The European Commission spoke up: New laws are being considered in the EU to force internet companies to grant access to sensitive and encrypted data from various messaging apps. According to EU Justice Commissioner Věra Jourová, an effort will be made by lawmakers in June to try and push for access to data stored in the cloud by encrypted apps and let law enforcement agencies make use of it.
In a public declaration, Jourová claimed she had been pushed by politicians all across Europe, and stated her intention to outline “three or four options” for online companies that range from voluntary agreements to strict legislation. The EC’s goal in that operation is to provide the police with a “swift and reliable” way to discover what users of encrypted apps have been communicating with others.
“At the moment, prosecutors, judges, also police and law enforcement authorities, are dependent on whether or not providers will voluntarily provide the access and the evidence. This is not the way we can facilitate and ensure the security of Europeans, being dependent on some voluntary action,” Jourová said according to EU policy site Euractiv. Putting the measures in place would make it easier for police to access data from online services such as Facebook that are registered outside the EU’s jurisdiction.
Threat of such legislation is usually used by governments to push companies into agreeing to provide access to what they want voluntarily. However, Jourová clearly expects some significant pushback from the tech industry – and most specifically from US corporations such as Facebook and Apple – and so declared that the voluntary, non-legislative approaches would only be provisional in order to get to “a quick solution,” with laws coming later.
What’s to be understood is that the European Commission is not bluffing : even though it will take a few years to pass such legislation, it is prepared to do so, and may even do so regardless of app-makers’ compliance. The announcement is only one of a number of recent aggressive pushes by European governments against social media companies – political pressure is strong on the EU commissioner to introduce new rules and laws to help local police and/or law enforcement agencies obtain access to data requiring secure encryption hacking.
Last month, the German government made headlines when it actively threatened Facebook, Google and Twitter of a 50 million euro fine to force the tech giants to act on hate speech by removing “obvious” criminal content within 24 hours of its posting. A few days later, the EC said it was going to insist on social media companies changing their terms and conditions to remove various efforts meant to legally insulate them from content issues (for example, the requirement for anyone to sue them in a California court rather than in their home country).
One day after the March 22 murderous attack in the heart of London, the UK government showed public criticism of the failure of companies like Google and Facebook to remove extremist content on the internet, arguing that they “can and must do more.” The declarations were shortly followed by a statement issued by Amber Rudd, UK Home Secretary, who pointed that law enforcement should be given access to the Westminster attacker’s encrypted communications on Whatsapp, because the messaging service acts as a place for terrorists to communicate in secret. The messaging service was also recently suspended in Brazil due to an access dispute in a criminal investigation.
Opposition of the measure is fairly widespread, and activists argue it is impossible to create a backdoor exclusively for law enforcement: According to Lawfare, any breach in the encryption system would allow cybercriminals or unauthorized hackers access to the same data. If crypto backdoors are created, it will be impossible to ensure that only the “good guys” can use this special access, thus undermining end-to-end encrypted systems and encrypted storage. Sadly, politicians and law enforcement insist they want to be able to access people’s private communications and stored data, no matter how, particularly if they have a warrant regarding suspected criminal behavior.
Tech giants such as Facebook and Apple have already pushed back such measures in the past, and proved not to be impressed by governmental pressure. Apple in particular ended up fighting the FBI over access to an iPhone that was used by a shooter in San Bernardino (California).
Andrus Ansip, technology policy chief for the European Commission, publicly opposed a move to weaken encryption systems, and even the EU anti-terrorism coordinator, Gilles de Kerchove, has publicly asked: “The question is, can you open a backdoor for Europol only, or would that at the same time create a vulnerability and open a backdoor for the Russian mafia or third party state spies?”
It is known supporters of such invasive measures almost always point to the risk of terrorism, using the series of attacks perpetrated in Paris in 2015 as an example. Yet, in that case, the attackers didn’t use encryption services at all, but relied on disposable phones to communicate and coordinate the attack. Skepticism is hence fairly big among European citizens and internet users as to how loosening encryption methods would actually help fight terrorism and crime.
Tim Cook expressed his point of view on the matter in a rare open letter to the public, and Edward Snowden and Chelsea Manning as an example, saying they had shown us that all it takes is one rogue operative within the bureaucracy to lead to a huge data leak.
If the European Commission gets its way in June and following President Trump’s bill signature repealing American privacy protection rules, it is fair to assume those within the EU may soon find themselves asking similar questions.
