« Back to the Reclaiming the Internet Forum

End-To-End Encryption About To Be Bypassed?

With neural processors and software like Windows Recall and Apple's mediaanalysisd doing on-device scanning prior to encryption and after decryption, E2EE could soon become virtually useless:

https://www.youtube.com/watch?v=c52pKpYeZ74

https://www.youtube.com/watch?v=WTGY4kJRXu0

Even if sending messages or media from an old computer or phone with no NPU and free from such scanning software how do you ensure there isn't scanning on the recipient's side?  How do we stop or overcome this?


Report Topic

9 Replies

Sort Replies:

Reply by NosyCat

posted

I'd be more worried about the Chat Control directive, which attacks E2EE directly. Recall is an abomination too, but it's a lot easier to fight.


Permalink Report Reply

Reply by Virtual Insanity

posted

Hi NosyCat, thanks for jumping in.

I think I had heard of this chat control stuff before.  I don't really see that as a separate issue, client side scanning is a way to get around E2EE, chat control is a way to make that 'legal' and force it onto people.  One is a demand to do something and the other is a method to do it, they're joined at the hip.  Though it sounds like there would be other ways chat control would be implemented such as by modifying apps and web technologies to make them insecure and tattle on the user, not just OS level stuff.

I've read a couple of Patrick Breyer's articles now and watched an interview with him, he makes some great points.  I would have thought evidence collected in such a manner would not be admissible in court anyway.

For sure, the claimed usage will be the thin end of the wedge.


Permalink Report Reply

Reply by jojo

posted

saw a github repo showing how hackers can use the recall feature to spy on people not just microsoft.


Permalink Report Reply

Reply by Virtual Insanity

posted

Is that the Total Recall hack?

I really hope that Recall has pushed people who were thinking of jumping off of Windows to take the plunge.


Permalink Report Reply

Reply by Carboniferous

posted
updated

Hand-delivering messages seems like the only secure way in this day and age XD


Permalink Report Reply

Reply by Deafcake

posted
updated

LMAO, move to linux


Permalink Report Reply

Reply by Virtual Insanity

posted

Carboniferous - I was thinking almost the same thing; old fashioned letters.


Deafcake - I'm already on Linux, that doesn't fix the problem.  My system can be as clean as a whistle, if the person I'm sending a message or a file to has device scanning (like mediaanalysisd, Recall or whatever comes in the future) then E2EE is circumvented.  I have no control over what is running in the background on someone else's device and no way of knowing who's system is clean and who's is scanning and tattling.


Permalink Report Reply

Reply by KALLUM

posted

im gonna invest in a homing pigeon dude


Permalink Report Reply

Reply by Virtual Insanity

posted

I think a lot of people are asleep at the wheel on this.

I titled this thread "End-To-End Encryption About To Be Bypassed?", but it's not just messages, it's the broader scanning of everything on devices.  I can avoid scanning on my devices by using Linux or off-line computers, but the messaging side of the problem highlights how much of our privacy can be impacted by the practices (or ignorance) of others.


Permalink Report Reply