Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

Ex-Anduril engineer raises $42 million for Amazon composite parts maker

Squishmallows, dentures and an ‘I Heart Hot Dads’ bag: Uber found thousands of items left in robotaxis

Because VivaTech 2026 is the place to see Europe’s AI strategy taking shape

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Cyera eyes $12B valuation at 80x ARR multiple despite operating losses

    3 June 2026

    Anthropic scales Claude Mythos to critical infrastructure in 15+ countries

    2 June 2026

    Florida sues OpenAI’s Sam Altman in first-of-its-kind violent crime lawsuit

    2 June 2026

    The internet is being remade for machines

    1 June 2026

    Understanding the AI ​​psychosis debate

    31 May 2026
  • Apps

    Google Launches Fake Call Detection to Protect Against AI Impersonation Scams

    3 June 2026

    Meta is testing ‘Series’ for episodic Reels on Instagram and Facebook

    2 June 2026

    A new app, The Mall, creates a universal flow for online shopping

    2 June 2026

    DuckDuckGo makes its ‘AI-free’ search engine easier to access as traffic grows

    1 June 2026

    TikTok’s road to becoming a super app

    31 May 2026
  • Crypto

    Startup Battlefield 200 applications close today

    27 May 2026

    5 days left: Save up to $410 on Disrupt 2026 passes

    25 May 2026

    As crypto cools, a16z crypto raises $2.2 billion in capital

    6 May 2026

    Coinbase to lay off 14% of staff as part of broader restructuring

    5 May 2026

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026
  • Fintech

    Last 24 hours to save up to $410 on your Disrupt 2026 ticket

    29 May 2026

    2 days left: Lock in up to $410 in ticket savings for Disrupt 2026

    28 May 2026

    Robinhood now allows your AI agents to trade stocks

    28 May 2026

    Disrupt 2026 Early Bird ticket savings expire in 3 days

    27 May 2026

    Disrupt 2026 Early Bird ticket prices end May 29

    26 May 2026
  • Hardware

    Cyberdecks are having a moment, rejecting big tech surveillance with style and substance

    3 June 2026

    Nvidia chases $200 billion CPU market with AI agent computing from Microsoft, Dell and HP

    2 June 2026

    This $300 Pizza Oven Can Easily Help Revive Your Summer Pizza Nights

    30 May 2026

    Kiwibit’s artificial intelligence bird feeder is my new backyard friend

    29 May 2026

    Vertu wants CEOs to run companies from a foldable AI starting at $6,880

    29 May 2026
  • Media & Entertainment

    A startup, Everand, is now bringing together e-books, audiobooks and book clubs as a challenge to Amazon

    2 June 2026

    The two biggest movies of this weekend were both directed by YouTubers

    31 May 2026

    The two biggest movies of this weekend were both directed by YouTubers

    30 May 2026

    YouTube will automatically flag videos with artificial intelligence

    28 May 2026

    Meta launches Instagram, Facebook and WhatsApp subscriptions, with more to follow, including AI plans

    27 May 2026
  • Security

    Password manager Dashlane says hackers stole some customers’ password vaults

    2 June 2026

    Hackers took over Instagram accounts by tricking the Meta AI support chatbot into granting access

    1 June 2026

    Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover

    30 May 2026

    Microsoft is under fire for threatening a security researcher with a criminal investigation

    29 May 2026

    A security flaw in prison payphone service Pay Tel exposed publicly the driver’s licenses of more than 300,000 callers

    29 May 2026
  • Startups

    Ex-Anduril engineer raises $42 million for Amazon composite parts maker

    3 June 2026

    Board, the new gaming startup from Mirror founder Brynn Putnam, raises $20 million, has already sold thousands

    2 June 2026

    From Stage to Future: Where Are Startup Battlefield Alumni Now?

    2 June 2026

    Revolut offers service to thousands of users in India ahead of wider rollout

    1 June 2026

    The deadline to submit applications for the Startup Battlefield 200 has been extended to June 8

    30 May 2026
  • Transportation

    Squishmallows, dentures and an ‘I Heart Hot Dads’ bag: Uber found thousands of items left in robotaxis

    3 June 2026

    Defense tech darling Mach Industries hits $1.8 billion valuation, 4x jump in one year

    2 June 2026

    SpaceX says it may issue ‘significant’ equity in ‘future transactions’

    1 June 2026

    TechCrunch Mobility: It doesn’t matter that people hate the Ferrari Luce

    31 May 2026

    Rivian is under investigation for rear suspension failures on R1 models

    30 May 2026
  • Venture

    Because VivaTech 2026 is the place to see Europe’s AI strategy taking shape

    3 June 2026

    How Europe’s AI strategy diverges from Silicon Valley’s

    2 June 2026

    How to make the Startup Battlefield Top 20 — and what each company gets regardless

    2 June 2026

    Black founders raise highest quarterly funding since 2022, but there’s a catch

    31 May 2026

    Snap alums reveal Ghost Angels fund

    31 May 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»EU plan to force messaging apps to scan for CSAM risks millions of false positives, experts warn
Security

EU plan to force messaging apps to scan for CSAM risks millions of false positives, experts warn

techtost.comBy techtost.com3 May 202408 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Eu Plan To Force Messaging Apps To Scan For Csam
Share
Facebook Twitter LinkedIn Pinterest Email

A controversial push by European Union lawmakers to legally require messaging platforms to scan citizens’ private communications for child sexual abuse material (CSAM) could lead to millions of false positives a day, hundreds of security experts and privacy. I open a letter Thursday.

Concern over the EU proposal has been building since the Commission proposed the CSAM scanning plan two years ago — with independent experts, lawmakers from the European Parliament and even the bloc’s Data Protection Supervisor among those sounding the alarm .

The EU proposal does not only require scanning by messaging platforms that receive a CSAM detection mandate known CSAM? they would also have to use unspecified detection scanning technologies to try to locate unknown CSAMs and identify grooming activity as it occurs — leading to accusations of lawmakers indulging in magical levels of tech thinking.

Critics argue that the proposal is asking for the technologically impossible and will not achieve the stated goal of protecting children from abuse. Instead, they say, it will destroy Internet security and Internet users’ privacy by forcing platforms to deploy blanket surveillance of all their users by deploying dangerous, unproven technologies such as client-side scanning.

Experts say there is no technology capable of achieving what the law requires without causing far more harm than good. However, the EU is plowing independently.

The latest open letter refers to amendments to the draft CSAM scanning regulation recently proposed by the European Council, which the signatories argue do not address fundamental flaws in the draft.

The letter’s signatories—numbering 270 at the time of writing—include hundreds of academics, including well-known security experts such as Professor Bruce Schneier of the Harvard Kennedy School and Dr. Matthew D. Green of Johns Hopkins University, along with some researchers working for technology companies such as IBM, Intel and Microsoft.

An older one I open a letter (last July), signed by 465 academics, warned that the detection technologies that the legislative proposal hinges on forcing platforms to adopt are “deeply flawed and vulnerable to attack” and would lead to a significant weakening of vital protections provided by end-to-end encrypted communications (E2EE).

Little attraction to counter-proposals

Last fall, MEPs in the European Parliament united to push back with a substantially revised approach — which would limit scanning to individuals and groups already suspected of child sexual abuse. limit it to known and unknown CSAM, removing the scan requirement for grooming. and remove any risks to E2EE by limiting it to platforms that are not end-to-end encrypted. However, the European Council, the other co-legislator involved in EU law, has yet to take a position on the matter and where it goes will affect the final shape of the law.

The latest amendment on the table was tabled by the Belgian presidency of the Council in March, which is leading discussions on behalf of representatives of EU member state governments. However, in the open letter, experts warn that this proposal still fails to address the fundamental flaws in the Commission’s approach, arguing that reviews still create “unprecedented capabilities to monitor and control Internet users” and would “undermine… secure digital future for our society and could have huge implications for democratic processes in Europe and beyond.”

Amendments to be discussed in the Council’s amended proposal include a proposal that detection orders can be more targeted by implementing risk categorization and mitigation measures. and cybersecurity and encryption can be protected by ensuring that platforms are not required to create access to decrypted data and by controlling detection technologies. But the 270 experts suggest that this amounts to a hassle bordering on a security and privacy disaster.

From a “technical point of view, to be effective, this new proposal will completely undermine the security of communications and systems,” they warn. Although we rely on “flaw detection technology” to identify cases of interest in order to send more targeted detection orders, it will not reduce the risk that the law will usher in a dystopian era of “mass surveillance” of internet users’ messages. analysis.

The letter also discusses a proposal by the Council to limit the risk of false positives by defining a “person of interest” as a user who has already shared CSAM or attempted to groom a child — which is envisaged to be done through automated assessment. such as waiting 1 visit for known CSAM or 2 for unknown CSAM/treatment before the user is formally identified as a suspect and reported to the EU Center, which would handle CSAM reports.

Billions of users, millions of false positives

Experts warn that this approach is still likely to result in huge numbers of false alarms.

“The number of false positives due to detection errors is very unlikely to decrease significantly unless the number of replicates is so large that detection ceases to be effective. Given the large number of messages sent on these platforms (in the billions), one can expect a very large number of false alarms (in the millions),” they write, noting that the platforms are likely to end up being slapped with an order tracker can have millions or even billions of users, like WhatsApp owned by Meta.

“Since there has been no public information on the performance of the detectors that could be used in practice, let’s imagine that we would have a detector for CSAM and grooming, as stated in the proposal, with a false positive rate of only 0.1%. (ie, one in a thousand times, misclassifies non-CSAM as CSAM), which is much lower than any currently known detector.

“Given that WhatsApp users send 140 billion messages a day, even if only 1 in a hundred was a message checked by such detectors, there would be 1.4 million false positives every day. To reduce false positives to hundreds, statistically one would need to identify at least 5 replicates using different, statistically independent images or detectors. And that’s just for WhatsApp – if we consider other messaging platforms, including email, the number of iterations required will increase significantly to the point where CSAM sharing capabilities are not effectively reduced.”

Another Council proposal to limit detection orders to messaging apps deemed to be “high risk” is a useless revision, in the view of the signatories, as they argue that it will likely still “indiscriminately affect a huge number of people”. Here they point out that only standard functions such as image sharing and text chat are required for CSAM exchange — functions that are widely supported by many service providers, meaning that a high-risk categorization “will undoubtedly affect many services.”

They also point out that E2EE adoption is increasing, which they suggest will increase the likelihood that services distributing it will be classified as high risk. “This number may increase further with the interoperability requirements introduced by the Digital Markets Act which will result in messages flowing between low and high risk services. As a result, almost all services could be classified as high risk,” they argue. (Note: Message interoperability is a key element of the EU DMA.)

A backdoor for the backdoor

When it comes to safeguarding encryption, the letter reiterates the message that security and privacy experts have been repeatedly shouting to lawmakers for years: “Tracing into end-to-end encrypted services undermines the protection of encryption by definition.”

“The new proposal has as one of its goals to ‘protect cyber security and encrypted data while keeping services that use end-to-end encryption within the scope of detection orders.’ As we have explained before, this is an oxymoron” they emphasize. “The protection provided by end-to-end encryption means that no one other than the intended recipient of a communication should be able to learn any information about the content of that communication. Enable traceability, either for encrypted or pre-encrypted data; it violates the very definition of confidentiality provided by end-to-end encryption.”

In recent weeks, police chiefs across Europe have drawn up their own joint statement — expressing concerns about the expansion of E2EE and asking platforms to design their security systems in such a way that they can still detect illegal activity and send reports for content of messages to law enforcement authorities.

The intervention is widely seen as an attempt to pressure lawmakers to pass laws like the CSAM scanning regulation.

Police chiefs deny they are calling for backdoor encryption, but have not explained exactly what technical solutions they want the platforms to adopt to allow the intended “legitimate access”. Squaring this circle puts a very loosely shaped ball back in the legislators’ court.

If the EU continues on its current path — provided the Council does not change course, as MEPs have urged — the consequences will be “disastrous”, the letter’s signatories then warn. “It sets a precedent for internet filtering and prevents people from using some of the few tools available to protect their right to privacy in the digital space. it will have a chilling effect, especially on teenagers who rely heavily on online services for their interactions. It will change the way digital services are used around the world and is likely to negatively impact democracies around the world.”

An EU source close to the Council could not provide information on current discussions between member states, but noted that there is a working group meeting on May 8, where they confirmed that the proposal for a regulation to combat child sexual abuse will be discussed.

apps CSAM eh encryption eu csam-scanning proposal experts false Force messaging millions plan positives Risks Scan Warn
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThe Hubble network makes a Bluetooth connection with a satellite for the first time
Next Article Kajabi’s online course platform allows creators to build their own branded apps
bhanuprakash.cg
techtost.com
  • Website

Related Posts

Password manager Dashlane says hackers stole some customers’ password vaults

2 June 2026

Hackers took over Instagram accounts by tricking the Meta AI support chatbot into granting access

1 June 2026

Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover

30 May 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

Ex-Anduril engineer raises $42 million for Amazon composite parts maker

3 June 2026

Squishmallows, dentures and an ‘I Heart Hot Dads’ bag: Uber found thousands of items left in robotaxis

3 June 2026

Because VivaTech 2026 is the place to see Europe’s AI strategy taking shape

3 June 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Last 24 hours to save up to $410 on your Disrupt 2026 ticket

29 May 2026

2 days left: Lock in up to $410 in ticket savings for Disrupt 2026

28 May 2026

Robinhood now allows your AI agents to trade stocks

28 May 2026
Startups

Ex-Anduril engineer raises $42 million for Amazon composite parts maker

Board, the new gaming startup from Mirror founder Brynn Putnam, raises $20 million, has already sold thousands

From Stage to Future: Where Are Startup Battlefield Alumni Now?

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.