- Apple and Meta oppose Canadian Bill C-22, they warn that the legislation could force them to break encryption and insert backdoors into their products.
- Law enforcement supports the bill as a tool to investigate security threats faster, but civil liberties groups warn it could eternally damage privacy rights and cybersecurity for all Canadians.
- The Canadian bill follows a UK order that prompted Apple to remove encrypted cloud storage features from British users, but officials later dropped that demand after US intelligence raised concerns.
Bill C-22 is currently up for debate in the House of Commons and has created an ongoing battle between large technology firms and government representatives. The tech giants, Apple and Meta, have raised objections against this law, stating that it will require them to compromise their encryption of users’ data.
The bill comes from Canada’s ruling Liberal Party, which was able to pass its legislation by gaining its own parliamentary majority last month. While Canada pushes forward with encryption-breaking legislation, some US states are moving in the opposite direction. California recently chose to abstain from a federal anti-privacy bill, preserving stronger privacy protections for its residents amid growing concerns about government overreach.
Government officials have taken a supportive approach to this bill by arguing that this law would assist law enforcement agencies in identifying potential security threats sooner and responding to those threats faster. The tech companies see things very differently. They warn that the bill, depending on how officials implement its provisions, could resemble a UK data access order that Apple faced last year.
Apple Refuses to Create Security Holes in Its Products
Apple has issued a firm response regarding its perspective. The company stated that with malicious actors continuing to pursue access to consumer information, the passage of Bill C-22 will reduce their ability to provide their users with the privacy and security features they expect from the company.
The legislation could let the Canadian government force companies to break their encryption by creating backdoors into some of their products. According to Apple’s statement, they will never perform this act.
End-to-end encryption allows only the person with a key to access specific information – neither Apple, Meta, nor law enforcement agencies have access to these records without a user’s private key. Services such as Apple’s iMessage and Meta’s WhatsApp use this technology to encrypt billions of messages every day.
Security experts agree that creating backdoors for police would create openings for criminals, too. Any weakness deliberately built into encryption would inevitably be exploited by hackers, foreign spies, and organized crime groups.
Meta Calls the Bill Dangerous and Overbroad
Meta prepared testimony for the parliamentary hearings on the bill. Rachel Curran, the company’s head of public policy for Canada, and Robyn Greene, its privacy and public policy director, wrote that the bill’s minimal oversight, sweeping powers, and lack of adequate safeguards could actually make Canadians less safe.
The legislation could require companies like Meta to build capabilities that weaken, break, or circumvent encryption. Also, it could force providers to install government spyware directly onto their systems.
Some civil liberties groups are working with the tech companies to oppose the legislation. According to a statement from the Canadian Civil Liberties Association, this bill has fundamental flaws that represent a strong risk to privacy rights in the country.
Open Media, which promotes digital rights, claims that there is no back door available to law enforcement that cannot also be exploited by other criminal actors. Any security feature created for police use will eventually face criminal abuse.
The Bill Follows a Troubling Global Pattern
Bill C-22 continues a broader push by governments worldwide to gain lawful access to encrypted data. The United Kingdom attempted a similar move last year when officials demanded that Apple provide blanket access to all encrypted user content stored in the cloud.
Apple refused that demand and instead removed its Advanced Data Protection feature from British users. US officials later stated that Britain dropped the request after Director of National Intelligence Tulsi Gabbard highlighted the concerns about potential violations of a cloud data agreement.
The Internet Society warned that similar encryption-breaking powers in Canada could harm the economy and national security. Natalie Campbell, Senior Director at the Internet Society, stated that the Salt Typhoon digital espionage campaign exploited an authorized backdoor within US telecommunications. She warned that Canada could face similar attacks if the bill passes.
Public Safety Canada attempted to reassure critics, stating that the law would not require technology firms to introduce systemic vulnerabilities into their encryption protections. However, Apple and Meta remain unconvinced, pointing to the UK incident as proof of where such laws can lead.
Share this article
About the Author
Farwa is an experienced InfoSec writer and cybersecurity journalist skilled in writing articles related to cybersecurity, AI, DevOps, Big Data, Cloud security, VPNs, IAM, and Cloud Computing. Also a contributor on Tripwire.com, Infosecurity Magazine, Security Boulevard, DevOps.com, and CPO Magazine.
More from Farwa SajjadRelated Posts
Google and FBI Disrupt NetNut Residential Proxy Network Used by 2M+ Devices
Google worked with the FBI and Lumen to disrupt the NetNut residential proxy network, also known as ...
Opera Launches Paste Protect to Block ClickFix Clipboard Attacks
Opera’s Paste Protect blocks harmful commands from reaching the clipboard, preventing ClickFix...
Reddit Introduces Mandatory Age Verification for EU Teens Accessing NSFW Content
Reddit will require European Union users under 18 to verify their age before viewing mature or NSFW ...
Popular ‘Adblock for YouTube’ Chrome Extension Found With Remote Code Execution Risk
The popular “Adblock for YouTube” Chrome extension now carries an architectural weakness...
Texas Hunting and Fishing License Data Breach Affects 3 Million Customers
Approximately 3 million Texas hunting and fishing license customers were affected by a data breach i...
FBI Warns of ‘Kali365’ Subscription Service Targeting Microsoft 365 Accounts
The FBI’s sounding the alarm on Kali365, a site where criminals can pick up ready-to-use tools for s...