Client-side scanning: how it defeats encryption
On-device scanning does not touch the encryption, it reaches in before it. Why that is the real heart of chat control, calmly explained.
One clunky term keeps coming up in the chat control debate: client-side scanning. It sounds like a specialist detail, but it is the heart of the dispute. Stay calm, it can be explained. And it matters, because this one point decides whether end-to-end encryption still means anything.
What client-side scanning actually is
The "client" is the device in your hand. So client-side scanning means this: it is not the server that searches your messages, your own device does it. And it does so at exactly the moment when the message is still in plaintext, that is, before it gets encrypted and sent. If the software reports a hit, the finding leaves your device.
Technically this usually runs on a perceptual hash. A short fingerprint is calculated from an image, one that still matches even if the image was altered slightly. That fingerprint is checked against a list of known fingerprints. Apple presented exactly such a system in 2021, it was called NeuralHash.
The fallacy: the encryption stays intact, the protection does not
Supporters like to say: we are not touching the encryption at all. And that is even true. The access simply happens before it. The maths remains sound, the confidentiality does not.
In 2021, fourteen well-known cryptographers and security researchers published a paper on this, "Bugs in our Pockets", among them Whitfield Diffie, Ronald Rivest, Bruce Schneier and Ross Anderson. In 2024 it appeared peer-reviewed in the Journal of Cybersecurity. Their verdict: "CSS neither guarantees efficacious crime prevention nor prevents surveillance." And further: while communications can be encrypted, users' data is still "searched and scrutinized in ways that cannot be predicted or audited by the users".
Four objections that keep coming back
- It can be evaded. An image can be altered so minimally that no human sees a difference, yet the fingerprint no longer matches. The research group around Lukas Struppek demonstrated this on NeuralHash: hits can be forced or prevented with small targeted changes, and sometimes plain standard transformations such as rotating, cropping or a contrast change are enough. Anyone who really has something to hide encrypts it separately beforehand anyway.
- It hits the innocent. The same trick works in the other direction. A perfectly harmless image can be prepared so that it triggers a hit. The researchers name it plainly: innocent users can be framed this way.
- It invites scope creep. A capability, once built, does not stay with its first purpose. "Once capabilities are built, reasons will be found to make use of them", the fourteen experts write. Abuse material today, copyright tomorrow, political symbols the day after. You never get to see the list your device checks against.
- It enlarges the attack surface. Your device would then run software that works against your interests in the background. Whoever takes it over no longer has to break the encryption. They already sit where the plaintext is.
Apple built it, then shut it down
The strongest evidence does not come from activists. Apple announced NeuralHash in 2021 and abandoned it in December 2022. In 2023, Erik Neuenschwander, Apple's director of user privacy and child safety, explained the decision in detail. The company concluded it was "not practically possible to implement without ultimately imperiling the security and privacy of our users". Scanning "every user's privately stored iCloud data would create new threat vectors for data thieves to find and exploit". And the sentence this article is about: "Scanning for one type of content, for instance, opens the door for bulk surveillance."
The Struppek group independently reached the same conclusion: perceptual hashing in its current form is "generally not ready for robust client-side scanning".
Where the EU currently stands
The long version is in the chat control article. On 9 July 2026 the European Parliament only extended the voluntary rule. It covers unencrypted content, encrypted messengers are explicitly exempt, and mandatory on-device scanning is not part of it.
The big one is the CSA regulation, and negotiations on it continue. According to internal documents, the institutions have provisionally agreed to exempt encrypted content, which should take client-side scanning out of the text. I would not rely on that: this is precisely the question the negotiations hinge on, and provisional means provisional.
What this means for PriChat, honestly
With us, encryption happens in the browser. The key is derived from your password when you log in and lives only in memory; if you use the passkey login, the same key is unlocked with your passkey instead. Of your messages, our server only ever sees ciphertext. We do not search them, and we have built nothing that could. To be honest about the rest, because it belongs here: not everything with us is encrypted. Group names, group pictures, profile pictures and status texts do sit in our database in plaintext, and a support request to us is by its nature not an end-to-end encrypted message. Message content always is.
That does not change the underlying situation, though, so I would rather say it myself: client-side scanning targets the one place we cannot encrypt away, namely your device and our app. Our app is not open source and has not been independently audited. You cannot verify that there is no scanner inside it, you have to take our word for it. With Signal you could read the source code. That is a genuine advantage for Signal, and it would be dishonest to pretend otherwise. What I can promise: we will not build such a thing voluntarily. And if a law ever forces us to, you will read it here before you notice it.
Encryption protects the journey. Client-side scanning starts at the beginning of the journey, in your hand. That is why making the encryption stronger does not help: it was never the target of the attack.
In short
Client-side scanning has your own device search your messages before they are encrypted. The encryption stays formally untouched and practically pointless. It is evadable for those who want to hide something, and dangerous for everyone else. Fourteen leading cryptographers wrote exactly that, and Apple switched off its own system for the same reasons.
Sources
- Abelson u. a. · Bugs in our Pockets (Journal of Cybersecurity, 27.01.2024)
- Abelson u. a. · Preprint (arXiv, 14.10.2021)
- Struppek u. a. · Learning to Break Deep Perceptual Hashing (ACM FAccT 2022)
- AppleInsider · 31.08.2023 (Stellungnahme Erik Neuenschwander)
- netzpolitik.org · 12.06.2026
- netzpolitik.org · 09.07.2026