To come to that conclusion, it referred to the wide-scale impact such a weakening of E2E through backdoors would have and referred to "calls for alternative 'solutions to decryption without weakening the protective mechanisms, both in legislation and through continuous technical evolution.'" Looking at the cited material, these include traditional policing, undercover operations, metadata analysis, international police cooperation, live forensics on seized devices, guessing or obtaining private keys held by parties to the communication, using vulnerabilities in the target’s software or sending an implant to targeted devices.
While a ruling on a specific case (and law), the Court seems quite skeptical towards any "requirement that providers of such services weaken the encryption mechanism for all users". If I were the UK government, I would be quite worried that the UK Online Safety Bill will be overturned by domestic courts (or the European Court) on the basis of this ruling.
(It should be noted that, although the backdooring of E2E was considered to go beyond how the right to privacy may legitimately be restricted, the right to privacy is a so-called derogable right, i.e. a government can, upon declaration of a state of emergency, derogate from the right insofar that is necessary to address an emergency "threatening the life of the nation" (Art 15 ECHR))
Relevant paragraphs are paras 76-80 here: https://hudoc.echr.coe.int/eng/#{%22itemid%22:[%22001-230854...}
It's worth noting that UK courts can't overturn Acts of Parliament.
The best they can do is issue a declaration of incompatibility, which enables ministers to use secondary legislation to correct any defect rather than having to go through the process of passing another act (if they have the political will to do so...).
Having said that, a lot of how the Online Safety Act tries to get things done is through secondary legislation and statutory codes and guidelines; these all can be quashed by the courts (unless the Act constrains the way the other instruments are made in such a way that it'd be illegal not to make an infringing instrument) so it'll be interesting to see how that plays out.
*when no adequate safeguards against abuse are in place
Unfortunately it is not as straightforward as that it's incompatible altogether. Per this ruling, it's only incompatible when there are no good safeguards (they use the word "adequate" in one place and "suitable" in another, neither is very specific about what it means)
The UK wants to leave the ECHR[0], so they might be able to get around it — unfortunately.
—
[0]: https://www.chathamhouse.org/2023/03/uk-must-not-sleepwalk-l...
That reminds me of Lavabit, which I once used as my primary email. In response to demands for decryption information, Lavabit handed over their private keys. On paper. Typed out. Possibly with a typo somewhere on page 6, or 12.
https://thenextweb.com/news/you-wont-believe-what-email-prov...
It has nothing to do with the pirate party or chatcontrol or any such thing. The court case was one person against the Russian government for fining Telegram when they didn't hand over plain text chat messages, if I'm skimming the initial facts section correctly. The whole article doesn't even contain the word russia. What is the article reporting on and why does it portray it as being related to the recent chatcontrol legislation?!
Edit: found the decision
> 80. The Court concludes from the foregoing that the contested legislation providing for the retention of all Internet communications of all users, the security services’ direct access to the data stored without adequate safeguards against abuse and the requirement to decrypt encrypted communications, as applied to end-to-end encrypted communications, cannot be regarded as necessary in a democratic society.
> 81. There has accordingly been a violation of Article 8 [privacy] of the Convention [of human rights]
Sounds like you can indeed extend that to any other encryption-circumventing law, like chatcontrol, but without considering the specific circumstances that were present in this Russian law, I'm not sure that it will be accurate. Note, for example, the wording in paragraph 80 "without adequate safeguards against abuse". Maybe chatcontrol had those, if that had been brought in front of the same judges
I was worried the "let's think of the children" narrative would take over.
The value of encryption has a future in Europe at least.
Without some local pressure, this cedes encryption commercialization to the US. Sure academics will still love their novel algos but until someone can make money from them, they'll sit in papers, ready for the enterprising american dev to turn into the next big encrypted chat app that is more secure than Signal or something like that.
Good riddance.
Better read the decision.
https://hudoc.echr.coe.int/eng/#{%22itemid%22:[%22001-230854...}
CASE OF PODCHASOV v. RUSSIA
(Application no. 33696/19)
And the actual decision is quite readable; on a quick skim it seemed to agree with what the article said.
> The applicant, Anton Valeryevich Podchasov, is a Russian national who was born in 1981 and lives in Barnaul (Russia).
> Mr Podchasov was a user of Telegram, a messaging application which was listed as an “Internet communications organiser” (организатор распространения информации в сети Интернет) by the Russian State. It was therefore obliged by law to store all communications data for a duration of one year and the contents of all communications for a duration of six months and to submit those data to law-enforcement authorities or security services in circumstances specified by law, together with information necessary to decrypt electronic messages if they were encrypted.
> Relying on Article 8 (right to respect for correspondence) and Article 13 (right to an effective remedy) of the Convention, Mr Podchasov complains of the legal requirements to store, pass on and decrypt data, and that he did not have an effective remedy for this complaint.
> Violation of Article 8
> Just satisfaction: The finding of a violation constitutes in itself sufficient just satisfaction for any non-pecuniary damage sustained by the applicant
Source: (this is broken) https://hudoc.echr.coe.int/eng-press/#{%22fulltext%22:[%2233...}
Edit: Yuck, this website makes it impossible to permalink anything. What a horrible idea for an organization that's supposed to make very important decisions that people need to reference.
FOR THESE REASONS, THE COURT
Holds, unanimously, that it has jurisdiction to deal with the applicant’s complaints in so far as they relate to facts that took place before 16 September 2022;
Declares, unanimously, the complaint concerning the alleged violation of the right to respect for private life and correspondence admissible;
Holds, unanimously, that there has been a violation of Article 8 of the Convention;
Holds, by five votes to two, that there is no need to examine the complaint under Article 13 of the Convention;
Holds, by six votes to one, that the finding of a violation constitutes in itself sufficient just satisfaction for any non-pecuniary damage sustained by the applicant;
Dismisses, by six votes to one, the applicant’s claim for just satisfaction.
Done in English, and notified in writing on 13 February 2024, pursuant to Rule 77 §§ 2 and 3 of the Rules of Court.> (γ) Statutory requirement to decrypt communications
> 76. Lastly, as regards the requirement to submit to the security services information necessary to decrypt electronic communications if they are encrypted, the Court observes that international bodies have argued that encryption provides strong technical safeguards against unlawful access to the content of communications and has therefore been widely used as a means of protecting the right to respect for private life and for the privacy of correspondence online. In the digital age, technical solutions for securing and protecting the privacy of electronic communications, including measures for encryption, contribute to ensuring the enjoyment of other fundamental rights, such as freedom of expression (see paragraphs 28 and 34 above). Encryption, moreover, appears to help citizens and businesses to defend themselves against abuses of information technologies, such as hacking, identity and personal data theft, fraud and the improper disclosure of confidential information. This should be given due consideration when assessing measures which may weaken encryption.
> 77. As noted above (see paragraph 57 above), it appears that in order to enable decryption of communications protected by end-to-end encryption, such as communications through Telegram’s “secret chats”, it would be necessary to weaken encryption for all users. These measures allegedly cannot be limited to specific individuals and would affect everyone indiscriminately, including individuals who pose no threat to a legitimate government interest. Weakening encryption by creating backdoors would apparently make it technically possible to perform routine, general and indiscriminate surveillance of personal electronic communications. Backdoors may also be exploited by criminal networks and would seriously compromise the security of all users’ electronic communications. The Court takes note of the dangers of restricting encryption described by many experts in the field (see, in particular, paragraphs 28 and 34 above).
> 78. The Court accepts that encryption can also be used by criminals, which may complicate criminal investigations (see Yüksel Yalçınkaya v. Türkiye [GC], no. 15669/20, § 312, 26 September 2023). However, it takes note in this connection of the calls for alternative “solutions to decryption without weakening the protective mechanisms, both in legislation and through continuous technical evolution” (see, on the possibilities of alternative methods of investigation, the Joint Statement by Europol and the European Union Agency for Cybersecurity, cited in paragraph 33 above, and paragraph 24 of the Report on the right to privacy in the digital age by the Office of the United Nations High Commissioner for Human Rights, cited in paragraph 28 above; see also the explanation by third-party interveners in paragraph 47 above).
> 79. The Court concludes that in the present case the ICO’s statutory obligation to decrypt end-to-end encrypted communications risks amounting to a requirement that providers of such services weaken the encryption mechanism for all users; it is accordingly not proportionate to the legitimate aims pursued.
> (δ) Conclusion
> 80. The Court concludes from the foregoing that the contested legislation providing for the retention of all Internet communications of all users, the security services’ direct access to the data stored without adequate safeguards against abuse and the requirement to decrypt encrypted communications, as applied to end-to-end encrypted communications, cannot be regarded as necessary in a democratic society. In so far as this legislation permits the public authorities to have access, on a generalised basis and without sufficient safeguards, to the content of electronic communications, it impairs the very essence of the right to respect for private life under Article 8 of the Convention. The respondent State has therefore overstepped any acceptable margin of appreciation in this regard.
> 81. There has accordingly been a violation of Article 8 of the Convention.
The European Court of Human Rights ... the court our idiotic UK gvoernment are trying to paint with the same brush they painted the EU.
@dang ?
translated via google "As the United Nations Human Rights Council has stated, blocking an Internet page implies any measure taken to prevent certain online content from reaching an end user. In this regard, it must be taken into account that restrictions on the human right of freedom of expression should not be excessively broad, on the contrary, they should refer to specific content; Hence, generic prohibitions on the operation of certain websites and web systems, such as blocking, are incompatible with the human right of freedom of expression, except in truly exceptional situations, which could arise when the contents of an Internet page are translate into prohibited expressions, that is, classified as crimes in accordance with international criminal law, among which the following stand out: (I) incitement to terrorism; (II) the advocacy of national, racial or religious hatred that constitutes incitement to discrimination, hostility or violence - dissemination of "hate speech" on the Internet; (III) direct and public incitement to commit genocide; and (IV) child pornography. Likewise, the exceptional situation regarding the prohibition of generic restrictions on the right of expression could also be generated when the entire contents of a web page are illegal, which logically could lead to its blocking, as it is limited only to hosting expressions that are not permissible by law. the legal framework."
Also, here's a better article: https://fortune.com/2024/02/13/end-to-end-encryption-russia-...
There’s a quote from some party member who doesn’t seem directly involved, and almost no information about the actual case / ruling.
That looks like a bad judgement, to me; exploiting vulnerabilities, or using implants, is generally some kind of criminal hacking. So the court seems to be saying that's not OK, unless you're a government. I.e., governments don't have to obey the law.
There are quite a few EU governments that would prefer not to have to comply with the law. Every EU government gets to plant a judge on the ECHR bench.