Cryptocurrencies Have ‘No Way’ to Comply With US Anti-Encryption Bills
Multiple bills that threaten encryption are moving through the U.S. Senate and could pose a threat to technology that protects usersâ privacy, industry pros say.
These bills include the Lawful Access to Encrypted Data (LAED) Act and the Eliminating Abusive and Rampant Neglect of Interactive Technologies (âEARN ITâ) Act. While the Lawful Access to Encrypted Data Act was only recently introduced to the Senate, the EARN IT act has been in the works for months, and has been amended a number of times.Â
Privacy advocates and product designers say such legislation would also curtail peopleâs privacy to a huge degree, fundamentally change existing technology and have an impact on everything from messaging and file sharing to privacy coins.Â
âThe government basically would have mass surveillance powers into all of our communications,â said Zcoin Project Steward Reuben Yap, referring to the LAED Act. âItâs saying, âLetâs drop the pretense and letâs just go for it.â I think itâs really scary. Itâs not just about cryptocurrencies as a whole though, itâs really about freedom.â
The bills in question
Sponsored by three Republicans, the LAED Act seeks to end encrypted communications by building in a backdoor for law enforcement to use. The bill lays out a legal framework for law enforcement to access encrypted data with a court order.Â
The explicit goal of the EARN IT Act is to curb the spread of child exploitative content online, such as child sexual abuse imagery, though its impact could be far wider. In an initial draft, this was going to be done through stripping tech companies of liability protections for the content that is posted on their platforms. These protections currently exist in Section 230 of the Communications Decency Act, which prevents social media companies such as Facebook, Twitter and Reddit from content liability.Â
Under an earlier draft of the EARN IT Act, companies would lose Section 230 protections if they didnât follow the recommendations of a federal commission on child exploitative content. This could renderÂ companies likeÂ WhatsApp, which offers end-to-end encryption, liable for communications on the platform, unless they revoked end-to-end encryption.
âThey communicate using virtually unbreakable encryption. Predatorsâ supposed privacy interests should not outweigh our privacy and security,â said Attorney General William Barr at an event the day the bill was introduced.
Barr has long been a critic of encryption, dating back to his days in the George W. Bush Administration.Â
The most recent version of the bill gets rid of the commission idea, delegating power to state legislatures to bring lawsuits against companies. It also adds an amendment that explicitly protects encryption. But organizations such as the Electronic Frontier Foundation (EFF), Center for Democracy and Technology and Internet Society claim the bill might respect encryption in name, but not in practice.Â
Tools like client-side scanning, which could be used to check for child exploitative content, employs software to check files that are being sent against a database of âhashes,â or unique digital fingerprints. If it finds a match to certain kinds of images, they could be blocked, with the recipient notified, or the message could be forwarded to a third party without the userâs knowledge. Organizations such as EFF have said this violates encryption on a fundamental level.
âTech companiesâ increasing reliance on encryption has turned their platforms into a new, lawless playground of criminal activity,â said Republican Sen. Tom Cotton of Arkansas and one of the sponsors (with Sens. Lindsey Graham and Marsha Blackburn) of the LAED, in a public statement.
âCriminals from child predators to terrorists are taking full advantage. This bill will ensure law enforcement can access encrypted material with a warrant based on probable cause and help put an end to the Wild West of crime on the Internet.â
Child sexual abuse imagery is proliferating at an alarming rate on the internet. In 2019, tech companies reported nearly 70 million pieces of exploitative child content to authorities. Criminals also often use encrypted communications. EncroChat, a encrypted communications platform, protected criminals and their communications from the police, until law enforcement managed to infiltrate it.Â
But weakening tools that protect everyoneâs privacy may not be the best solution, say privacy advocates.Â Â
The impact on tech and cryptocurrency
Yap, of Zcoin, said many kinds of technology could be impacted by the billâs broad sweep.Â
The LAED Act is aimed at electronic devices and operating systems. Providers of âremote computing servicesâ are included, presumably to cover cloud computing services like Dropbox.
However, Yap said the billâs definition of remote computing services can be stretched to include cryptocurrencies as well, because financial transactions are conceivably just another form of electronic communication.
âGiven the trajectory of this legislation, people in the cryptocurrency industry, especially those like Zcoin [that] are privacy-focused, will very likely be affected,â said Yap.Â
âIt could mean that âprovidersâ of a privacy cryptocurrency that provided service to more than 1,000,000 users in the US are required to insert a backdoor.â
Ian Dixon, a Nevada-based programmer who previously mined bitcoin and runs a validator on a privacy-oriented blockchain network, said the bills are repackaged attacks on privacy, just with different language.Â
âIt doesnât really seem possible to enforce, but it would essentially make blockchains illegal in general,â said Dixon. âThere is no way for ethereum, bitcoin and other cryptocurrencies to comply.â
Matt Hill, the co-founder of Start9 Labs in Colorado, which develops decentralized internet tech, says he sees both pieces of legislation as falling into the same bucket, even if they are different in flavor.Â
âThe ultimate meaning is the same, which is that if you are a service provider of privacy or encryption, you are going to be subject to the whims of politics,â said Hill.Â
âWe hope politicians and our political system stays rational, and upholds individual rights to privacy, but if they donât you are going to be subjected to force, whether itâs building a backdoor or handing over user data.â
Hill said that even if these bills donât pass, the very fact theyâre sitting on the table and being taken seriously should be enough of a warning signÂ for us to start thinking outside the political box.
âPrivacy is not safe in their hands,â said Hill. âSo we have to protect privacy with technology, as opposed to with laws.â
This is privacy-by-design tech, the kind that Start9 Labs develops, including a server that lets users run their own private networks and cut out middlemen who would otherwise have access to their data.Â
Start9 Labâs tech is built such that it canât hand over any user data, even if legally compelled to, because it doesnât have it. It builds the tech but doesnât run the services on it. Given its products are open source, they can continue to run and protect user privacy, even if the company is shut down.Â
Encrypted communications are regularly used by people such as dissidents and journalists, and are often a means of protecting sources or organizing in authoritarian countries. There is a risk that if the U.S., which has long held itself up as an example of freedom and democracy, moves to eliminate end-to-end encryption, other countries would also follow suit, and use such legislation to crack down on dissent.Â
Finally, backdoors inevitably get used by bad guys, not just law enforcement.Â
âThereâs no such thing as a backdoor just for good guys,â said Daisy Soderberg-Rivkin, a fellow focusing on children and technology at the R Street Institute, a policy think tank in Washington, D.C. âThis opens up usersâ information to a whole mess of bad actors.â
UPDATE: The section about the EARN IT Actâs potential impact on services like WhatsApp has been updated.
- Start9 Labs Pitches a Private At-Home Server. And It Works
- With Chat Privacy Under Threat in US, Firm Develops â100% User-Controlledâ Messaging
The views and opinions expressed herein are the views and opinions of the author and do not necessarily reflect those of Nasdaq, Inc.