Meredith Whittaker, president of the Signal Foundation, argues that the European Union's (EU) new proposal to scan messages users' to detect child sexual abuse material (CSAM) poses serious security and privacy risks.

Whittaker specifically addressed how end-to-end encryption (E2EE) will be affected in the messaging app Signal, an app known for its focus on user privacy.
“ Mandatory mass scanning of private communications fundamentally undermines encryption ,” Whittaker said . “ Whether that happens through a breach, or by implementing a key escrow system, or by forcibly monitoring communications before they are encrypted .”
See also: How does end-to-end encryption enhance crime?
Meanwhile, lawmakers in the EU are enacting regulations to combat CSAM content, with a new provision called “upload supervision” that allows messages to be checked before encryption.
A recent report by Euractiv revealed that voice communications are not affected by this law and that users must consent to this monitoring, according to the terms and conditions of the service provider. Those who do not consent will be able to communicate with others, but will not be able to send visual content and URLs.
This kind of surveillance, of course, belies the importance of end-to-end encryption (in Signal messages and beyond). While the intention behind the regulation is good – protecting vulnerable children from exploitation – implementation could have far-reaching consequences. E2EE allows only the sender and recipient of a message to see its contents, making it nearly impossible for anyone else (including law enforcement or hackers) to intercept or read the messages.
However, encryption has been a major concern for authorities in the past year. In late April 2024, Europol called on technology companies and governments to prioritize public safety. It warned that security measures such as E2EE could prevent law enforcement agencies from accessing illegal/dangerous content. All of this has led to an ongoing debate about balancing privacy with the fight against serious crime.
See also: Hackers access your encrypted conversations using AI!
Europol also asked platforms to design security systems in such a way that they can detect and report harmful and illegal activity to law enforcement authorities.

Apple had announced a child sexual abuse material (CSAM) screening app , but withdrew it in late 2022 after continued backlash from privacy and security advocates.
Signal's Whittaker believes that the EU's new proposal for message scanning amounts to introducing a backdoor, essentially creating a security vulnerability that can be exploited by malicious actors and state hackers.
“Either end-to-end encryption protects everyone and ensures security and privacy, or it is breached for everyone,” he said. “And breaking end-to-end encryption, especially at such a geopolitically volatile time, is a disastrous proposition.”
If implemented, the regulation would essentially require messaging services like Signal to create a vulnerability in their encryption system, weakening their overall security . This could potentially expose sensitive information not only of those suspected of illegal activity but also of innocent users.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Zoom: Brings post-quantum end-to-end encryption to Zoom Meetings
Furthermore, this approach could be ineffective in combating CSAM, as perpetrators could easily adopt alternative methods of communication or simply encrypt their messages using other means. As seen with previous attempts to regulate encrypted messaging services , such measures have driven criminals to other methods, making them difficult for law enforcement to track.
In conclusion, while the goal of protecting children is a worthy cause, there are concerns about the safety of millions of innocent users. It is vital for policymakers to consider alternatives that do not compromise E2EE (in Signal messaging and elsewhere) and to work closely with technology companies and advocacy groups to find effective ways to combat CSAM while protecting user privacy.
Source: thehackernews.com
