back
258 comments
For a better understanding: The Court held (in the circumstances of this case) that a legal obligation to decrypt E2E communications is a disproportionate interference with the right to privacy. The law in question specifically obligated messengers such as Telegram to hand over communications alongside the "information necessary to decrypt electronic messages if they were encrypted".

To come to that conclusion, it referred to the wide-scale impact such a weakening of E2E through backdoors would have and referred to "calls for alternative 'solutions to decryption without weakening the protective mechanisms, both in legislation and through continuous technical evolution.'" Looking at the cited material, these include traditional policing, undercover operations, metadata analysis, international police cooperation, live forensics on seized devices, guessing or obtaining private keys held by parties to the communication, using vulnerabilities in the target’s software or sending an implant to targeted devices.

While a ruling on a specific case (and law), the Court seems quite skeptical towards any "requirement that providers of such services weaken the encryption mechanism for all users". If I were the UK government, I would be quite worried that the UK Online Safety Bill will be overturned by domestic courts (or the European Court) on the basis of this ruling.

(It should be noted that, although the backdooring of E2E was considered to go beyond how the right to privacy may legitimately be restricted, the right to privacy is a so-called derogable right, i.e. a government can, upon declaration of a state of emergency, derogate from the right insofar that is necessary to address an emergency "threatening the life of the nation" (Art 15 ECHR))

Relevant paragraphs are paras 76-80 here: https://hudoc.echr.coe.int/eng/#{%22itemid%22:[%22001-230854...}

>While a ruling on a specific case (and law), the Court seems quite skeptical towards any "requirement that providers of such services weaken the encryption mechanism for all users". If I were the UK government, I would be quite worried that the UK Online Safety Bill will be overturned by domestic courts (or the European Court) on the basis of this ruling.

It's worth noting that UK courts can't overturn Acts of Parliament.

The best they can do is issue a declaration of incompatibility, which enables ministers to use secondary legislation to correct any defect rather than having to go through the process of passing another act (if they have the political will to do so...).

Having said that, a lot of how the Online Safety Act tries to get things done is through secondary legislation and statutory codes and guidelines; these all can be quashed by the courts (unless the Act constrains the way the other instruments are made in such a way that it'd be illegal not to make an infringing instrument) so it'll be interesting to see how that plays out.

> The Court held that a legal obligation to decrypt E2E communications is a disproportionate interference with the right to privacy.

*when no adequate safeguards against abuse are in place

Unfortunately it is not as straightforward as that it's incompatible altogether. Per this ruling, it's only incompatible when there are no good safeguards (they use the word "adequate" in one place and "suitable" in another, neither is very specific about what it means)

> the UK Online Safety Bill will be overturned by domestic courts (or the European Court) on the basis of this ruling.

The UK wants to leave the ECHR[0], so they might be able to get around it — unfortunately.

[0]: https://www.chathamhouse.org/2023/03/uk-must-not-sleepwalk-l...

>> information necessary to decrypt electronic messages if they were encrypted

That reminds me of Lavabit, which I once used as my primary email. In response to demands for decryption information, Lavabit handed over their private keys. On paper. Typed out. Possibly with a typo somewhere on page 6, or 12.

https://thenextweb.com/news/you-wont-believe-what-email-prov...

Perhaps a dumb question, but why would the EU courts be able to overturn laws in the UK now that the UK is not part of the EU anymore?
The UK government almost seem to be deliberately passing multiple pieces of legislation that they know will be overturned due to ECHR, because they believe such rulings would strengthen their argument for withdrawing from the convention.
I am a bit confused. The article seems fairly political, quoting some promotional text by the pirate party and not describing what case was brought in front of a judge and what the ruling bans specifically, so I clicked through to the actual court case linked at the bottom.

It has nothing to do with the pirate party or chatcontrol or any such thing. The court case was one person against the Russian government for fining Telegram when they didn't hand over plain text chat messages, if I'm skimming the initial facts section correctly. The whole article doesn't even contain the word russia. What is the article reporting on and why does it portray it as being related to the recent chatcontrol legislation?!

Edit: found the decision

> 80. The Court concludes from the foregoing that the contested legislation providing for the retention of all Internet communications of all users, the security services’ direct access to the data stored without adequate safeguards against abuse and the requirement to decrypt encrypted communications, as applied to end-to-end encrypted communications, cannot be regarded as necessary in a democratic society.

> 81. There has accordingly been a violation of Article 8 [privacy] of the Convention [of human rights]

Sounds like you can indeed extend that to any other encryption-circumventing law, like chatcontrol, but without considering the specific circumstances that were present in this Russian law, I'm not sure that it will be accurate. Note, for example, the wording in paragraph 80 "without adequate safeguards against abuse". Maybe chatcontrol had those, if that had been brought in front of the same judges

Its a judgement that will provide precedence. A Pirate Party member of the European Parliament comments because its a core issue to the party. Why would there be anything about the Pirate Party in the ruling?
The article is not the original. The original text can be found here: https://www.patrick-breyer.de/en/european-court-of-human-rig...
It's nice to know this also applies to the UK even after Brexit (still a member of the ECHR).
The Tories have been talking about leaving the ECHR for years now.
Azerbaijan is in the ECHR too; doesn't stop them from imprisoning political dissidents, employing slave labor, committing war crimes, attacking other ECHR members, or performing ethnic cleansing.
Man, Europe is really setting an example lately for how it's possible to roll out sensible technology regulations.
This decision was needed because the EU was about to ban end-to-end encryption. It’s not the EU commission, but a judge that ruled. AFAIK Commission can still ignore this.
Now if they could only do a good job developing the technology itself…
Honestly, after so many things turning into "they'll just come back and try again in two years", it's a little reassuring to see some longer term roadblocks being put in place against these anti-E2EE proposals.
yeah, preferably through the Agricultural and Fisheries Commission or a similar body
Europe has done something that I actually love.

I was worried the "let's think of the children" narrative would take over.

The value of encryption has a future in Europe at least.

Despite the name, it's not the eu :D
There's a degree of push/pull on government and industry as far as encryption is concerned. Government shouldn't be injecting vulnerabilities into algos but they also need a way to read messages from criminals and terrorists. Industry wants some way for customers to feel safe using their product to message or whatever their (legal) use case.

Without some local pressure, this cedes encryption commercialization to the US. Sure academics will still love their novel algos but until someone can make money from them, they'll sit in papers, ready for the enterprising american dev to turn into the next big encrypted chat app that is more secure than Signal or something like that.

Nice. I can imagine certain ISPs (that I will not shame by name) won't be very happy right now. This really throws a wrench in some proxy models.

Good riddance.

Please do name and shame. This would benefit everyone.
The article is semi-garbage (politics aside it is a badly written/biased article).

Better read the decision.

https://hudoc.echr.coe.int/eng/#{%22itemid%22:[%22001-230854...}

CASE OF PODCHASOV v. RUSSIA

(Application no. 33696/19)

In defence of the article - it linked the decision. That means it is automatically in something close to the top 20% of articles about political topics.

And the actual decision is quite readable; on a quick skim it seemed to agree with what the article said.

Relevant English text from the Court's press release:

> The applicant, Anton Valeryevich Podchasov, is a Russian national who was born in 1981 and lives in Barnaul (Russia).

> Mr Podchasov was a user of Telegram, a messaging application which was listed as an “Internet communications organiser” (организатор распространения информации в сети Интернет) by the Russian State. It was therefore obliged by law to store all communications data for a duration of one year and the contents of all communications for a duration of six months and to submit those data to law-enforcement authorities or security services in circumstances specified by law, together with information necessary to decrypt electronic messages if they were encrypted.

> Relying on Article 8 (right to respect for correspondence) and Article 13 (right to an effective remedy) of the Convention, Mr Podchasov complains of the legal requirements to store, pass on and decrypt data, and that he did not have an effective remedy for this complaint.

> Violation of Article 8

> Just satisfaction: The finding of a violation constitutes in itself sufficient just satisfaction for any non-pecuniary damage sustained by the applicant

Source: (this is broken) https://hudoc.echr.coe.int/eng-press/#{%22fulltext%22:[%2233...}

Edit: Yuck, this website makes it impossible to permalink anything. What a horrible idea for an organization that's supposed to make very important decisions that people need to reference.

HN markup seems to be breaking the link, here's an alternative one: https://hudoc.echr.coe.int/eng/?i=001-230854

  FOR THESE REASONS, THE COURT
  
  Holds, unanimously, that it has jurisdiction to deal with the applicant’s complaints in so far as they relate to facts that took place before 16 September 2022;
  Declares, unanimously, the complaint concerning the alleged violation of the right to respect for private life and correspondence admissible;
  Holds, unanimously, that there has been a violation of Article 8 of the Convention;
  Holds, by five votes to two, that there is no need to examine the complaint under Article 13 of the Convention;
  Holds, by six votes to one, that the finding of a violation constitutes in itself sufficient just satisfaction for any non-pecuniary damage sustained by the applicant;
  Dismisses, by six votes to one, the applicant’s claim for just satisfaction.
  
  Done in English, and notified in writing on 13 February 2024, pursuant to Rule 77 §§ 2 and 3 of the Rules of Court.
Relevant paras:

> (γ) Statutory requirement to decrypt communications

> 76. Lastly, as regards the requirement to submit to the security services information necessary to decrypt electronic communications if they are encrypted, the Court observes that international bodies have argued that encryption provides strong technical safeguards against unlawful access to the content of communications and has therefore been widely used as a means of protecting the right to respect for private life and for the privacy of correspondence online. In the digital age, technical solutions for securing and protecting the privacy of electronic communications, including measures for encryption, contribute to ensuring the enjoyment of other fundamental rights, such as freedom of expression (see paragraphs 28 and 34 above). Encryption, moreover, appears to help citizens and businesses to defend themselves against abuses of information technologies, such as hacking, identity and personal data theft, fraud and the improper disclosure of confidential information. This should be given due consideration when assessing measures which may weaken encryption.

> 77. As noted above (see paragraph 57 above), it appears that in order to enable decryption of communications protected by end-to-end encryption, such as communications through Telegram’s “secret chats”, it would be necessary to weaken encryption for all users. These measures allegedly cannot be limited to specific individuals and would affect everyone indiscriminately, including individuals who pose no threat to a legitimate government interest. Weakening encryption by creating backdoors would apparently make it technically possible to perform routine, general and indiscriminate surveillance of personal electronic communications. Backdoors may also be exploited by criminal networks and would seriously compromise the security of all users’ electronic communications. The Court takes note of the dangers of restricting encryption described by many experts in the field (see, in particular, paragraphs 28 and 34 above).

> 78. The Court accepts that encryption can also be used by criminals, which may complicate criminal investigations (see Yüksel Yalçınkaya v. Türkiye [GC], no. 15669/20, § 312, 26 September 2023). However, it takes note in this connection of the calls for alternative “solutions to decryption without weakening the protective mechanisms, both in legislation and through continuous technical evolution” (see, on the possibilities of alternative methods of investigation, the Joint Statement by Europol and the European Union Agency for Cybersecurity, cited in paragraph 33 above, and paragraph 24 of the Report on the right to privacy in the digital age by the Office of the United Nations High Commissioner for Human Rights, cited in paragraph 28 above; see also the explanation by third-party interveners in paragraph 47 above).

> 79. The Court concludes that in the present case the ICO’s statutory obligation to decrypt end-to-end encrypted communications risks amounting to a requirement that providers of such services weaken the encryption mechanism for all users; it is accordingly not proportionate to the legitimate aims pursued.

> (δ) Conclusion

> 80. The Court concludes from the foregoing that the contested legislation providing for the retention of all Internet communications of all users, the security services’ direct access to the data stored without adequate safeguards against abuse and the requirement to decrypt encrypted communications, as applied to end-to-end encrypted communications, cannot be regarded as necessary in a democratic society. In so far as this legislation permits the public authorities to have access, on a generalised basis and without sufficient safeguards, to the content of electronic communications, it impairs the very essence of the right to respect for private life under Article 8 of the Convention. The respondent State has therefore overstepped any acceptable margin of appreciation in this regard.

> 81. There has accordingly been a violation of Article 8 of the Convention.

Excellent news.

The European Court of Human Rights ... the court our idiotic UK gvoernment are trying to paint with the same brush they painted the EU.

I realise the article contains the same typo, but the title is bugging me – it needs a space between "end" and "encryption". "Endencryption" is not a word.

@dang ?

Ah, apologies about that, I didn't even notice it. Happy to see it corrected.
They also ruled a while ago on site blocking, which has at least been tested in the Mexican supreme court[0]

translated via google "As the United Nations Human Rights Council has stated, blocking an Internet page implies any measure taken to prevent certain online content from reaching an end user. In this regard, it must be taken into account that restrictions on the human right of freedom of expression should not be excessively broad, on the contrary, they should refer to specific content; Hence, generic prohibitions on the operation of certain websites and web systems, such as blocking, are incompatible with the human right of freedom of expression, except in truly exceptional situations, which could arise when the contents of an Internet page are translate into prohibited expressions, that is, classified as crimes in accordance with international criminal law, among which the following stand out: (I) incitement to terrorism; (II) the advocacy of national, racial or religious hatred that constitutes incitement to discrimination, hostility or violence - dissemination of "hate speech" on the Internet; (III) direct and public incitement to commit genocide; and (IV) child pornography. Likewise, the exceptional situation regarding the prohibition of generic restrictions on the right of expression could also be generated when the entire contents of a web page are illegal, which logically could lead to its blocking, as it is limited only to hosting expressions that are not permissible by law. the legal framework."

[0] https://vlex.com.mx/vid/tesis-aisladas-683012725

Weakening of secure end-to-end encryption means the encryption is worthless.
this is a HUGE win and could very much help set precedent across the globe (looking at our congress specifically, USA). Still more hurdles to jump over but a great step in the right direction
Good news
What the hell is wrong with our democratic values to begin with? Why do we need high court decisions for these insane ideas of making a better world. Are these people infected by some corporate lobby or what is it why they cannot think in favour of human kind. I cannot phantom this.
Reminder that the European Court of Human Rights, although very powerful and influential, does not have the authority to force anyone to abide by their rulings.

Also, here's a better article: https://fortune.com/2024/02/13/end-to-end-encryption-russia-...

Is there an exception for emergency purposes?
A "Court of Human Rights" that counts Azerbaijan as a member is not a court that should be taken seriously.
This article doesn’t actually contain any information that backs up the title, or if the title is true at all.

There’s a quote from some party member who doesn’t seem directly involved, and almost no information about the actual case / ruling.

> The judgement cites using vulnerabilities in the target’s software or sending an implant to targeted devices as examples [of legitimate ways to defeat E2E encryption].

That looks like a bad judgement, to me; exploiting vulnerabilities, or using implants, is generally some kind of criminal hacking. So the court seems to be saying that's not OK, unless you're a government. I.e., governments don't have to obey the law.

There are quite a few EU governments that would prefer not to have to comply with the law. Every EU government gets to plant a judge on the ECHR bench.