Chat Control is the European regulation that introduces a system for monitoring conversations on online platforms in search of crimes. We interviewed Stefano Zanero, professor at the Polytechnic University of Milan, to understand what the critical points of these rules are.
Holiday photos. A few days of rest by the seawith the whole family. You want to keep some print, to avoid forget the pictures somewhere in the phone’s memory. It’s in the photo the whole family in costume. Select the shots. Send everything. A warning arrives: “You sent an email with child pornography material. We have notified the competent authorities.” Or worse. Nothing arrives and in some attorney in Europe a file opens with your name on it. Reading the analyzes released in recent days, this is one of the perspectives that the Chat Controlthe European regulation that aims to monitor certain online conversation spaces to find materials related to crimes involving minors: from sexual abuse to child pornography.
We already have them on Fanpage.it spoken several times. Here you can find further information on the regulation and the status of its approval. And here instead a focus on the platforms that are actually affected, given that after the vote in the European Parliament on July 9th the text has been changed again. A fairly heated debate has arisen on social media, but to understand exactly what changes we talked to Stefano Zanerocybersecurity expert and teacher of Polytechnic of Milan.
What is the purpose of the regulation known as Chat Control?
The declared objective is to stem the spread of child pornography images. It is a goal that no one can dispute. The means chosen, however, is to impose a preventive analysis of the contents exchanged in private chats.
Chat Control, which messages can be read: from Gmail to Instagram DMs
It’s not a simple transition. What are the problems?
The first problem is that automatically identifying sexual content involving minors is not at all trivial. Of course, you might think that an image of a naked minor would automatically be classified as prohibited but it depends on the context. If, for example, the image in question is a photograph of a child at the seaside that one parent is sending to the other, we immediately understand that the context makes it irrelevant. A computer, however, will never be able to analyze or understand this aspect.
The European Union is discussing Chat Control 1.0. But Commissioner Henna Virkkunen proposed a text for Chat Control 2.0, where end-to-end encryption is also included.
Today, almost all of our private messaging apps, from WhatsApp to Signal, are end-to-end encrypted. The messages are readable only by the sender and the recipient (Telegram is an exception, as the operator has the possibility of reading the messages there). When you impose content censorship, you implicitly require that end-to-end encryption can be bypassed by the provider, effectively nullifying its effectiveness.
Is there a way to apply Chat Control without entering chats?
The only way would be to scan on the endpoint, i.e. scan the attachments directly on the device that sends or receives them. This hypothesis had been floated by Apple in the past, but was later discarded due to the problem of false positives. Since algorithms will inevitably make errors, both for reasons of context and for technical imperfections, and considering that we are talking about criminal crimes, it will always be necessary to verify whether a report is correct or not. The only possible way is to employ human operators who analyze these reports.
We are talking about a huge number of reports.
Yes, it generates a huge volume of potential reports to manually look at, inevitably violating the confidentiality of communications, because there is no other technical way to do it. Even trying to circumvent some technical problems, the fundamental issue is not resolved: the analysis is entrusted to algorithms which, in fact, are not adequate for the enormous volume of messages we exchange every day. This is a known problem in the theory of malicious activity detection: it’s called the Base Rate Fallacy.
Let’s take an example with another case.
It would work the same way if we decided to install cameras in airports to automatically identify wanted criminals based on a list of faces. The Base Rate Fallacy is based on the fact that there are far fewer child pornography images than harmless memes on WhatsApp, just as there are far fewer criminals than normal citizens at an airport. Consequently, the overriding factor is not so much the algorithm’s ability to find illicit content, but how often it will accidentally click on good content. This creates a veritable deluge of false positives, which is why these types of systems typically fail in practice.
The crimes for which Chat Control is introduced concern all child abuse.
Any crime that affects children is clearly a very strong motivation, which on a personal level I find compelling and which deserves every possible effort. On the other hand, however, it is also a powerful rhetorical lever to pass controversial surveillance regulations. When the doubt is raised that these tools can then be used for other purposes, one is often accused of resorting to the “slippery slope” argument. It would be a fair objection, if we hadn’t already seen exactly this happen in the past.
Any examples?
Just think of DNS filtering: created to exclusively block child pornography sites, it slowly extended to terrorist sites, then to gambling and betting sites, finally arriving at computer piracy. The tool, once created, is inevitably used for something else. As long as it involves blocking access to a site, we could consider it a still viable model but the intervention within personal chats is the very definition of Chinese censorship. The substantial difference between WhatsApp and WeChat in China is precisely that on the latter there are censors who read what users write to each other.
What tools are there to stem these crimes?
The aim of protecting minors is shared by everyone, but we must ask ourselves whether the means chosen actually leads to that result. More than 800 European cybersecurity experts have signed open letters to report these critical issues. In those letters we underlined the existence of alternative approaches, currently ignored, which would go in the true direction of combating the phenomenon. For example, the greatest danger for minors lies not only in the dissemination of the material, but above all in solicitation. Solicitation must be countered first of all with education, an aspect and an investment on which the current legislation is extremely vague and lacking. If we had to choose where to start, educational prevention would be the fundamental point to start from, yet it is the great absentee in these directives.

