CSAM Regulation Update: Dutch Intelligence agency weighs in - Bert Hubert's writings
a day ago
- The European Commission and EU member states have considered forcing messaging platforms to scan private messages for child sexual abuse material (CSAM), which would break end-to-end encryption.
- The proposal includes fuzzily scanning for known CSAM now and adding AI scanning for text messages in three years, but this is seen as highly ineffective and risky.
- Dutch intelligence agency AIVD warns that scanning applications on all mobile phones create a complex system with large security risks to digital resilience.
- Inserting a scanning layer expands the threat surface, as image parsing is hard to secure; hackers could exploit the CSAM filter to access phones.
- Platforms like Facebook/Meta would bear the cost of installing and maintaining the scanning infrastructure without financial incentive, potentially leading to poor security.
- Drafts of the CSAM regulation include an opt-out for intelligence services, indicating acknowledged privacy risks.