Hackers vs. the EU: the backdoor that opens the door to everyone

5 min read Original article ↗

The scene is grotesque: while the European Union insists on implementing “Chat Control,” the hacker group LunarisSec has issued an ultimatum to European lawmakers, as reported by FrenchBreaches. The demand is clear:

Abandon the project or face cyberattacks.

This is not merely a provocation. LunarisSec has already claimed responsibility for doxing campaigns and the leak of sensitive contact data – precisely the type of information that apps like Meishi are committed to protecting through peer-to-peer architectures. The threat is not abstract: it demonstrates that any attempt to insert a “backdoor” for surveillance inevitably creates an opening that can be exploited by anyone, including criminals and radical activist groups.

The paradox is clear: lawmakers want to scan private chats to “protect minors,” but in doing so, they are legalizing the creation of systemic vulnerabilities that jeopardize everyone’s security.

This is where the fundamental contradiction emerges – the one that makes the current situation so grotesque. Western governments, particularly the EU and the U.S., present themselves as champions of digital freedom against the power of Big Tech. However, when it comes to private communications, these same governments switch roles. From defenders of data sovereignty, they become advocates of mass surveillance.

Let’s see how they behave in diametrically opposite ways depending on who they’re dealing with:

  1. Against Big Tech: With the DMA in Europe and the AICOA in the U.S., they mandate interoperability, ban self-preferencing, and force platforms to open up their ecosystems to break up monopolies. In this scenario, the government says: “Companies shouldn’t control your data; you must have freedom of choice.”

  2. Against citizens: With Chat Control, the EU is requiring companies to scan private communications, creating the infamous backdoors. In this scenario, the government says: “We must monitor everything to protect minors, even at the cost of violating everyone’s privacy.”

It’s an irreconcilable contradiction. How can they expect companies to open up their systems to guarantee user freedom, while at the same time forcing those same companies to install surveillance windows in private chats? The result is that governments, in an attempt to “protect minors” (a noble goal but one used as a pretext), are legalizing the creation of systemic vulnerabilities. They’re telling hackers:

Here, we’ve created a special backdoor for ourselves. If you want, you can use it too.

In reality, users clearly perceive that neither governments nor Big Tech deserve trust. The former pretend to promote market openness only to then impose legal backdoors that make every platform vulnerable; the latter, though forced to open their closed ecosystems, remain de facto gatekeepers. The result is that users find themselves defenseless against two powers that, though in conflict with one another, converge in denying them real control over their own data.

The solution cannot come from new laws or corporate firewalls: centralizing data – whether on private or public servers – inevitably makes it a vulnerable target. The true defense lies in a paradigm shift in architecture toward decentralization. When contact data and communications do not reside on a central server but are distributed among users via P2P (Peer-to-Peer) protocols and protected by E2EE (End-to-End Encryption), the very concept of “data theft” changes in nature. There is no longer a database to breach.

Precisely for this reason, tools like Meishi represent the only coherent response to the threat posed by LunarisSec. Since the hacker group has claimed to have accessed contact data specifically, the solution is not to improve server security, but to eliminate the server altogether. With a P2P architecture, contacts cannot be exfiltrated from a central point, rendering cyberattack threats ineffective: there is nothing to steal if there is no target.

Protocols such as Bitchat have already demonstrated the feasibility of this decentralized resistance, even defying the Indian government’s attempts to block them in order to impose control over private communications. Data sovereignty is not a political promise that changes with elections, but a technical reality that we build ourselves by choosing tools that respect our autonomy rather than attempting to control it.

The current situation is paradoxical. Hackers are threatening Europe with attacks if it doesn’t abandon surveillance; Europe responds that surveillance is necessary for security. Big Tech companies are trying to maintain control, while governments are trying to impose their own. Everyone is afraid. Everyone is trying to control. No one is on the user’s side.

We are on the user’s side.

And yes, in a somewhat ironic sense, we are also “on the hackers’ side” in the sense that we recognize the threat is real only because the system is broken. If we had built a world where data truly belongs to its owners, thanks to decentralized protocols and strong encryption, those threats would be pointless.

Data sovereignty isn’t a luxury – it’s the only defense against a world where technology has been turned into a weapon of mutual control. Don’t wait for governments to protect you from the consequences of their own laws.

Take back control. Adopt solutions that have no backdoors. Build your own independence.

The concept of Data Sovereignty in the Meishi Manifesto is missing here. If access to our data is restricted for commercial, regulatory, power, or security reasons, are we owners or just renters of our own lives? Data Sovereignty isn’t a gift – it’s a right we build ourselves. While you wait for the next post, I ask you:

Who do you want to control your data?

  1. 5–7 Big Tech companies

  2. 200+ governments

  3. You

Choose wisely!

✊❤️🔒
Own Your Data
Marco Parisi

Discussion about this post

Ready for more?