Site navigation

Online Safety Bill: Privacy Experts Challenge Encryption Clause

Elizabeth Greenberg

,

online safety bill
The Online Safety Bill has come under continuous fire for threatening to compromise end-to-end encryption. 

Privacy and security experts across the UK have signed an open letter explaining their alarm at the UK’s proposals to dismantle end to end encryption as part of the draft Online Safety Bill.

Clause 110 of the Bill proposes the scanning of end-to-end encrypted messages prior to their encryption for child sexual exploitation and abuse content.

The clause provides Ofcom with the powers to make tech companies use “accredited technology” to take down child sexual abuse content, including providers of encrypted messages such as WhatsApp, Signal, and Element.

These companies have already claimed they may leave the UK market if encryption is compromised.

According to the open letter, the UK government plans to scan encrypted messages through one of two ways: via a ‘backdoor’ after the messages are sent and protected by cryptography, or on a client-side scanning before messages are encrypted and sent.

The privacy and security experts stipulate that both methods impede privacy rights, increase security risks, and could create a slipper slope towards more state surveillance.

In the case of cryptographic backdoors, the experts said that this method would allow not only the State to view every private message, but any actor with access to the relevent monitoring facilities as well. This increases the security risks already facing nation-states, and would provide third party access to private messages.

Client-side scanning, on the other hand, would require “a mandatory, always-on automatic wiretap” in every device to monitor prohibited content. This is not necessarily a straw-man argument – in order to scan messages prior to them being sent, third party applications will be needed to monitor user activities and messages for prohibited content.

Robin Wilton, Director of Internet Trust at Internet Society, said commented on the proposed technological solutions, saying: “There is no such thing as a safe back door to encryption. If a back door is known to exist, it will be found and exploited by criminals and malicious governments, making everyone less safe.

“Nor is client-side scanning is the answer. Even the Government’s own Home Office-funded prototypes weren’t effective, and would face legal challenges if used.

“Sooner or later the Government must admit that its goals are counter-productive and its proposals don’t work.”

Further, these monitors are not always effective, according to letter’s signatories, and can have further capabilities, like facial recognition, added on. Further, the researchers say that “sufficiently reliable solutions for detecting child sexual exploitation and abuse content do not exist.”

However, earlier in the letter, the signatories did admit that “We cannot speak to the relative merit of this step in preventing harm to children in our professional capacities.” The “step” refers to the monitoring of encrypted messaging.


Recommended


It appears the experts may have the populous on their side: a survey conducted by Element of 2,000 Brits found that the majority (83%) think private messages should remain private from the government, and that 70% say that ending encryption will not stop illegal activity.

Further research shows how much Brits rely on encrypted messaging services to share private information. Polling conducted on behalf of Index on Censorship shows that almost two thirds (61%) of Brits shared information about their children’s health, and over a third (39%) shared their children’s location data on private messaging platforms, with 55% reporting information about their children’s schools.

Jessica Ni Mhainin, Policy and Campaigns manager at Index on Censorship said: “This polling shows once again that the British public do not support the erosion of their privacy. By ending encryption, the Bill mandates government censorship and oversight of private messages by the backdoor: but mass surveillance is not the solution to online safety. Peers must support amendments to stop the monitoring of private conversations.”

Dr Monica Horten, Policy Manager for Freedom of Expression at Open Rights Group said: “This bill will damage the security infrastructure that provides encrypted chat services.“The government insists that Ofcom will not mandate anything that compromises end-to-end encryption. But this is the opposite of what the Bill says. It gives Ofcom powers to require AI-driven screening software installed on everyone’s phones to check their messages before sending.

“That’s not possible without compromising encryption, and should not be put into law without judicial oversight, under human rights law. Better still, peers should act to delete private chat services from this Clause.”

One expert, however, says that the issue is not entirely clear cut.

Brian Higgins, Security Specialist at Comparitech: “The encryption debate surrounding the Online Safety Bill is incredibly divisive. Unfortunately the two sides are polarised to such an extent right now that any potential middle ground is currently a very lonely place.

“Allowing criminals unimpeded use of end-to-end encryption will certainly facilitate the continuation of Child Sexual Exploitation and other activities. This is a fact. Law enforcement are still making arrests after the Encrochat network was infiltrated in 2020. Encryption is a popular criminal tool.

“It’s also worth remembering that Article 8. (in the U.K. and across Europe) is a Qualified Right. A Right which ‘may be interfered with in order to protect the rights of another or the wider public interest’.

“Protecting children from sexual exploitation and the wider citizenry from crime must surely meet this Qualification, so regardless of how many CEOs complain that the Bill will affect their business model the Government are legislating correctly in this instance.

“Is the Bill cumbersome and overly heavy-handed? Yes it is. Should it be re-considered? Yes it should. But just making threats or telling everyone that the right technology doesn’t exist yet so we shouldn’t bother to address the problem at all are unhelpful and irresponsible positions to take. A real expert is someone who is always learning about their field, not just sitting in it and refusing to open the gate.”

Elizabeth Greenberg

Staff Writer

Latest News

Awards Featured Finance Technology

Deadline Extended For Scottish Financial Technology Awards 2026

AI Technology

Glasgow Researchers Test Virtual Agents for Safer Driving

Cryptocurrency Editor's Picks

HMRC Warns Crypto Investors to Pay Their Dues

Events Featured

ScotSoft Returns to Edinburgh This September!