In opposition of ChatControl (Open letter)

NoteThis is a letter I sent to my representatives on . To date, the only reply I've received has been from Vänsterpartiet, who also opposes Chat Control.

Hello,

I am a developer and an IT security specialist with over a decade in the industry. A significant portion of this time has been in the role of a penetration tester, which is a role in IT security where my task is to find and exploit security vulnerabilities, to enable my customers to address the issues I find and improve their security. My work as a developer has also centered around IT security, 3 years of which was spent working on encrypted communication solutions for military applications. Apart from my professional experience in the field, cryptography is a big personal interest of mine. Speaking of personal interest, I'm also a father wanting to protect my children. This letter is my own personal and professional opinions without any usage of AI or online templates.

I'm writing in the strongest possible opposition of chat control.

In December of 2024, the American FBI urged users to stop sending SMS, because they had reason to believe that Chinese adversaries had gained access to the US phone infrastructure. In 2019, The Guardian reported that Poland had arrested Huawei employees on espionage charges. In Sweden we've blocked Huawei from participating in the Swedish 5G network, because of (very legitimate) security concerns. We have very real adversaries with massive resources trying to gain access to our communications. This is one of many good reasons to use strong encryption. Trying to weaken or circumvent this encryption also opens the door to these adversaries.

Proponents of this law are claiming that this protection can be added without breaking the security. This is a completely false claim. There are no equivalents to sniffer dogs for encryption. Looking at the encrypted message you can deduce an approximate size of the original package, intended receiver of the package, in some cases the sender of the package, and the time and quantities of messages. That's it. Anything more than this and you will have to break encryption. Even if we assume that the technology works as intended, as in only collecting suspicious material, users will never know if anything they send will also be secretly sent to an unknown third party. This inherently leads to self censorship, especially in countries with growing antidemocratic forces, and for a very valid reason. For historical precedence look at Netherlands. In the 1930s, they had records that allowed their tax collectors to collect taxes for religious institutions. This was great for churches and their members alike. It was also great for the Nazis, leading to 70% of the Jewish population being murdered. It's very hard to know today what will be a secret in 10 years.

The suggested solution on how to do this without compromising security is to scan messages for prohibited material before the messages are encrypted. This means that you have one of two solutions. Either you make every provider of chat services implement this solution by themselves, or you provide them with a solution from a third party. Alternative 1 forces them to become experts in an extremely complex technology far outside of their primary business, where mistakes may completely break their users privacy and overload law enforcement. This pretty much means that you will have to provide the solution from a third party.

There are two main techniques that can be used:

  1. The black list, where images sent are compared to known thumbprints of prohibited images, which are not sensitive to recompression artefacts. This is technology that Apple, one of the most advanced and financially capable companies in the world, has attempted and failed to implement for the last couple of years.
  2. Heuristic analysis, where AI is an example. This introduces a ridiculous amount of complexity and trust. The reason for this is that AI models are huge sets of opaque variables. These models can be (very shallowly) tested, but they cannot be reviewed, and they are notoriously hard to control. An AI model can easily be trained to increase trigger rate for users with undesired political opinions measured over thousands of messages in a way that will never be caught in a test.

Whoever is tasked with developing this technology is granted the ability to run code that will scan pretty much every single message sent inside of the European Union. If developers get corrupted, they can covertly convert the analysis tool into a tool that spies and collects information on the entire European union in a way that has never been seen before. While the intention is to only send back information when abuse material is is found, the information sent back can easily be encoded to include hidden information with steganographic methods. They gain the ability to collect opinions, political leanings, secrets, insecurities, and fears of the entire European population. That is information that in the wrong hands can completely topple democracy. How far do you think a foreign adversary would go to gain access to this information? This ability in combination with the low transparency of AI models (thus low detectability of malicious applications) means that anyone tasked with developing this technology will be put at significant personal risk, as will their families.

You add exclusions for national security purposes, what does that even mean? What about the phones of their partners, children, and friends? In OSINT there is the concept of aggregated data, meaning that you combine incomplete data from multiple sources to create a bigger picture. An AI model can be trained to specifically to target people with proximity to a target, and any data collected can be excused as false positives that will be ignored. This technology would be a threat even to the stated exclusions in the proposals. Besides the issue with data collection, this also risks actually good tools used both by Swedish companies and your own military to communicate, such as Signal, simply being lost. This would introduce a meaningful risk to companies and our military alike.

The proponents want to make you feel as if you either support Chat Control or you enable child sexual abuse. This is manipulation, known as the false dilemma or false dichotomy. I'm not saying it won't catch child abusers, I really can't predict that, but I'm saying that you're given the apparent option of catching or not catching child abusers. Another way of catching child abusers would be to arrest and investigate every single grown up working with konfirmationsläger. Very few of them would actually get charged, but you would catch child abusers that directly hurt children. If you don't do this, does that mean that you are opposed to catching child abusers, or simply that you have respect for individual legal rights? I've seen the statistics, I know that the numbers are really bad for the EU, so I recognize that you're desperate for a solution. Chat Control is not that answer. It's a Hail Mary grounded in a very low technical understanding of cryptography and that very same desperation.

If the intent of this proposal is to find child abusers, then I think it's a very over engineered proposal with huge ramifications for citizens and businesses alike, financial costs, and likely underwhelming results. On the other hand, if the intent is to actually map and track every single European citizen, then this is a very efficient (albeit also very risky) proposal. This leads me to to the conclusion that at least one of following is true for anyone supporting the suggestion:

Beyond the very questionable legality around this proposal (which other people cover way better than I possibly could), I do think it is an actual huge threat to democracy, even if implemented perfectly. While I find the first three reasons way more likely than the last two options, I have yet to find a reason to support this proposal that does not erode trust in politicians. As my representative in the European Union I urge you to please oppose this proposal or enlighten me if you think I'm wrong in my conclusion.

Med vänliga hälsningar,
Marcus Ofenhed