The Senate’s Draft Encryption Bill Is ‘Ludicrous, Dangerous, Technically Illiterate'

In fact, the Burr-Feinstein bill is so bad for privacy that it may be good for privacy in the long run, say experts.
Image may contain Building Architecture Dome Symbol and Flag
Getty Images

As Apple battled the FBI for the last two months over the agency's demands that Apple help crack its own encryption, both the tech community and law enforcement hoped that Congress would weigh in with some sort of compromise solution. Now Congress has spoken on crypto, and privacy advocates say its "solution" is the most extreme stance on encryption yet.

On Thursday evening, the draft text of a bill called the "Compliance with Court Orders Act of 2016," authored by offices of Senators Diane Feinstein and Richard Burr, was published online by the Hill.1 It's a nine-page piece of legislation that would require people to comply with any authorized court order for data---and if that data is "unintelligible," the legislation would demand that it be rendered "intelligible." In other words, the bill would make illegal the sort of user-controlled encryption that's in every modern iPhone, in all billion devices that run Whatsapp's messaging service, and in dozens of other tech products. "This basically outlaws end-to-end encryption," says Joseph Lorenzo Hall, chief technologist at the Center for Democracy and Technology. "It's effectively the most anti-crypto bill of all anti-crypto bills."

Kevin Bankston, the director of the New America Foundation's Open Technology Institute, goes even further: "I gotta say in my nearly 20 years of work in tech policy this is easily the most ludicrous, dangerous, technically illiterate proposal I’ve ever seen," he says.

The bill, Hall and Bankston point out, doesn't specifically suggest any sort of backdoored encryption or other means to even attempt to balance privacy and encryption, and actually claims to not require any particular design limitations on products. Instead, it states only that communications firms must provide unencrypted data to law enforcement or the means for law enforcement to grab that data themselves. "To uphold the rule of law and protect the security and interests of the United States, all persons receiving an authorized judicial order for information or data must provide, in a timely manner, responsive and intelligible information or data, or appropriate technical assistance to obtain such information or data."

Hall describes that as a "performance standard. You have to provide this stuff, and we're not going to tell you how to do it," he says. George Washington Law School professor Orin Kerr points out on Twitter that the text doesn't even limit tech firms' obligations to "reasonable assistance" but rather "assistance as is necessary," a term that means the bill goes beyond current laws that the government has used to try to compel tech firms to help with data access such as the All Writs Act.

Even more extreme, the draft bill also includes the requirement that "license distributors" ensure all "products, services, applications or software" they distribute provide that same easy access for law enforcement. "Apple’s app store, Google's play store, any platform for software applications somehow has to vet every app to ensure they have backdoored or little enough security to comply," says Bankston. That means, he says, that this would "seem to also be a massive internet censorship bill."

X content

This content can also be viewed on the site it originates from.

X content

This content can also be viewed on the site it originates from.

X content

This content can also be viewed on the site it originates from.

Burr and Feinstein's bill disappoints its privacy critics in part because it seems to entirely ignore the points already made in a debate that's raged for well over a year, and has its roots in the crytpo wars of the 1990s. Last summer, for instance, more than a dozen of the world's top cryptographers published a paper warning of the dangers of weakening encryption on behalf of law enforcement. They cautioned that any backdoor created to give law enforcement access to encrypted communications would inevitably be used by sophisticated hackers and foreign cyberspies. And privacy advocates have also pointed out that any attempt to ban strong encryption in American products would only force people seeking law-enforcement-proof data protection to use encryption software created outside the U.S., of which there is plenty to choose from. Apple, in its lengthy, detailed arguments with the FBI in front of Congress and in legal filings, has called that weakening of Americans' security a "unilateral disarmament" in its endless war with hackers to protect its users' privacy.

Tom Mentzer, a spokesman for Senator Feinstein, told WIRED in a statement on behalf of both bill sponsors that "we're still working on finalizing a discussion draft and as a result can't comment on language in specific versions of the bill. However, the underlying goal is simple: when there's a court order to render technical assistance to law enforcement or provide decrypted information, that court order is carried out. No individual or company is above the law. We’re still in the process of soliciting input from stakeholders and hope to have final language ready soon."

The Burr/Feinstein draft text may in fact be so bad for privacy that it's good for privacy: Privacy advocates point out that it has almost zero likelihood of making it into law in its current form. The White House has already declined to publicly support the bill. And Adam Schiff, the top Democratic congressman on the House of Representatives' intelligence committee, gave WIRED a similarly ambivalent comment on the upcoming legislation yesterday. "I don’t think Congress is anywhere near a consensus on the issue," Schiff said, "given how difficult it was to legislate the relatively easy [Cyber Information Sharing Act], and this is comparatively far more difficult and consequential."

Bankston puts it more simply. "The CCOA is DOA," he says, coining an acronym for the draft bill. But he warns that privacy activists and tech firms should be careful nonetheless not to underestimate the threat it represents. "We have to take this seriously," he says. "If this is the level of nuance and understanding with which our policymakers are viewing technical issues we’re in a profoundly worrisome place."

1Correction 4/8/2016 1:00pm EST: A previous version of this story stated that the draft bill text had been released by the senators, which a spokesperson for Senator Burr has since said in a statement to WIRED she didn't "believe was consistent with the facts."