https://www.theregister.com/2024/02/15/echr_backdoor_encryption/ # # Sign in / up The Register(r) -- Biting the hand that feeds IT # # # Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal TechCxOPublic Sector (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Special Features Special Features All Special Features Cloud Infrastructure Week Cybersecurity Month Blackhat and DEF CON Sysadmin Month The Reg in Space Emerging Clean Energy Tech Week Spotlight on RSA Energy Efficient Datacenters Vendor Voice Vendor Voice Vendor Voice All Vendor Voice Amazon Web Services (AWS) Business Transformation DDN Google Cloud Infrastructure Hewlett Packard Enterprise: AI & ML solutions Hewlett Packard Enterprise: Edge-to-Cloud Platform Intel vPro VMware (X) Resources Resources Whitepapers Webinars & Events Newsletters [front] Security 212 comment bubble on white European Court of Human Rights declares backdoored encryption is illegal 212 comment bubble on white Surprising third-act twist as Russian case means more freedom for all icon Thomas Claburn Thu 15 Feb 2024 // 07:26 UTC # The European Court of Human Rights (ECHR) has ruled that laws requiring crippled encryption and extensive data retention violate the European Convention on Human Rights - a decision that may derail European data surveillance legislation known as Chat Control. The court issued a decision on Tuesday stating that "the contested legislation providing for the retention of all internet communications of all users, the security services' direct access to the data stored without adequate safeguards against abuse and the requirement to decrypt encrypted communications, as applied to end-to-end encrypted communications, cannot be regarded as necessary in a democratic society." The "contested legislation" mentioned above refers to a legal challenge that started in 2017 after a demand from Russia's Federal Security Service (FSB) that messaging service Telegram provide technical information to assist the decryption of a user's communication. The plaintiff, Anton Valeryevich Podchasov, challenged the order in Russia but his claim was dismissed. [front] In 2019, Podchasov brought the matter to the ECHR. Russia joined the Council of Europe - an international human rights organization - in 1996 and was a member until it withdrew in March 2022 following its illegal invasion of Ukraine. Because the 2019 case predates Russia's withdrawal, the ECHR continued to consider the matter. [front] [front] The court concluded that the Russian law requiring Telegram "to decrypt end-to-end encrypted communications risks amounting to a requirement that providers of such services weaken the encryption mechanism for all users." As such, the court considers that requirement disproportionate to legitimate law enforcement goals. * Privacy crusaders accuse X of ad-targeting that flouts EU rules * German Digital Affairs Committee hearing heaps scorn on Chat Control * Open Source Policy Summit: Where FOSS and government meet * Scanning phones to detect child abuse evidence is harmful, 'magical' thinking While the ECHR decision is unlikely to have any effect within Russia, it matters to countries in Europe that are contemplating similar decryption laws - such as Chat Control and the UK government's Online Safety Act. Chat Control is shorthand for European data surveillance legislation that would require internet service providers to scan digital communications for illegal content - specifically child sexual abuse material and potentially terrorism-related information. Doing so would necessarily entail weakening the encryption that keeps communication private. Efforts to develop workable rules have been underway for several years and continue to this day, despite widespread condemnation from academics, privacy-oriented orgs, and civil society groups. [front] Patrick Breyer, a member of the European parliament for the Pirate Party, hailed the ruling for demonstrating that Chat Control is incompatible with EU law. "With this outstanding landmark judgment, the 'client-side scanning' surveillance on all smartphones proposed by the EU Commission in its chat control bill is clearly illegal," said Breyer. "It would destroy the protection of everyone instead of investigating suspects. EU governments will now have no choice but to remove the destruction of secure encryption from their position on this proposal - as well as the indiscriminate surveillance of private communications of the entire population!" (r) Get our Tech Resources # Share More about * Encryption * European Commission * Law More like these x More about * Encryption * European Commission * Law * Security * Surveillance Narrower topics * 2FA * Advanced persistent threat * Antitrust * Application Delivery Controller * Authentication * BEC * Black Hat * BSides * Bug Bounty * Common Vulnerability Scoring System * Cross-border data flow * Cybercrime * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Data Breach * Data Protection * Data Theft * DDoS * DEF CON * Digital certificate * Digital Services Act * Exploit * Firewall * Hacker * Hacking * Hacktivism * Identity Theft * Incident response * Infosec * Kenna Security * Let's Encrypt * NCSAM * NCSC * NSO Group * Palo Alto Networks * Password * Phishing * Privacy Shield * Quantum key distribution * Ransomware * Remote Access Trojan * REvil * RSA Conference * Signal * Spamming * Spyware * TLS * Trojan * Trusted Platform Module * Vulnerability * Wannacry * Zero trust Broader topics * European Union More about # Share 212 comment bubble on white COMMENTS More about * Encryption * European Commission * Law More like these x More about * Encryption * European Commission * Law * Security * Surveillance Narrower topics * 2FA * Advanced persistent threat * Antitrust * Application Delivery Controller * Authentication * BEC * Black Hat * BSides * Bug Bounty * Common Vulnerability Scoring System * Cross-border data flow * Cybercrime * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Data Breach * Data Protection * Data Theft * DDoS * DEF CON * Digital certificate * Digital Services Act * Exploit * Firewall * Hacker * Hacking * Hacktivism * Identity Theft * Incident response * Infosec * Kenna Security * Let's Encrypt * NCSAM * NCSC * NSO Group * Palo Alto Networks * Password * Phishing * Privacy Shield * Quantum key distribution * Ransomware * Remote Access Trojan * REvil * RSA Conference * Signal * Spamming * Spyware * TLS * Trojan * Trusted Platform Module * Vulnerability * Wannacry * Zero trust Broader topics * European Union TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like Apple promises to protect iMessage chats from quantum computers Easy to defend against stuff that may never actually work - oh there we go again, being all cynical like Research21 Feb 2024 | Dems are at it again, trying to break open black-box algorithms Opening up code used in criminal prosecutions for scrutiny? But where's the text-to-vid hype and doomsaying? AI + ML16 Feb 2024 | 35 The spyware business is booming despite government crackdowns Updated 'Almost zero data being shared across the industry on this particular threat,' we're told Security7 Feb 2024 | 35 Safeguarding against the global ransomware threat How Object First's Ootbi delivers ransomware-proof and immutable backup storage that can be up and running in minutes Sponsored Feature [front] Crims found and exploited these two Microsoft bugs before Redmond fixed 'em Patch Tuesday SAP, Adobe, Intel, AMD also issue fixes as well as Google for Android Patches14 Feb 2024 | 5 Ignore Uncle Sam's 'voluntary' cybersecurity goals for hospitals at your peril Interview What is on HHS paper will most likely become law, Google security boss says Cyber-crime5 Feb 2024 | 12 Google open sources file-identifying Magika AI for malware hunters and others Cool, but it's 2024 - needs more hype, hand wringing, and flashy staged demos to be proper ML CSO17 Feb 2024 | 9 FBI: Give us warrantless Section 702 snooping powers - or China wins Analysis Never mind the court orders obtained to thwart Volt Typhoon botnet Security9 Feb 2024 | 22 Miscreants turn to ad tech to measure malware metrics Now that's what you call dual-use tech Research15 Feb 2024 | 4 Korean eggheads crack Rhysida ransomware and release free decryptor tool Great news for victims of gang behind the big British Library hit in October Cyber-crime13 Feb 2024 | 6 Raspberry Pi Pico cracks BitLocker in under a minute Windows encryption feature defeated by $10 and a YouTube tutorial Research7 Feb 2024 | 142 Meta says risk of account theft after phone number recycling isn't its problem to solve Leaves it to carriers, promoting a complaint to Irish data cops from Big Tech's bete noire Personal Tech13 Feb 2024 | 107 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * T's & C's * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2024 no-js