EU’s ‘Going Dark’ Expert Group Publishes 42-Point Surveillance Plan For Access To All Devices And Data At All Times

from the they-never-give-up dept

Techdirt has been covering the disgraceful attempts by the EU to break end-to-end encryption — supposedly in order to “protect the children” — for two years now. An important vote that could have seen EU nations back the proposal was due to take place recently. The vote was cancelled — not because politicians finally came to their senses, but the opposite. Those backing the new law were worried the latest draft might not be approved, and so removed it from the agenda, to allow a little more backroom persuasion to be applied to holdouts.

Although this “chat control” law has been the main focus of the EU’s push for more surveillance of innocent citizens, it is by no means the end of it. As the German digital rights site Netzpolitik reports, work is already underway on further measures, this time to address the non-existent “going dark” threat to law enforcement:

The group of high-level experts had been meeting since last year to tackle the so-called „going dark“ problem. The High-Level Group set up by the EU was characterized by a bias right from the start: The committee is primarily made up of representatives of security authorities and therefore represents their perspective on the issue.

Given the background and bias of the expert group, it’s no surprise that its report, “Recommendations from the High-Level Group on Access to Data for Effective Law Enforcement”, is a wish-list of just about every surveillance method. The Pirate Party Member of the European Parliament Patrick Breyer has a good summary of what the “going dark” group wants:

according to the 42-point surveillance plan, manufacturers are to be legally obliged to make digital devices such as smartphones, smart homes, IoT devices, and cars monitorable at all times (“access by design”). Messenger services that were previously securely encrypted are to be forced to allow for interception. Data retention, which was overturned by the EU Court of Justice, is to be reenacted and extended to OTT internet communications services such as messenger services. “At the very least”, IP connection data retention is to be required to be able to track all internet activities. The secure encryption of metadata and subscriber data is to be prohibited. Where requested by the police, GPS location tracking should be activated by service providers (“tracking switch”). Uncooperative providers are to be threatened with prison sentences.

It’s an astonishing list, not least for the re-appearance of data retention, which was thrown out by the EU’s highest court in 2014. It’s a useful reminder that even when bad laws are overturned, constant vigilance is required to ensure that they don’t come back at a later date.

Follow me @glynmoody on Mastodon and on Bluesky.

Filed Under: , , , , , , , , , , , , , , , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “EU’s ‘Going Dark’ Expert Group Publishes 42-Point Surveillance Plan For Access To All Devices And Data At All Times”

Subscribe: RSS Leave a comment
27 Comments

This comment has been flagged by the community. Click here to show it.

Anonymous Coward says:

Pretty sure they can already do all that – this is just theatre to let them start acting on it. I used to think – oh well, nvm – whats the chance of them noticing me when I’m being shady amongst a continent of occasionally-shady people? But add AI to the mix to filter thorough the vast piles of data and a truly terrifying future takes shape..

Anonymous Coward says:

Re: Re:

Considering what people can do with a bunch of public records, Google and a lot of free time…

Bacon on ice cream is probably the last thing you should worry about.

Do you want the government to have the power to send you to jail for merely looking at something a politician did not like at a bare minimum? Perhaps have a government-aligned brownshirt orchestrate a government-sanctioned harassment campaign aimed at you and everyone you know? Surprise crossbow bolt in your chest? Or perhaps a wee bit of polonium or two bullets in the back of your head?

Would you like any of that done to you?

Anonymous Coward says:

Re:

I’m trying to imagine what it was like in the Roman times when their ‘security’ was made aware of the RO13 algorithm for encryption.

Encryption probably existed prior to this notorious method of obfuscation, but this is easy to use as an example of the first known (to me) use of the nefarious form of criminal activity known as encryption.

Side note, if the government was not doing things the citizens disapprove of then maybe the government would not be so concerned about who knows about it. They bring this upon themselves.

Anonymous Coward says:

If this goes into effect...

…then among the many interesting outcomes will be the quick emergence of a healthy marketplace selling evasion methods and devices, including some which generate a lot of plausible but fake data. This is already a well-understood problem space (we were generating and feeding fake data to spammers decades ago) (and now we’re doing it to the crawlers run by AI companies) so it’s only a matter of time until someone applies the same techniques to counter this attempt at pervasive surveillance.

Another outcome will be that the Russians, the Chinese, and any other major government with a competent intelligence service will get their hands on all of it. And the Chinese in particular will do better and faster analysis that anyone of the EU countries, and one of the outcomes of THAT will be that EU governments will have quite effectively bugged their own politicians.

Anonymous Coward says:

Re:

Those methods work against spammers and AI companies because they require their data input to be accurate. Even small amounts of innacurate data are large problems for their operations.

The government by contrast has no particular need or desire to avoid innacurate data, it doesn’t actually harm them. Their goal is not to hope that massive amounts of data collection will identify heretofore unknown criminals, it is to find any excuse to claim that a specific person is a criminal. If there is a crime, picking someone conveninent to parade in front of the media is just as good as picking the culprit. If there isn’t a crime, there is always someone who made an enemy of the government to make an example of.

Making the haystack bigger only hurts if your goal is to characterize the haystack. When you’re just looking for a needle, a magnet works on any amount of hay.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Subscribe to Our Newsletter

Get all our posts in your inbox with the Techdirt Daily Newsletter!

We don’t spam. Read our privacy policy for more info.

Ctrl-Alt-Speech

A weekly news podcast from
Mike Masnick & Ben Whitelaw

Subscribe now to Ctrl-Alt-Speech »
Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Loading...