{"id":40479,"date":"2022-07-21T18:19:00","date_gmt":"2022-07-21T18:19:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/40479"},"modified":"2022-07-21T18:19:00","modified_gmt":"2022-07-21T18:19:00","slug":"gchq-experts-back-scanning-of-encrypted-phone-messages-to-fight-child-abuse","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=40479","title":{"rendered":"GCHQ experts back scanning of encrypted phone messages to fight child abuse"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/07\/gchq-experts-back-scanning-of-encrypted-phone-messages-to-fight-child-abuse.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Companies could police encrypted messaging services for possible child abuse while still preserving the privacy and security of the people who use them, government security and intelligence experts said in a discussion paper published yesterday.<\/p>\n<p>Ian Levy, technical director of the UK National Cyber Security Centre (NCSC), and Crispin Robinson, technical director for cryptanalysis at GCHQ, argued that it is \u201cneither necessary nor inevitable\u201d for society to choose between making communications \u201cinsecure by default\u201d or creating \u201csafe spaces for child abusers\u201d.<\/p>\n<p>The technical directors proposed in a discussion paper, <em><a href=\"https:\/\/www.computerweekly.com\/news\/252523028\/%E2%80%9CWe%20have%20found%20no%20reason%20as%20to%20why%20client-side%20scanning%20techniques%20cannot%20be%20implemented%20safely%20in%20many%20of%20the%20situations%20society%20will%20encounter,%E2%80%9D%20they%20said.\">Thoughts on child safety on commodity platforms<\/a>,<\/em> that client-side scanning software placed on mobile phones and other electronic devices could be deployed to police child abuse without disrupting individuals\u2019 privacy and security.<\/p>\n<p>The proposals were criticised yesterday by technology companies, campaign groups and academics.<\/p>\n<p>Meta, owner of Facebook and WhatsApp, said the technologies proposed in the paper would undermine the internet, would threaten security and damage people\u2019s privacy and human rights.<\/p>\n<p>The Open Rights Group, an internet campaign group, described Levy and Robinson\u2019s proposals as a step towards a surveillance state.<\/p>\n<p>The technical directors argued that developments in technology mean there is not a binary choice between the privacy and security offered by end-to-end encryption and the risk of child sexual abusers not being identified.<\/p>\n<p>They argued in the paper that the shift towards end-to-end encryption \u201cfundamentally breaks\u201d most of the safety systems that protect individuals from child abuse material and that are relied on by law enforcement to find and prosecute offenders.&nbsp;<\/p>\n<p>\u201cChild sexual abuse is a societal problem that was not created by the internet, and combating it requires an all-of-society response,\u201d they wrote.<\/p>\n<p>\u201cHowever, online activity uniquely allows offenders to scale their activities, but also enables entirely new online-only harms, the effects of which are just as catastrophic for the victims.\u201d<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"Neural Hash on hold\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Neural Hash on hold<\/h3>\n<p>Apple <a href=\"https:\/\/www.computerweekly.com\/news\/252504970\/Apple-unveils-plans-to-scan-US-iPhones-for-child-sex-abuse-images\">attempted to introduce client-side scanning technology<\/a> \u2013 known as Neural Hash \u2013 to detect known child sexual abuse images on iPhones last year, but put the plans on indefinite hold following an outcry by leading experts and cryptography experts.<\/p>\n<p>A report by 15 leading computer scientists, <em><a href=\"https:\/\/arxiv.org\/abs\/2110.07450\">Bugs in our pockets: the risks of client-side scanning,<\/a><\/em> published &nbsp;by <a href=\"https:\/\/www.cs.columbia.edu\/~smb\/papers\/bugs21.pdf\">Columbia University<\/a>, identified multiple ways that states, malicious actors and abusers could turn the technology around to cause harm to others or society.<\/p>\n<p>\u201cClient-side scanning, by its nature, creates serious security and privacy risks for all society, while the assistance it can provide for law enforcement is at best problematic,\u201d they said. \u201cThere are multiple ways in which client-side scanning can fail, can be evaded and can be abused.\u201d<\/p>\n<p>Levy and Robinson said there was an \u201cunhelpful tendency\u201d to consider end-to-end encrypted services as \u201cacademic ecosystems\u201d rather than the set of real-world compromises that they actually are.<\/p>\n<p>\u201cWe have found no reason as to why client-side scanning techniques cannot be implemented safely in many of the situations that society will encounter,\u201d they said.<\/p>\n<p>\u201cThat is not to say that more work is not needed, but there are clear paths to implementation that would seem to have the requisite effectiveness, privacy and security properties.\u201d<\/p>\n<p>The possibility of people being wrongly accused after being sent images that cause \u201cfalse positive\u201d &nbsp;alerts in the scanning software would be mitigated &nbsp;in practice by multiple independent checks before any referral to law enforcement, they said.<\/p>\n<p>The risk of \u201cmission creep\u201d, where client-side scanning could potentially be used by some governments to detect other forms of content unrelated to child abuse could also be prevented, the technical chiefs argued.<\/p>\n<p>Under their proposals, child protection organisations worldwide would use a \u201cconsistent list\u201d of known illegal image databases.<\/p>\n<p>The databases would use cryptographic techniques to verify that they only contained child abuse images and their contents would be verified by private audits.<\/p>\n<p>The technical directors acknowledged that abusers might be able to evade or disable client-side scanning on their devices to share images between themselves without detection.<\/p>\n<p>However, the presence of the technology on victims\u2019 mobile phones would protect them from receiving images from potential abusers, they argued.<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Detecting grooming\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Detecting grooming<\/h3>\n<p>Levy and Robinson also proposed running \u201clanguage models\u201d on phones and other devices to detect language associated with grooming. The software would warn and nudge potential victims to report risky conversations to a human moderator.<\/p>\n<p>\u201cSince the models can be tested and the user is involved in the provider\u2019s access to content, we do not believe this sort of approach attracts the same vulnerabilities as others,\u201d they said.<\/p>\n<p>In 2018, Levy and Robinson proposed allowing government and law enforcement \u201c<a href=\"https:\/\/www.lawfareblog.com\/principles-more-informed-exceptional-access-debate\">exceptional access<\/a>\u201d to encrypted communications, akin to listening in to encrypted communications services.<\/p>\n<p>But they argued that countering child sexual abuse is complex, that the detail is important and that governments have never clearly laid out the \u201ctotality of the problem\u201d.<\/p>\n<p>\u201cIn publishing this paper, we hope to correct that information asymmetry and engender a more informed debate,\u201d they said.<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Analysis of metadata ineffective\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Analysis of metadata ineffective<\/h3>\n<p>The paper argued that the use of artificial intelligence (AI) to analyse metadata, rather than the content of communications, is an ineffective way to detect the use of end-to-end encrypted services for child abuse images.<\/p>\n<p>Many proposed AI-based solutions do not give law enforcement access to suspect messages, but calculate a probability that an offence has occurred, it said.<\/p>\n<p>Any steps that law enforcement could take, such as surveillance or arrest, would not currently meet the high threshold of evidence needed for law enforcement to intervene, the paper said.<\/p>\n<p>\u201cDown this road lies the dystopian future depicted in the film <em>Minority Report<\/em>,\u201d it added.<\/p>\n<p>\u201cThe Online Safety Bill is an opportunity to tackle child abuse taking place at an industrial scale. Despite the breathless suggestions that the Bill could \u2018break\u2019 encryption, it is clear that legislation can incentivise companies to develop technical solutions and deliver safer and more private online services.\u201d<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Online Safety Bill\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Online Safety Bill<\/h3>\n<p>Andy Burrows, head of child safety online policy at children\u2019s charity the NSPCC, said the paper showed it is wrong to suggest that children\u2019s right to online safety can only be achieved at the expense of privacy.<\/p>\n<p>\u201cThe report demonstrates that it will be technically feasible to identify child abuse material and grooming in end-to end-encrypted products,\u201d he said. \u201cIt is clear that the barriers to child protection are not technical, but driven by tech companies that don\u2019t want to develop a balanced settlement for their users.\u201d<\/p>\n<p>Burrows said the proposed Online Safety Bill is an opportunity to tackle child abuse by incentivising companies to develop technical solutions.<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Proposals would \u2018undermine security\u2019\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Proposals would \u2018undermine security\u2019<\/h3>\n<p>Meta, which owns Facebook and WhatsApp, said the technologies proposed in the paper by Levy and Robinson would undermine the security of end-to-end encryption.<\/p>\n<p>\u201cExperts are clear that technologies like those proposed in this paper would undermine end-to-end encryption and threaten people\u2019s privacy, security and human rights,\u201d said a Meta spokesperson.<\/p>\n<p>\u201cWe have no tolerance for child exploitation on our platforms and are focused on solutions that do not require the intrusive scanning of people\u2019s private conversations. We want to prevent harm from happening in the first place, not just detect it after the fact.\u201d<\/p>\n<p>Meta said it protected children by banning suspicious profiles, restricting adults from messaging children they are not connected with on Facebook, and limiting the capabilities of accounts of people aged under 18.<\/p>\n<p>\u201cWe are also encouraging people to report harmful messages to us, so we can see the reported contents, respond swiftly and make referrals to the authorities,\u201d the spokesperson said.<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"UK push \u2018irresponsible\u2019\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>UK &nbsp;push \u2018irresponsible\u2019<\/h3>\n<p><span>Michael Veale, an associate professor in digital rights and regulations at UCL, <a href=\"https:\/\/twitter.com\/mikarv\/status\/1550028562006155264\">wrote in an anlaysis on Twitter<\/a> that it was irresponsible of the UK to push for client-side scanning.<\/span><\/p>\n<p><span>\u201cOther countries will piggyback on the same (faulty, unreliable) tech to demand scanning for links to abortion clinics or political material,\u201d he wrote.<\/span><\/p>\n<p>Veale said the people sharing child sexual abuse material would be able to evade scanning by moving to other communications services or encrypting their files before sending them.<\/p>\n<p><span>\u201cThose being persecuted for exercising normal, day-to-day human rights cannot,\u201d he added.<\/span><\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Security vulnerabilties\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Security vulnerabilties<\/h3>\n<p>Jim Killock, executive director of the Open Rights Group, said client-side scanning would have the effect of breaking end-to-end encryption and creating vulnerabilities that could be exploited by criminals, and state actors in cyber-warfare battles.<\/p>\n<p><strong>\u201c<\/strong>UK cyber security chiefs plan to invade our privacy, break encryption, and start automatically scanning our mobile phones for images that will turn them into a \u2018spies in your pocket\u2019,\u201d he said<strong>.<\/strong><\/p>\n<p>\u201cThis would be a massive step towards a Chinese-style surveillance state. We have already seen China wanting to exploit similar technology to crack down on political dissidents.\u201d<\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Companies could police encrypted messaging services for possible child abuse while still preserving the privacy and security of the people who use them, government security and intelligence experts said in a discussion paper published yesterday. Ian Levy, technical director of the UK National Cyber Security Centre (NCSC), and Crispin Robinson, technical director for cryptanalysis at [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":40480,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-40479","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/40479","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=40479"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/40479\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/40480"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=40479"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=40479"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=40479"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}