Mass surveillance and censorship are escalating in many countries right now. There is a global attack on secure encrypted communication. Often, authorities, politicians, and tech companies work together to push for new laws. One example: when Ashton Kutcher (yes, the actor), through his tech company Thorn, tried to introduce total surveillance of all EU citizens through undemocratic and corrupt methods.
First, Ashton Kutcher convinced the EU Commission that they could scan everything on an EU citizen’s phone or computer (messages, photos, emails, phone calls, all of it) for child sexual abuse material without, at the same time, looking at the content of other types of communication.
And then?
And then EU Commissioner Ylva Johansson presented the legislative proposal called Chat Control, which aimed to scan everything on all EU citizens' phones and computers (including conversations in end-to-end-encrypted messaging services). The message from the Commission was: we will only search for child sexual abuse material (CSAM).
And then?
And then experts from all over the world explained to her that the kind of scanning she was talking about (as Ylva described it: a drug-sniffing dog that can detect illegal content in a message without reading the message) simply cannot be done safely, and that Chat Control would mean the end of privacy and pose a security threat to all Europeans. Ylva responded with: “what about the children?”
And then?
And then it was revealed that Thorn, the organization founded by Ashton Kutcher and which had been lobbying for Chat Control from the beginning, was selling the kind of scanning technology that could be used for Chat Control – despite being registered as a charity organization in the EU’s lobbying registry.
And then?
And then it was revealed that Thorn, together with the EU Commission, had also started and funded “children’s rights organizations” that had supported the proposal. What appeared publicly to be charitable organizations were in fact lobby groups.
And then?
And then it was revealed that Europol wanted unlimited access and wanted to use the scanning for more than just child abuse crimes, saying that all data – also unfiltered and innocent material – should be stored because it “could at some point be useful to law enforcement”.
And then?
And then it was revealed that employees at Europol had joined Thorn, to lobby their old colleagues.
And then?
And then politicians in Brussels wanted to exempt themselves from the scanning.
And then?
And then the European Parliament, in an almost historic consensus, voted against the proposal and called Chat Control nothing but mass surveillance. As one of the members of the parliament said: “The Commission wasn’t focusing on protecting children but wanted mass surveillance.”
And then?
And then The Council of the EU (law proposals must go through both the Parliament and the Council), after three years of negotiation, finally reached a common position on Chat Control. The requirement for mandatory scanning (including end-to-end encrypted messaging services) was removed, which is a major victory, but several problematic elements remain in the Council's position. For instance, the Council wants to demand ID Control to use messaging services (including end-to-end encrypted).
And then?
And then, in 2026 the final negotiations began, between the European Commission, the European Parliament, and the Council of the EU. At the same time, the European Commission is working on a Plan B, through the initiative Going Dark/ProtectEU, where they once again try to force total surveillance (this time organized crime is the excuse) on the citizens of the EU.
And then?
https://t.co/2uxBeeNr3p
Right now there are a lot of new eyes on Signal, and not all of them are familiar with secure messaging and its nuances. Which means there’s misinfo flying around that might drive people away from Signal and private communications.
One piece of misinfo we need to address is the claim that there are ‘vulnerabilities’ in Signal. This isn’t accurate. Reporting on a Pentagon advisory memo appears to be at the heart of the misunderstanding: https://t.co/QfWgOxHAzp. The memo used the term ‘vulnerability’ in relation to Signal—but it had nothing to do with Signal’s core tech. It was warning against phishing scams targeting Signal users.
Phishing isn’t new, and it’s not a flaw in our encryption or any of Signal’s underlying technology. Phishing attacks are a constant threat for popular apps and websites.
In order to help protect people from falling victim to sophisticated phishing attacks, Signal introduced new user flows and in-app warnings. This work has been completed for some time and is unrelated to any current events. If you’re interested in learning more, this WIRED article from February 19th (over a month ago) goes into more detail:
https://t.co/xvVVdPDhSs
Signal is open source, so our code is regularly scrutinized in addition to regular formal audits. We also constantly monitor [email protected] for any new reports, and we act on them with quickness while also working to protect the people who rely on us from outside threats like phishing with warnings and safeguards.
This is why Signal remains the gold standard for private, secure communications.
I wouldn’t say that Will and I are battling but I do disagree. Because there are big differences between Signal and WhatsApp.
Signal is the gold standard in private comms. We’re open source, nonprofit, and we develop and apply e2ee and privacy preserving tech across our system to protect metadata and message contents. Check out <signal dot org slash bigbrother> to see just how little data we are able to provide in response to the subpoenas we’re not able to resist.
Now, WhatsApp licenses Signal’s cryptography to protect message contents for consumer WhatsApp. Not on WhatsApp for business. Neither consumer nor business WhatsApp protects intimate metadata—like contact list, who’s messaging whom, when, profile photo, etc. And, when compelled, like all companies that collect the data to begin with, they turn this important, revealing data over.
Don’t misunderstand—we love that WhatsApp uses our tech to raise the privacy bar of their app. Part of Signal’s mission is to set, and encourage the tech ecosystem to meet, this high privacy bar.
But these are key differences when it comes to meaningful privacy and the public deserves to understand them, given the stakes. Not have them clouded in marketing.
In 2010, Aaron Swartz downloaded 70GBs of articles from JSTOR. He faced $1 million fine and 35 years in jail. He took his life in 2013.
Meta illegaly downloaded 80+ terabytes of books from LibGen, Anna's Archive, and Z-library to train their AI models without any punishment.
The Swedish and French governments are following in the footsteps of the FBI and want to demand backdoors in end-to-end encrypted messaging services like @signalapp as @mer__edith said in the Swedish news:
"There is no such thing as a backdoor that only the good guys can access.”
The reason it’s not getting more coverage is that remedying the conditions that led to this, which we’ve been warning about for years, would require unwinding dangerous x surveillant norms the current tech industry relies on.
Coverage or no, the find out era has arrived and a fix is urgently needed, however painful.
PSA: we've addressed this rumor repeatedly. Tldr there is no evidence of a vulnerability in Signal, and our code is open source.
No report of this issue was ever made to [email protected], and no CVE was filed. There is no truth to the assertion that a phone number enables access to a Signal account.
Taken at face value, what's being described is most likely an issue at the device level, via spyware or direct access to Carlson's phone. NOT an issue with Signal.
Please take care with these kinds of rumors. They can lead people who require privacy in high stakes situations to choose less secure alternatives when it matters, and thus do harm.
Case in point: there's no way to build a backdoor that only the "good guys" can use.
When the entire technical community says that the EU's ChatControl legislation + similar pose serious cybersecurity threats, we're not exaggerating for effect.
Exploring the Carlsten Fortress in Marstrand 📷
A lot of climbing through dark corridors and up long staircases was involved.
The view from the top was amazing, but the tornado winds were less amazing. Can definitely recommend though 👍
#Carlsten#Sweden#Marstrand#castle
Staycation with the family in Falkenberg 😎
We rented a really nice house for a few days so we could properly explore the whole area. Everything from big rocks and long beaches to good food and not as good shopping malls.
Can definitely recommend a visit 👌
#Falkenberg#Sweden
📣Official statement: the new EU chat controls proposal for mass scanning is the same old surveillance with new branding.
Whether you call it a backdoor, a front door, or “upload moderation” it undermines encryption & creates significant vulnerabilities
https://t.co/g0xNNKqquA
Swedish police laughably claiming "only criminals use" Signal. And every journo, human rights worker, dissident, military, CEO...
Still shocked by how baldly law enforcement will lie in pursuit of eroding the human right to privacy.