UK Government Pauses Demands For Broken Encryption In Its Online Safety Bill

from the citizens-briefly-allowed-continued-access-to-widely-used-services dept

The UK government is still pushing a bill that would give it more direct control of the internet, but it has, at least for the time being, decided against mandating broken encryption.

For months now, supporters of the Online Safety Bill have insisted the only way to stop the spread of child sexual abuse material (CSAM) is to engage in always-on scanning of user content. Services that utilized end-to-end encryption (like Signal, WhatsApp, and Apple’s iMessage) would be forced to break encryption to scan content.

That mandate has provoked an intense amount of backlash from the affected service providers. The three listed above have all informed the UK government that they would pull their services from the UK, rather than comply with this mandate.

As these entities pointed out (on multiple occasions), introducing deliberate security flaws makes everyone less secure, not just those engaged in criminal activity. The government’s own Information Commissioner arrived at the same conclusion: that breaking end-to-end encryption would actually make children less safe and more likely to be targeted/located by sexual abusers.

The good news is that, for the moment, the UK government has decided to drop this mandate, as 9to5Mac reports, quoting from a (paywalled) Financial Times article.

The Financial Times reports that the government has now agreed to drop from the Online Safety Bill the requirement to scan messaging apps for illegal content.

The UK government will concede it will not use controversial powers in the online safety bill to scan messaging apps for harmful content until it is “technically feasible” to do so, postponing measures that critics say threaten users’ privacy.

A planned statement to the House of Lords on Wednesday afternoon will mark an eleventh-hour bid by ministers to end a stand-off with tech companies, including WhatsApp, that have threatened to pull their services from the UK over what they claimed was an intolerable threat to millions of users’ security.

It’s a win, especially for UK citizens, who were facing loss of access to some of the most popular communication services on the planet. But it’s not a complete victory for anyone. Minister Lord Stephen Parkinson still seems to believe it’s possible to compromise encryption without, you know, compromising it. The big nerds at Big Tech just need to work harder at ushering this magical form of technology into existence.

Parkinson said that Ofcom, the tech regulator, would only require companies to scan their networks when a technology was developed that was capable of doing so.

[…]

“As has always been the case, as a last resort, on a case-by-case basis and only when stringent privacy safeguards have been met, [the legislation] will enable Ofcom to direct companies to either use, or make best efforts to develop or source, technology to identify and remove illegal child sexual abuse content — which we know can be developed,” the government said.

Pressing pause on the mandate, but still living in denial. There’s no such thing as securely compromised encryption. Either it’s secure or it isn’t. Just because the security flaws have been introduced by a government mandate doesn’t make these flaws any less exploitable by more malicious entities. And it doesn’t make it any less likely governments with histories of human rights abuses will leverage these mandates and the resulting broken encryption to engage in even more human rights abuses.

It either works or it’s broken. The UK government needs to fully accept this fact if it’s ever going to move on towards actually doing something useful to protect children from sexual abusers. As long as it continues to pretend the impossible is constantly just over the tech horizon, it will only reduce its citizens communication options and put every user of these services — no matter where they’re located — at risk.

Filed Under: , , , ,

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “UK Government Pauses Demands For Broken Encryption In Its Online Safety Bill”

Subscribe: RSS Leave a comment
10 Comments
Anonymous Coward says:

Re: Re:

Our government hasn’t actually dropped it – a junior minister told the House of Lords they won’t use that provision at the moment but they haven’t removed it from the actual bill.

Also the FT article this story is based on is a week old and the UK Government has already denied they agreed to remove or not enforce this:
https://www.independent.co.uk/business/ministers-deny-concessions-as-online-safety-bill-returns-to-commons-b2410089.html

That One Guy (profile) says:

'Nerd Harder', take... I lost count

It’s a nice continuation of the usual shifting of the blame on the subject, claiming that they’ll only force companies to scan everything when there is tech in place to do it ‘securely’ while in the very next breath claiming that said tech is entirely possible to create if only those self-centered tech companies cared enough about the problem to create it.

Anonymous Coward says:

As noted, various governments have been whining about wanting a super-sekrit backdoor that everyone knows will be cracked five minutes after introduction.

What I always wonder about this is how they account for financial transactions. Today’s world economy is built on secure financial communication. It would fall apart without it. Does this bill even address that?

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Subscribe to Our Newsletter

Get all our posts in your inbox with the Techdirt Daily Newsletter!

We don’t spam. Read our privacy policy for more info.

Ctrl-Alt-Speech

A weekly news podcast from
Mike Masnick & Ben Whitelaw

Subscribe now to Ctrl-Alt-Speech »
Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...
Loading...