this post was submitted on 24 Jul 2026
141 points (100.0% liked)

Europe

11661 readers
606 users here now

News and information from Europe 🇪🇺

(Current banner: La Mancha, Spain. Feel free to post submissions for banner images.)

Rules (2024-08-30)

  1. This is an English-language community. Comments should be in English. Posts can link to non-English news sources when providing a full-text translation in the post description. Automated translations are fine, as long as they don't overly distort the content.
  2. No links to misinformation or commercial advertising. When you post outdated/historic articles, add the year of publication to the post title. Infographics must include a source and a year of creation; if possible, also provide a link to the source.
  3. Be kind to each other, and argue in good faith. Don't post direct insults nor disrespectful and condescending comments. Don't troll nor incite hatred. Don't look for novel argumentation strategies at Wikipedia's List of fallacies.
  4. No bigotry, sexism, racism, antisemitism, islamophobia, dehumanization of minorities, or glorification of National Socialism. We follow German law; don't question the statehood of Israel.
  5. Be the signal, not the noise: Strive to post insightful comments. Add "/s" when you're being sarcastic (and don't use it to break rule no. 3).
  6. If you link to paywalled information, please provide also a link to a freely available archived version. Alternatively, try to find a different source.
  7. Light-hearted content, memes, and posts about your European everyday belong in other communities.
  8. Don't evade bans. If we notice ban evasion, that will result in a permanent ban for all the accounts we can associate with you.
  9. No posts linking to speculative reporting about ongoing events with unclear backgrounds. Please wait at least 12 hours. (E.g., do not post breathless reporting on an ongoing terror attack.)
  10. Always provide context with posts: Don't post uncontextualized images or videos, and don't start discussions without giving some context first.

(This list may get expanded as necessary.)

Posts that link to the following sources will be removed

Unless they're the only sources, please also avoid The Sun, Daily Mail, any "thinktank" type organization, and non-Lemmy social media (incl. Substack). Don't link to Twitter directly, instead use xcancel.com. For Reddit, use old:reddit:com

(Lists may get expanded as necessary.)

Ban lengths, etc.

We will use some leeway to decide whether to remove a comment.

If need be, there are also bans: 3 days for lighter offenses, 7 or 14 days for bigger offenses, and permanent bans for people who don't show any willingness to participate productively. If we think the ban reason is obvious, we may not specifically write to you.

If you want to protest a removal or ban, feel free to write privately to the admin that applied the rule (check modlog first to find who was it.)

founded 2 years ago
MODERATORS
 

The only good thing is that end-to-end encrypted messaging services such as Signal are temporarily safe. However, this law fundamentally threatens encryption and citizen safety. There is something you can do about that:

https://fightchatcontrol.eu/

you are viewing a single comment's thread
view the rest of the comments
[–] ReluctantZen@feddit.nl 6 points 3 days ago (1 children)

Chat control is specifically about scanning chats to see if there's no CSAM. That's mass surveillance (one that child protection services and such don't think'll work).

E2E-protection means nothing when the scanning is done on the client.

[–] ExLisper@lemmy.curiana.net -3 points 3 days ago (1 children)

That's what Chat Control 1.0 is about and the scanning is voluntary. Here is the text of Chat Control 2.0: https://data.consilium.europa.eu/doc/document/ST-15318-2025-INIT/en/pdf

Can you point me to the part about scanning chats? Because the entire text doesn't even contain the word 'scan'. It barely mentions CSAM or chats. It does say:

nothing in this Regulation should be interpreted as prohibiting, weakening or circumventing, requiring to disable, or making end-to-end encryption impossible. Providers should remain free to offer services using end-to-end encryption and should not be obliged by this Regulation to decrypt data or create access to end-to-end encrypted data

In order to facilitate the providers’ voluntary activities under Regulation (EU) 2021/1232 the EU Centre should make available to providers detection technologies that they may choose to use, on a free-of-charge basis, for the sole purpose of carrying out voluntary activities in line with Regulation (EU) 2021/1232

So detection is still specifically voluntary and e2e encryption protected. Which part of this document introduces mandatory chat scanning? But please, point me parts of the document, not some vague blog posts. I'm not saying it's not there, just that I read it and didn't find it. If you're claiming it's there I'm sure you will be able to show it.

[–] ReluctantZen@feddit.nl 6 points 3 days ago* (last edited 2 days ago) (1 children)

You're right, it doesn't use the word "scan", it uses "detect". It doesn't say "chat", it says "interpersonal communication". There are 335 mentions of "child sexual abuse", I wouldn't call that "barely mentions". All of it is mentioned in the opening paragraph as background info.

Detection obligations have indeed been removed since the linked document (it wasn't before that, as you can see in that same document, page 3), thanks to the EP, but it still provides the legal framework for companies to do so anyway, without any reasonable suspicion. That's already bad enough.

Moreover, there are mitigation obligations:

Certain providers of high-risk services will have the obligation to take measures to develop relevant technologies to mitigate the risk of child sexual abuse identified on their services

In order to prevent and combat online child sexual abuse effectively, providers of hosting services and providers of publicly available interpersonal communications services should take all reasonable measures to mitigate the risk of their services being ~~mis~~used for such abuse, as identified through the risk assessment

Mitigation is very hard to do without identifying it. For that you'll have to detect it in some way, f.e. by scanning chats, which you are allowed to do through this. Scanning might not be the only way (though I can't think of another way), but it is the easiest way.

In particular, given the importance of ensuring that all possible risk mitigation measures have been taken in accordance with this Regulation, the competent authorities should be granted specific powers to require providers to adjust their risk assessment or mitigation measures so as to ensure compliance with the relevant requirements of this Regulation

Authorities can adjust the risk assessment themselves.

Accordingly, this Regulation should not apply to interpersonal communications services that are not available to the general public and the use of which is instead restricted to persons involved in the activities of a particular company, organisation, body or authority.

Very ironic. The ruling class and elites are excluded.

E2EE protection is nice, but pretty irrelevant. With clientside scanning, the E2EE is not broken, because your device has already decrypted it. It simply negates E2EE

This EU explainer, puts the document in simpler language: https://www.consilium.europa.eu/en/press/press-releases/2025/11/26/child-sexual-abuse-council-reaches-position-on-law-protecting-children-from-online-abuse/

The new law, once adopted, comes with obligations for digital companies to prevent the dissemination of child sexual abuse material and the solicitation of children.

How would a chat company do such a thing without scanning chats?

But, even if all of it was fully voluntary (what chat control 1 more or less is), it's still really bad. Why do we want to give companies the legal right to scan everything we do on their platforms?

I recommend taking a look at Patrick Breyer's site (ex-MEP for the Pirate Party) and the EDRi.

[–] ExLisper@lemmy.curiana.net -5 points 2 days ago (1 children)

Detection obligations have indeed been removed

Ok, thanks. So hopefully you will stop spreading misinformation that in introduces mandatory scanning now.

[–] ReluctantZen@feddit.nl 7 points 2 days ago* (last edited 2 days ago) (1 children)

Did you read the rest of my comment?

Voluntary scanning is bad enough, but it still introduces mandatory mitigation, which may as well be the same thing as mandatory scanning in all but name.

That's why people are still up in arms about it.

[–] ExLisper@lemmy.curiana.net -2 points 2 days ago (1 children)

You said:

They are actively working on Chat Control 2.0, the permanent, mandatory scanning of everything including encrypted stuff.

You're right, Chat Control 2.0 will make client side scanning more difficult to avoid but it's still just client side scanning, not breaking encryption and it's still only specific mitigation for sharing CSAM and part of broader evaluation. Services that are not likely to be used to share CSAM will not be forced to mitigate anything. Another mitigation could simply be disabling sharing of media - text messages will not have to scanned. So we're basically talking about checking hashes of shared media against some database in some of the services and not "permanent, mandatory scanning of everything including encrypted stuff".

I'm not saying you have to like and support Chat Control 2.0. I'm not even saying it's harmless legislation. Just admit it's not about "permanent, mandatory scanning of everything including encrypted stuff".

[–] ReluctantZen@feddit.nl 5 points 2 days ago* (last edited 2 days ago) (1 children)

You said:

I did not. I responded to the comment that said that. I said that they kept bringing CC2.0 back.

I did also say that it's specifically about scanning, but that's indeed not entirely accurate. That's part of it, but it's broader than that.

but it's still just client side scanning, not breaking encryption

Not sure what you mean by "still just". Client side scanning just sidesteps encryption, making the encryption useless. It's like saying "we'll never open your posted letters in transit, but we'll look over your shoulder while you write/read it".

Services that are not likely to be used to share CSAM will not be forced to mitigate anything.

Sure, but chat apps are pretty likely, no? And authorities are allowed to adjust the risk assessments.

Another mitigation could simply be disabling sharing of media - text messages will not have to scanned

I mean, sure, but that doesn't seem like a feasible solution. People'd just leave that platform. Imagine if WhatsApp blocked sending images or files.

So we're basically talking about checking hashes of shared media against some database in some of the services

This wouldn't catch new CSAM though (thus not protecting children).

[–] ExLisper@lemmy.curiana.net -2 points 2 days ago* (last edited 2 days ago) (2 children)

Ok, sorry, I see it was /u/gratux@lemmy.blahaj.zone who said it. I often lose track when people jump into conversation like that...

You're mostly right, my whole point is that it's more nuanced than "they will scan everything". People like gratux simplify it, post exaggerated claims, it spreads and then everyone who thinks they know something posts "EU Is A SurvEillAnCe StAte!!!1".

Reading Chat Control 2.0 I see a measured response to a problem. They want to fight grooming and sharing of CSAM. How can you do it? The least invasive way is to identify services where grooming and sharing of CSAM happens and then, if the risk is high, separate children from adults (age verification) and scan media client side. That really is the least they can do. Now, we can argue if grooming and CSAM is a real problem and if EU should be trying to address it (I would argue it's not. parents should be monitoring their kids, not EU and police has tools to fight CSAM without client side scanning) but it's definitely not an attempt to break e2e encryption and monitor all communications.

If EU is trying to introduce mass surveillance like that then they are doing shit job. Most people would be completely fine with WhatsApp scanning their media, they already post everything on Instagram. WhatpsApp actually doesn't want to scan anything because it's extra work for them with no gains. People who worry about those things use Signal of Matrix. Most of them would disable media sharing as a last resort. No one is going to read our text messages or decrypt our files.

[–] huey_m@piefed.social 3 points 2 days ago* (last edited 2 days ago) (1 children)

I often lose track when people jump into conversation like that…

I was appreciating what you added to the conversation at first, but man... giving a bad faith one line response to a long, well thought out comment, now being unable to admit a mistake without passive aggressively implying it's the others person's fault you didn't read thoroughly...

I guess I do appreciate knowing who to block before I need to personally interact with them.

[–] ExLisper@lemmy.curiana.net 0 points 2 days ago* (last edited 2 days ago)

That was a very valuable addition to this this conversation, thanks.

It will be great a loss to be blocked by you. Not.

[–] ReluctantZen@feddit.nl 2 points 2 days ago (1 children)

we can argue if grooming and CSAM is a real problem

I don't think we need to argue that. It is a real problem. It's more that measures like this, aren't likely to be particularly effective in combatting CSA. It's not for nothing that many digital rights organizations like the EDRi and EFF are advocating against this. Even child protection services aren't necessarily in favour of this. This proposal does little to actually help the victims of CSA (even more so because of the exclusions of software that isn't publically available).

That leaves the question, who does it benefit?

parents should be monitoring their kids, not EU and police has tools to fight CSAM without client side scanning

Agreed!

it's definitely not an attempt to break e2e encryption and monitor all communications.

Maybe not explicitly, but it sure makes it easier.

If EU is trying to introduce mass surveillance like that then they are doing shit job

Thanks to the EP. I agree that CC2.0 has lost a lot of its teeth due to the exclusion of explicit mandatory scanning (though it's still problematic). Before those changes, it was absolutely mass surveillance imo. Currently, I'd say it's more of a stepping stone.

Most people would be completely fine with WhatsApp scanning their media, they already post everything on Instagram

Most people don't seem to care about privacy in general unfortunately, though posts on instagram are not the same as WhatsApp messages and the like.

WhatpsApp actually doesn't want to scan anything because it's extra work for them with no gains

I kinda doubt that. Meta already has those tools.

[–] ExLisper@lemmy.curiana.net 1 points 2 days ago* (last edited 2 days ago) (1 children)

I don’t think we need to argue that.

I obviously meant it as "we can argue if it's sufficiently widespread and common problem to mandate this type of legislation from EU". And by "this type" I mean fairly measured. And I would argue it's not. If we agree that it its actually very harmful and EU should do whatever it can to stop it than I think we will eventually agree that we should do age verification and client side scanning as the best privacy preserving options.

That leaves the question, who does it benefit?

Ok, let's stop here. This link read like total bull shit. They claim that tech corporation spread some misinformation to support Chat Control 2.0 and then say that (if I understand this correctly) the right solution is:

Strict default settings and protective mechanisms (Security by Design) to make cybergrooming technically harder from the outset and prevent the creation of CSAM.
Targeted telecommunications surveillance based on judicially confirmed suspicion.
Proactive search by a new EU Center and immediate takedown obligations for providers and law enforcement on the open internet and darknet — removing illegal material at source.

This is fucking Chat Control 2.0! Half of the legislation talks about "Security by Design" and preventing grooming. They want strong default that will shield children, periodic evaluation and forced mitigation for companies that fail to adapt proper measures. The second half is about takedown obligations. What is going on here? The only difference is that Chat Control also want's to stop spreading of CSAM because there's a lot of it that already exists so clearly preventing it's creation will not be sufficient. So they say "no, let's not do Chat Control 2.0! Let's do Chat Control 2.0 but let's also ignore part of the problem we don't know how to solve".

Thanks to the EP. I agree that CC2.0 has lost a lot of its teeth due to the exclusion of explicit mandatory scanning

Yes, EP is working on it, negotiating and looking for the right solution. So far it didn't find one so nothing was passed. Why do people claim they are looking to introduce mass surveillance when they clearly don't? And don't get me wrong, I'm sure intelligence services and police would love for EP to break encryption. It would make their jobs so much easier. I'm sure there are forces inside EU that push for this but it's definitely not the agenda of EU as a whole, not even close.

I kinda doubt that. Meta already has those tools.

With Chat Control 1.0 it was legal to scan messages for 5 years already. Why no one is doing this? Because they already have the info they need and scanning memes that people send to each other is not valuable enough for them.

[–] ReluctantZen@feddit.nl 1 points 2 days ago (1 children)

So they say “no, let’s not do Chat Control 2.0! Let’s do Chat Control 2.0 but let’s also ignore part of the problem we don’t know how to solve”.

Well, the idea is that if the creation is prevented, the spreading will solve itself. Chat Control 2.0 also isn't judicially targeted. And to be clear, that summary is based on what the EP is advocating for (and is, I believe, part of the basis for amendments in the earlier document you linked).

Btw, there are 2 links in my post. The 1st one is more interesting in my opinion.

Why do people claim they are looking to introduce mass surveillance when they clearly don’t?

Because the initial proposals from the Council and Commission more or less were mass surveillance. Only after a couple of years has it done away with the mandatory scanning (for now anyway) after it became clear the EP wouldn't be in favour (again). People are understandably suspicious. Unfortunately, people tend to conflate the entire EU into one thing, in large part because reporting tends to just say "EU". The EP certainly isn't looking to introduce mass surveillance, that much should be clear by now.

Why no one is doing this?

Why do you say no one is doing this? Big Tech isn't advocating for the continuation of (the temporary) CC1.0 because they're not using it.

[–] ExLisper@lemmy.curiana.net 1 points 2 days ago

Ok, the links are next to each other so they look like one. So the other one talks about connections to AI companies that would sell tech used by Chat Control 2.0. This is kind of obvious. EU is not immune to lobbying and different companies are involved in pretty much everything it does. How much influence they have is a separate issue.

Well, the idea is that if the creation is prevented, the spreading will solve itself

You will not prevent creation with "stronger defaults". Not all CSAM is created online. AI is/will be new source of it that will not be stopped by Chat Control. A lot of CSAM already exists. So the idea that just by preventing grooming we will stop all CSAM is silly, we will only stop some of it. So what can actually be done about using e2e encrypted apps to share CSAM? I see two options: do nothing or scan client side. What other options are there? Besides breaking e2ee obviously. So at this point I see it as EP saying "let's include it in the solution" and privacy activists saying "no, let's ignore it".

Because the initial proposals from the Council and Commission more or less were mass surveillance.

Agree. Sadly people don't understand what happened and the conversation got stuck. People are still opposing something that is no longer on the table instead of thinking about real solutions. This is bad because it's not bringing us closer to a compromise. It just helps to spread misinformation and weakens EU as a whole.