EU v/s Encryption

by allsparkinfinite on 2025-05-17

The tech culture in USA and in Europe are quite different when it comes to privacy. The EU has stronger data protection laws, and companies looking to exploit user data generally find less success in Europe. Tuta, a company offering private email and cloud storage, is located in Germany. Proton, a similar company which also offers a VPN, is in Switzerland. Other privacy-and-digital-ownership-affirming tech companies also tend to be based in Europe.

This doesn't mean that Europe is a bastion of privacy and digital rights. Digital rights can be eroded and we must stay alert and fight back.

Switzerland's Surveillance Law

Switzerland is considering an amendment to its surveillance laws that would enforce VPNs, messaging apps, and social networks to keep more logs on users. While encryption is not currently being touched, the government wants to enforce identification for all users of major platforms (defined as exceeding either $100 million in turnover or 5000 active users), and for the platform to maintain logs on who talks to whom. This monitoring already exists for mobile networks and ISPs, and the new legislation would simply expand the set of platforms subject to these log-keeping rules.

Proton claims the new laws would make it "less secure than Google", which is an exaggeration in my opinion. However, the laws would force Proton to change its strict no-logs policy, something that Proton's leadership is unwilling to do. Proton would then have no choice to leave Switzerland, a sentiment echoed by NymVPN - a new player in the privacy-respecting VPN market.

The time window for public commentary ended on the 6th earlier this month and now we wait for the government's decision.

European Union's ProtectEU

The European Union previously considered an act called Chat Control which aimed to create backdoors in encryption, in order to ensure no CSAM is shared over encrypted channels. While the intent is noble, it is not possible to have encryption that is strong against snoopers while simultaneously being decryptable by those with the purest of hearts. Any ways to bypass encryption can be exploited by hackers, by rogue actors within the government/company, or even by an authoritarian policy.

How do we reconcile an individual's right to privacy with the government's duty to protect its citizens?
The answer already exists: warrants. We already have systems where law enforcement needs a judge's permission to enter a person's home. This is not a perfect solution but it leaves a trail of accountability, allowing for a better balance between privacy and law enforcement. An encryption backdoor would be a tool for surveillance that can be used silently and without accountability. Proposed solutions - like client-side scanning-and-reporting - may appear privacy-respecting on the surface, but ultimately are flawed and allow bulk surveillance.

Even from a governance perspective, having strong end-to-end encryption is a prerequisite for national security, a recent example being the Salt Typhoon attack. This saw Chinese government-sponsored hackers being able to monitor telecom traffic in the USA. Detection is not everything, as the FBI could not get the attackers out of the systems (as of 5 December 2024) even months after detecting them. The hackers managed to intercept phone calls of high-profile individuals, using systems used by law enforcement for surveillance.
"Government backdoors can be misused by hackers" is not purely hypothetical.

The Cybersecurity and Information Security Agency recommended Signal for securing sensitive conversations, and with good reason. Signal's end-to-end encryption is designed in such a way (and has been audited by cybersecurity experts) to be secure even if the communication is being monitored.