The proposed bill contains a clause that would allow the use of a tool to flag when people are trying to share illegal images in a practice called client-side scanning, where messages could be scanned before being encrypted and sent.
However many are pushing back against the use of this tool, as pro-active scanning of supposed encrypted messages erodes the purpose of end-to-end encryption all together.
In the open letter, stakeholders remind Chloe Smith – the secretary of state at the Department for Science, Innovation and Technology – that scanning encrypted messages would involve providers such as WhatsApp to form a work-around, potentially opening up an avenue for threat actors on the whole network.
“It is not possible to create a backdoor that only works for “good people” and that cannot be exploited by “bad people.” read the open letter by the Open Right Group (ORG).
In an interview with the Guardian in April, WhatsApp chief Will Cathcart said he would rather leave the UK than weaken the app’s encryption. “Ninety-eight per cent of our users are outside the UK,” he said in an interview with the Guardian. “It would be an odd choice for us to choose to lower the security of the product in a way that would affect those 98% of users.”
According to ORG, client-side scanning would see the UK become the first liberal democracy to mandate routine scanning of individuals’ private chat messaging. Further, the technology could be used to search private messages and perform facial recognition according to a study by Imperial College London.
Dr Yves-Alexandre de Montjoye, the author of the Imperial College London study said: “It is our opinion that client-side scanning is not the innocuous ‘single purpose’ technology it has been described to Parliament as.
“We call on policymakers to thoroughly evaluate the pros and cons of client-side scanning, including the risk of it being abused, before passing laws that could result in its installation on millions of phones.”
Recommended
- How MadeBrave is Fostering Creativity in a Post-Pandemic Workforce
- New KPMG Report Shows the Jobs Potentially Most Impacted by AI
- Tech Figureheads Gather for First DSIT Startup Board Meeting
The UK government maintains that client-side scanning would not compromise message privacy.
However, the ORG open letter points out that the scanning software would need to be pre-installed on people’s phones without their full awareness. The underlying databases for that software could be targeted by malicious actors, leaving individual users’ phones domestically and internationally vulnerable to attacks.
“As an international community, we are deeply concerned that the UK will become the weak link in the global system. The security risk will not be confined within UK borders. It is difficult to envisage how such a destructive step for the security of billions of users could be justified,” read the letter.
The bill is currently in the report stage in the House of Lords, before the 3rd reading. After this stage, the bill will enter the consideration of amendments phase before receiving Royal Assent.





