When you build a backdoor
The sentence is thirteen words. The engineering truth behind it is absolute.
"When you build a backdoor into an encrypted device, anyone can walk through."
Erik Neuenschwander, Apple's senior director of user privacy and child safety, delivered the statement yesterday evening to the Canadian House of Commons Standing Committee on Public Safety and National Security during the final scheduled hearing on Bill C-22, the Lawful Access Act, 2026.
Google's Katherine Charlet, senior director of privacy, safety and security, added that the bill's powers are "boundless" and could have "global impacts since Canadians interact with people all over the world." Google's Jeanette Patell, director of government affairs and public policy in Canada, stated: "Secret orders are out of step with other democratic countries and would severely restrict companies' ability to be transparent with users about how their data is protected."
The two largest technology companies in the world told the Canadian Parliament, on the record, that this bill threatens the security of every person who uses their products.
What Bill C-22 does
Bill C-22 does not use the word "encryption." It does not explicitly require companies to break their encryption.
What it does is create a legal framework under which the government can issue secret technical capability notices — orders requiring electronic service providers to modify their systems to enable lawful interception of communications. The bill compels "core providers" to retain metadata for up to one year. It establishes a "reasonable suspicion" threshold for access, lower than the probable cause standard used in the United States.
The technical capability notices can be issued secretly. There is no judicial oversight of the technical requirement itself — only the interception warrant receives judicial scrutiny. There is no transparency obligation. There is no mechanism for the company to disclose to its users that it has been ordered to modify its systems. There is no public reporting requirement.
Public Safety Minister Gary Anandasangaree has described the bill as "encryption-neutral." Apple and Google told Parliament yesterday that this characterization does not match the bill's operative text.
Salt Typhoon
Apple's Neuenschwander made a specific evidentiary argument yesterday that the committee had not previously engaged: the Salt Typhoon cyberattack.
In 2024, Chinese state-sponsored hackers from the group known as Salt Typhoon compromised the lawful interception infrastructure of major US telecommunications carriers — the systems built specifically to comply with the Communications Assistance for Law Enforcement Act. The hackers exploited the access points that existed because the law required them to exist. They accessed real-time call data, text messages, and the communications of senior government officials and political figures.
Apple told the committee: the US lawful access legislation "was narrower than Bill C-22," and Salt Typhoon exploited it. The backdoor the US government required was the backdoor China walked through.
The structural argument is not hypothetical. It is a documented case where the lawful access infrastructure of the world's most technically sophisticated intelligence community was compromised by a foreign adversary through the access points the law mandated.
The exit threats
The testimony follows weeks of escalating warnings from privacy-focused companies.
Signal's VP of strategy, Udbhav Tiwari, stated the company "would rather pull out of the country than be compelled to compromise on the privacy promises we have made to our users."
Windscribe, a VPN provider headquartered in Toronto, confirmed it would relocate its headquarters outside Canada rather than comply with metadata retention requirements. Windscribe's no-logs policy was validated in a 2025 Greek court case.
NordVPN stated: "There isn't a scenario in which we would compromise our no-logs architecture or encryption protections."
ExpressVPN called its encryption and no-logs architecture "non-negotiable."
Apple and Meta have both raised public concerns. More than 200 cryptography experts and computer scientists signed an open letter opposing the bill's approach to encryption.
Michael Geist, Canada Research Chair in Internet and E-commerce Law at the University of Ottawa, called the bill "the Lawful Access Two-Headed Surveillance Monster" and compared the government's dismissal of industry warnings to the "disastrous Online News Act playbook" — a reference to Canada's 2023 legislation that prompted Meta to block news content in Canada.
OpenMedia told the committee to "withdraw Bill C-22 or gut its surveillance provisions."
The UK precedent
The United Kingdom's Investigatory Powers Act contains similar technical capability notice provisions. In 2025, Apple received a secret order under the Act requiring the company to provide access to encrypted iCloud data.
Apple's response was not to build the backdoor. It was to withdraw the Advanced Data Protection feature from the United Kingdom entirely — removing end-to-end encryption for iCloud backups for all British users. The users lost the security feature. The government did not gain the access it sought. The adversaries who target British users now face weaker encryption on their iCloud backups.
This is the operational consequence of the backdoor architecture: the company that refuses to compromise encryption removes the feature rather than weakening it. The users lose protection. The government gains nothing. The adversaries gain a softer target.
When asked whether Apple would take the same action in Canada, Neuenschwander declined to speculate but said the company was engaging with the committee to seek "positive amendments."
The committee session
Yesterday's hearing was the final scheduled witness session before the Standing Committee on Public Safety and National Security considers amendments. The committee heard from dozens of witnesses across three meetings.
Conservative MP Frank Caputo pushed to extend the debate, arguing the bill is being "rammed through Parliament." The session was adjourned before the amendment process began.
A Canadian Association of Chiefs of Police representative told the committee that three years of metadata retention would be "ideal" — longer than the one year the bill currently mandates.
Public Safety Minister Anandasangaree has stated he is "open to amendments" and hopes to pass the bill before Parliament's summer break. The bill has completed two of three House of Commons readings and will go to the Senate for final review.
The pattern
Bill C-22 is not an isolated legislative event. It is the latest in a concurrent push across democratic countries to mandate lawful access to encrypted communications.
The United Kingdom's Online Safety Act includes provisions that could require scanning of encrypted messages. Signal's president Meredith Whittaker stated the company will leave the UK before compromising encryption. Ofcom was expected to finalize technical standards by April 2026.
Sweden's parliament is considering a law requiring messaging apps to store and provide access to user communications. Sweden's own Armed Forces CIO officially adopted Signal for non-classified communications — then the government proposed mandating access to the same tool.
Australia's Assistance and Access Act of 2018 was the first democratic country to pass encryption-undermining legislation. It has been used to compel companies to build interception capabilities without public disclosure.
The United States does not currently mandate encryption backdoors, but the FBI has repeatedly called for "responsible encryption" that provides lawful access. The Salt Typhoon breach of US lawful interception systems has weakened the FBI's argument.
In each case, the legislative mechanism is the same: grant the government power to issue secret orders requiring technical modifications to enable interception, with no public disclosure and limited judicial oversight of the technical requirement. In each case, the privacy and security community's response is the same: the backdoor built for the government is exploitable by every adversary, and the documented evidence — Salt Typhoon — proves it.
The architecture that has no backdoor
The user-side response to the backdoor mandate is the same response this publication has documented across every domain of internet freedom.
End-to-end encrypted protocols where the key is held by the user, not the service provider. The provider cannot comply with a technical capability notice because the provider does not hold the key. The architecture is the legal defense.
Signal's protocol. Matrix's encryption. Briar's peer-to-peer transport. URnetwork's peer-to-peer overlay. Each distributes the key to the endpoints and removes the intermediary's ability to decrypt. A government order to the intermediary produces nothing because the intermediary holds nothing.
Open-source implementations where the code is auditable and backdoor insertion is detectable. The transparency of the code is the defense against secret modification orders. If the code is open, the order cannot be secret — because the modification would be visible.
Federated and self-hosted services where the user controls the server. A technical capability notice served on a user's own server is a search warrant, not a backdoor — it requires individual judicial process, not blanket technical modification.
The architectural counter to Bill C-22 is not a legal argument. It is a design choice. The system that never holds the key cannot be ordered to surrender it. The system whose code is open cannot secretly modify it. The system whose server is the user's own cannot be silently compromised by an order served on a company.
"When you build a backdoor into an encrypted device, anyone can walk through."
The architecture that has no backdoor has no door for anyone to walk through — not the government, not the adversary, not the company that built it.
URnetwork is a peer-to-peer overlay for censorship-resistant transport. The URnetwork overlay distributes encryption keys to the endpoints. The intermediary holds no key and cannot comply with a technical capability notice because there is nothing to surrender.
https://ur.io
References (10 sources)
References
- CBC News: Committee studying lawful access bill urged to protect encryption
- Global News: Apple, Google say lawful access bill could undermine privacy
- Bloomberg: Apple, Google blast Canada's plan to expand police data powers
- AppleInsider: Canada's online safety bill could threaten encryption
- Cybernews: Apple and Google want judges to review government encryption orders
- TechRadar: Windscribe joins Signal in threatening Canada exit
- TechRadar: ExpressVPN joins the backlash against Bill C-22
- Michael Geist: The Lawful Access Two-Headed Surveillance Monster
- OpenMedia: Withdraw Bill C-22 or gut its surveillance provisions
- Parliament of Canada: Bill C-22 LEGISinfo