In a free society, people should not have their private correspondence constantly examined. U.S. lawmakers, we would hope, understand that individuals have the right to a private conversation without the government looking over their shoulder.Ā
So itās dismaying to see a group of U.S. Senators attempting for a third time to passĀ the EARN IT ActĀ (S. 1207)āa law that could lead to suspicionless scans of every online message, photo, and hosted file. In the name of fighting crime, the EARN IT Act treats all internet users like we should be in a permanent criminal lineup, under suspicion for child abuse.Ā
Protect Our PrivacyāStop “EARN IT”
What The New āEARN ITā Does
The EARN IT Act creates an unelected government commission, stacks it with law enforcement personnel, and then tasks it with creating ābest practicesā for running an internet website or app. The act then removes nearly 30-year-old legal protections for users and website owners, allowing state legislatures to encourage civil lawsuits and prosecutions against those who donāt follow the governmentās ābest practices.āĀ
As long as they somehow tie changes in law to child sexual abuse, state lawmakers will be able to avoid longstanding legal protections, and pass new rules that allow for criminal prosecutions and civil lawsuits against websites that donāt give police special access to user messages and photos. Websites and apps that use end-to-end encryption to protect user privacy will be pressured to remove or compromise the security of their services, or theyāll face prosecutions and lawsuits.Ā
If EARN IT passes, weāre likely to see state lawmakers step in and mandate scanning of messages and other files similar to the plan that AppleĀ wisely walked away fromĀ last year.Ā
Thereās no doubt the sponsors intend this bill to scan user messages, photos, and files, and they wrote it with that goal in mind. They even suggested specific scanning software that could be used on users in aĀ documentĀ published last year. The bill also makes specific allowances to allow the use of encryption to constitute evidence in court against service providers.Ā
Bill Language Purporting To Protect Encryption Doesnāt Do The Job
Under pressure, the bill sponsors did add language that purports to protect encryption. But once you take a closer look, itās a shell game. The bill clearly leaves room to impose forms of āclient-side scanning,ā which is a method of violating user privacy by sending data to law enforcement straight from user devices, before a message is encrypted. EFF has long held thatĀ client-side scanning violates the privacy promise of end-to-end encryption, even though it allows the encryption process to proceed in a narrow, limited sense. A 2021 paper by 10 leading technologists held that client-side scanners are a danger to democracy, amounting to ābugs in our pockets.āĀ
The Chat-Scanning Software Being Pushed By This Bill Doesnāt Work
But the available evidence shows that scanning software that looks for Child Sexual Abuse Material, or CSAM, is far from perfect. Creators of scanning software say they canāt be fully audited, for legal and ethical reasons. But hereās the evidence so far:Ā
- Last year, a New York TimesĀ storyĀ showed how Googleās CSAM scannersĀ falsely accused two fathers of sending child pornography. Even after the dads were explicitly cleared by police, Google kept their accounts shut down.Ā
- Data being sent to cops by the U.S. National Center for Missing and Exploited Children (NCMEC)āthe government agency that will be tasked with analyzing vastly more user data if EARN IT passesāis far from accurate. In 2020, the Irish police received 4,192 reports from NCMEC. Of those,Ā only 852 (20.3%) were confirmed as actual CSAM. Only 9.7% of the reports were deemed to be āactionable.āĀ
- A Facebook study found thatĀ 75% of the messages flagged by its scanning systemĀ to detect child abuse material were not āmalicious,ā and included messages like bad jokes and memes.Ā
- LinkedIn reported 75 cases of suspected CSAM to EU authorities in 2021. After manual review,Ā only 31 of those casesāabout 41%āinvolved confirmed CSAM.
The idea of subjecting millions of people to false accusations of child abuse is horrific. NCMEC will export those false accusations to vulnerable communities around the world, where they can be wielded by police forces that have even less accountability than law enforcement in the United States. False accusations are a price that EARN IT supporters seem willing to pay.Ā
We need your support to stop the EARN IT Act one more time.Ā Digital rights supporters sent more than 200,000 messages to Congress to kill earlier versions of this bill. Weāve beaten it twice before, and we can do it again.
There are currently dangerous proposals that could mandate client-side scanning schemes in theĀ U.K.Ā andĀ European Union, as well. But we donāt need to resign ourselves to a world of constant surveillance. In democratic nations, supporters of a free, secure, and private internet can wināif we speak up now.Ā
Protect Encrypted MessagingāStop “EARN IT”
ZNetwork is funded solely through the generosity of its readers.
Donate