Without a doubt, the European law known as Chat Control that is being imposed in the EU represents a very serious violation of the right to privacy, among other things. It is above all dangerous because of what it implies, the intentions behind it, and because it sets a legal precedent that goes against the very liberal democracy that the European institutions profess, turning the EU into an authoritarian democracy; with Chat Control, voting would cease to be anonymous and secret de facto, for example.
But the law is just a way of forcing companies that offer messaging services to store unencrypted messages so that the authorities can do with them as they please. Things that they probably already do in secret, which means they would now have the legal framework on their side. On a technical level, what they are asking for has two limitations:
-
If the service is not offered by a company, but is self‑managed or Free Software, it does not seem possible to impose the obligation to comply with the law.
-
Mathematics.
Let’s start with the second limitation. Even if corporations and states can see our messages, any classical cryptography method could already prevent them from reading our information without further ado: It is enough to establish a shared code between the sender and the receiver to substitute letters or words with anything. In short: we can bypass Chat Control using the Kama Sutra or the Enigma Machine, for example.
Even so, if the authorities are investigating a specific person, the obsolete classical techniques are not sufficient. Because they will use a counter‑algorithm to recover the messages. We must resort to the universality of mathematics, which is above any human law.
Asymmetric cryptography is a well‑known and popular technique, usually based on algorithms that work with prime numbers. Nowadays it is known that the only way to break this encryption method is through quantum computing, which in its current state still cannot manage to do so, and which arrives too late, because there are already algorithms that could not be broken even then. Using these algorithms is simple and within anyone’s reach.
Android applications like OpenKeychain make it possible to encrypt and decrypt messages that can be sent over insecure channels; the only thing the intermediary will see is meaningless random text. Classic email encryption with PGP, which is already integrated into Thunderbird or that can be used on any online service with Mailvelope, is just as secure, and Chat Control cannot, ironically, impose any control over its use. Even if all current encryption software were banned, any mediocre AI or mathematics student can create a new one in no time.
And so we arrive at the first limitation of this legislation. The software that anyone can make at home and share freely in a non‑commercial way is not regulated. Encrypted applications can endure just like WikiLeaks or The Pirate Bay. The algorithms are already invented and documented. And free protocols such as XMPP, Matrix or Meshtastic allow secure, federated, decentralized and freely usable communication, in such a way that no authoritarian regime can block them directly.
This leads us to suspect that Chat Control is only a formula to legitimise what companies like Meta or Apple probably already do in secret: store our unencrypted messages and hand them over to the authorities, or keep the keys to decrypt the content at their request. But this only works on one condition: that users continue to use these services as they do now, ignoring that every single one of their movements is already being monitored.
Nevertheless, it is not advisable to let our guard down: we must demand our rights and prevent Chat Control from becoming a reality, because it is not the only danger. The metadata of our communications is already compromised without this law, facial recognition is more and more entrenched, the police are increasingly pressuring us to obtain our DNA at police stations…