Posts / privacy
Chat Control, Age Verification, and the Slow Boil of 'Just Trust Us'
There’s a post doing the rounds on r/privacy this morning with a headline that made me laugh out loud: “Turns out Brits would quite like their private messages to stay private.” Nearly a thousand upvotes, which tells you something about the appetite for stating the obvious. Apparently the UK government ran an ad campaign trying to soften people up for chat control style legislation, and the public response was roughly: no, get stuffed.
I don’t live in the UK. But this stuff never stays in one postcode. The EU has been circling its own version of chat control for years now, client-side scanning, message content checked before encryption even kicks in, all in the name of catching child abuse material. Which, to be clear, is a real and horrific problem that deserves a real response. The trouble is the proposed fix doesn’t just catch predators. It puts a permanent, silent auditor in every conversation, and once that infrastructure exists, the conversation about “who else gets to look” never actually ends. It just gets renegotiated every few years by whoever’s in government.
One thing that stuck with me from the comments was someone pointing out the pattern: frame it as protecting children, or stopping terrorism, or finding drugs in the post. It’s the same move every time, and it works often enough that governments keep reaching for it. I’m not cynical about the underlying problems, they’re genuine. I’m cynical about the solution always landing on “read everyone’s messages” rather than, say, properly funding the police units that already investigate this stuff with warrants and due process. We had that system. It worked reasonably well. It’s slower and less satisfying than a dashboard that flags keywords, but slower and more accountable is usually the better trade.
Here at home we’ve had our own entry in this genre. Online age verification for social media landed last year with the same “won’t somebody think of the children” energy, and now half of Reddit and Twitter apparently flicker in and out of demanding you prove your age depending on some mood only the algorithm understands. A few people in that thread were asking why it’s inconsistent, why it shows up for a month then vanishes then comes back. Nobody really knows. That’s the bit that gets me more than the policy itself: even the people implementing it can’t tell you clearly how it works or what it’s checking. My daughter got hit with an age gate on a completely unrelated app a few months back and had to scan her face to prove she was a teenager, which is a genuinely strange thing to watch happen to your kid over a mobile game.
I work in tech, DevOps mostly, and I spend a fair amount of my week thinking about what happens to data once a system exists to collect it. Not maliciously, just structurally: logs get kept longer than intended, access creeps, someone changes teams and the old rules don’t get enforced the same way. Systems built for one purpose get repurposed for another because the capability is just sitting there and it would be a shame to waste it. That’s not a conspiracy theory, it’s just how large organisations behave, government or private. Chat control isn’t dangerous because today’s government is evil. It’s dangerous because it removes the option for tomorrow’s government to not have the capability at all.
None of this means I think privacy absolutism is free of tension. I want serious crimes investigated. I want kids protected online. I use plenty of services that I know are hoovering up more of my data than I’d like, because the alternative is opting out of modern life, and I’m not ready to live in a cabin with a Nokia 3310, tempting as that sounds some weeks. I hold both of those things at once: genuine concern about real harms, and genuine discomfort with the tools being proposed to address them. I don’t think that tension resolves neatly, and I’m suspicious of anyone who tells you it does, on either side of this argument.
What actually gives me a bit of hope is that the public reaction, in the UK at least, wasn’t apathy. It was a clear, loud “no.” Governments do occasionally listen when the backlash is big enough and comes from ordinary people rather than just the EFF and a few noisy subreddits. Encryption fights have been won before on exactly that kind of pressure. So write to your local member if you’re the letter writing type, or just don’t stay quiet about it at the pub. It’s one of the few areas left where public opinion still visibly moves the needle, and that’s worth using while it lasts.