Technologists broadly agree that end-to-end encryption E2EE is one of the best tools to secure data. Nonetheless, governments around the world have proposed legislation that would compromise communications security by undermining encryption. Proposals include giving law enforcement a key to encrypted communications as well as imposing a “duty of care” on communications service providers to detect and block child sexual abuse material (CSAM) and terrorist content. To detect such information, providers must be able to access it, and that access defeats the protection promised by E2EE
Various schemes that purport to provide such access while preserving E2EE — such as client side scanning and adding a secret “ghost” participant to otherwise private chats — all create security risks. Alternatives to compromising encryption, such as the analysis of metadata and enhancing the ability of users to report objectionable content, are partial solutions, but are preferable to compromising communications security.
Latest Insights
Canadians Value Encryption and Reject Key Surveillance Powers in Bill C-22
Canadian Government Proposes Legislation To Enable Encryption Backdoors
Meta’s Rollback of Encryption on Instagram Undermines Privacy and Civil Rights
Global Encryption Coalition Steering Committee Statement on Council of the EU Position on the European CSA Regulation
CDT Europe Feedback on the Danish Presidency’s Proposal on the Child Sexual Abuse Regulation
CDT Joins Partners Around the World for Global Encryption Day