Technologies and Technical Measures to Address Online Harms – WS 03 2026

From EuroDIG Wiki
Jump to navigation Jump to search

27 May 2026 | 11:30 - 12:30 CEST | LORD JENKINS | Video recording | Transcript
Consolidated programme 2026

Proposals: #24, #44

You are invited to become a member of the Session Org Team by simply subscribing to the mailing list. By doing so, you agree that your name and affiliation will be published at the relevant session wiki page. Please reply to the email send to you to confirm your subscription.

Kindly note that it may take a while until the Org Team is formed and starts working.

Check the discussion tab and the mailing list archive for information on the development of the session.

Session teaser

This session will bring in a critical discussion on the do’s and don’ts of using technical measures to mitigate online scams and how to address online harms without breaking the Internet. It will bring together technical operators, policymakers and Internet governance experts to examine:

  • The real-world impact of DNS and IP blocking on Internet integrity
  • The security implications of interfering with DNS, including DNSSEC deployment
  • The effectiveness and limits of existing anti-spoofing and authentication technologies
  • Approaches that target harms at their source rather than distorting core infrastructure

Session description

Always use your own words to describe the session. If you decide to quote the words of an external source, give them the due respect and acknowledgement by specifying the source.

Format

Following EuroDIG technical workshop tradition, the session will have a short presentation by the key participants (10 min), followed by interactive Q&A with the audience.

Further reading

(content is offered in no particular order)

People

Programme Committee members

  • Filip Lukáš, Policy Advisor at CENTR, Belgium (Rapporteur for this session)
  • Nicolas Zahn, Senior Engagement Manager at ELCA Advisory, Managing Director of f0t1 GmbH and the association Swiss Internet & Digital Governance, Switzerland
  • Regina Filipová Fuchsová, Industry Relations Manager at EURid, Czechia

The Programme Committee (PC) supports the programme planning process throughout the year and works closely with the Secretariat. Members of the PC give advice on the topics, cluster the proposals and assist session organisers in their work. They also ensure that session principles are followed and monitor the complete programme to avoid repetition. 1-2 PC members have signed up to each session and will compile the messages.


Co Focal Points (also session moderators)

Focal Points take over the responsibility and lead of the session organisation. They work in close cooperation with the Programme Committee and the EuroDIG Secretariat and are kindly requested to follow EuroDIG's session principles


Organising Team (Org Team)

(listed by sign up order)

The Org Team is a group of people shaping the session. Org Teams are open and every interested individual can become a member by subscribing to the mailing list.


Key Participants

Key Participants are experts willing to provide their knowledge during a session – not necessarily on stage. Key Participants should contribute to the session planning process and keep statements short and punchy during the session. They will be selected and assigned by the Org Team, ensuring a stakeholder balanced dialogue also considering gender and geographical balance. Please provide short CV’s of the Key Participants involved in your session at the Wiki or link to another source.


Remote Moderators

Messages

Rapporteur: Filip Lukáš, CENTR

  1. The ever-evolving nature of online harms requires a multistakeholder collaboration to be tackled effectively. This may take the form of collaboration among industry players, or cross-industry and the government.
  2. Intervention on the technical layer by blocking the IP addresses or DNS have significant impact on the availability of online resources, like websites, and cause unnecessary collateral damage without necessarily addressing the illegal content in question.
  3. Interventions on illegal content to increase online safety should be proportionate so that the rights of individuals are respected.

Video record

https://youtu.be/A2fM4gVPifA

Transcript

Disclaimer: This is not an official record of the session. The DiploAI system automatically generates these resources from the audiovisual recording. Resources are presented in their original format, as provided by the AI (e.g. including any spelling mistakes). The accuracy of these resources cannot be guaranteed.

The Geneva Internet Platform will provide transcript, session report and additional details shortly after the session.


André Melancia: Shop number three, technologies and technical measures to address online harms. Both me and Philip will be moderating the session. My name is André Monsilla. We have Philip Zdrav. Apologies if some of the names that we say are going to sound terribly, terribly wrong, but we have multicultural names here everywhere, and, well, we are in the right place to get them wrong in the European Commission anyway. So with us we have, I will try to say this correctly, Miguel de Brucke, okay, and we have Raffaele Zometzi, okay, with us, and they will start the panel. And we also have, of course, and again, I will try to say this correctly, Philip Lukacs. okay and we have our two moderators there as well so they will help us out if anyone is remotely at this point you are more than free to ask questions and we will take questions from the audience remotely our idea for this is that in the spirit of juridic to spend the most amount of time actually getting interaction from the audience so we will have a starting five minutes introduction at most from each of our key speakers and then from that point on we’ll open it up to questions from the audience questions and of course comments okay please remember that while four or five of us are here on this side and also a lot more people in the back and in the front everyone here is an expert and you have valid points to share so we want to hear it as well okay so anything we should mention no i think we heard yesterday that there are still a lot of online harms to be addressed and the first key participant that we invited is Miguel Dubrakis.

He’s Director General of the Center for Cybersecurity Belgium and he wants to give some insights on the Belgian anti -phishing shield. So the floor is yours, Miguel. Miguel, just before you begin, let me put this up on screen. So we’re going to have some of these topics that we’re going to talk about. We’re not going to pretend that we are going to do them in an exact order because this will be very difficult, but we will try to talk about all of these. I know some of you are not technical people, right? So what we actually added is a few slides that over time we will share with you to actually explain some of the concepts that we will talk about later on.

But for now, let’s just share your slides.

Miguel De Bruycker: Yes. That’s my last one. Oh, okay. Thank you very much. Good day to everyone. So my name is Miguel de Bruyckers. As I was introduced, I’ll push this button. Center for Cybersecurity Belgium created 10 years ago, 8 years ago, we launched a campaign warning the people against phishing. You cannot trust every message, every email that you receive. And the call to action was if you see something suspicious, forward it to us. So we created a mail address in four languages. In English, it’s suspicious at safeonweb .be. And, well, it went a little bit crazy in the sense that, and I’ll put the numbers immediately on top of this, that last year, on average, we received 27 ,000 emails per day from the population.

It’s a small population, 27 ,000 emails. This is a lot to process. Now, in January, that went up to 35 ,000. In April, we were at 42 ,000. So it’s going up very fast. And AI and AI possibilities to create malicious, malicious content is certainly playing an important role of that. What do we do with that? We share it, for instance, with Microsoft and Google, the malicious domains. or for instance Google Safe Browsing we have the Belgian Anti -Phishing Shield we have an app warning people be careful now there is a large campaign using B -Post or using TaxPay or whatever, don’t get caught so we have quite a lot of different systems so 8 years ago we created that mail address 7 years ago we created the BAPS system the Belgian Anti -Phishing Shield that is actually with the main internet service providers voluntarily, they subscribe we take responsibility we filter out the malicious domains from those let’s say 14 ,000 emails that we get every day and through DNS RPC synchronization reads that our DNS is synchronizing with their DNS meaning that if you get a link with a domain of a domain that by us is flagged as …

99 .999 % for sure malicious, you will get a warning page. So we do an evaluation of all those domains. We have a low -risk approach. Like, for instance, we have made a huge list of what we know as the known good to make sure that we never warn for one of those domains. But there are a lot of other mechanisms. We detect phishing kits and things like that. It’s an op -out system. So by default, if you are under one of those five main Internet service providers, you are under that secure DNS. You get a warning page that is something like this. And you will see also that we also say, okay, we don’t want this secure DNS.

So we tell you how can you switch to another DNS that we provide where that security is not. But it’s an op -out. You have to do it yourself. Or you can say, I absolutely don’t agree with this warning. And then you can say, why and 24 -7 we will remove it from the mops list. after an evaluation. There are some criteria to remove it to make sure that criminals don’t abuse this. Why do we do it? Well, for instance, this is an example of the last few weeks. Last few weeks, thousands of Belgians, especially women, between 40 and 65, were being targeted with publicities for brands, Marimero, Marijoev. I’ve learned a lot. I had to ask my wife what is this.

They have created thousands of malicious domains, all linking to those brands and trying to convince those people to buy online with 80 % of discounts. This is, for instance, one of yesterday. Now they have switched because we have taken action. I have to admit, even together with Meta, there were advertisements online for these websites, and Meta is responding and is removing them, but it’s going so fast. So now they are switching from these brands to Fritz’s A .S. Adventure. That was yesterday. what are the benefits well I know that there are risks there are questions like for instance well if you set out those warnings you don’t remove the content and the effectiveness is limited of what you’re doing and that is absolutely correct but imagine that there is a hole in the street and you know that there is a hole I think as a government it’s important that you put out some warnings and that people can still fall into that and that there are ways to circumvent that I know but for the moment that is working we send out that warning page last year 185 million times so we do see a positive effect of what we’re doing it’s not perfect but at least it’s doing something you can have false positives there is the risk of over blocking of government abuse of that that is for us very important that is that proportionality, that is that transparency.

We do what we say and we say what we do. That is one of our mantras and people know that very well. And it must be proportioned what we’re doing. So we will only warn for a domain when we are as good as sure that it is 100 % malicious and the goal remains to protect people. Think about my last slide. Follow this. Yes. So as a conclusion, I think you cannot build a secure environment without some kind of protection. If you want to stop cyber crime, you will need to warn and even stop malicious processes using antivirus. You have to stop malicious emails using spam filters. And I think you have to warn for malicious domains.

using, well, DNS warning systems. And the big question is, of course, how do you find the right balance? And I think since we are doing this for seven years and we have no official complaints, no mistakes, no problems in using that system. Thank you.

André Melancia: Okay, so I think one of the things that we can do right now is open this up for one or two questions, and I will actually have a question myself. So when we saw your numbers and you mentioned 20 ,000, 40 ,000 requests per day, how do you process them? Do you use AI? Do you use humans? Is there an uncertainty here?

Miguel De Bruycker: Yes, thank you. Well, you have to use a lot of tools, and we have different methods. Okay. I cannot reveal it publicly how we’re doing it, but for instance, I have a question for you. we have a whole system that is detecting phishing kits. More than 90 % of those phishing mails are being sent using phishing kits, software that is used, that is rented on the dark web, $100 per month. You use that, and we create signatures of those phishing kits. So if we can detect, okay, we receive a link, we receive an email, we extract automatically, this is all done at our CCB, we anonymize it, and then it goes through the engine, and we will try to detect if we see, for instance, those phishing kits.

There are also some other parameters, and then together with a few commercial partners, there are actually two companies that are helping us to evaluate the anonymized links to flag them as malicious.

André Melancia: Okay, so let’s open this up to questions at any time. If you also have questions. If you have questions remotely, you guys will let us know. So any questions so far? We have a question there.

Nenad Bogunovic: Just a short question. Thank you so much. Well, first of all, I’m from Serbia, from the Cybercrime Unit, and we are currently developing a national cybercrime report system, and your system was one of the, sorry, yeah, and your, sorry, of course, Nenad Bogunovic, I’m the acting deputy head of the Cybercrime Unit in Serbia. So one of the key components we are using is also anti -fraud system, anti -phishing system. My only question is to you, I see that you’re more oriented to links and fake websites and so on and so on. Will you evolve your anti -phishing system to the evolution of phishing today, you know, more spear phishing, AI, generated content, SMS phishing, and so on and so on?

Because I see that. Maybe it’s, you know, maybe it should evolve in this regard as well. That’s at least something we are trying to do, and it’s really a big challenge from our side at least. thank you

Miguel De Bruycker: thank you very much well we have a new project that is up and running and that should be in production by the end of this year to to take all those malicious signals or scam indicators like phone numbers whatsapp accounts on a messenger like types a lot of other things that are being used now so this is a project that is up and running and that will be normally in use by the end of

André Melancia: more question of one question there yes when shock building around serve on the board of your Riddick come from Switzerland but I admit I’m not a technician how does this work the screening with end -to -end encryption did messaging systems

Miguel De Bruycker: Okay, so somebody receives a message Our system was built especially for emails But for instance, if you receive a WhatsApp message And there is a link to a WhatsApp account You can just take a screenshot And you can forward it to that mail address So that means that, imagine that you receive an email You have it in your inbox Now the population is aware through media That they can send it to suspicious at saveonweb .be And this is like a little bit of crowdsourcing You are using the population as a first filter To evaluate that something is wrong So the first evaluation actually is done by the population They see something suspicious, they say This doesn’t look right And they forward it to us And then that is where the analysis starts So we get actually the message from the population And then we extract everything that is related to personal, so we have a strong EPA in Belgium, and we’re under their control.

So we’re doing, as I said, we’re saying what we do and we do what we say, and this is quite important. So the fact that they extracted themselves and they forwarded to us the encryption is not an issue.

Philip Struyf: Thank you, Miguel, for the interesting presentation and addressing those questions. We will now hand over to Raffaele Sommese, professor at Twente University, who will present his research on the Italian Paris Shield and the collateral damages and the efficacy of that system.

Raffaele Sommese: Thanks a lot. So let me start first with, I mean, internet blocking is something that has been given as a sort of big blanket towards two different concepts. One is the concept that Miguel was introducing that was protecting the security of end users. From, for example, financial scam or financial harm. And the other aspect is implementing governmental or judge or private party decision for protecting certain sector. And the problems start to rise when we have the second category of implementation, because the current technology that we have is not actually the right tool. And the reason why it’s not the right tool is because the way it’s implemented is mostly with two aspects of the Internet.

One is the IP protocol and one is the DNS protocol. Now, for the one in the room that are not familiar with this concept, imagine the IPs as to be the phone number of the Internet, like a series of digits. And you call the house of someone. And then when you call them, you’re not sure of the person that will respond on the other side. There may be multiple persons. There may be like a 20 -story building office that you’re calling. So you want a specific person out of that number. To get a specific person out of that number, what we use is the IDN. It’s basically this phone book of the Internet that provides this translation from names, things that we can easily remember, Europa .eu, for example, to something that is more difficult to remember that are these numbers.

But they also give us the opportunity to select who we want when we call a specific number in that building. And blocking IPs from a perspective of a government, it’s very straightforward. You just order all the Internet service provider in your country to block that specific IP, and then all the customers for your country will be not able to access that IP. The problem is that you will cause a lot of collateral damage, because then all the people in that 20 -story building will be unable to access their services. And that’s the scenario nowadays in the Internet with the content delivery network, for example. To block DNS, it’s a bit more difficult concept, because you can do it, you can do it at an additional level, but…

But when you cross the border of national level, when you ask like a public recursive resolver out there to block specific names, you encounter the problem of extraterritoriality where basically you don’t know where the client that are connecting to this recursive resolver are from because on the Internet, we don’t have a stable way to determine where an IP address is connecting from, from which country it is. All the service that we have out there, all the geolocation providers that we have out there, they tell you, we do the best effort to provide you this information, but we cannot tell you this user is from Italy and we cannot swear this information in front of the judge.

So it’s a very challenging technical problem. And the other problem is, while this problem exists, this has been ignored by the regulation that is coming up in Europe, especially in Italy and Spain and in France. And in Italy, we have like a very bad case. That’s named piracy shield. So what is Piracy Shield? Piracy Shield is a platform that exists in Italy to try to prevent basically the online football streaming piracy. And while it has been considered by someone a good example of how to implement this, we did the research on this topic and we demonstrated basically with numbers that this is a very bad example. Because Piracy Shield as of today has blocked more than 10 ,000 IPs and 40 ,000 domains in all Italy and has caused thousands of collateral damage to legitimate websites.

Sorry that I was describing you before of the building. Imagine that when we did the research, we found like a lot of websites that were completely not piracy related, websites of web shops, websites of car repairs. It was like actually the case that I always report is this case of a Portugal hosting provider that was blocked because they rented. The infrastructure that was previously abused by someone that was streaming illegal content. and they ended up with an address that was blocked in Italy and they were not able to send invoices to their customer in Italy for an entire month. And they didn’t know that their address was blocked by this platform because the other problem is that there is no transparency in this platform.

The requests for blocking are requested and the cooperator should comply within 30 minutes. There are extra judicial orders because the requests for blocking are inserted by private parties that are the copyright owners and there is no vetting of these requests. There is just a forensic proof that is attached to this platform but actually no one is vetting this forensic proof. And the other problem is that there is no transparency. The list of block is not public. So you just notice that something is blocked because you see that you cannot connect to the website but you will never know why it has been blocked. This information is not provided to you. This is a video that was recorded in the last week of May.

And the other problem is, despite causing a lot of collateral damages, this platform has proven to be ineffective because the Internet is a big place and illegal services evades very easily these blocks. I mean, an IP address on the market today costs 30 cents to lease and 20 euro to buy. You can get, if you go like on an IP leasing market, you can get like an entire network block and a single IP will cost you 30 cents. So if they block an IP, these streamers will just need to allocate 30 cents of their money to get a new one and evade the block. And same goes for domain names. Domain names goes from 50 cents to 15 euro. So again, if you are a platform that is making a lot of money out of this illegal streaming, you have a very easy tool to evade this kind of blocking.

You can invest money and just escape the blocking. And the problem is that blocking, the way that they are implemented, lasts forever. There is no verification after if the illegal resource is not there anymore. So we are polluting the Internet with blocks at a level that they should not be there. And these blocks are lasting forever and harming users that will reuse these resources later on. Because, yes, Internet is a big place, but we reuse resources constantly on the Internet. IP gets reused. They get reassigned to new people. You can lease the IP that someone else was leasing before. You can register a domain that expires after someone was using the domain before. And the other problem is that it’s also being proved ineffectively from an economic perspective.

Because the amount of subscription after this platform was introduced in Italy didn’t went up. And so it has been considered a good example, but the numbers show that this is not a really good example. And Spain and France that are once ago down the same road, and some other European countries that were once ago down the same road, seems to not understand that this is not a good solution. and now to solve this problem basically the Italian regulator wants to be even more aggressive with the internet providers saying that these blocks need to be applied to all VPNs all the recursive resolver, all the CDN out there but again we cannot differentiate traffic when it comes from a specific country and it’s very hard to do and unless we accept the faith that these blocks should be done for all the internet users something that is illegal in a specific country may not be illegal in another country and we should not harm users in other countries this may be problematic and it in general violates the idea of extraterritorial and the fact that we will reduce the freedom on the internet and the freedom for the user of the internet so the question that I have for the public is actually do we have a better alternative or not?

the majority of blocks that Piracy Shield issued were towards servers that reside within the European Union 77 % of the server blocks were within the European Union we have legislative instruments to go after these people within the border of the EU this bulletproof hosting way that they are named that are within the European Union and actually take them down and perform what’s called follow the money so basically trace back the transaction, the economic transaction that led to the creation of this service and the client of this service to actually take down this business so can we do something else? Thanks

André Melancia: Let’s have a look at some questions that are presented remotely We have one question and it is w

Participant: hat is the amount in percent of scans you block and how do you work with online platforms?

Miguel De Bruycker: Okay, thank you It was a question for me, I suppose How do you work with online platforms? First of all, with the Belgian internet service providers There is a constructive, non -legal, non -binding collaboration Allow me also to say that The idea of blocking IP addresses I think it’s not a good idea Because there you have too much collateral damage And it’s too difficult Collaboration with, let’s say, US hyperscalers To name them Is improving a lot the last year It is really changing For instance, there is something like The Global Signal Exchange It’s a spin -off of the Oxford University And there you have the big players The Googles, the Microsofts, the Metas Who are linked to that Global Signal Exchange platform And there you have the big players our Belgian Anti -Phishing Shield, our domains, the domains that we flag as 100 % or as good as malicious are uploaded.

And for instance, what they are doing now is they are moving emails that have links to those malicious domains from the inbox to the spam folder. So they are not deleting them, but in an automated way, they are saying they are not on the inbox anymore, they are in the spam folder. So yes, you can go to a website like that. Yes, you can click on that link, but at least you will have the notification that, well, it was in the spam folder. It’s less trustworthy. So bit by bit, we see that, for instance, last weekend, apparently Meta did remove advertisements to those malicious online shops. And they did it within hours, which for us was quite new.

So I have the impression that the last six months to one year, the collaboration is starting and that they understand that as a service provider online, when you provide a service and that can be a telco that provides a phone number or an email address, an IP address, hosting of a website, that when your service is being abused for cybercrime and you get a notification, well, you get some kind of not legal, but you get some kind of liability. So we don’t oblige internet service providers in Belgium to collaborate with us by law, but we explain them that, well, if we get notified by the population that something is wrong, that something is like the hole in the street, there is a hole, well, at least let’s work together to put a warning sign in front of that.

And the other question was, do you have any idea how much you’re blocking? I have to admit that with the more or less 40 ,000 emails that we get every day, we have quite a good view, a representative view, on phishing campaigns being sent out in Belgium. So we are doing, for the moment, analysis. And I have to admit that at the beginning, we were only able to extract 25 to 30 percent of the malicious links, because we had to be very, very, very cautious. We don’t want to be seen as government censorship, and we will not allow our system to be used as government censorship. We want to filter out malicious domains, cybercrime. Now we are pulling that up, and I think more or less we are at 60 to 70 percent.

That is what we can filter out. We see a lot of other domains that we consider as malicious, but we’re not sure enough. So I have to admit that we cannot go to 99 percent. That will probably be, but it’s a little bit like a spam filter. A spam filter is not perfect. It’s not perfect, but it’s not perfect. But imagine that we would take out spam filters on our mailbox. Our mailbox is dead, honestly. 95 % of all emails that are being sent out worldwide are being filtered out by spam filters what you get in your spam folder is less than 10 % of what is being filtered out so you have to do something to protect the environment and I think that we are at a level now if you see how it is going up that you are at a point where you have to accept that DNS warning like a spam filter is more than necessary

André Melancia: Thank you Miguel for a clear and elaborate answer I believe we have another question

Participant: Hi, so thank you for your attention my name is Stigl Fernandes I was a student two years ago and now I’m a university student who’s really interested in technical application to policy so I have two questions actually but maybe we can do one on one how much time do we have? do we have enough time? alright then, I’ll go right away so my first question is regarding the first presentation my understanding is that all reports come directly from users is that the case? or do you have also forwarded reports from Google for instance Gmail, Hotmail or is there maybe an automatic mail filtering system in place and the second answer is regarding last presentation It was mentioned that it is often cited as an example, the IP blocking of CDNs and such, but by whom?

Is it usually like the legislators, just the legislators for doubling down? is it the ISB companies or what stakeholders is mainly coming from? Thank you very much.

Miguel De Bruycker: Okay, thank you. Let’s say up until more or less a year ago, it was 100 % feeds of the population. What we now did is in collaboration with Belgian banks and with our more or less digital identity provider on a national level, it’s called It’s Me. We have a system, It’s Me, it’s our digital identity. That there were so much campaigns against banks and against It’s Me that they have a separate priority channel to notify malicious domains. So that is one additional channel that we have because if they get notified that, for instance, a certain bank is that there is a campaign, there is abuse of a bank and there is a malicious domain. they can notify it to us through a priority channel.

That’s one thing. And another project is called Fishnemo. I will not reveal too much because is this like public?

André Melancia: Fully public. Fully public.

Miguel De Bruycker: Then I have to be careful because if I tell too much, how, okay. Okay, let’s say we’re trying to find domains that are linked to Belgian government and critical infrastructure but have been registered for malicious intent. So I will not explain how we’re doing this because if I explain how, it’s probably a bit easier to circumvent. But that is an additional system. So we’re trying. Okay, is there, are there domains that are being created linked to critical infrastructure that are not owned by that critical infrastructure? absolutely what you’re trying to do.

Raffaele Sommese: Thanks again, Miguel. I’ll answer the second question. So, of course, I mean, the people that are, the stakeholders interested in this system are the copyright owners first, because they are the ones that pushed for the creation of this anti -piracy system, but there is also a lot of support from government, so from government bodies, and actually in Italy from our national regulator, that is Agicom, the regulator for the communication. And on the opposite side, I mean, operators and internet users and companies for freedom of the internet are completely against this platform. Operators mainly also because of a cost problem that this platform introduced, that they need to, the burden is on them and they don’t get any compensation for implementing these blocks.

André Melancia: Okay, so we already have three questions, so we have a question from so let’s take your questions first

Participant: good afternoon everyone thank you for your excellent presentation gentlemen we have representation from belgium from italy and from serbia in the room we’re talking about very similar activities i’m from an organization called clean dns we work extensively in this space i’d like to ask the presenters about the importance of collaboration between member states because it seems as though we’re all pursuing very similar interests at a national level and greater collaboration could be of extreme advantage to citizens and to governments how can we pursue that uh further in terms of the presentation that identified uh ip address uh restrictions uh reputation block list if you like i also agree that that is not uh a panacea however i can understand how at a certain level of government taking activity through what is perhaps perceived as an easy option will give a certain profile an advantage, but this is a multifaceted environment where we need all stakeholders to be involved.

So in terms of taking action to restrict phishing and those activities which are malicious, what else should be done, especially at the infrastructure level, thinking of the different providers in the chain to help us address this at a

André Melancia: Again, that’s a very good question, and we are in a perfect place to debate that kind of question in the European Commission. Next door, of course, we have the Parliament. One of the recommendations that I would say is get in touch with other people around the European Union one by one, grow bigger, and then you’ll be noticed a bit more by the people who usually are around these buildings and maybe sometimes, something… completely European can be born to actually attack that problem. Sadly, usually our colleagues that usually live here usually pay attention only when things get bigger enough for that. But I will pass on to both of you if you want to comment.

Raffaele Sommese: I have a comment on that. Basically, a couple of years ago already there was published a study that a collaboration between several European and CCTLD, I can pass you the name later on, several European and CCTLD led to an increased phishing detection for these CCTLDs because they were able to share the machine learning model they used trained on the different data of each CCTLD and they were able basically to detect abuse going from one CCTLD to the other CCTLD. So yes, collaboration is the key from this perspective.

André Melancia: Thank you. So, I guess we go to the next question. Gentleman at the end.

David Frautschy: Hello, I’m David from the Internet Society. So, I have a few comments from the presentations and also a couple of questions. On the comments, I think the analogy of IP addresses like telephone numbers can be misleading. Because when you have an urge to cut a telephone line, it’s unique. So, you can cut this line or you can cut my home line. And it will be only my house. And that’s it. IP addresses, as you explained very well, when you block IP addresses, you will be blocking many other websites, potentially. So, the impacts are enormous, potentially. You explained extensively the case of Italy. I know more. In the case of Spain. Nowadays websites Many times are composed by blocks That are just appearing in front of your face But it’s not coming from a single address But just coming in And for instance One of the blockings recently affected A payment gateway So it was all e -commerce affected In the country during this football match Not all e -commerce but most e -commerce Because when payments were to be done Requests to verify Credit card information was not possible Because this website was shut down So I think this analogy Can mislead Policymakers who just don’t know What we are talking about here So The other thing I don’t Agree is with the Blockings are difficult to do I think they are easy to do Too much easy to do Especially if the ISP doing the Blockings is an interested party Like in the case of Spain Where Where the blockings are issued by the content right ownership, right hold owner, and then in many cases they are issued and to be executed by Telefonica which is the retailer of the football matches themselves by the channel, so they are forced immediately, they want to do the blockings.

So my questions are why these policy makers are listening more to rights holders than to the technical community. We are trying to explain this is wrong. There are notorious cases of blockings. Why is this happening? That we are not able to reach out our voice correctly to the right people and explain this is wrong. Now the other question is, do you think a liability scheme would be appropriate so that right holders would be required to pay to those websites that are being affected by their IP requests

Raffaele Sommese: t

David Frautschy: o be blocked? I didn’t… O

Raffaele Sommese: kay. so on the on the example of the phone number uh i tried to explain it’s more the phone number of an entire building so the the phone number for example of a company that has many employees they’re not the phone number your phone numbers your cell phone number to make it clear um um on the on the question of the uh whatever uh this it’s easy or not it’s easy to mandate it’s easy to request the internet service provider in your country because they need to comply they cannot i mean otherwise you go then we’re there with police and you arrest whatever is not complying with that rules and regulation so the technical way exists the difficult part is what if you want to do these on a service that is residing outside the country and you want to country just for the italian users you cannot do this because there is no way you can enforce that users from italy goes here and users from all the other countries goes in another direction On the question of liability, I think you raised an important point.

And Piracy Shield blocked in October of 2024 in Italy for more than a couple of hours, drive .google .com, so the domain name of Google Drive, basically. And that block lasted for many hours. Now, arguably, Google Drive is a service that is used for many, many users for many, many companies. So it’s very hard to quantify the business impact of that blocking. We were lucky that the blocking happened on a Saturday evening where possibly not a lot of people were working. But that may have had tremendous consequences. Yet no liability was given to the content blocker. And there is no discussion of giving. Giving that liability. Basically, there is no discussion of what if something goes wrong, who needs to pay.

and the other problem is that to have that kind of liability you need to have transparency in the system so the system of the blocks that are requested needs to be public because there needs to be someone that can audit these blocks and can tell this block can happen from this day to this day hence the financial consequences that happen for me are these but none of this is in the current regulation and none of this is in the current

André Melancia: So we have two more questions so I’ll ask Arun and Samridhi to actually read it out and then we’ll hand it

Participant: So the question is from the perspective of a media regulatory authority that orders DNS blocks, all of the money is only a better alternative when it comes to precisely such cases of copyright infringement, pornographic platforms etc. but it doesn’t help with sites containing other types of content harmful to minors, the providers themselves as well as the hosting providers cannot be reached So what would be the better alternative here from your view?

Raffaele Sommese: That’s something very hard and that’s something where a stricter block to a certain extent is somehow required. I mean, side hosting, CSAM content are arguably illegal in the whole European country and probably the whole world. So that’s a case where you can say you need to have a block that goes beyond, even to the risk of causing collateral damage, may go beyond basically the intended purposes. The problem is also that, I mean, a lot of these content are hosted on platforms that are not responding to legal authority. And we need to make an effort to curb down the fact that these bulletproof hosting out there exist. And they can host this content that are illegal.

Not removable by any legislation in the world.

Miguel De Bruycker: well my experience is that there are different ways and a lot of different ways to respond to these crimes you can of course can follow the money you can count on law enforcement and that is absolutely necessary because if those bad guys are never caught I mean it’s like well it’s a never ending story on the other hand we can do a lot and it’s true that Belgian people that go abroad or use another provider than the five that are currently in our system they will not be warned that’s correct but let’s at least try to warn those people that we can warn my experience is that for most of the providers and for me a provider that can be a telco for a phone number that can be whatsapp can be meta that can even be a bank that provides an online bank account or a credit card company that can be a telco for a phone number that can be a bank account or a credit card company that provide us, if you notify them that their services are being abused, they’re listening.

What they don’t want, like for instance, we have a program that is evaluating online advertisements. And at the beginning, we were notifying to Meta Advertisements, giving the references, the legal references of Belgian law. This is an infraction of Belgian law, article Y. They said, please don’t do that, because when you deliver something to Meta that has a legal reference that says, this is an infraction of law, we have to immediately send it to our legal department. And they have to start an investigation because they have, of course, that umbrella. They will take the responsibility, but it will be through their legal department. So if you want a response within hours and not days or weeks, it’s better not to put.

So we created, we looked at the policies of Google, of Meta, and we said, well, we’re going to do this. And to be honest, everything that is illegal in Belgium is almost forbidden in their policy. so it’s better to put references in general saying okay this is impersonational and you say this is what they are doing but in their terms and conditions and my experience is that they do respond and they do take action but that’s not the case for all providers on the web unfortunately

André Melancia: Okay so we have a few more questions there’s also another one remotely so we will try to make this quick so that everyone is heard before handing it over to Peter let me just add something to this question because this question mentions some of this one of the things that we’ve been seeing about internet blocking in general is situations where we have internet social media for instance in Australia being blocked to minors in the UK they want to implement a verification that actually causes a lot of issues, especially related to freedoms, because suddenly you are not free, you are not allowed to look at the Internet in an anonymous way. So we still have a few minutes to talk about this later, but it is important to point out that this actually causes a lot of harms related to the freedoms that we have, freedom of speech, and especially the typical scenarios of countries, and we have seen this, a lot of countries trying to control the population that is no longer able to use the Internet as a means to gather and as a means to start some peaceful protests, etc.

So let’s hand it over to Peter at this moment. Yeah, thank you. Very interesting. Peter, do you want to? Did it work? No, it worked. Sorry. Peter Kovdynik, apologies.

Peter Kovdynik: So again, interesting discussion. Not the first time we’re having this topic, and discussion is progressing, but we always get new players in the game. I think there are a couple of things, or a couple of parts that may deserve a bit more attention, like cross -border issues, voluntary versus involuntary blocking, and circumvention technologies. And then I’ve heard twice I can’t tell you what we’re doing, because otherwise some things would happen. That’s a bit between security by obscurity and a magician sharing all their tricks. But from a state actor, or from a public authority, I do think there’s a certain transparency obligation, especially given that there are private markets participants that provide protection services, and sometimes public authorities are actually interfering with that part of the market.

Finally, I think the most important part when we talk about DNS or internet blocking… I still don’t understand why content mitigation, which is at the application layer or the user level, would have to happen at the infrastructure level, which is the core governance question. Why do we fiddle with it, even though it is not very granular? And what would the participants do to arrive at more appropriate and more granular alternatives? We’ve heard about spam folders that address mail issues. There are browser plug -ins and so on and so forth, which are more lean towards the user, give the user more control over the blocking and the protection, and also would not fiddle with the core infrastructure and avoid the cross -border issues as well.

Thank you so much.

André Melancia: Miguel, could you address the transparency?

Miguel De Bruycker: Yes, absolutely. As I said, everything we do is transparent, but that doesn’t mean you have to be transparent. You have to make it public. If you have security measures in place, I mean it’s like an antivirus you don’t publish all signatures that you have found immediately otherwise the counterpart knows that that’s the way you try to protect your environment and of course those systems can be abused to my knowledge ours is absolutely not and I would never accept that. A spam filter could be abused by governments to remove specific content if you say we don’t want people to receive messages with this content or on this topic technically you could do that but that doesn’t mean that we have to remove spam filters as I said if we would do that the email system is dead so it’s about finding the right balance between applying security measures in a correct way, in a transparent way and as I said we are very transparent and we are under the control of the DPA and well, protecting your citizens and finding that right balance that is I think what is first the most important, but I do understand the concerns but on the other hand not doing nothing is I think more of a concern than trying to do something

Raffaele Sommese: And I want to add that I completely agree IP and DNS are the wrong place where to block things for certain kind of content and you need to go to the source, you need to block the content and then source, especially if the content are within the European Union, because we have other mechanisms to act

André Melancia: Okay, so I think we have about 10 minutes and we still have to see the messages let’s do it like this, so we have four pending questions let’s take the questions now and then we’ll try to come up with answers for all of them if that’s okay feel free to start.

Participant: Yeah, I’m sure quickly here. Could you just once again explain in a way to a layman, to a child, or to an average politician, why exactly the technical framework is not apt to help with the question of child protection online? So what’s really a very, very basic explanation why not for a politician? Please continue.

Olivier Crepin Leblond: Thank you, Olivier Crepin-Leblanc. I’m with the United Kingdom Charter of the Internet Society. We’ve had to deal for a long time with the UK government in regards to age verification, online harms, etc. One of the problems we find with politicians is that they have a very limited lifespan of a few years and need immediate solutions. They like silver bullet scenarios and some firms… Some companies go, speak to them, and say, we have this stuff about it. We have the answer for you, this immediate thing, which unfortunately is not the solution because it’s got a whole lot of repercussions. Unless we can prove that there are no silver bullets and these are complicated issues that need balance, that need certain mitigation and analysis, we will continue having problems where there will be the false positives and the Internet will be somehow a lot harder to use if all these things are implemented, such as age verification, etc., etc.

Petra, you were there.

Petra Arts: Yes, thank you. Petra Arts from Klaus Flair. Two small comments. Thank you, Alfredo, I think, for also highlighting the issues around global resolvers. We obviously have quite a lot of concerns around that from some of the developments that are happening in some of the countries from the legislation perspective. Thank you for highlighting that. I wanted just to point to people that want to kind of know more about the economic impact of looking to a study that we commissioned last year from Analysis Mason, a consultant center. it’s to be found online it’s called the economic cost of network blocking where we try to also illustrate a number of these kind of the things that were mentioned by a number of people in the room and maybe it’s helpful for for people as a resource so thank

Philip Struyf: you yeah i think it’s also listed in the further reading uh section of the on the wiki yeah yeah it’s there now final question online um do you have supervised methodology to ensure that you preserve freedom of speech ensuring you’re not turning into a censorship arm of a government or

Miguel De Bruycker: even private parties oh yes absolutely we are um we are detecting phishing emails so it’s like an antivirus um it is detecting the known bad it’s about identifying the known bad and bad means you know you’re not you’re not you’re not you’re not you’re not you’re not you’re not within a specific cyber crime domain and not in a content domain. And we do check that we never go on content. It’s not because somebody is saying something like adult sites trying to protect young people that is currently absolutely not what we are doing because we don’t have a correct solution for that. And coming back to, for instance, Cloudflare, we are actually in good contact with Cloudflare.

Because more than half of the malicious domains are using Cloudflare, are using that infrastructure to anonymize themselves partially. But as we understand with the collaboration of Cloudflare, they don’t want to be, let’s say, a provider for cybercrime too. And they’re also asking, okay, how can we collaborate and how can we with governments have a better exchange so that… we are not those ones that make sure that those bad guys are never being called so it’s about finding a way in a balanced way together with those I also call you a service provider in that way you’re delivering a service on how can we do it but not by law, by talking to each other by listening to each other what can we do together and that is I think the model that we set up and that we’re trying to defend

André Melancia: Raffaele?

Raffaele Sommese: I will be extremely brief to answer, there is no silver bullet and everything we do on the internet as consequence every action that we take and where we interact with the internet protocol in general as consequence there is all there needs always to be a balance between the risks and the benefit of the action that we take and that balance needs to be discussed with technical brewers that’s the important part

André Melancia: thank you, now over to Philip for the messages from this session

Philip Lucas: yes, I’ll very briefly share the messages I did my best to to summarize the conversation, so you should be able to see that now, so so, the first message is that the evolving nature of online harms requires a multi -stakeholder collaboration to be tackled effectively, as we heard from Miguel and this may take form of collaboration among industry players or across industry and the government second, intervention of the technical area by blocking the IP addresses or DNS have significant impact on the availability of online resources, like websites and cause unnecessary collateral damage without necessarily addressing the legal content in question and thirdly that interventions on illegal content to increase online safety should be proportionate so the rights of

André Melancia: Okay, we have one or two minutes if anyone wants to comment

Participant: Thank you, Rishi, Clint, DNS I’d like to ask the panelists this is coming just on the apologies I was going to ask for the youth diggers for one recommendation for them to think about arising out of this session

Raffaele Sommese: Sorry, can you repeat?

Participant: I would like to ask for one recommendation from the panelists for the youth diggers attending this session

Raffaele Sommese: Be active and participate in this discussion because I mean, some of these discussions center around the fact that part of these blocking are for protecting young people on the Internet. You need to have a voice on what is really the harm you want to be protected from. It’s more important that this comes from you.

Miguel De Bruycker: The Internet is not public space. What I mean is that when I leave this building, I’m on the street. There, as a government, you can put cameras, you can even put policemen, you can control. The Internet, when I connect here to the web, it’s a privately owned… Well, this is now government, but that’s the exception. I mean, you have a private device connecting to a private ISP, going to carriers, services. They’re all owned by companies. As a government, you don’t enter private space just like that. It’s a different story. Meaning that if you want to achieve something, we will have to collaborate. With respect for each other and understanding that ecosystem. It’s private space. It’s privately owned.

Yes, but that means that those service providers, those private companies, they’re taking a lot of responsibility. And we have to, together with governments, figure out how to secure that in a balanced way together in that private space.

André Melancia: Okay, so we are perfectly on time So let’s just wrap this up for today I think that it’s not going to be the end of this conversation because this topic will go on forever So let me just mention that at this moment we have 73% of countries which are no longer democracies if some of them ever were and these kind of limitations that we see especially the last topics that we talked about these kind of problems are growing more and more so we will discuss them in future events as well. We want to thank you all very much for being here. We want to especially thank Miguel and Rafael for being our guests. We also want to thank everyone who participated, and especially we want to thank Philip Lucas, and we want to thank Arun and Samridi for moderating remote sessions.

And of course, Philip and I, we really want to thank everyone for being here in person or remotely, and I hope you have a great event coming up. Okay, thank you everyone.