Meta-Conclusion (2026-07-16)
After comprehensive analysis of the CSAR proposal — examining its legislative context, its impact on end-to-end encryption, the promises and limits of fully homomorphic encryption (FHE), zero-knowledge proofs (ZKP), alternatives to mass scanning, external encryption with shared keys, and the connections with Obscura, historical key escrow, mass surveillance and structural privacy — the following conclusions emerge from the intersection of all these perspectives.
Summary of Findings
| Document | Topic | Main Finding |
|---|---|---|
| Chat Control — Definition and context | Legislative context and status of CSAR | The proposal remains stalled in negotiation; the core problem is mathematical, not political |
| Encryption and surveillance | Why mass scanning breaks E2EE | There is no way to scan encrypted content without breaking encryption; any access mechanism is an attack surface |
| Homomorphic cryptography | Promises and limits of FHE | FHE does not scale to global messaging (10⁴-10⁷× gap); it does not prevent retrospective re-scanning or classifier expansion |
| Zero-knowledge proofs | ZKP and CSAM detection | ZKPs cannot detect uncatalogued material (the majority of CSAM); cannot run complex classifiers at scale |
| Alternatives to mass scanning | Technical and policy strategies | Viable alternatives exist (improved reporting, metadata, public upload, report threshold) that preserve E2EE, though none is perfect |
| External encryption and shared keys | User sovereignty | Technically sound for individuals, but does not scale as a systemic solution; the law would close the loophole and the user would be detectable as an "evader" |
| Chat Control + Obscura | The paradox of protection | The same defender-attacker asymmetry from fingerprinting replicates exactly in messaging: protecting yourself betrays that you protect yourself |
| Chat Control + Key Escrow | The historical pattern | All key escrow attempts (Clipper Chip, CALEA, UK IPA, Australia) have failed for the same reason: encryption does not distinguish between legitimate and illegitimate uses |
| Chat Control + Mass surveillance | The expansion pattern | No mass surveillance system has remained within its original limits; scanning infrastructure, once created, inevitably expands |
| Chat Control + Structural privacy | The sealed envelope problem | The content of an encrypted communication cannot be known without violating its privacy; the inspector paradox is ontological, not technical |
Key Findings
1. The structural impossibility of secure scanning
The most important finding, underlying all others, is that there is no technical solution that simultaneously meets security, precision, scalability and privacy for scanning encrypted communications. This impossibility is not technological in the sense of "we haven't invented it yet": it is structural. The properties of a secure encryption scheme imply that anyone who does not have the key cannot determine any function of the content.
| Approach | Allows scanning? | Preserves E2EE? | Scalable? |
|---|---|---|---|
| Client-Side Scanning (CSS) | Yes | No | Yes |
| FHE | No (impractical) | Yes | No |
| ZKP/PSI | Partial (hashes only) | Yes | No |
| External encryption | No | Yes | No (does not scale) |
| Metadata | No (signals only) | Yes | Yes |
No cell in this table is fully green. The combination the law demands does not exist.
2. Alternatives exist, but none is a silver bullet
The public debate presents the problem as a false dichotomy: either everything is scanned or nothing is detected. The research shows that multiple alternatives exist — strengthening reporting, metadata detection, public upload analysis, report threshold systems — that can detect a significant fraction of CSAM without breaking encryption. None achieves the coverage of mass scanning, but mass scanning is not perfect either (it has its own problems with false positives, evasion, and structural breach of encryption).
The correct question is not "which alternative detects as much CSAM as mass scanning?" but "which combination of alternatives maximizes detection subject to the constraint of preserving E2EE?"
3. The defender-attacker asymmetry is transversal
One of the most revealing discoveries of this research is that the same asymmetry documented in Obscura for browser fingerprinting replicates at every layer of the Chat Control problem:
| Domain | Defender | Attacker |
|---|---|---|
| Fingerprinting (Obscura) | Must normalize all signals | Only needs one inconsistency |
| External encryption | Must protect all messages | Only needs one high-entropy message |
| Key escrow | Must safeguard all keys | Only needs one leak |
| Surveillance expansion | Must maintain all limits | Only needs one crisis |
The structure is the same. The layer changes, not the asymmetry.
4. The historical pattern is unequivocal
The history of key escrow (Clipper Chip 1993, CALEA 1994, UK IPA 2016, Australia 2018) shows a recurring sequence that Chat Control repeats: a government identifies a threat, proposes an access mechanism, the technical community demonstrates it is unsafe, the government insists, the law is passed, companies refuse to implement it, and the law remains in legal limbo. Technology changes; the structure does not.
The most important lesson from this history is that every mass surveillance mechanism tends to expand until it occupies all available legal space. Not out of malice, but through incrementalism: each step of expansion is individually reasonable.
5. Privacy is a structural property, not a collection of tools
The conclusion that emerges from crossing all perspectives is that communications privacy is not a feature that can be added retroactively through scanning, classification or key escrow mechanisms. It is a structural property that requires:
- That content is only accessible to the endpoints (definition of E2EE)
- That the platform has no inspection capability (definition of encryption)
- That the user is not penalized for protecting themselves (condition of possibility for privacy)
Chat Control violates all three. Not because CSAM is not a real threat, but because the proposed approach destroys the structure that makes privacy possible for everyone.
Final Assessment
| Aspect | Verdict |
|---|---|
| Technical feasibility of secure scanning | Impossible — no scheme meets all four properties simultaneously |
| FHE as a solution | Inviable — performance gap of 10⁴-10⁷×; does not prevent expansion or re-scanning |
| ZKP as a solution | Insufficient — does not detect new material; cannot run complex classifiers |
| Alternatives without scanning | Viable — none perfect, but the combination offers significant detection |
| External encryption as individual defense | Sound — but does not scale and the user is detectable |
| Historical pattern | Unequivocal — Chat Control repeats the Clipper, CALEA, UK IPA sequence |
| Expansion risk | High — scanning infrastructure will inevitably expand |
| Obscura lessons | Applicable — the defender-attacker asymmetry is structural, not circumstantial |
| Legislative status (July 2026) | Deadlocked — the proposal remains unpassed; the technical impossibility persists |
Final Word
Chat Control represents the irresolvable tension between two legal interests that the CSAR proposal seeks to reconcile: child protection and communications privacy. After examining all perspectives — technical, historical, philosophical, political — the conclusion is that there is no technical solution that allows scanning encrypted content without breaking encryption. Not because technology is insufficient, but because the problem is ill-posed: you cannot know what is inside a sealed envelope without opening it, and an envelope that can be opened is not a sealed envelope.
The contribution of this research is not merely negative. By documenting the asymmetric structure shared by fingerprinting, key escrow, mass surveillance and communications encryption, it reveals a common pattern that transcends each particular case: privacy is not lost through a single mechanism, but through the convergence of multiple vectors that share a common asymmetric structure. Understanding this structure is the first step toward designing systems that resist it.
"Perfect privacy is impossible. Meaningful privacy is not."