Mullvad argues that mass surveillance is no longer just an authoritarian-regime story but a competition between democracies, citing concrete legislation: EU Chat Control, UK Online Safety Act Section 122, France's Article 8ter, and Sweden's FRA law. They contend these aren't isolated overreaches — each law normalizes the next, with 'we already do this in the UK' becoming the justification for similar measures in Berlin or Paris.
By submitting the Mullvad post with the framing-forward title 'Countries are competing to see which can carry out mass surveillance the best,' the submitter endorses the competitive-ratchet thesis. The 256-point score suggests the HN audience found the framing resonant with the pattern of legislation they've been tracking.
The editorial identifies a technical through-line buried in the policy debate: because server-side interception fails against E2EE by design, every major proposal — Chat Control's CSAM hash matching, the UK's 'accredited technology notices,' Apple's withdrawn 2021 NeuralHash plan — converges on scanning content on the user's device before encryption. This makes client-side scanning, not backdoored servers, the actual battleground.
The editorial explicitly flags that Mullvad sells privacy as a product and is therefore not a neutral observer, but verifies that the legislative citations check out: the UK Online Safety Act passed October 2023, France's Article 8ter cleared June 2023, Sweden expanded FRA powers in 2024, and the EU has re-tabled Chat Control roughly every six months since 2022. The chronology, even from a biased source, is uncomfortable on its own merits.
Mullvad — the Swedish VPN company that famously refuses to know who its customers are — published a long-form policy piece arguing that mass surveillance has stopped being a story about authoritarian regimes and become a story about democracies competing with each other. The post catalogs concrete legislation: the EU's Chat Control proposal (CSA Regulation) mandating client-side scanning of private messages, the UK's Online Safety Act and its Section 122 powers to compel platforms to break E2EE, France's Article 8ter allowing law enforcement to silently activate cameras and microphones on suspects' devices, and Sweden's FRA law authorizing bulk interception of all cross-border cable traffic.
The framing is the part that's getting traction on Hacker News (256 points): these aren't isolated overreaches. They're a competitive ratchet, where each new law gives the next government cover to go further, and "we already do this in the UK" becomes the justification for doing it in Berlin. The post lands at a moment when the Council of the EU is again attempting to push Chat Control through under the Danish presidency, after the Belgian and Hungarian presidencies failed to assemble a qualified majority.
Mullvad is not a neutral observer — they sell privacy as a product — but the legislative citations are accurate, and the chronology is uncomfortable. The UK passed the Online Safety Act in October 2023. France's Article 8ter cleared in June 2023. Sweden expanded FRA powers in 2024. The EU has been re-tabling Chat Control roughly every six months since 2022.
The interesting technical claim buried in the policy argument is that client-side scanning is becoming the convergent architecture. Server-side interception doesn't work against E2EE by design, so every one of these proposals — Chat Control's CSAM hash matching, the UK's "accredited technology notices," Apple's withdrawn 2021 NeuralHash plan — ends up at the same place: scan the plaintext on the device before it's encrypted, then report matches upstream. Once that primitive exists on a billion phones, the policy fight is no longer about whether scanning happens, but about what the scan list contains — and the scan list is necessarily secret.
The cryptography community has been unusually unified on this. The October 2023 open letter signed by 300+ researchers (Bellare, Bernstein, Green, Schneier, Rivest) argued that client-side scanning "creates serious security and privacy risks for all society while the assistance it can provide for law enforcement is at best problematic." The EU's own legal service issued an opinion in April 2023 that the original Chat Control proposal likely violated Article 7 and 8 of the Charter of Fundamental Rights. Neither has stopped the legislation from being re-tabled.
The Mullvad piece's strongest move is refusing to grade on a curve. China and Russia are not in this list because they're not competing on the same axis — they already won that race domestically. The competition Mullvad describes is among countries that still ostensibly have rule-of-law constraints, judicial review, and elections, and that's exactly what makes the trajectory worth tracking. Authoritarian surveillance is a constant; democratic surveillance is the variable.
There's a real disagreement worth surfacing here. The European Commission's argument is that the scanning is narrowly targeted (CSAM, then terrorism, then organized crime), supervised by a new EU Centre, and that not scanning is itself a policy choice with victims. That argument isn't crazy. The counter-argument, which Mullvad makes implicitly, is that the technical primitive doesn't care about its policy wrapper — once shipped, it can scan for anything a future government adds to the list, and the half-life of "narrowly targeted" surveillance powers is historically short.
If you ship anything that touches end-to-end encryption — Signal Protocol implementations, WebRTC with SFrame, password managers, encrypted backup, even client-side encryption for cloud storage — the threat model has shifted. The adversary you need to plan for in 2027 is not a state-sponsored attacker; it's a lawful intercept order from your own jurisdiction telling you to ship a client update with a scan hook. Signal's Meredith Whittaker has been explicit that Signal will withdraw from the UK rather than comply with a Section 122 notice. Threema and Tutanota have made similar statements about Chat Control. Most companies will not.
Practically: if you're building developer tools, this affects key-distribution architecture. Forward secrecy and post-compromise security are necessary but no longer sufficient — neither protects against an attacker who can mandate code changes on the endpoint. The defenses that actually matter are reproducible builds (so a backdoored client is detectable), binary transparency logs (so the build you ship is the build users get), and jurisdictional architecture (so no single legal order can compromise the whole user base). Signal's recent work on "sealed sender" and Apple's Advanced Data Protection are pointing in the right direction; most of the ecosystem is not.
For anyone running infrastructure in the EU or UK, the legal exposure window is real and short. The EU's CSA Regulation has been re-tabled for the Danish presidency in late 2026, with reported support from Germany's new coalition. The UK's Ofcom has been quietly drafting accredited technology guidance under Section 122 since early 2025. Plan now for the engineering and legal questions of how you'd respond to a compelled-scanning order, because the lead time on "we'll just leave" is longer than the lead time on the order.
The Mullvad post is advocacy, but the underlying observation is right: surveillance policy in Europe is being made through a ratchet, where each country watches what its neighbors get away with and matches. The technical community's job isn't to win the policy fight — that's lobbyists and the EFF and EDRi. The job is to make the engineering of compliance expensive enough, and the engineering of resistance cheap enough, that the policy fight is fought on honest ground. Reproducible builds, binary transparency, and clear jurisdictional separation aren't political — they're just good engineering that happens to make backdoors visible. Ship them anyway.
Spoiler alert : Singapore won the race years ago. Cameras everywhere, and mostly : the singaporian civilian population is educated to surveil peers so that they don't commit incivilities. Here is an article about it : https://gcctvms.com/smart-city-surveillance-singapore-camera..
reddit started asking KYC yesterday.You (and me) can bitch all you want, but reddit has well prepared for us whining and being sad will change nothing.Mark my words: KYC will be required on HN in about two years. Not because dang will want it, but because that's the direction the world is going
VPNs are great and all but many that are well advertised here in North America are a huge source of attacks, abuse, etc. so it’s pretty desirable just to block them. They sometimes have agreements with residential ISPs to get around the bans.
Governments are casting a wide a net but it all seems aimed at a foreign influence and espionage Cold War going on. The thought of using this for crime in most countries is tertiary and the real reasons for implementing these systems are so embarrassing to their respective governments that they will
Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.
The internet, as it was before the one-way ratchet started to close, feels more and more like a lightning in a bottle that nobody in power wants repeating ever again. Everything in the past couple years has been going towards the centralization into a small number of services, walled wastelands that