
Getty Images
The nonprofit behind the Signal messenger app will withdraw from the UK if the UK asks encrypted communications providers to change their products so that user messages do not contain material harmful to children. i am ready.
Signal CEO Meredith Whittaker told Ars: “The UK is no exception.”
Whittaker’s comments come as the UK Parliament is drafting a bill known as the Online Safety Bill. The bill, introduced by former Prime Minister Boris Johnson, would require nearly all providers of user-generated content to block child sexual abuse content (often abbreviated as CSAM or CSA). Comprehensive law. Providers must also ensure that legal content accessible to minors (including self-harm topics) is age-appropriate.
Crosshair E2EE
The bill’s provisions specifically aim for end-to-end encryption, a form of encryption that allows only the sender and recipient of a message to access human-readable content. Commonly abbreviated as E2EE, it uses a mechanism that makes encrypted messages unreadable even to service providers. His robust E2EE, enabled by default, is Signal’s biggest selling point to its over 100 million users. Other services that offer E2EE include Apple iMessages, WhatsApp, Telegram and Meta’s Messenger, but not all offer it by default.
Under one provision of the Online Safety Bill, service providers are prohibited from “providing encrypted information.” [UK telecommunications regulator] ofcom to understand it, or to create an encrypted document that renders Ofcom unable to understand the information it contains” and that the intent is to prevent UK oversight authorities from understanding such information. if there is.
An impact assessment drafted by the UK’s Department for Digital, Culture, Media and Sport clearly states that E2EE is within the law. One section of the evaluation states:
Governments advocate strong encryption to protect user privacy, but if public safety issues are not considered, a move to an end-to-end encryption system would be a threat to existing online There are concerns that it erodes many of its safety methodologies. I have. Businesses should regularly assess the risks of harming their services, including the risks associated with end-to-end encryption. Also, risk should be assessed before any significant design change, such as moving to end-to-end encryption. Service providers must take reasonably practicable steps to mitigate identified risks.
The bill does not provide specific methods for providers of E2EE services to comply. Instead, it will fund five organizations to develop “innovations that can detect and respond to sexually explicit images and videos of children within end-to-end encrypted environments while respecting user privacy.” Develop a method.