News: 1707981968

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

European Court of Human Rights declares backdoored encryption is illegal

(2024/02/15)


The European Court of Human Rights (ECHR) has ruled that laws requiring crippled encryption and extensive data retention violate the European Convention on Human Rights – a decision that may derail European data surveillance legislation known as Chat Control.

The Court issued a [1]decision on Tuesday stating that "the contested legislation providing for the retention of all internet communications of all users, the security services’ direct access to the data stored without adequate safeguards against abuse and the requirement to decrypt encrypted communications, as applied to end-to-end encrypted communications, cannot be regarded as necessary in a democratic society."

The "contested legislation" mentioned above refers to a legal challenge that started in 2017 after a demand from Russia's Federal Security Service (FSB) that messaging service Telegram provide technical information to assist the decryption of a user's communication. The plaintiff, Anton Valeryevich Podchasov, challenged the order in Russia but his claim was dismissed.

[2]

In 2019, Podchasov brought the matter to the ECHR. Russia joined the [3]Council of Europe – an international human rights organization – in 1996 and was a member until it withdrew in March 2022 following its illegal invasion of Ukraine. Because the 2019 case predates Russia's withdrawal, the ECHR continued to consider the matter.

[4]

[5]

The Court concluded that the Russian law requiring Telegram "to decrypt end-to-end encrypted communications risks amounting to a requirement that providers of such services weaken the encryption mechanism for all users." As such, the Court considers that requirement disproportionate to legitimate law enforcement goals.

[6]Privacy crusaders accuse X of ad-targeting that flouts EU rules

[7]German Digital Affairs Committee hearing heaps scorn on Chat Control

[8]Open Source Policy Summit: Where FOSS and government meet

[9]Scanning phones to detect child abuse evidence is harmful, 'magical' thinking

While the ECHR decision is unlikely to have any effect within Russia, it matters to countries in Europe that are contemplating similar decryption laws – such as [10]Chat Control and the UK government's [11]Online Safety Act .

[12]Chat Control is shorthand for European data surveillance legislation that would require internet service providers to scan digital communications for illegal content – specifically child sexual abuse material and potentially terrorism-related information. Doing so would necessarily entail weakening the encryption that keeps communication private.

Efforts to develop workable rules have been underway for several years and continue to this day, despite widespread condemnation from [13]academics , [14]privacy-oriented orgs , and [15]civil society groups .

[16]

Patrick Breyer, a member of the European parliament for the Pirate Party, hailed the ruling for demonstrating that Chat Control is incompatible with EU law.

"With this outstanding landmark judgment, the 'client-side scanning' surveillance on all smartphones proposed by the EU Commission in its chat control bill is clearly illegal," said Breyer.

"It would destroy the protection of everyone instead of investigating suspects. EU governments will now have no choice but to remove the destruction of secure encryption from their position on this proposal – as well as the indiscriminate surveillance of private communications of the entire population!" ®

Get our [17]Tech Resources



[1] https://hudoc.echr.coe.int/eng/#{%22itemid%22:[%22001-230854%22]}

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Zc3u2X@9QQDde10zCjzwEwAAAEw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.coe.int/en/web/portal

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zc3u2X@9QQDde10zCjzwEwAAAEw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Zc3u2X@9QQDde10zCjzwEwAAAEw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2023/12/14/x_illegally_targeted_ads_suit/

[7] https://www.theregister.com/2023/03/03/german_digital_committee_hearing_heaps/

[8] https://www.theregister.com/2023/02/09/open_source_policy_summit/

[9] https://www.theregister.com/2022/10/13/clientside_scanning_csam_anderson/

[10] https://www.patrick-breyer.de/en/posts/chat-control/

[11] https://www.theregister.com/2023/10/27/online_safety_act_charles/

[12] https://www.theregister.com/2023/03/03/german_digital_committee_hearing_heaps/

[13] https://www.theregister.com/2022/10/13/clientside_scanning_csam_anderson/

[14] https://tutanota.com/blog/posts/germany-against-client-side-scanning-csam

[15] https://freiheitsrechte.org/en/themen/digitale-grundrechte/chatkontrolle

[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Zc3u2X@9QQDde10zCjzwEwAAAEw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[17] https://whitepapers.theregister.com/



Well good thing the UK had Brexit

DS999

They will be able to continue their attempt to go down this path without those Euro do gooders raining on their parade!

Re: Well good thing the UK had Brexit

Filippo

Just in case...

The ECHR is a part of the Council of Europe.

The CoE is not the EU. They are two unrelated things, and they do very different things.

The UK withdrew from the EU, but is still within the CoE.

So the UK is still, in theory, bound by ECHR decisions.

Yes, there are a whole lot of supernational institutions in this continent, they each have their own partially overlapping set of adhering countries, and their nomenclature is extremely confusing.

Re: Well good thing the UK had Brexit

Richard 12

The ECHR is the one that the Tories are currently declaring that they can ignore in their vain attempt to send a couple of hundred people (at most) to Rwanda.

Re: Well good thing the UK had Brexit

Anonymous Coward

I suspect that the Rwanda story is just a facade. There were Tory MPs trying to get the UK out of the ECHR before government ministers even knew where Rwanda is (or what a small boat is, for that matter).

The European Convention on Human Rights stands between the man and woman in the street and what the Conservative Party wants to do to them. That's why they want to get rid the European Convention on Human Rights and the Human Rights Act. There's that old saying that ' the way a government treats refugees is very instructive because it shows you how they would treat the rest of us if they thought they could get away with it ' that feels very apt.

Re: Tory MPs trying to get the UK out of the ECHR

Anonymous Coward

How about those Tory MPs who don't like the ECHR put a provision in place to allow people to opt out of it's protections. Then they can sign up and show us all how much better off they are without this meddling legislation.

Yeah, funnily enough it's always someone else's human rights that should be ignored.

Re: Well good thing the UK had Brexit

Jellied Eel

There's that old saying that 'the way a government treats refugees is very instructive because it shows you how they would treat the rest of us if they thought they could get away with it' that feels very apt.

Except the problem is determining if people are actually refugees, or just economic migrants and thus illegal. Especially given most of the UK's 'refugees' are fleeing from an extremely oppressive France. If they are genuine refugees, there's no reason why they couldn't apply for asylum or refugee status in any of the EU countries they've passed through on the way to France or in France itself. Then if they are determined to be illegal, we should be able to deport them back to country of origin, or entry.

Re: Well good thing the UK had Brexit

Necrohamster

Britain doesn't like to be reminded of it, but it invaded and colonised plenty of countries over the years. Think of this as the universe's way of giving something back to you.

Re: Well good thing the UK had Brexit

Jellied Eel

Britain doesn't like to be reminded of it, but it invaded and colonised plenty of countries over the years.

The Italians, French, Dutch, Scandanavians also did the same to us. Where's our reparations? I'm still puzzled why France can't police it's borders, or so may people are desperate enough to risk their lives escaping France for the UK.

Re: Well good thing the UK had Brexit

Doctor Syntax

And assorted North Africans, AKA Barbary Coast pirates.

Re: Well good thing the UK had Brexit

Necrohamster

Ah, whataboutism...

Unfortunately for the purpose your argument, the crimes of others don't excuse your own crimes.

I suggest you write a strongly-worded letter to the French ambassador.

Re: Well good thing the UK had Brexit

Anonymous Coward

The old French Letter trick!!

Re: Well good thing the UK had Brexit

Anonymous Coward

I am under the impression that part of the allure of Britain is the fact that many of these people know some English, and it's not as widely used in mainland Europe. But maybe I'm wrong.

Re: Well good thing the UK had Brexit

Anonymous Coward

Economic migration is legal, in case you hadn't noticed. The vast majority of immigration into this country is, in fact, legal and for economic reasons.

But I know your posting history and can assume only you're a Mail / GB News / Express subscriber.

Re: Well good thing the UK had Brexit

Doctor Syntax

Legal with a visa, illegal without.

Re: Well good thing the UK had Brexit

Necrohamster

Not strictly true. Irish citizens (who are also EU citizens) don't need a visa to enter the UK, nor do they need to apply to the "EU Settlement Scheme"

Re: Well good thing the UK had Brexit

Necrohamster

"But I know your posting history and can assume only you're a Mail / GB News / Express subscriber."

If that's directed at me, I can only say you haven't analysed my post history very well

Re: Well good thing the UK had Brexit

Binraider

Indeed, and there are a bunch of muppets that have gotten far too much influence now talking about leaving the CoE because they can't run their internment camps and exfiltration programs the way they want to.

If anyone is in any doubt to the dangers that these morons are pushing for in the name of "taking back control" and "claims on sides of buses" then this should be it.

GB News watchers will be GB News watchers though.

Re: Well good thing the UK had Brexit

Necrohamster

I look forward to tens of replies to your comment from people who don't know the difference between:

the European Convention on Human Rights (ECHR)

and

the European Court of Human Rights (ECtHR)

TheMaskedMan

"EU governments will now have no choice but to remove the destruction of secure encryption from their position on this proposal"

That seems unreasonably optimistic to me. No government is going to abandon such a long soughtafter goal - the urge to monitor all the things, all the time is far too deeply ingrained. If this finding cannot be overturned or kicked into the long grass, it will be worked around or just plain ignored.

Anonymous Coward

I think the stress in the judgement may be

"the security services’ direct access to the data stored WITHOUT ADEQUATE SAFEGUARDS AGAINST ABUSE and the requirement to decrypt encrypted communications, as applied to end-to-end encrypted communications, cannot be regarded as necessary in a democratic society"

The ECHR includes exceptions eg "interests of national security" and "territorial integrity or public safety" under Right of Expression

jmch

"the requirement to decrypt encrypted communications, as applied to end-to-end encrypted communications, cannot be regarded as necessary in a democratic society"

This part of the ruling, though, is absolute (before even considering technically impossibility of having only the 'good guys' able to decrypt e2e encrypted comms and not the 'bad guys' (and further, before even considering the moral and social impossibility of knowing who are the 'good guys' and 'bad guys'))

Anonymous Coward

There is [1]an interesting thread on Mastodon about whether this ruling also covers client side scanning and the UK's Online Safety Act. British internet lawyer Neil Brown seems to think it may not.

[1] https://akademienl.social/@Frederik_Borgesius/111928798458137059

Necrohamster

Something like legislation never stopped the spooks.

Britain gets the US to do the dirty work and pass along the required info, and vice versa.

Dr Dan Holdsworth

The goal of monitoring everyone is apparently so attractive to the American government that they have huge data warehouses that store harvested encrypted comms in the rather vain hope that at some point in the near-enough-to-be-useful future they will happen upon a magical encryption decryption tool that will enable them to break these communications and do something useful with the data.

In the mean time, it isn't their money that they are wasting, but merely that of the American citizenry so they continue to store petabytes of useless garbage.

All in all, this is basically really rather silly. Most criminal enterprises require the participants to actually do something, whether this be sell small packets of dubious powder or wave guns at bank clerks and so on. Modern interception can tell who is talking to whom for the most part (criminals have yet to be brave enough to encrypt their messaging and stick it on Usenet for all to see, but not see who it is intended for) and thus knowing that at least a few in a network are known wrong 'uns would lead one to the strong suspicion that the entire network is mostly criminal and all members ought to be briefly scrutinised.

Of course this does fall flat if a few bank robbers are also part of an internet knitting club and are covertly exchanging patterns, but then that's what policing is supposed to sort out.

Cue Daily Heil headline "Euro Court Won't Protect Our Children"

Empire of the Pussycat

The post is required, and must contain letters.

Re: Cue Daily Heil headline "Euro Court Won't Protect Our Children"

b0llchit

Indeed! A really bad headline would be "Euro Court Protects Everybody".

Re: Cue Daily Heil headline "Euro Court Won't Protect Our Children"

Jellied Eel

It's not just the Daily Fail, others are at it as well-

https://www.bbc.co.uk/news/uk-68300969

Brianna Ghey's mother Esther says Online Safety Act does not go far enough

"The [Online Safety Act] is not going to protect children and young people from seeing that kind of horrible content because I don't think that would be deemed as harmful."

But defining harmful is a wicked problem to do at the (nanny) state level..

"The way they have been created, it's based on the [gambling model]," she said. "It's [about] having that constant gratification from people.

"When I was young, it was so much easier to parent. Now the introduction of smart phones and the access to the online world, social media, it's just made everything 10 times more difficult."

She said smartphone companies have a "moral responsibility" to protect young people from the dangers of the internet, and should not just be focused on profit.

Sadly, parents also have the same moral and legal responsibility. Kids spending too much time on their phones? Take them off them. Kids surfing stuff you'd rather they didn't? Explain to them why they shouldn't, or take their phones off them. What is really needed are smartphone companies, ie mostly Apple and Android to create parent/child relationships between devices so that parents can monitor what their children are up to. But too many parents seem to want to push parental responsibilities onto the State, or innocent SPs. Or too many parents are just irresponsible and don't know how to, or want to parent properly. So we end up with tragedies like this.

She told the BBC's Breakfast programme that it was "not feasible" to expect parents to be able to work full time, raise children and run a home, while also requiring them to be on top of the latest technology.

Tough. It's the responsibility of the parent to do this, legally and morally. If parents don't understand what their kids are doing with their phones... maybe, just maybe don't let them have them, or at least monitor them a bit more carefully. There's no way an SP is going to be able to correlate mobile data with any mood or behaviour changes in a kid, but parents can and should be able to do this.

SnailFerrous

Assorted governments ask their lawyers "Does it still count if we don't tell any one we are doing it?"

Anonymous Coward

So, you have heard of the NSA...

Anonymous Coward

I find it astonishing that this spectacularly bad idea keeps showing up. If you need any help understanding why it is a bad idea, go to Amazon and search for 'TSA key'. That's what happens to protected information (say, credit card details) if that backdoor key leaks, and it will.

Besides, I don't understand why they need more access. Don't they get enough from Microsoft already?

re: Don't they get enough from Microsoft already?

Anonymous Coward

Grey beard alert.

If you genuinely think MS are the tracking problem, and not Google's snooping hand held devices, you are about 30 years out of date. How much live location data do you think Microsoft has? Enough to do a traffic map like Google can with the Android device locations?

Try and keep up with who it's cool to hate. MS just aren't that relevant any more.....

Re: re: Don't they get enough from Microsoft already?

Jellied Eel

Try and keep up with who it's cool to hate. MS just aren't that relevant any more.....

I think they are, they're just not mobile. Why else is that Microsoft Seach process always running in the background? And yet when we try to search for documents or stuff we know exists on our PCs, Search can't find it.

Plus MS has always been rumored to have backdoors anyway. Or instead of expecting poor'ol ISPs to intercept and decrypt traffic in transit, it would be a lot easier and more effective to put that burden on the OS vendors instead. Especially as they're always constantly rummaging through our personal information in an effort to flog us stuff anyway. But I also hope this decision may be extended to prevent the data rapists doing this as well.

Re: I find it astonishing that this spectacularly bad idea keeps showing up.

EricM

Easy.

Simple sounding but stupid ideas appeal to people working in governments the same way as they appeal to the general population voting for the strong but stupid guy touting thge easy path forward...

Problem solved

Herring`

The method for cracking encryption is known and public. Yes it would take an unfeasible amount of computing power for a ridiculous amount of time, but your message provider can explain how to decrypt messages to the security services. Job done.

More realistically though, the actual issue seems to be not with the amount of intelligence data, but the lack of staff to do anything about it. MI5 knew about the Manchester Arena bomber months before it happened, but didn't have the resources to follow it up.

Re: Problem solved

Doctor Syntax

"MI5 knew about the Manchester Arena bomber months before it happened, but didn't have the resources to follow it up."

And quite a few others IIRC.

Three cheers...

jmch

...for the European Court of Human Rights!!!

Puzzled....Again!!

Anonymous Coward

Quote: "...the requirement to decrypt encrypted communications, as applied to end-to-end encrypted communications...."

(1) But why do ALL discussions about "encryption", "decryption", "end-to-end encrytion" and similar...why do all these discussions ASSUME that the discussion applies to services provided by huge internet service providers? (Such as Meta, Signal, Telegram, Apple, SWIFT....)

Another quote: "Doing so would necessarily entail weakening the encryption that keeps communication private."

Yes.....but mostly for users of aforementioned huge internet providers.

(2) In actual fact, NOTHING AT ALL prevents groups of users implementing their own encryption, irrespective of service providers, so that these users can "keep communication private".

(3) So....private encryption IN ADDITION to the end-to-end encryption in, for example WhatsApp, probably provides more difficulties for snoops, and another help to "keep communication private".

To get to the point.....this ASSUMPTION about internet service providers is being used to subcontract "privacy" to internet service providers....when people need to take personal responsibility for their own privacy!!

Re: Puzzled....Again!!

Kevin Johnston

I would mostly agree with this but by extension anyone who is using private encryption becomes 'of interest' so in essence they are trashing the privacy of 99.999% of people so they can see who the targets actually are

Kind of like the idea of shooting everyone and letting $Deity sort out which are the good guys and which are the bad

Re: Puzzled....Again!!

Anonymous Coward

@Kevin_Johnston

So.....just because I'm responsible for my own privacy.....I'm automatically a "person of interest". And how does that personal responsibility affect anyone else?

I thought "personal responsibility" was one of the foundations of an open society! Sad that you imply otherwise!

Re: Puzzled....Again!!

Doctor Syntax

Don't complain to Kevin, complain to your MP or whatever party. (Who will almost certainly, given that there's an election in the offing, reply with a platitude but otherwise ignore you.)

Re: Puzzled....Again!!

Jellied Eel

(2) In actual fact, NOTHING AT ALL prevents groups of users implementing their own encryption, irrespective of service providers, so that these users can "keep communication private".

Actual fact. For many years, encryption was illegal in France. I have my WMD RSA t-shirt from those days. So nothing at all prevents politicians going back to declaring any non-backdoored or official, weak encryption is illegal. Then anything an ISP can't decrypt is obviously evidence of criminal activity (a lot of MMO game traffic is encrypted) and so the participants must be hanged by their thumbs until they've coughed up their decryption keys.

Politicians of course will be exempt. Mainly to stop miscreants compromising their devices and spoofing conversations between them and endpoints in Russia, China, DPRK etc. Well, it wouldn't stop the compromises, but it would stop politicians being thrown in jail for not being able to decrypt 'their' traffic. Unfortunately.

Re: Puzzled....Again!!

Doctor Syntax

"Politicians of course will be exempt."

They'll backdoor their communications anyway. One of them will hand over all their messages to a journalist who's going to ghost write their autobiography for them and then publish elsewhere whatever else they find of interest.

Tubz

OK, don't cancel me but I voted for Brexit and still believe in it, if done properly with UKGov and EUssr discussing like adults and not two old senile woman arguing over a fence, but also believe that the UK must stay in ECHR as a check against governments overreaching the power we gave them to make decisions on our behalf.

Filippo

I have a poor opinion of Brexit, but you seem to have actually thought about the issue, and having an articulated stance that involves the difference between EU and ECHR gains you a lot of respect from me. However, I have to note that using terms like "EUssr" kinda undermines the objective of "discussing like adults".

Necrohamster

"...EUssr..."

Yeah I stopped reading your clearly intelligent and well-thought-out post after that.

Even if you hadn't admitted to voting for Brexit we could've figured it out pretty quickly

gryphon

Unfortunately Douglas Adam's old comment about lizards / politicians comes to mind.

If anyone ever wants to run for office then they should automatically be excluded from doing so.

If AI carries on we'll end up with Asimov's idea of 'The Voter', one person deciding the entirety of the govt. from a discussion with a computer.

Jellied Eel

If AI carries on we'll end up with Asimov's idea of 'The Voter', one person deciding the entirety of the govt. from a discussion with a computer.

I also like Alistair Reynolds "The Prefect". That has an interesting take on democracy-

https://en.wikipedia.org/wiki/The_Prefect

All habitats in the glitter band represent a different format of society, all linked by the common right to vote. A giant computer network runs thousands of polls everyday to decide the general actions of the Glitter Band as a whole.

Your privacy is very important

Anonymous Coward

Trust us, we know.

Thank you citizen, move along.

Fill what's empty, empty what's full, scratch where it itches.
-- Alice Roosevelt Longworth