• @[email protected]
    link
    fedilink
    49
    edit-2
    1 year ago

    It’s literally in the article: They want to use client-side scanning. The client already has the data decrypted. This is much like what Apple wanted to introduce with CSAM scanning a while back. It’s a backdoor in each client and it’s a matter of time until it will be abused by malicious entities.

    • @[email protected]
      link
      fedilink
      131 year ago

      Yea, it is clear if there is just one closed-source app. But if we’re talking XMPP/Matrix - they have multiple open-source clients, even if some of them does introduce scanning, no way it wouldn’t be forked to remove it.

      • @[email protected]
        link
        fedilink
        71 year ago

        If a messaging service is non-compliant, the government could theoretically take action with court orders against domain owners, server owners or pursue anyone hosting a node in case of a distributed setup. In a worse case scenario, they might instruct ISPs via court orders to block these services (e.g. The Pirate Bay in some countries)

        • @[email protected]
          link
          fedilink
          71 year ago

          Yeah let’s have them block github. I kind of want to see a federated git hosting platform integrated with the fediverse

          • @[email protected]
            link
            fedilink
            English
            51 year ago

            They literally will do that. GDPR shows that they will go after big American companies (That’s the point, a huge chunk of this is protectionism to build a tech industry in the EU that they control)

        • @[email protected]
          link
          fedilink
          21 year ago

          Where I live, a lot of popular services, including major foreign social media and torrents everyone uses, are blocked - yet they still have a massive userbase.

          And since the scanning is supposed to be client-side, how would a server check if the scanning was really performed? What if the server does receive and log the needed responses, just to be safe, but the client actually just sends them automatically while lacking such functionality?