Security

Stop playing games with online security, Signal president warns EU lawmakers

Comment

Signal messaging application President Meredith Whittaker.
Image Credits: PATRICIA DE MELO MOREIRA/AFP / Getty Images

A controversial European Union legislative proposal to scan the private messages of citizens in a bid to detect child sexual abuse material (CSAM) is a risk to the future of web security, Meredith Whittaker warned in a public blog post Monday. She’s the president of the not-for-profit foundation behind the end-to-end encrypted (E2EE) messaging app Signal.

“There is no way to implement such proposals in the context of end-to-end encrypted communications without fundamentally undermining encryption and creating a dangerous vulnerability in core infrastructure that would have global implications well beyond Europe,” she wrote.

The European Commission presented the original proposal for mass scanning of private messaging apps to counter the spread of CSAM online back in May 2022. Since then, Members of the European Parliament have united in rejecting the approach. They also suggested an alternative route last fall, which would have excluded E2EE apps from scanning. However the European Council, the legislative body made up of representatives of Member States governments, continues to push for strongly encrypted platforms to remain in scope of the scanning law.

The most recent Council proposal, which was put forward in May under the Belgian presidency, includes a requirement that “providers of interpersonal communications services” (aka messaging apps) install and operate what the draft text describes as “technologies for upload moderation”, per a text published by Netzpolitik.

Article 10a, which contains the upload moderation plan, states that these technologies would be expected “to detect, prior to transmission, the dissemination of known child sexual abuse material or of new child sexual abuse material.”

Last month, Euractiv reported that the revised proposal would require users of E2EE messaging apps to consent to scanning to detect CSAM. Users who did not consent would be prevented from using features that involve the sending of visual content or URLs it also reported — essentially downgrading their messaging experience to basic text and audio.

Whittaker’s statement skewers the Council’s plan as an attempt to use “rhetorical games” to try to rebrand client-side scanning, the controversial technology which security and privacy experts argue is incompatible with the strong encryption that supports confidential communications.

“[M]andating mass scanning of private communications fundamentally undermines encryption. Full stop,” she emphasized. “Whether this happens via tampering with, for instance, an encryption algorithm’s random number generation, or by implementing a key escrow system, or by forcing communications to pass through a surveillance system before they’re encrypted.”

“We can call it a backdoor, a front door, or ‘upload moderation’. But whatever we call it, each one of these approaches creates a vulnerability that can be exploited by hackers and hostile nation states, removing the protection of unbreakable math and putting in its place a high-value vulnerability.”

Also hitting out at the revised Council proposal in a statement last month, Pirate Party MEP Patrick Breyer — who has opposed the Commission’s controversial message-scanning plan from the start — warned: “The Belgian proposal means that the essence of the EU Commission’s extreme and unprecedented initial chat control proposal would be implemented unchanged. Using messenger services purely for texting is not an option in the 21st century.”

The EU’s own data protection supervisor has also voiced concern. Last year, it warned that the plan poses a direct threat to democratic values in a free and open society.

Pressure on governments to force E2EE apps to scan private messages, meanwhile, is likely coming from law enforcement.

Back in April European police chiefs put out a joint statement calling for platforms to design security systems in such a way that they can still identify illegal activity and send reports on message content to law enforcement. Their call for “technical solutions” to ensure “lawful access” to encrypted data did not specify how platforms should achieve this sleight of hand. But, as we reported at the time, the lobbying was for some form of client-side scanning. It looks no accident, therefore, that just a few weeks later the Council produced its proposal for “upload moderation”.

The draft text does contain a few statements that seek to pop a proverbial fig leaf atop the gigantic security and privacy black hole that “upload moderation” implies — including a line that states “without prejudice to Article 10a, this Regulation shall not prohibit or make impossible end-to-end encryption”; as well as a claim that service providers will not be required to decrypt or provide access to E2EE data; a clause saying they should not introduce cybersecurity risks “for which it is not possible to take any effective measures to mitigate such risk”; and another line stating service providers should not be able to “deduce the substance of the content of the communications”.

“These are all nice sentiments, and they make of the proposal a self negating paradox,” Whittaker told TechCrunch when we sought her response to these provisos. “Because what is proposed — bolting mandatory scanning onto end-to-end encrypted communications — would undermine encryption and create a significant vulnerability.”

The Commission and the Belgian presidency of the Council were contacted for a response to her concerns but at press time neither had provided a response.

EU lawmaking is typically a three-way affair — so it remains to be seen where the bloc will finally end up on CSAM scanning. Once the Council agrees on its position, so-called trilogue talks kick off with the parliament and Commission to seek a final compromise. But it’s also worth noting that the make-up of the parliament has changed since MEPs agreed their negotiating mandate last year following the recent EU elections.

More TechCrunch

How is the European Union’s bid to get Elon Musk to follow its rules going? Judging by the memes, not well.

EU warns X over illegal content risks. Musk replies with Tropic Thunder insult meme

Sarvam’s voice-enabled AI agents can be deployed on WhatsApp, within an app, and can even work with traditional voice calls.

Why this AI startup is betting on voice-enabled bots to scale AI adoption in India

The irony was not lost on her. Growing up the daughter of a family obsessed with car racing, Danielle Walsh had become — in her late 20s — the head of…

She grew up a gearhead — now her startup has raised $4.3M to cut CO2 from trucking

Opera is releasing its redesigned Opera One browser on iOS as a stable release after testing it in the beta phase for weeks. The new browser has a bottom placed…

Opera is releasing its redesigned browser on iOS

In Puerto Rico, tax breaks enacted in 2012 aimed to juice the economy by encouraging mainland U.S. citizens to do business and live on the island, where they could apply…

The crypto founder who didn’t save Puerto Rico after all

Elon Musk and Donald Trump’s joint X Spaces event appears to have crashed Monday afternoon. The conversation between the owner of X and the former President was scheduled for 5…

Elon Musk and Donald Trump’s X Spaces event crashes

Antler, the Singapore VC that focuses on early-stage investments, just closed its second Southeast Asia fund. It’s raised $72 million to double down on startups in Singapore, Indonesia, Vietnam and…

Antler doubles down on Southeast Asia with $72M second startup fund

It racked up around 18,000 users, made 8,000 matches, and gathered a lot of insights on the current dating scene.

Score, the dating app for people with good to excellent credit, quietly shuts down

Fram2 would launch into a polar orbit from Florida in late 2024, after which it will stay up at 425-450 kilometers of altitude for three to five days.

Crewed commercial SpaceX mission will traverse the poles like the explorers of old

A class action lawsuit filed by artists who allege that Stability, Runway and DeviantArt illegally trained their AIs on copyrighted works can move forward, but only in part, the presiding…

Artists’ lawsuit against generative AI makers can go forward, judge says

Tally, a nine-year-old fintech that helped consumers manage and pay off their credit card debt, has shut down, according to the company. In a LinkedIn post that was shared earlier…

a16z-backed fintech Tally, which raised $172M in funding, is shutting down after running out of cash

Dawn Aerospace Mk-II is essentially “an aircraft with the performance of a rocket, not a rocket with wings.”

TechCrunch Space: It’s a bird, it’s a plane — it’s a rocket-powered aircraft!

The U.S. Securities and Exchange Commission (SEC) is suing a crypto startup, NovaTech, for allegedly fraudulently raising more than $650 million from over 200,000 investors, many in the Haitian-American community.…

SEC charges crypto firm NovaTech with fraud

The FBI’s takedown of the Radar/Dispossessor ransomware and extortion gang is a rare win in the fight against ransomware.

FBI takes down ransomware gang that hacked dozens of companies

Featured Article

The biggest data breaches in 2024: 1 billion stolen records and rising

Some of the largest, most damaging breaches of 2024 already account for over a billion stolen records. Plus, some special shout-outs.

The biggest data breaches in 2024: 1 billion stolen records and rising

In the last 12 months, Balderton has announced 12 new investments.

Euro VCs welcome Balderton’s fresh $1.3B but grumble about Europe’s AI misses

TikTok looks to be taking on popular messaging services like Meta’s WhatsApp and Apple’s Messages, as the company announced on Monday that it’s adding group chats to its platform. You…

TikTok comes for messaging apps with the addition of group chats

There’s a fascinating look by John Herrman over at NYMag today at one of the big proposed uses of AI: summarizing content. We all need things summarized, right? Everybody’s too…

What is AI good for anyway? Maybe not summarizing

Waymo plans to start testing its fully autonomous vehicles with no human safety driver on freeways in the San Francisco Bay Area this week. Its employees will be the first…

Waymo to begin testing driverless robotaxis on San Francisco freeways

Anduril and Palantir delivered the first Tactical Intelligence Targeting Access Node (TITAN) — the first major milestone in its $178 million contract.

Anduril reaches milestone with major defense hardware contract

Google Pixel 8 devices made in India start rolling off the production lines just ahead of the Pixel 9 launch.

Google begins shipping locally made Pixel 8 in India ahead of Pixel 9 launch

Apple has threatened to remove creator platform Patreon from the App Store if creators use unsupported third-party billing options or disable transactions on iOS, instead of using Apple’s own in-app…

Apple says Patreon must switch to its billing system or risk removal from App Store

Elevate your brand’s presence at TechCrunch Disrupt 2024 in San Francisco by hosting a custom Side Event during “Disrupt Week,” taking place October 26 through November 1. Engage face-to-face with…

Enhance your brand: Host a Side Event at TechCrunch Disrupt 2024

Meta and Universal Music Group (UMG) announced on Monday the expansion of their multi-year music licensing agreement, which enables users to share songs from UMG’s music library across Meta’s platforms…

Meta, Universal Music Group address AI music in new licensing agreement

WeRide, a Chinese autonomous vehicle company, is officially gearing up for a U.S. public debut, over a year after China started easing its effective ban of foreign IPOs. The company is…

China’s autonomous vehicle startup WeRide seeks US IPO at $5B valuation

When users click on an event on Polymarket, they will now see a summary of news related to the event based on search results from Perplexity.

Prediction marketplace Polymarket partners with Perplexity to show news summaries

The U.K. antitrust regulator has confirmed that it’s carrying out an early-stage inquiry into Synopsys‘ plans to buy Ansys. The Competition and Markets Authority (CMA) has opened an “invitation to…

Synopsys’ plans to buy Ansys for $35B falls on UK regulatory radar

Here is a look back at the top security research from the annual hacker conferences, Black Hat and Def Con 2024.

The best hacks and security research from Black Hat and Def Con 2024

Cross-border payments for businesses in emerging markets remain significantly untapped, despite small to large businesses using banks and legacy fintechs to transact trillions of dollars in transaction volume annually.  A…

Conduit’s cross-border payments expand from LatAm into Africa with $6M round

BT, the U.K.’s former incumbent telecoms carrier, is picking up a major new investor today as telecoms companies look for stronger footing in the rapidly shifting technology and communications market.…

Bharti will become BT’s biggest shareholder after buying a 25%, $4B stake from Altice