Security

What’s all this about Europe wanting crypto backdoors?

Comment

phone encryption
Image Credits: Bryce Durbin / TechCrunch

A press report emerged over the weekend claiming European lawmakers who are worried about terrorism are speeding towards a ban on end-to-end encryption. Spoiler: It’s a little more nuanced than that. Read on for our break down of what’s actually going on… 

Is Europe about to ban E2E Encryption?

No.

A report in the Austrian press yesterday appeared to suggest a ban incoming on end-to-end encryption which the headline linked to a recent terror attack in the country. In fact there have been discussions ongoing between Member States on the topic of encryption — and whether/how to regulate it — for several years now.

The report is based on a draft resolution of the Council of the European Union (CoEU), dated November 6. Per the draft document a final text, which could incorporate further amendments, is due to be presented to the Council on November 19 for adoption.

The CoEU decision-making body is comprised of representatives of Member States’ governments. It’s responsible for setting the political direction for the bloc however it’s the European Commission which is responsible for drafting legislation. So this is not in any way ‘draft EU legislation’.

One Commission insider we spoke to who’s involved in cyber security strategy couched the resolution as a “political gesture” — and most likely an empty one.

What does the CoEU draft resolution actually say? 

It starts by asserting the EU’s full support for “the development, implementation and use of strong encryption” — which would be a very odd position to hold if you also intended to ban E2EE.

Then it discusses “challenges” to public security that flow from criminals having easy access to the same technologies that are used to protect vital civic infrastructure — suggesting criminals can use E2EE to make “lawful” access to their communications “extremely challenging” or “practically impossible”.

This is of course a very familiar discussion in security circles — regularly fuelled by the ‘Five Eyes’ nations’ push for greater surveillance powers — and one which recurs repeatedly in relation to the technology industry owing to developments in communications tech. But note the CoEU does not say access to encrypted data is actually impossible.

Instead the resolution moves on to call for discussion of how to ensure the powers of competent security and criminal justice authorities can be preserved — while ensuring full respect for due legal process and EU rights and freedoms such as (notably the right to respect for private life and communications; and the right to the protection of personal data).

The document suggests a “better” balance should be created between these competing interests. “The principle of security through encryption and security despite encryption must be upheld in its entirety,” is how it’s phrased.

The specific call is for “governments, industry, research and academia… to work together to strategically create this balance”.

Click to access 783284_fh_st12143-re01en20_783284.pdf

Does the draft resolution call for encryption to be backdoored?

No.

Indeed, the Council of Ministers specifically writes [emphasis ours]: “Competent authorities must be able to access data in a lawful and targeted manner, in full respect of fundamental rights and the data protection regime, while upholding cybersecurity. Technical solutions for gaining access to encrypted data must comply with the principles of legality, transparency, necessity and proportionality.”

So the push here — beyond the overarching political push to be seen to be doing something ‘pro-security’ — is for ways to improve targeted access to data but also that such targeting respect key EU principles that link to fundamental rights (like privacy of communications).

That doesn’t sum to an E2EE ban or backdoor.

But what does the resolution say about the legal framework? 

The Council of Ministers want the Commission to carry out a review of relevant existing regulations with relevance to ensure it’s all pulling in the same direction and therefore contributing to law enforcement being able to operate as efficiently as possible.

There is a mention of “potential technical solutions” at this point — but again the emphasis is on any such law enforcement aids supporting the use of their investigatory powers within domestic frameworks that comply with EU law — and a further emphasis on “upholding fundamental rights and preserving the advantages of encryption”. Security of information is a vital advantage of encryption previously discussed in the document so it’s essentially calling for preserving security without literally spelling that out. 

This portion of the draft document has several strike-throughs so looks most likely to be subject to wording changes. But for a signal of the direction of travel one bit of rewording emphasises the need for transparency should there be joint working with comms services providers on developing any “solutions”. (And a backdoor that everyone is told about obviously wouldn’t be a backdoor.)

Another suggestion in the draft calls for upskilling relevant authorities to boost their technical and operational expertise — aka more cyber training for police.

In a final section, joint working to improve relevant co-ordination and expertise across the EU is again highlighted by the CoEU as key to bolstering authorities’ investigative capabilities.

There is also talk of developing “innovative approaches in view of new technologies” — but the conclusion makes a point of stating clearly: “there should be no single prescribed technical solution to provide access to encrypted data”. Aka no golden key/universal backdoor.

So there’s nothing to be worried about then? 

Well, the Commission may feel some pressure over the issue as it works on its new cyber strategy so it could get some political push on specific policy ideas — although we’re unlikely to see anything much on this front before next year. The CoEU isn’t setting out any policy ideas yet. At most it’s asking for help formulating some.

TechCrunch spoke to Dr Lukasz Olejnik, an independent cybersecurity researcher and consultant based in Europe, to get his thoughts on the draft resolution. He agreed there’s no broadside against E2EE in the draft, nor any near-term prospect of legislation flowing from it. Indeed, he suggested the CoEU appears not to know what to do — hence looking to outside experts in academic and industry for help.

“First, there is no talk of backdoors. The message sets things clearly with respect to encryption being important for cybersecurity and privacy,” he told us. “As for the topic of this document, it is a long-term process in the exploratory phase now. Problems and ideas are identified. Nothing will happen immediately.

“It’s not getting even near to banning E2EE. It appears they do not know what to do exactly. So among the ideas is to perhaps set up a ‘high level expert group’ — the document speaks about engaging ‘academia’. This process is sometimes initiated by the Commission to identify ‘recommendations’ which may or may not be used in the policy process. It would then revolve around who would get to be admitted to such a group, and this varies a lot.

“For example the AI group was seen as quite reasonable, while the other dedicated one on disinformation was in fact geared towards the EU media figures rather than researchers or concrete expertise. We do not know where all this will lead.”

Olejnik expressed doubt that the Council could drive legislation on its own in this case, given the complexity involved. “It’s too premature to speak of any legislation,” he said. “Legislative process in the EU can be quite complex to understand but the EU Council would be unable to pull such a complex thing on their own.”

But he did highlight the CoEU’s coining of the phrase ‘security despite encryption’ as a noteworthy development — suggesting it’s unclear where this novel framing might lead in policy terms. So, as ever, the security debate around encryption demands a close eye.

“What I find of particular importance is coining the term ‘security despite encryption’. It is both unfortunate and ingenious. But the problem with this technology policy term is that it may consciously blend policy understanding of (physical?) security with technology security, as guaranteed today by encryption. This puts the two in direct opposition,” he said, adding: “Where the fallout would lead is anyone’s guess. I believe this process is far from over.”

But couldn’t there be a push to introduce some kind of ‘lawful intercept mechanism’ across the EU?

There would be huge challenges to such a step given all the EU legal principles and rights that any mechanism would need to respect.

The CoEU’s draft resolution reiterates this multiple times — highlighting the need for security activity to respect fundamental rights like privacy of communications and principles of legality, transparency, necessity and proportionality, for example.

Domestic surveillance laws in several EU Member States have also recently been found falling short in this regard by Europe’s highest court — so there would be a clear path to challenging any security overreach in the courts.

That means that even if some kind of intercept mechanism could be pushed through an EU legislative process, via enough political will to drive it, there’s no doubt it would face fierce legal challenge and the prospect of being unpicked by the courts.

https://twitter.com/maxschrems/status/1325576358957879299

Asked for a view on the notion put forward in the draft resolution — of seeking a “better” balance between security and privacy — and whether it might be a push towards something like the ‘ghost protocol’ advocated by GCHQ in recent years as an “exceptional access mechanism” (but which critics argue would both undermine user trust and introduce a blanket security risk that’s all but equivalent to a backdoor) — Olejnik told us: “Undermining encryption is a tricky territory because modern technology goes in a direction of more security, not less. In modern security ecosystems it would be hard to imagine a lawful intercept functionality known from the telecommunication infrastructure. For private business it’s also a question of trust. Can the individual users freely move their social interactions online even further? It’s a question measured in billions of dollars.”

What does the Commission say? 

The Commission declined to comment on the CoEU draft resolution — but a spokesperson sent us some general comments on encryption, describing the technology as “an important tool to enhance cyber security and for the protection of fundamental rights, such as privacy, including the confidentiality of communications, and personal data”.

The executive body also noted the concern being raised by the Council, writing: “At the same time, it can also be used by perpetrators seeking a secure channel to hide their actions from law enforcement and the judiciary, making it difficult to investigate, detect and prosecute criminal offences.”

“Member States have on a number of occasions, in different forums in the Council, discussed the challenges linked to the use of encryption for criminal purposes. They have called for solutions that allow law enforcement and other competent authorities to gain lawful access to digital evidence, without prohibiting or weakening encryption directly or indirectly, and in full respect of privacy and fair trial guarantees consistent with applicable law,” it also said.

The executive body added that following its Security Union Strategy, presented in July — which talks about working to “further strengthen cooperation and information exchange, with all the necessary safeguards” as a strategy for fighting crime in the digital age — it will “explore and support balanced technical, operational and legal solutions, and promote an approach which both maintains the effectiveness of encryption in protecting privacy and security of communications, while providing an effective response to serious crime and terrorism”.

This report was updated with comment from the Commission once we’d received it

More TechCrunch

The Series C funding, which brings its total raise to around $95 million, will go toward mass production of the startup’s inaugural products

AI chip startup DEEPX secures $80M Series C at a $529M valuation 

A dust-up between Evolve Bank & Trust, Mercury and Synapse has led TabaPay to abandon its acquisition plans of troubled banking-as-a-service startup Synapse.

Infighting among fintech players has caused TabaPay to ‘pull out’ from buying bankrupt Synapse

The problem is not the media, but the message.

Apple’s ‘Crush’ ad is disgusting

The Twitter for Android client was “a demo app that Google had created and gave to us,” says Particle co-founder and ex-Twitter employee Sara Beykpour.

Google built some of the first social apps for Android, including Twitter and others

WhatsApp is updating its mobile apps for a fresh and more streamlined look, while also introducing a new “darker dark mode,” the company announced on Thursday. The messaging app says…

WhatsApp’s latest update streamlines navigation and adds a ‘darker dark mode’

Plinky lets you solve the problem of saving and organizing links from anywhere with a focus on simplicity and customization.

Plinky is an app for you to collect and organize links easily

The keynote kicks off at 10 a.m. PT on Tuesday and will offer glimpses into the latest versions of Android, Wear OS and Android TV.

Google I/O 2024: How to watch

For cancer patients, medicines administered in clinical trials can help save or extend lives. But despite thousands of trials in the United States each year, only 3% to 5% of…

Triomics raises $15M Series A to automate cancer clinical trials matching

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Tap, tap.…

Tesla drives Luminar lidar sales and Motional pauses robotaxi plans

The newly announced “Public Content Policy” will now join Reddit’s existing privacy policy and content policy to guide how Reddit’s data is being accessed and used by commercial entities and…

Reddit locks down its public data in new content policy, says use now requires a contract

Eva Ho plans to step away from her position as general partner at Fika Ventures, the Los Angeles-based seed firm she co-founded in 2016. Fika told LPs of Ho’s intention…

Fika Ventures co-founder Eva Ho will step back from the firm after its current fund is deployed

In a post on Werner Vogels’ personal blog, he details Distill, an open-source app he built to transcribe and summarize conference calls.

Amazon’s CTO built a meeting-summarizing app for some reason

Paris-based Mistral AI, a startup working on open source large language models — the building block for generative AI services — has been raising money at a $6 billion valuation,…

Sources: Mistral AI raising at a $6B valuation, SoftBank ‘not in’ but DST is

You can expect plenty of AI, but probably not a lot of hardware.

Google I/O 2024: What to expect

Dating apps and other social friend-finders are being put on notice: Dating app giant Bumble is looking to make more acquisitions.

Bumble says it’s looking to M&A to drive growth

When Class founder Michael Chasen was in college, he and a buddy came up with the idea for Blackboard, an online classroom organizational tool. His original company was acquired for…

Blackboard founder transforms Zoom add-on designed for teachers into business tool

Groww, an Indian investment app, has become one of the first startups from the country to shift its domicile back home.

Groww joins the first wave of Indian startups moving domiciles back home from US

Technology giant Dell notified customers on Thursday that it experienced a data breach involving customers’ names and physical addresses. In an email seen by TechCrunch and shared by several people…

Dell discloses data breach of customers’ physical addresses

Featured Article

Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

The Israeli startup has raised $5.5M for its platform that uses “statistical AI” to generate synthetic data that it says is as good as the real thing.

20 hours ago
Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

Hydrow, the at-home rowing machine maker, announced Thursday that it has acquired a majority stake in Speede Fitness, the company behind the AI-enabled strength training machine. The rowing startup also…

Rowing startup Hydrow acquires a majority stake in Speede Fitness as their CEO steps down

Call centers are embracing automation. There’s debate as to whether that’s a good thing, but it’s happening — and quite possibly accelerating. According to research firm TechSci Research, the global…

Retell AI lets companies build ‘voice agents’ to answer phone calls

TikTok is starting to automatically label AI-generated content that was made on other platforms, the company announced on Thursday. With this change, if a creator posts content on TikTok that…

TikTok will automatically label AI-generated content created on platforms like DALL·E 3

India’s mobile payments regulator is likely to extend the deadline for imposing market share caps on the popular UPI (unified payments interface) payments rail by one to two years, sources…

India likely to delay UPI market caps in win for PhonePe-Google Pay duopoly

Line Man Wongnai, an on-demand food delivery service in Thailand, is considering an initial public offering on a Thai exchange or the U.S. in 2025.

Thai food delivery app Line Man Wongnai weighs IPO in Thailand, US in 2025

Ever wonder why conversational AI like ChatGPT says “Sorry, I can’t do that” or some other polite refusal? OpenAI is offering a limited look at the reasoning behind its own…

OpenAI offers a peek behind the curtain of its AI’s secret instructions

The federal government agency responsible for granting patents and trademarks is alerting thousands of filers whose private addresses were exposed following a second data spill in as many years. The…

US Patent and Trademark Office confirms another leak of filers’ address data

As part of an investigation into people involved in the pro-independence movement in Catalonia, the Spanish police obtained information from the encrypted services Wire and Proton, which helped the authorities…

Encrypted services Apple, Proton and Wire helped Spanish police identify activist

Match Group, the company that owns several dating apps, including Tinder and Hinge, released its first-quarter earnings report on Tuesday, which shows that Tinder’s paying user base has decreased for…

Match looks to Hinge as Tinder fails

Private social networking is making a comeback. Gratitude Plus, a startup that aims to shift social media in a more positive direction, is expanding its wellness-focused, personal reflections journal to…

Gratitude Plus makes social networking positive, private and personal

With venture totals slipping year-over-year in key markets like the United States, and concern that venture firms themselves are struggling to raise more capital, founders might be worried. After all,…

Can AI help founders fundraise more quickly and easily?