Multiple Attempts At Government Backdoors

by allsparkinfinite on 2025-03-22

UK

The United Kingdom implemented the Investigative Powers Act in 2016, which set out the limits of electronic surveillance by the government. This was widely unpopular. The law was amended in 2024 to further expand the government's surveillance powers, with one of the provisions requiring all telecommunication providers to be able to decrypt encrypted data - essentially to install an encryption backdoor.

Apple has opted to comply with this order by disabling end-to-end encryption in the UK, rather than to install backdoors, as reported here.
Note: this article, being centered around how Apple is dealing with the law, says that the UK gave itself the authority to compel Apple to break end-to-end encryption. While this is technically true, the law is not targeted specifically at Apple, but at everyone in the digital communications space.

Users of iCloud in the UK soon be unable to access iCloud unless they disable end-to-end encryption - it is the nature of end-to-end encryption that it cannot be disabled remotely without a backdoor, which the UK government wanted in the first place.
You may think "is it really more secure to disable encryption entirely than to install a backdoor for the government?" Assuming a spherical government in a frictionless vacuum, it isn't. Realistically, though, that backdoor will eventually find its way into the hands of criminals, while those that do want to be secure will use other open-source tools, where it is harder for the UK government to enforce its newfound encryption-breaking powers. In other words, the government will only be surveilling those who think "I have nothing to hide", most people will be lulled into a false sense of security, and hackers have been served up a backdoor on a silver platter.

Apple did appeal this law in the court, but it is expected to comply with the ruling until a verdict is given.

Other issues with this bill, as pointed out by Center for Cybersecurity Policy are that the UK government now gains the power to block security updates and that there is limited transparency to keep the government accountable.

France

France's government is in the middle of passing a Drug Trafficking Act, and Article 8 in it would have required all email and messaging services to be able to decrypt user data upon the request of authorities.
Ironically, a French-grown messaging app called Olvid - officially certified by the country's cybersecurity agency and recommended to government officials - would have its encryption weakened as well. If this regulation had come to pass and Olvid did install a backdoor into its encryption, it could choose to decrypt chats without government request (remember, the government holds no keys, only the warrant), potentially obtain sensitive information discussed by government officials, and use that information for either insider trading or blackmail. Or both.

Luckily, the MPs rejected this provision, saving encryption in France until the next time politicians decide that the government's need to investigate supersedes a person's right to privacy against hackers. Or even their right to privacy against an overreaching government.

Closing Remarks

It is impossible to create a system that is insecure against good people but secure against bad people. There is also no such thing as a perfectly secure system, only a system with a minimised attack surface. You could have all the latest and greatest encryption on your devices, but if someone kidnaps you and threatens to beat you up, you will be giving up your passwords.
Now imagine increasing the number of people who could give up your passwords under threat or bribery.