HomeCybercrime Law › Module 8 · Encryption

Module 8 · Encryption and protected data

What this module covers and why it matters. This module covers what the state can do when the data it wants to read is encrypted. It sits at the fourth stage of the subject's arc from offences to jurisdiction to investigations to cooperation. Having placed the offence and settled which state may try it and armed the investigator with powers to gather evidence the next problem is that the evidence may be unreadable. Encryption turns intelligible plaintext into unintelligible ciphertext and end-to-end encryption puts the plaintext beyond the reach even of the provider carrying the message. Around that problem sit two rival claims and a menu of legal responses. The first claim is that the state is "going dark" because it can no longer read what it is lawfully entitled to read. The second claim is that this is instead a "golden age of surveillance" because so much other data is now available. The legal responses run from criminalising encryption to compelling disclosure to requiring provider assistance to building exceptional access to government hacking. The centrepiece Australian response is the industry-assistance framework in Part 15 of the Telecommunications Act 1997 inserted by the TOLA Act 2018 and its critical limit that a notice must not require a systemic weakness. This is the essay-richest module in the subject so the Debate section is long and carries most of the weight.

How to use this guide. The Debate section is the centre of gravity because the assessment includes a 3000-word research essay and this module is the one where the essay questions are richest. The RULE cards state the operative Australian statutory powers and their systemic-weakness limit. The Map of the debate box replaces the attack plan used in the offence modules because this module is analysed as a set of controversies rather than worked as a problem question. Read once to learn the two rival claims and the menu of responses and then revise from the headings and boxes.

Instruments at a glance

Instrument Key provisions What it does
Telecommunications Act 1997 (Cth), Part 15 (industry assistance) s 317B definitions; s 317G technical assistance request; s 317L technical assistance notice; s 317T technical capability notice; s 317ZG systemic-weakness limitation; s 317ZH interaction with warrants Australia's industry-assistance framework inserted by the TOLA Act 2018. Lets agencies enlist a communications provider to help access data and caps that power at the systemic-weakness line
Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (Cth) Schedule 1 inserting Part 15 The amending Act ("TOLA") that created the three notice types and the systemic-weakness limitation. The Act is the reform, Part 15 is where the operative rules now sit
Budapest Convention on Cybercrime (ETS 185, 2001) Art 6 misuse of devices; art 19(4) power to order a person with knowledge to give information to access a computer system Supplies the treaty hooks for two responses. Article 6 criminalises supply of tools and article 19(4) grounds a duty to disclose the means to access protected data (Walden)
Crimes Act 1914 (Cth) s 3LA assistance order Compels a specified person to give the information or assistance needed to access encrypted or password-protected data covered by a warrant. This is the Australian compelled-decryption power (see Module 7)

Map of the debate

This module is analysed as a set of controversies rather than worked as a problem question so the frame to hold in mind is a map of the live debates. There are four, each returned to in the Debate section.

  1. Going dark or a golden age of surveillance. Is encryption a fundamental and irreversible shift of power to criminals or an exaggeration given how much other data is now available. Walden and Swire and Ahmad frame this.
  2. Exceptional access and the systemic-weakness line. Can a provider be required to build a means of lawful access without weakening security for everyone. This is where the Australian s 317ZG limitation and the technical critique meet.
  3. Compelled decryption of a suspect. Should the law require a person to hand over a key or password and should refusal be a separate offence. This raises the privilege against self-incrimination.
  4. Alternatives to weakening encryption. Is government hacking a preferable response and can cross-border access to encrypted data be managed without breaking the encryption at all. Scott and Ó Floinn and Abraha frame these.

Two organising ideas run under the whole map. The first is Walden's menu of options which sorts the responses from criminalisation through to metadata. The second is the distinction Scott and Ó Floinn draw between a technical backdoor built into software and a legal backdoor built into a statute that undermines encryption without saying so.

The encryption problem and the menu of responses

What this section covers and why it matters. Before the debates can be understood the problem must be stated plainly and the range of responses laid out because each debate is really an argument about which response to prefer. This section defines encryption and the going-dark claim and then sets out Walden's menu of options as a scaffold to organise everything that follows. Anchor the abstraction to a concrete example the moment it appears.

Start with the technology. Encryption turns intelligible information called the plaintext into unintelligible information called the ciphertext (Scott and Ó Floinn 2024). A message might be encrypted only in transit so that the provider storing it keeps access to the decrypted plaintext. Increasingly encryption is end-to-end which means the plaintext is encrypted on the sender's device and not decrypted until it reaches the recipient's device. The provider transmitting the message then holds only the encrypted version with no capacity to access the plaintext (Scott and Ó Floinn 2024).

Worked example. A user sends a message on an end-to-end encrypted messaging app. The message is locked on the sender's phone and unlocked only on the recipient's phone. The provider carrying the message can see that a message passed but cannot read its content. A warrant served on the provider for the content produces ciphertext the provider cannot turn into plaintext. This is the going-dark problem in a single case.

The going-dark claim generalises that case. Law-enforcement figures argue that the spread of encryption makes the landscape they oversee go dark so that they cannot investigate terrorism or ordinary crime even with lawful authority to intercept (Scott and Ó Floinn 2024, quoting Comey). Walden accepts that this phenomenon represents a real challenge to law-enforcement agencies but does not accept the stronger implication that encryption is a fundamental and irreversible shift in the balance of power between criminals and their investigators. Such claims tend to lack historical perspective (Walden 2018).

To organise the responses Walden sets out a menu of options. Read it as a checklist because a strong answer names several responses and compares them rather than seizing on one.

Walden's menu of responses to the going-dark problem.

  1. Criminalise the supply, possession or use of encryption. Article 6 of the Budapest Convention already criminalises supply of tools and some states make use of encryption in crime an aggravating factor.
  2. Compel disclosure. Require the person holding the data or the key to disclose the plaintext or the key, analogous to an offence of obstruction of justice.
  3. Require provider assistance. Require the provider to remove any protection it applied, so-called managed access.
  4. Build exceptional access. Require industry to design a backdoor or master key that law enforcement can use, the code-based option.
  5. Participate. Infiltrate the network and read the communications from the inside, going undercover.
  6. Break the protection. Hack the target or exploit a vulnerability, law-enforcement hacking.
  7. Go beyond content. Use the metadata that surrounds a communication rather than its content (Walden 2018).

Consolidation. Encryption converts readable plaintext into unreadable ciphertext and end-to-end encryption puts the plaintext beyond even the provider. The going-dark claim says this is a fundamental shift. Walden treats it as a real but overstated challenge and offers a menu of seven responses. The rest of this module works through the responses that matter most and the Australian law built around them.

The Australian industry-assistance framework

What this section covers and why it matters. Australia's answer to the going-dark problem is the industry-assistance framework and this section states its three notice types and the limit that caps them because that limit is the twist the whole regime turns on. The framework sits in Part 15 of the Telecommunications Act 1997 which the TOLA Act 2018 inserted. It lets agencies enlist a designated communications provider to help access data. It runs from a voluntary request through to a compulsory notice to build a new capability and it cannot cross the systemic-weakness line.

Start with who is covered and what protection is in issue. A designated communications provider is the broad class of carriers, carriage-service providers and others who supply communications products and services. Electronic protection is defined to include authentication and encryption (Telecommunications Act s 317B). The three notice types then rise in coerciveness.

RULE. A technical assistance request asks a designated communications provider to do specified acts or things to help an agency access data. It may be given by the Director-General of Security or the head of ASIS or ASD or the chief officer of an interception agency. Compliance is voluntary (Telecommunications Act 1997 (Cth) s 317G).
RULE. A technical assistance notice requires a designated communications provider to do specified acts or things that the provider is already capable of doing to help an agency. It may be given by the Director-General of Security or the chief officer of an interception agency. Compliance is compulsory (Telecommunications Act 1997 (Cth) s 317L).
RULE. A technical capability notice requires a designated communications provider to build a new capability so that it can later give assistance. It may be given only by the Attorney-General with the approval of the Minister for Communications. Compliance is compulsory (Telecommunications Act 1997 (Cth) s 317T).

The three notices differ along two axes. The first axis is whether compliance is voluntary or compulsory, which separates the request from the two notices. The second axis is whether the provider uses a capability it already has or must build a new one, which separates the technical assistance notice from the technical capability notice. The technical capability notice is the most intrusive so it attracts the tightest control including the Attorney-General plus Minister approval and, on the provider's request, an assessment by two assessors one of whom is a former judge and one of whom has technical knowledge (Telecommunications Act s 317WA).

Now the limit that caps all three. It is a genuine unless-clause on the assistance power so it earns the twist chip.

RULE. twist A designated communications provider must not be requested or required by any of the three notices to implement or build a systemic weakness or systemic vulnerability into a form of electronic protection. A notice also must not prevent a provider from rectifying a systemic weakness or vulnerability (Telecommunications Act 1997 (Cth) s 317ZG).

The limit turns on a defined line between a systemic weakness and a targeted one. A systemic weakness is a weakness that affects a whole class of technology. It does not include a weakness that is selectively introduced to one or more target technologies connected with a particular person and it is immaterial whether the person can be identified (Telecommunications Act s 317ZG; s 317B). A systemic vulnerability is defined the same way. The line is between weakening a product for everyone who uses it and weakening a device connected to one target.

Worked example. An agency asks a provider to help unlock a single suspect's phone by targeting that handset. That is directed at a target technology connected with a particular person so it is not a systemic weakness. Now the agency asks the provider to insert a flaw into the encryption used across the whole product line so that any device can be opened. That affects a whole class of technology so s 317ZG forbids it. The same request phrased two ways falls on opposite sides of the line.

RULE. A notice must not require a provider to do an act for which a warrant or authorisation is required under another law. The assistance framework supplements the warrant regime rather than replacing it so the underlying access still needs its own lawful authority (Telecommunications Act 1997 (Cth) s 317ZH).

Consolidation. The framework runs from a voluntary request to a compulsory use of an existing capability to a compulsory build of a new one, given respectively under s 317G, s 317L and s 317T. Every notice is capped by s 317ZG which forbids a systemic weakness while allowing a weakness targeted at one person's technology. Whether that line can hold in practice is the central debate.

Compelled decryption and provider assistance

What this section covers and why it matters. Two of Walden's options work by ordering someone to hand over the plaintext or the means to read it and this section states the Australian and treaty forms of each because they raise the sharpest rights question in the module. The first form orders the suspect. The second orders the provider. Both avoid weakening encryption for everyone and instead compel disclosure in the individual case.

Start with the suspect. The Budapest Convention grounds a duty to disclose. Article 19(4) empowers authorities to order any person who has knowledge about the functioning of a computer system or the measures applied to protect the data to provide the information necessary to access it (Budapest art 19(4)). Walden treats this as analogous to an offence of obstruction of justice (Walden 2018).

Australia gives effect to this through the assistance order in the search-and-seizure regime rather than through Part 15.

RULE. An assistance order compels a specified person to provide the information or assistance that is reasonable and necessary to allow an officer to access, copy or convert data covered by a warrant. It reaches encrypted or password-protected data and failure to comply is an offence (Crimes Act 1914 (Cth) s 3LA).

The rights concern is that compelling a person to disclose a key or password may breach the privilege against self-incrimination. Walden records that the issue was examined in the United Kingdom in S and A where the court decided the privilege was not engaged and that even if it were the procedural safeguards were sufficient. Similar issues continue to be argued in other jurisdictions (Walden 2018). The disagreement is not settled and it is one of the essay strands below.

Now the provider. Article 19(4) is not limited to the suspect so the most obvious alternative source is the provider carrying or storing the data. Walden calls this managed access. The provider may hold a copy of the suspect's password or more commonly may have applied protection to the data in the course of providing the service which it can then be required to remove (Walden 2018). This is exactly what the Australian technical assistance notice and technical capability notice do.

A design defence has been argued against a provider duty. In a Belgian case involving the Microsoft-owned Skype the provider argued that its peer-to-peer architecture made compliance technically impossible. The court rejected the argument on the ground that Skype had created that impossibility itself by organising its service that way and it was convicted (Walden 2018). The lesson is that a provider cannot always escape an assistance duty by pointing to a design it chose.

Consolidation. Compelled disclosure orders the individual rather than weakening the technology. Australia orders the suspect through the s 3LA assistance order and orders the provider through the Part 15 notices, both grounded in the logic of Budapest art 19(4). The suspect form raises the privilege against self-incrimination and the provider form raises whether a design choice can defeat the duty.

Government hacking as an alternative

What this section covers and why it matters. If weakening encryption is dangerous then hacking the target may be the better response and this section states it as Walden's option six because it recurs as the leading alternative in the essay debate. Government hacking accesses the plaintext by breaking into the device or exploiting a vulnerability rather than by requiring the provider to build a backdoor.

Walden lists breaking the protection as a distinct option. Numerous terms describe it including computer network exploitation, equipment interference and network investigative techniques. Walden refers to it as law-enforcement hacking. One avenue is to exploit an existing vulnerability in the target application which overlaps with the exceptional-access option, the distinction being the source of the vulnerability (Walden 2018).

Scott and Ó Floinn treat lawful hacking as a regulatory alternative to attacks on encryption albeit an imperfect one. It is performed on the target system without the knowledge or consent of the technology company. Liguori highlights its benefit that instead of asking companies to sabotage their own security systems this approach exploits pre-existing and often unintended security holes (Scott and Ó Floinn 2024, citing Liguori).

Worked example. In Operation Venetic the United Kingdom National Crime Agency obtained a targeted equipment-interference warrant to receive the fruits of the French and Dutch penetration of EncroChat, an encrypted handset system favoured by organised crime. The encryption was never broken by weakening the product. The plaintext was obtained by hacking the system itself (Scott and Ó Floinn 2024).

The important qualification is that hacking is not cost-free. Scott and Ó Floinn note that in the United Kingdom the very powers that stand behind interception and equipment interference can compel technology companies to facilitate the hacking, so the companies may be not only targets but also compelled facilitators (Scott and Ó Floinn 2024). Walden adds that exploiting a vulnerability requires the state to decide whether to disclose the flaw so it can be patched or to keep it secret and exploit it, which is the vulnerabilities-equities problem (Walden 2018).

Consolidation. Government hacking obtains the plaintext by attacking the target rather than by weakening the encryption for everyone. It avoids the systemic-weakness problem but it raises its own costs including the compelled facilitation of hacking and the choice whether to disclose or hoard a vulnerability. Whether it is preferable to exceptional access is a live essay question.

Common confusions

These are the errors that cost marks. Each states the mistake and then the correction.

Confusion. A technical assistance notice and a technical capability notice are the same power. They are not. A technical assistance notice requires the provider to use a capability it already has under s 317L while a technical capability notice requires the provider to build a new capability under s 317T, so the notice to build attracts the tighter Attorney-General plus Minister approval (Telecommunications Act ss 317L, 317T).
Confusion. A technical assistance request is compulsory. It is not. A request under s 317G is voluntary and only the two notices under s 317L and s 317T are compulsory, so the request is the least coercive rung of the framework (Telecommunications Act s 317G).
Confusion. The systemic-weakness limit bans all weakening of encryption. It does not. Section 317ZG forbids only a weakness that affects a whole class of technology and expressly permits a weakness selectively introduced to a target technology connected with a particular person, so a targeted attack on one suspect's device is not caught (Telecommunications Act s 317ZG).
Confusion. A backdoor and a frontdoor are different in what they do. They are not. Both perform the same function of letting a non-party access an encrypted communication and the only difference is that a backdoor is kept secret while a frontdoor is openly acknowledged, so both create the same basic security weakness (Scott and Ó Floinn 2024).
Confusion. Compelling a provider to remove protection is the same as compelling a suspect to disclose a key. They are not. The provider duty runs through the Part 15 notices while the suspect duty runs through the s 3LA assistance order, and only the suspect duty raises the privilege against self-incrimination (Telecommunications Act Part 15; Crimes Act s 3LA).
Confusion. Government hacking is a way of weakening encryption. It is not. Hacking obtains the plaintext by attacking the target device or exploiting a vulnerability and leaves the encryption product intact for everyone else, which is why Walden treats it as a distinct option from building exceptional access (Walden 2018).

Debate

This is the centre of gravity for the research essay and this module carries the longest Debate section in the subject. Each strand is a two-sided contest with the leading voices named and each closes with questions to test a position rather than settle it.

Are we going dark or living in a golden age of surveillance? On one side law-enforcement and intelligence figures argue that the spread of encryption, and default end-to-end encryption in particular, makes the state unable to read what it is lawfully entitled to read. Comey framed the disconnect between legal authority and technical ability as "going dark" and figures such as Rosenstein and Rudd have called encrypted communications law-free zones (Walden 2018; Scott and Ó Floinn 2024, quoting Comey). On the other side the claim is overstated. Walden accepts encryption is a real challenge but rejects the implication that it is a fundamental and irreversible shift in the balance of power because such claims lack historical perspective and the same fears drove the crypto-wars of the 1990s (Walden 2018). Swire and Ahmad argue the opposite thesis that the volume and variety of metadata generated by our online activities means we live in a golden age for surveillance, so law enforcement has an alternative investigative route to accessing protected content (Walden 2018, citing Swire and Ahmad). Scott and Ó Floinn add that some pronouncements exaggerate the problem because companies that monetise user data are incentivised against encryption, encryption is often used incorrectly or not at all, and metadata frequently cannot be encrypted without breaking the system (Scott and Ó Floinn 2024). The deeper point is that the evidence for the true extent of going dark is thin, so the debate is partly about who bears the burden of proof.

Can exceptional access be built without a systemic weakness? The exceptional-access option would require industry to design a backdoor or master key that law enforcement could use in appropriate cases. On one side governments argue the door can be limited to good actors used only under proper legal process. On the other side the technical community argues that it is not possible to design a door that only good actors can use. The door is by definition available to bad actors too and its very existence weakens the security of everyone using the software (Scott and Ó Floinn 2024). Walden records the same objection that backdoors build insecurity into software and that even the standards process can be quietly corrupted, as the Snowden disclosures suggested for the Dual EC DRBG standard (Walden 2018). The Australian statute tries to draw exactly this line. Section 317ZG forbids a systemic weakness that affects a whole class of technology but permits a weakness targeted at one person's device (Telecommunications Act s 317ZG). The GCHQ "ghost protocol" proposal is the most discussed attempt to stay on the permitted side by adding a silent extra participant to a targeted conversation rather than breaking the encryption itself (Scott and Ó Floinn 2024, citing Levy and Robinson). The critics answer that the distinction is unstable because building the capability to add a ghost or to target a device may itself require a change to the product that weakens it for all, and the terms of the Australian limit such as "class of technology" are ambiguous. In Podchasov v Russia the European Court of Human Rights treated a requirement to decrypt end-to-end encrypted communications as one that could not be limited to specific individuals and would weaken encryption for everyone, and held it disproportionate (Scott and Ó Floinn 2024, discussing Podchasov v Russia).

Are technical backdoors the only threat, or do legal backdoors matter as much? Scott and Ó Floinn draw a distinction that reframes the whole debate. A technical backdoor is a mechanism programmed into software. A legal backdoor is a legal rule that has the effect, and may be intended to have the effect, of undermining encryption without making that effect clear (Scott and Ó Floinn 2024). Their argument is that the law on encryption risks a shallow form of legal secrecy where the rules are public but their implications for encryption are unclear and seemingly deliberately so. They contrast a legal frontdoor where it is clear the law regulates encryption with a legal backdoor where it is not even clear the law touches encryption at all (Scott and Ó Floinn 2024). They read the United Kingdom technical capability notice regime, and less obviously the Telecommunications Security Act 2021 and the Online Safety Act 2023, as capable of undermining encryption in this hidden way. Against this a defender would say the ambiguity is unavoidable because the technology changes and the state must keep its methods secret to stay effective. Scott and Ó Floinn answer that the history of investigatory powers in the United Kingdom, where statutory powers were repeatedly used in unpredicted ways, makes it hard to give the government the benefit of the doubt, and that such opacity may fail the quality-of-law requirement under Article 8 of the European Convention (Scott and Ó Floinn 2024).

Should the law compel a suspect to decrypt, and should refusal be a separate offence? On one side compelled decryption is the least dangerous response because it targets the individual and leaves the technology intact for everyone else. Budapest art 19(4) grounds a duty to provide the information needed to access a system and Australia enforces it through the s 3LA assistance order with refusal an offence (Budapest art 19(4); Crimes Act s 3LA). Walden treats the duty as analogous to obstruction of justice and notes that the United Kingdom makes failure to disclose a key a criminal offence carrying up to two years, rising to five for national-security or child-indecency cases (Walden 2018). On the other side compelling a person to hand over a key or password may breach the privilege against self-incrimination. Walden records that in S and A the court held the privilege was not engaged and that in any event the safeguards were sufficient, but that similar issues continue to be argued elsewhere and Koops has written on commanding decryption and the privilege (Walden 2018, citing Koops). The separate question is whether refusal should itself be a crime. Making refusal an offence gives the order teeth but it also punishes silence, and it can hand the suspect a choice between conviction for the underlying crime and conviction for refusing to assist. The deeper tension is between treating a password as testimony that the privilege protects and treating it as a key that the person can simply be ordered to produce.

Should providers be required to decrypt or remove protection? On one side the provider is the obvious source because it carries or stores the data and may hold the password or have applied the protection itself. Walden calls this managed access and the Skype case shows a court unwilling to accept a design-based excuse where the provider chose an architecture that made compliance impossible (Walden 2018). The Australian technical assistance notice and technical capability notice put this duty on a statutory footing (Telecommunications Act ss 317L, 317T). On the other side a provider duty pushes the systemic-weakness problem onto the provider and may compel it to redesign a service or to become a compelled facilitator of hacking. Scott and Ó Floinn stress that a technical capability notice might on one reading require a provider to remove or replace a system of end-to-end encryption or to institute the ghost protocol, and the secrecy attached to such a notice means the public might never know (Scott and Ó Floinn 2024). The design-versus-duty problem is real. If a provider builds true end-to-end encryption it cannot comply, so the pressure moves upstream to whether the law can forbid the provider from building that architecture in the first place. That is the very question the Australian systemic-weakness limit is meant to answer and the one the critics say it answers unclearly.

Is government hacking preferable to weakening encryption, and can cross-border access work without breaking it? On one side hacking the target leaves the encryption intact for everyone else, which is why Walden and Scott and Ó Floinn treat it as a distinct and often better option, and Operation Venetic shows it delivering evidence without a backdoor (Walden 2018; Scott and Ó Floinn 2024). On the other side hacking is not clean. It relies on exploiting vulnerabilities the state may prefer to hoard rather than disclose, which leaves the public exposed to the same flaws, and it may compel providers to facilitate the intrusion (Walden 2018; Scott and Ó Floinn 2024). A related strand is cross-border access. Much encrypted data sits with a provider in another country so the going-dark problem overlaps with the cross-border-access problem. Abraha maps the responses into a reformist approach that fixes the mutual-legal-assistance system, a unilateralist approach where a state compels production of foreign-held data, and an internationalist approach that seeks a global framework, and argues each must reconcile the competing interests of sovereignty, security and privacy (Abraha 2021). The CLOUD Act model of reciprocal bilateral agreements is the leading nuanced response and Australia is a party to that model (Abraha 2021). The point for encryption is that cross-border reform can deliver the data lawfully without ever touching the encryption, which makes it an alternative to both backdoors and hacking where the obstacle is location rather than ciphertext. This strand pairs with Module 9 on mutual legal assistance and Module 10 on direct access.

Discussion prompts

  1. Law-enforcement figures claim the state is going dark while others claim we are in a golden age of surveillance. Set out both claims with their leading proponents and argue which better describes the position given the evidence available.
  2. Evaluate whether law enforcement should be able to require exceptional access to encrypted data and assess whether the Australian systemic-weakness limitation in s 317ZG can hold the line it draws.
  3. Consider whether police should be able to require a suspect to decrypt data and whether refusal should be a separate offence, drawing on Budapest art 19(4), the s 3LA assistance order and the privilege against self-incrimination.
  4. Assess whether communications providers should be required to decrypt or remove protection they applied, using the managed-access idea and the Australian technical assistance and capability notices.
  5. Explain why government hacking is put forward as a preferable alternative to weakening encryption and evaluate the costs that make it an imperfect one.
  6. Using Scott and Ó Floinn's distinction between technical and legal backdoors assess whether a law that undermines encryption should be required to make that effect clear on its face.

Check your understanding

Auto-marked drills. Answer, then read the authority in the feedback.