Encryption is woven into everyday digital life. It protects our messages and passwords, but also banking and payments, health data, government services and the digital infrastructure societies rely on every day. Yet across jurisdictions, governments are increasingly considering laws that expand lawful access to data for law enforcement and national security purposes. In practice, this can mean requiring companies to create new ways to access encrypted data, introduce technical capabilities that bypass existing protections, or make otherwise secure systems insecure. These measures can weaken the very security encryption is designed to provide, with consequences for cybersecurity, privacy, fundamental rights and the wider economy. Canada’s Bill C-22 is the latest example of this trend, raising serious concerns about the security and privacy consequences of expanding government access to data.
For Mozilla, protecting that security is fundamental to both the products we build and the principles we advocate for. One of the foundational principles that guide Mozilla’s mission and work holds that individuals’ security and privacy on the internet are fundamental and must not be treated as optional. Protecting people’s privacy and security is not an aspiration for us, but shapes the products we build every day: Firefox blocks trackers, protects you from profiling via cookies and fingerprinting, comes with malware protection and a built-in VPN, offers HTTPs-only mode and protects your passwords and credit card information by encrypting them.
Some of these protections are being threatened by Canada’s Lawful Access Act, also known as bill C-22. Part two of the bill, the “Supporting Authorized Access to Information Act” (SAAIA) would introduce sweeping new powers to require electronic service providers to build and maintain capabilities that facilitate government access to information. If passed in its current form, companies could be asked to introduce vulnerabilities, build backdoors, bypass, weaken or otherwise defeat encryption, access data before encryption or decrypt encrypted data to provide access to law enforcement. Service providers could also be compelled to retain and access data they have purposefully chosen not to collect.
Let us be clear: there is no safe way to create exceptional access to encrypted data that only the intended actor can use. An access mechanism created for law enforcement can also be discovered, exploited or abused by potentially bad actors.
Such vulnerabilities and backdoors do not only undermine people’s fundamental rights to privacy and data protection, but also the trust and security premises societies everywhere depend on. The same encryption that protects a private conversation also protects financial transactions, sensitive health information, business systems and critical digital services.
Expanding capabilities of AI systems are only exacerbating these risks – governments should encourage the disclosure and patching of vulnerabilities, not compel companies to introduce insecurities deliberately. Only trustworthy and transparently governed digital infrastructures can be the basis for digitally sovereign societies.
We are also concerned by C-22’s scope, which does not stop at Canadian services or users. C-22 expansive surveillance capabilities and data retention obligations would undermine people’s privacy and security everywhere, and the bill’s confidentiality requirements would make it impossible for services to inform their users about security breaches or backdoors introduced.
Guided by our Surveillance Principles for a Secure, Trusted Internet, we call on Canadian policymakers not to rush the legislative process to take experts’ feedback into account in amending C-22 to protect everyone’s security and privacy. Canada’s interests are best served by regulation that protects encryption, strengthens cybersecurity and emphasizes transparency, checks and balances.