← Red Threads

The earlier encryption-policy route

The dated route reaches back before either 2024 report previously traced. A July2022 paper by Ian Levy and Crispin Robinson identifies their posts at the UK National Cyber Security Centre and GCHQ. The European Commission cited it in a public defence of its child-sexual-abuse proposal on 7August2022. eSafety cited it in an encryption position dated 13October2023. These are actual citations by public authorities, not merely institutional proximity.

The paper advocates technically possible client-side protections, but explicitly disclaims UK government policy or requirements and a complete security analysis (PDF10). Its discussion recognises coercion, database manipulation and mission creep; it reports no evidence for its considered charity-funding capture scenario (PDF41–42). It also points to REPHRAIN's separate Safety Tech Challenge Fund evaluation work (PDF6,56). That is not the later Toolbox award or proof of a common programme. Read cover, selected introduction/executive-summary pages, section6.1 and the opening of section8; no full technical validation claimed. Original arXiv PDF retained.

The Commission post is an archived policy argument dated 7August2022, not a legal-status determination. Its paragraphs naming Levy and Robinson use the paper to support possible detection within encrypted services. The current page attributes authorship to the Directorate-General for Communication; this investigation does not infer a named commissioner from first-person language. Original HTML retained.

The eSafety statement predates the 2024 DFC and SaferAI reports. PDF9–10 discusses client-side checks, secure enclaves, on-device detection and homomorphic techniques. It explicitly describes scalability and security concerns, with Levy/Robinson as the countervailing CSS citation. Its advertising-research references are not validation of an operational abuse-detection system. The date is printed on PDF11. This proves prior consideration; it does not prove how the later toolkit was drafted. Original retrieval timed out; the scoped web-reader observation is retained as a derivative, not a PDF capture.

WeProtect's January2024 submission to the Australian draft-standards consultation advocates client-side scanning, homomorphic encryption and secure enclaves while saying the technologies are nascent and require more testing (PDF4). Its disclaimer attributes the position to the Secretariat rather than necessarily to Alliance members (PDF10). Digital Rights Watch's opposing submission is dated 21December2023, despite the February2024 upload path. It disputes feasibility and privacy claims (PDF10–14). These are contrasting formal inputs, not proof either was adopted. Both scoped observations are derivatives after one original-retrieval timeout each.

The 2026 toolkit itself still includes general scale, latency and specialist-tool limitations in its common-barriers discussion (PDF11 / printed20–21). Consequently, we cannot claim all caveats disappeared. The specific homomorphic-encryption citation29 remains unresolved. A homomorphic-learning article in the same journal volume is only a title/topic match: no evidence identifies it as the intended citation, and no Ant Group influence node is earned. The earlier policy route is the stronger finding.

The next discriminating record is an actual reference-manager entry or tracked source substitution for citation29, together with comment dispositions connecting the 2023 statement or 2024 submissions to the later toolkit. Shared terminology alone does not establish that transmission.