Site navigation

Encryption Targeted Over Spread of Child Sexual Abuse Imagery

Elizabeth Greenberg

,

encryption CSAM
Yet again, end-to-end encryption is being called out for enabling the spread of child sexual abuse material. But privacy and safety remain at a standstill. 

A child protection advocacy group is calling on Meta to do more to prevent the spread of child sexual abuse material across the messaging platform WhatsApp.

WhatsApp’s end-to-end encryption messaging service has faced hot water by child protection groups before as their encryption methods make it impossible for the company itself or others to see or block criminal files being shared.

The platform, owned by Meta, is where disgraced BBC journalists Huw Edwards was sent illicit material, including category A imagery of children as young as seven, which is the most extreme category of child sexual abuse imagery.

Following this, safeguarding minister Jess Phillips has joined child protection charities and the National Crime Agency in calling on Meta to do more to stop images and videos of child sexual abuse from being shared on its platforms.

Meta contends that current methods of detecting and blocking child sexual abuse material (CSAM) are incompatible with end-to-end encryption, which the company says it uses to help keep people safe.

The continual debate around the need for end-to-end encryption, which protects private messages from being viewed by outsiders, companies, and governments, and the potential harm of the technology, is tricky to navigate from a security and safety perspective.

End-to-end encryption was a continual topic for controversy when the Online Safety Act was moving through Parliament, as MPs argued for its effectiveness in terms of privacy, while others pointed to how this very same privacy enables the sharing of illicit material.

As we see continual coverage highlighting the commonality of CSAM, child protection groups and government appear to be at a loss for what to do, and for what big tech companies are doing to prevent its spread across their platforms.

“I’d like to ask this question. How is Meta going to prevent this from happening again? What is stopping those images being shared again on that service today, tomorrow, and the next day?” Dan Sexton, chief technology officer a the Internet Watch Foundation said.

“We should not be seeing this in the news time and time again. It is a solvable problem.

“There are tried, trusted, and effective methods to detect images and videos of child sexual abuse and prevent them from being shared in the first place. But in WhatsApp, these safeguards are effectively switched off, with no alternative measures in place.

“This was a technology-enabled crime against children and I think this is where we need to see change.

How this change occurs, however, leaves even more questions. This was a point of major contention during Online Safety Act debates, as tech companies contended, and still contend, that there is no way to scan messages for illegal activities without compromising user safety.


Recommended


In a proposal to first scan messages for illegal content before encrypting them, many tech companies, including WhatsApp and Signal, informed the government that currently, no such technology exists, and doing so would completely derail the point of end-to-end encryption.

Further, WhatsApp and Signal both threatened to leave the UK market if the plan went ahead, saying that the proposal would go against a human rights to privacy.

On the other hand, end-to-end encryption does offer a safe harbour to criminal activities such as grooming, selling of illegal substances, and the sharing of illicit images, including CSAM.

While it is of course reasonable and often demanded that government officials take a hard line when it comes to CSAM – as Phillips said, “UK law is crystal clear,” implementing technology on the sharing end of CSAM is not so black and white.

“Technology exists to detect and prevent the abhorrent abuse of thousands of children and ensure victims are given privacy by stopping the repeated sharing and viewing of images and videos of their abuse,” the safeguarding minister said.

“Social media companies must act and implement robust detection measures to prevent their platforms being safe spaces for criminals.”

But how they act is not so simple. And more messaging services are moving towards enabling end-to-end encryption, much to the concern of child protection advocates. Meta added end-to-end encryption to its Messenger service, for instance.

Privacy experts are in favour of encryption, saying it prevents companies and governments from accessing people’s private correspondence, preventing surveillance. Child protection experts say end-to-end encryption is making their jobs harder, and enabling an easy avenue for criminals to share and spread child sexual abuse imagery, and often providing a lane for them to procure illicit images from children through grooming as well.

These two groups, while not necessary against the other in principle, are at a standstill when it comes to end-to-end encryption.

Currently, there are no effective methods to scan messages for illicit content while ensuring privacy – advocates argue that opening up this door could lead to surveillance, arrests of other non-connected crimes, and an overall invasion of privacy.

While this argument could be deemed a slippery slope, it is not ultimately unrealistic. Recently, UK police were able to gain a warrant to access and un-encrypt and entire server of an encrypted messaging service claiming it was only used by criminals – they are now facing scrutiny from UK citizens whose messages were accessed as part of the raid despite them not using the service for criminal activities.

This case also left a scary precedent, potentially enabling police to carry out mass warrants on encrypted messaging services if they decide enough criminal activity is being carried out on the service.

And still, end-to-end encryption is allowing criminals to proliferate CSAM online across platforms, evading law enforcement and detection efforts.

“It is fundamentally not acceptable for technology companies, with the resources they have at their disposal, to consciously step away from preventing the distribution of indecent images of children across their platforms,” Rick Jones, the acting director of intelligence at the National Crime Agency, contended.

“Technology is available to identify these images, but most companies are choosing to design their platforms in a way that does not allow it to be used either at all, or to its full effectiveness.

“When end-to-end encryption (E2EE) is used, technology companies cannot protect their customers, millions of whom are children, as they simply cannot see illegal behaviour on their own systems.”

Elizabeth Greenberg

Staff Writer

Latest News

AI Climate Energy

AI Net Climate Impact Could Be More Negative Than We Thought

AI Cybersecurity Funding Security

Cognition Eyes £40bn Valuation as OpenAI Unveils GPT-5.6-Cyber

AI

AI IaaS Spending to Surge 96% in 2026, Gartner Says

AI Editor's Picks

Anthropic’s Claude Introduces AI Watermark to Text