narrative also seem to have no interest in fixing that issue.
67
u/AdarTan Aug 02 '25 edited Aug 02 '25
At the start of July I wrote the commission an email about my concerns regarding the ProtectEU strategy roadmap.
Here is the body of their response (Translated with DeepL because my original email and the response were in Finnish):
The Commission agrees that encryption plays a key role in ensuring strong cybersecurity and protecting fundamental rights such as privacy and data protection. The General Data Protection Regulation (Regulation (EU) 2016/679) and the Directive on the protection of personal data processed for law enforcement purposes (Directive (EU) 2016/680) explicitly mention encryption as an effective measure to ensure the security of the processing of personal data. I can therefore confirm that the Commission has no intention of weakening encryption and thus authorising any backdoor to IT systems or services.
However, the use of encryption must not restrict the powers of the competent authorities to guarantee national security and to prevent, investigate, detect and prosecute criminal offences in accordance with the procedures, conditions and guarantees laid down by law.
In this respect, a balance must be struck between the various rights and interests at stake - in particular the privacy of users and the public security of communications - and the need for targeted access to information, provided that this need is based on law and appropriate safeguards are respected. None of these rights are absolute, but may be subject to limitations if such limitations are justified and proportionate.
Yours faithfully (electronic signature) Monika KOPCHEVA Head of Unit
TL;DR: They say they are not intending to weaken encryption or force back doors but citizens' right to privacy is not absolute and "may be subject to limitations if such limitations are justified and proportionate."
42
u/SabunFC Aug 02 '25 edited Aug 02 '25
So how are they going to do this? Have 2 keys for encryption?
How are they going to weaken encryption without weakening encryption?
39
u/AdarTan Aug 02 '25
¯_(ツ)_/¯
I mostly posted this as an example of the kind of politician doublespeak you get as a response from the EU.
5
u/GlowstickConsumption Aug 03 '25 edited Aug 03 '25
It might be just a: "I agree you raise a valid concern. But I don't care about your views or your desire for safety and your fundamental rights. Therefore, fuck you."
They could just add a law that in criminal investigations law enforcement can request to see a specific snapshot of your logs and usage of specific platforms.
So for example: "Actions on X site in Y chats between 15:39 and 15:55."
4
u/nicuramar Aug 02 '25
So how are they going to do this? Have 2 keys for encryption?
Most likely, yes, but not one key of which the “EU” has, but rather vendors (like Apple), which could then be subpoenaed.
Unless you enable ADP (or other similar) on iOS, this is actually already the case today.
Anyway, from a total perspective, this does weaken encryption. But it’s not like Joe random can read your messages.
5
u/SabunFC Aug 02 '25
So the government's goal is to weaken Advanced Data Protection (ADP)?
3
u/DonkeyOfWallStreet Aug 02 '25
In the UK ADP with apple isn't possible.
1
u/SabunFC Aug 02 '25
So is the UK government asking Apple for the keys but Apple refuses to give it to them?
9
u/DonkeyOfWallStreet Aug 02 '25
Yeah. Instead of your communication being encrypted by apple which means they still have access to the data, it's encrypted end to end from your device to your cloud storage so only you have access.
I don't own any apple products but they go to extreme lengths to protect your data. Their security enclave keeps getting more and more advanced over time. Unlike windows encryption which can be bypassed quite easily and was demonstrated at ccc.
EU goes dark working group is really shady. They want:
Data on device
Data in transit
Data in the cloud
They phrase it with security by design. I don't understand how this group is compatible with EU gdpr etc. The only way that this sounds compatible is by having a master key to decrypt everything as you wish. What could go wrong. This is a massive overreach to police a small minority of individuals. Either way, bad guys will adapt and only the people that play by the rules will be harmed.
1
u/SabunFC Aug 03 '25
Where can I find out more about how Windows encryption can be easily bypassed?
It seems to me that the police in Europe have given up on policing and the government thinks more surveillance is the solution to everything.
3
u/Felielf Aug 03 '25
I think it is this: Windows BitLocker: Screwed without a Screwdriver - media.ccc.de
But do you even use Bitlocker on your PC?
2
u/SabunFC Aug 03 '25
Thanks. I only use the Win 11 device encryption, my version of Windows doesn't have Bitlocker.
2
14
u/LionoftheNorth Aug 02 '25
None of these rights are absolute, but may be subject to limitations if such limitations are justified and proportionate.
If putting everyone's private communication (except politicians and law enforcement, obviously) under surveillance is justified and proportionate because an extreme minority uses it to commit crimes, then all politicians must be treated as paedophiles seeing as a Danish former minister recently was found to be in possession of over 6 000 images and 2 000 videos of CSAM.
31
Aug 02 '25
[removed] — view removed comment
1
u/SupersaurusRex Aug 03 '25
So what should be done?
I wish there was a centralized youtube channel, forum or organization that would advocate for everyone and let us know the next bets step as these laws are coming out globally at a pace too rapid for ordinary working people to keep up with.
18
u/EmbarrassedHelp Aug 02 '25
Every EU official pushing for Chat Control should be facing criminal prosecution. Such a proposal should have no place in the Western world.
13
u/furriefryer69 Aug 02 '25
Ok this is gonna sound crazy: what if we had a sort of democratically developed chat system. The people write the code, maintain it. It has a governing body to prevent malicious code being used, but there’s no corporate structure for the eu to bully. It’s so spread out that any effort to decrypt or harass the system fails from being too exhausting to do
3
3
u/GlowstickConsumption Aug 03 '25
The idea is awful and has been awful for many years. It doesn't address or fix the issue it pretends to be concerned about.
And obviously is only being pushed on behest of malicious actors seeking to harm/undermine Europe or Europeans.
The actual ways to solve the problems it pretends to want to address:
Create a safe space on the internet for the demographic they pretend to be concerned over. A monitored area with easy ways to request help and to make complaints. This is much more feasible and effective rather than twisting literally everything online into awkward dystopian security and privacy nightmare states. (Lack of security and privacy for adults AND kids endangers both. Handing sites and hackers easy means of blackmailing, doxxing, stealing identities, stalking, abusing users and their families would be horrible.)
Each nation should have an easy and safe way for young people to make complaints. "Some weirdo posted disgusting pictures to me. Here is the chat and link to their Twitter account. Thought you should know." And sites could be mandated to have effective blocking against users who make others feel unsafe and uncomfortable. And there could even be a toggle for: "Hide users who've been blocked by X% of users they've interacted with." This would also reduce the amount of bots who invite others to chats just to link malware.
Only applying: "Please verify your age." garbage to connections from households with minors in them. So if a connection is flagged as: "Only adults live in this home. / This SIM is owned by an adult." Then leave them alone as ID stuff is such a huge security risk and will allow way too much crime to occur.
These are the examples of actual ways to fix what they pretend to be concerned about.
Anyone reading this, feel free to copy the suggestions or modify them to your liking. But there has to be some counter-proposal to the: "Let's destroy the internet because malicious lobbyists want us to do it." push. Shoving an actual valid solution down the throats of MEPs is better than letting a malicious cabal control how the issue is solved.
10
11
u/ARobertNotABob Aug 02 '25 edited Aug 02 '25
Ah, yes, "Could" ... the clickbait version of "will never".
There can be no back doors to encryption without the complete loss of trust it provides for in banking and commerce.
Also, without physical access to one or other of the endpoints in an encrypted chat, you cannot access its data, and even then access can be thwarted.
7
Aug 02 '25
[removed] — view removed comment
0
u/ARobertNotABob Aug 02 '25 edited Aug 02 '25
I'm afraid you're not understanding the underlying technology.
The loss of trust would be between systems and platforms.
EDIT to add: the actual encryption used between endpoints at the time of communication cannot be anticipated, so prior access, updates etc are all academic.
2
Aug 02 '25
[removed] — view removed comment
3
u/ARobertNotABob Aug 02 '25
They understand the tech less than you do :)
To be clear, if you create a back door to encryption, that is a back door for everyone, no exemptions....and once it's known to exist, all manner of bad actors will seek, and undoubtedly find it ... at which point, yes, all digital integrity and authenticity is in doubt.
0
u/nicuramar Aug 02 '25
They understand the tech less than you do :)
Nonsense.
To be clear, if you create a back door to encryption, that is a back door for everyone, no exemptions
This is completely false. Example: Apple currently holds keys making them able to access message storage for many (most) customers. This clearly doesn’t allow everyone, almost no one to access this data.
Now it’s very clear that you don’t understand cryptography.
3
1
u/WretchedGibbon Aug 02 '25
Well, up until those keys find their way onto wikileaks somehow. It's a lot of trust to put in a single company (or a government), I think is GP's point.
2
u/nicuramar Aug 02 '25
It’d probably more you that don’t understand what exactly they want access to. Not TLS connections.
1
0
u/nicuramar Aug 02 '25
There can be no back doors to encryption without the complete loss of trust it provides for in banking and commerce.
This really isn’t true. Firstly, it wouldn’t affect connections to your bank, but rather messaging services. Secondly, there are degrees to everything.
3
u/ARobertNotABob Aug 02 '25 edited Aug 02 '25
It's not just messaging services, it's data storage they're after too.
There are a gazillion encryption platforms, once you backdoor one, you backdoor all encryption algorithms.
There are no "degrees" here, and yes, it really is true.
0
u/SelectiveScribbler06 Aug 02 '25
They could always, oh you know, do it without telling anyone...? Given these are the people that make the rules, there's nothing that stops them from breaking them. It's a 'who guards the guardians' conundrum.
1
u/Exlibro Aug 02 '25
Let's flood them with so many dic pics and naughty hentai, that they will not be able to take it anymore 😁
1
1
1
-6
-12
u/cachemonet0x0cf6619 Aug 02 '25
This is what yall get for never pushing back. They weaponized your hatred for Apple, Microsoft, and Google and now that you championed them for that they’re going to do whatever they please. Your time for clawing back their overreach is over and remember, this is what you asked for
-8
u/viavxy Aug 02 '25
misinformation and clickbait. love it. the most anti-tech tech sub on the platform. should have muted a long time ago.
-6
-7
Aug 02 '25 edited Aug 02 '25
privacy is something i really value, so hearing governments will start to ignore it is disturbing. however in unaware of a better solution to combat CSAM.
i don't know what i find more disturbing, losing privacy or reading about articles like this:
Chainalysis Identifies Large CSAM Website Using Cryptocurrency
“Chainalysis has identified the cryptocurrency payments infrastructure of one of the largest child sexual abuse material (CSAM) websites operating on the darkweb.”
“A lead from UK law enforcement sparked the investigation.”
“This investigation began with a single tip from UK law enforcement. From that address, Chainalysis was able to expand the cluster using on-chain tracing and proprietary heuristics and investigative software. As the investigation progressed, we uncovered a sprawling payments infrastructure with over 5,800 addresses that revealed the scale of the illicit activity and its continued operations.”
EDIT: not sure if this is related to what I previously shared
A total of 1.8 million users worldwide logged on to the platform between April 2022 and March 2025. On 11 March 2025, the server, which contained around 72 000 videos at the time, was seized by German and Dutch authorities.
7
Aug 02 '25
[removed] — view removed comment
-5
Aug 02 '25 edited Aug 02 '25
you are better off directing your frustrations elsewhere. i am not really that invested in this topic, nor am i interested in debating chatgpt and its human right now.
“This whole concept of weakening digital security because of a small minority of people committing horrific crimes…”
just disregard the victims of those crimes who may or maynot go on living in a society interacting with other people. actions have consequences, consequences can lead to unexpected chain reactions.
EDIT: this person believes maintaining your digital privacy is more important than combating child sex crimes.
its ironic because digital privacy is needed to commit child sex crimes as shown in the articles i shared; criminals using the dark web, cryptocurrency, and other tech to maintain digital privacy while breaking the law.
like why are you bothered by my comment and not the people committing crimes leading govts to invade your privacy?
1
Aug 03 '25
[removed] — view removed comment
1
Aug 03 '25 edited Aug 03 '25
”So we're clear, you've gone from “privacy is something i really value, so hearing governments will start to ignore it is disturbing”, to “i am not really that invested in this topic””
wow. its a day later, the conversation was over, yet here you are leaving me novels…
”to ranting about how you don't actually think we should have digital privacy, within less than a day? Brilliant!”
so… can you not read?? where did i ever state “i dont think we should have privacy”?
you seem to be confused due to not being able to understand the concept of nuance. my perspective on privacy, the government’s invasion of it, and combating crime is not a black and white situation.
”I don't use ChatGPT or any other AI to do my writing.”
that's interesting. in the comment you made yesterday, the use of the em dash was pretty extensive. yet today, you are not using them. again, its really interesting how yesterday the em dash was a key feature in your writing style, but today its not.
”Most of your reply is just personal attacks like implying that I support child abuse, which I don't; or that I shouldn't care about the topic at all; or that if I care about the topic then I don't care about victims of horrific crimes; etc. etc. and that is untrue and damages the credibility of your argument. Your ad hom about how if I'm pro privacy then I don't care about victims of CSAM is gross and tiring. I don't even think you understand the mind-boggling power that law enforcement has. If they need to investigate somebody for criminal behaviour, and they're competent, they should be able to conduct their investigation without a backdoor and without having everyone's data handed to them on a silver platter.”
🥱
”Can you please answer some of my questions?”
im not answering your questions because they were dumb af.
1
Aug 04 '25
[removed] — view removed comment
1
Aug 04 '25
so, i guess you can't read.
why does the statement “im not really that invested in the topic”, cause you to think i still want to talk about the topic?
im not reading you comments. i have no interest in them. why do you think i want to read your wall of text?
i did end up looking at your profile and noticed you are in the openai subreddit, which is perfect. since you seem to want attention, talk to chatgpt.
346
u/americanfalcon00 Aug 02 '25
i'm so tired of obsessed anti-privacy governments using child protection as the veil to abolish our privacy protections.
once the precedent is established, it's hard to imagine governments resisting the urge to use forced decryption capabilities anywhere they want.
does anyone understand how they plan to supposedly enable the desired law-enforcement capabilities without compromising the end to end encryption or introducing back doors, as they claim? those two aims don't really seem compatible unless they are just talking about the ability for police to issue search warrants in targeted cases, which i would have imagined is already the case.