Matthew Green argues — perhaps somewhat counter-intuitively — that as AI becomes better at finding vulnerabilities in software, the digital systems and services we use will become much more secure. So secure in fact, that they will become next to impossible to hack. As a result, law enforcement (and intelligence services) loose ‘lawful hacking’ as the only currently available method to get access to encrypted data stored on phones, or to listen in on encrypted communications. According to Green, everything is about to “go dark”. Is it? And does it matter?
At the CPFP conference last week I learned that the European Commission wants to impose interoperability requirements on Android, to allow third party AI services the same unrestricted access to an Android smartphone as Google’s own Gemini AI agent has. This is a bad idea.
Age assurance (reliably estimating or securely verifying someones age) has become an important – and controversial – topic recently. With rising concerns over the safety and well being of children online, it has been advocated as a possible tool to restrict access to certain content for minors. The underlying argument being that we also more or less successfully limit children’s access to certain content (porn, violence) and products (alcohol, cigarettes) in the physical world. Yet online age assurance raises thorny questions. And privacy is not one of them, really.
Bij een op de drie deurcamera’s die de openbare weg filmen en zijn aangemeld bij een speciaal politieregister staan de beelden langer opgeslagen dan “strikt noodzakelijk”. Maar er is meer aan de hand.
The Privacy Enhancing Technologies Symposium is considering an update to its policy regarding the use of (generative) AI. I have some problems with it.