Site navigation

Encryption: The UK’s Stalemate Between Security and Surveillence

Elizabeth Greenberg

,

UK encryption
Companies like Apple would rather remove their security features from the UK rather than compromise on encryption, but why has this become such a pivotal issue? 

The battle surrounding encryption is reaching new heights after Apple’s decision to withdraw its Advanced Data Protections from the UK rather than compromise its end-to-end encryption services following a request from the UK government.

In an unprecedented move late last week, Apple decided to pull its highest-level data protection tool from customers in the UK following a request from the UK Government – supposedly from the Home Office, according to sources close to the BBC and the Washington Post – to see encrypted data about Apple users.

Just days after this announcement, the Open Rights Group released a blog describing efforts to dismantle or create backdoors to encryption as ‘misguided’ and potentially jeopardising privacy whilst enhancing surveillance.

The issues surrounding encryption, its arguments for and against, are becoming ever more opaque as we try to navigate a space in which one end lies over-encroachment from government where accusations of fascism aren’t so hyperbolic. On the other hand, as the Open Rights Group Warns, there’s legitimate threats of continued terrorism, child abuse material, and crime that thrives on the protections offered by encryption.

The erosion of privacy rights has been a slow-moving but ongoing effort from law enforcement, which scorns end-to-end encryption as a shield for heinous criminal activity, the camouflage of terrorists, the purveyor of a parent’s worst nightmares.

Encryption laws came to a head in the UK as the Online Safety Act stumbled its way through the parliamentary process, eventually without stipulations to enable the use of client-side scanning or the creation of encryption backdoors.

Tech experts long warned of the impracticality of backdoors, client side scanning, and any interference with full end-to-end encryption. The creation of a backdoor for law enforcement to scan messages or access private data would also allow cyber-criminals to exploit the same backdoor, essentially negating the point of encryption in the first place.

“You can’t have encryption that has a back door for only the so-called “good guys” that isn’t then exploited in some ways by the bad guys,” Meredith Whittaker, president of Signal, an encrypted messaging platform, said to the Open Rights Group.

The argument seems to be stuck in a stalemate, with tech companies often unwilling to bend the knee even further to encroaching law enforcement requests to disable encryption.

What Happened with Apple?

The UK Home Office supposedly issued a notice to Apple, requesting it to create a backdoor to its end-to-end encryption for law enforcement, enabling the Home Office to scan messages that are meant to be private.

When asked by the BBC, the Home Office would neither confirm nor deny the existence of the request, stating: “We do not comment on operational matters, including for example confirming or denying the existence of any such notices.”

Apple, instead of creating such a backdoor, withdrew its Advanced Data Protection (ADP) offering from the UK, meaning that UK users will not have some of their stored data protected by end-to-end encryption.

“As we have said many times before, we have never built a backdoor or master key to any of our products, and we never will,” Apple said in a statement.

Users in the UK will now no longer be able to access this service, and existing users will have their service disabled.

Rather than have its encryption offering be dismantled or tampered with, Apple has chosen to withdraw the service.

However, the story does not stop there.

The UK is looking to enforce a monitoring protocol for encrypted messaging services as part of its Online Safety Act, which is currently undergoing a consultation.

Parliament is looking at potentially enabling client-side scanning, which it says will not infringe on people’s privacy. Client-side scanning typically entails that each message be pre-emptively scanned for illegal or criminal material prior to it being sent to its intended recipient, and then encrypted following this scan.

Eighty civil society organisations, academics, and cyber-experts have refuted the idea that client-side scanning or monitoring does not break with encryption and its intended assurances. It would not only invade privacy, increase the surveillance powers of the state, but it would also make people more vulnerable to hacking.


Recommended


A False Choice

Offering partial encryption, or monitored encryption, seemingly presents the perfect solution to ensure privacy whilst allowing for the monitoring of criminal activity and the prevention of the spread illegal content.

However, allowing for scanning would enable surveillance and the production of false positives, the Open Rights Group warned

The Council of Europe said that message scanning is a disproportionate response to address the spread of child sexual abuse material, despite this being the main argument for its use in the UK.

The current proposal in the UK would “apply without distinction to all the persons using that specific service, without those persons being, even indirectly, in a situation liable to give rise to criminal prosecution,” the Council warned.

Essentially, the monitoring has similar parallels to the increased use of CCTV across the UK – those who are not committing a crime or offence have little to fear. However, the monitoring of private messages is different from public acts, the requirements for continuous and labours monitoring, the targeting of certain groups, and the amount of false positives, are exacerbated in the cyber space.

The sheer amount of text messages sent, the requirement for monitoring from machines and people, and the amount of false positives flagged, can make the task seem insurmountable.

The Open Rights Group also pointed out the hypocrisy of the UK government’s moves to remove true end-to-end encryption, as politicians, journalists, and those with high-risk jobs typically use some of the most protected messaging platforms to ensure their security.

“End-to-end encryption exists, it works, and it makes sense. Tech companies know it and privacy campaigners know it. But so too do citizens. And, frankly, so too do policymakers,” Ciaran Martin, former head of the National Cyber Security Centre told the Open Rights Group.

Further, cyber-experts continue to warn that the happy medium the UK government claims is achievable to reach with encryption is simply impossible to achieve when faced with the technological reality.

“The consensus among cybersecurity experts could not be clearer: there is no way to provide government access to end-to-end encrypted data without breaking end-to-end encryption, thus putting every user’s security and privacy at risk,” a joint letter from the Global Encryption Coalition said.

As nations that once championed ideas of freedom and democracy continually fall to populist, fascist rhetoric, endangering more and more groups of people and increasingly relying on fear and hatred to secure power, vigilance against moves for increased surveillance is more paramount that ever before.

Policy will always come behind advancing technology, and those in control of the state are often not experts in the technology they rely on to stay secure, maintain privacy, or mitigate crime.

As companies continue to work with increasingly right-wing governments, it is vital privacy protections of individuals are protected as states attempt to increase their surveillance powers.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data