Evidence of meeting #138 for Access to Information, Privacy and Ethics in the 42nd Parliament, 1st Session. (The original version is on Parliament’s site, as are the minutes.) The winning word was elections.

A video is available from Parliament.

On the agenda

MPs speaking

Also speaking

Stephanie Kusie  Calgary Midnapore, CPC
Maxime-Olivier Thibodeau  Committee Researcher
André Boucher  Assistant Deputy Minister, Operations, Canadian Centre for Cyber Security, Communications Security Establishment
Dan Rogers  Deputy Chief, SIGINT, Communications Security Establishment
Allen Sutherland  Assistant Secretary to Cabinet, Machinery of Government and Democratic Institutions, Privy Council Office

Charlie Angus NDP Timmins—James Bay, ON

Mr. Chair, I just want to put a concern of mine on the record. From our meeting last week with Waterfront Toronto, we received two forms of correspondence. One was an official letter from Jim Balsillie in which he said that the parliamentary secretary had lied about what he said and was misrepresenting facts, and he wants to set the record straight.

We also received correspondence—I don't believe we got the letter—from Julie Di Lorenzo, who said that false statements were made.

I am concerned. We've been approaching all our work in a very particular way. I'm worried about turning this into a battle between Mr. Vaughan and Mr. Balsillie, but I think Mr. Balsillie has a right to appear. I also think that Julie Di Lorenzo, if she said false statements were made during that hearing, should be allowed to speak as well.

We just need to find a format to make it work so that they can present, and we can get to this and then move on.

4:50 p.m.

Conservative

The Chair Conservative Bob Zimmer

Yes, I'll speak to this.

The letter was received by the chair, and I believe we're just waiting for it to be translated. Mike has just said it should be ready by tomorrow afternoon.

Further to that, we have invited Mr. Balsillie to come back to speak to the committee. He's not able to come Thursday, so we're looking for a date when he is able to come back. Based on conversations I have had with the vice-chairs, I can say that's already been done.

It's just the letter to the committee that's outstanding, and it will be coming tomorrow.

Charlie Angus NDP Timmins—James Bay, ON

There's also Ms. Di Lorenzo, who I believe may have been on the real estate committee or had something to do with Waterfront Toronto. She said she was getting her lawyer to work with her on a letter, so I would like us to reach out to her in terms of whether we will be getting an official letter or if she will make a statement.

I want clarity in terms of what happened with testimony.

4:50 p.m.

Conservative

The Chair Conservative Bob Zimmer

Yes, the chair can do that. I'll just make sure the analysts have that request.

Maxime-Olivier Thibodeau Committee Researcher

Sure.

4:50 p.m.

Conservative

The Chair Conservative Bob Zimmer

Perfect.

There is no presentation from the group, so we're right into questions.

I'll give the first seven minutes to Mr. Erskine-Smith.

Nathaniel Erskine-Smith Liberal Beaches—East York, ON

Thanks to new witnesses and to witnesses we've had before.

Specifically for CSE, as a starting point, I've read a previous threat assessment. Has anything changed since that threat assessment that we should know about?

André Boucher Assistant Deputy Minister, Operations, Canadian Centre for Cyber Security, Communications Security Establishment

The publication of the update to the threat assessment is imminent. It's providing my team the time necessary to also build the advice and guidance that's focused and targeted to the elements of that report. I'd hate to pre-publish the report today, but I would assure you that we're not waiting for the report's publication to take action on the elements of it that we're already aware of.

By “imminent” publication, I mean probably days—weeks at the most.

Nathaniel Erskine-Smith Liberal Beaches—East York, ON

The minister said she was sitting down with social media platforms. From the security side of things, how much do you work directly with social media companies to ensure that their platforms are not being hijacked?

4:50 p.m.

Assistant Deputy Minister, Operations, Canadian Centre for Cyber Security, Communications Security Establishment

André Boucher

From a cyber centre perspective, the presence of the ecosystem...are all companies. My concern starts with the equipment we all use, the software that's on that equipment, and the way we interact with that equipment in those networks.

From my perspective, social media companies are one element of that complex ecosystem, and we treat them just the same. We engage with those companies and have the same expectations of their practices in cybersecurity measures and of their behaviour and responses in the ecosystem. This is similar to what other companies would have, from the device companies to the operating system or applications that ride on top.

Nathaniel Erskine-Smith Liberal Beaches—East York, ON

Would you share our committee's concerns with respect to hateful content, inflammatory content and content that incites violence, which stays on these platforms and is not appropriately dealt with in a timely fashion?

4:50 p.m.

Assistant Deputy Minister, Operations, Canadian Centre for Cyber Security, Communications Security Establishment

André Boucher

It is not the focus of the cyber centre to analyze or make comments on the information carried by computers, emails or social media content, but we expect all companies to behave as good Canadian citizens and be mindful of their presence and their responsibilities in that presence in Canada.

To get away from social media for a second, if a software company wasn't behaving as a good corporate citizen, we would have just as much of an objection with them.

Nathaniel Erskine-Smith Liberal Beaches—East York, ON

Sure. I always find it funny that Facebook is reliant upon free speech. I'm a great defender of it and I don't think people should necessarily be thrown in jail for saying absurd, ridiculous things. However, the idea that they can say these things on the Facebook platform and not have them taken down begs a question as to what community Facebook actually wants to build.

With respect to hijacking algorithms specifically, and let's use the Internet Research Agency as an example, they'll have a number of not just bots but people managing a number of accounts to amplify a particular message. Often, it's a message of disinformation or misinformation. Is that something your organization is seized with?

4:55 p.m.

Assistant Deputy Minister, Operations, Canadian Centre for Cyber Security, Communications Security Establishment

André Boucher

We certainly start a conversation with, “I expect all products in my ecosystem to be of the best quality possible,” so if we were to observe or someone was reporting to us that there was something not right with the software or the hardware, would we investigate and try to get to the bottom of the story? Absolutely, and we would absolutely do something with the company, but there's also an opportunity in the foreign space, which I'll let Dan answer.

Dan Rogers Deputy Chief, SIGINT, Communications Security Establishment

From the foreign intelligence perspective, we're looking at foreign actors outside of Canada and what their intentions might be toward Canada. One of the things we can do to help inform the cyber centre or help other elements of the Government of Canada to respond is to see those foreign actors. If we can identify what behaviours they're taking—if we can see their online infrastructure or the types of botnets or techniques they may be using—that will be an edge we can provide to the cyber centre and to other people in government who, within their mandates, can respond.

Nathaniel Erskine-Smith Liberal Beaches—East York, ON

Is there anything the platforms can do that they are not currently doing to combat this problem of hijacking algorithms?

4:55 p.m.

Assistant Deputy Minister, Operations, Canadian Centre for Cyber Security, Communications Security Establishment

André Boucher

The information would come to me from that team. We've never hesitated to engage with companies, domestic or foreign, regarding the quality and behaviour of their devices or software. We would do exactly the same in this instance.

Nathaniel Erskine-Smith Liberal Beaches—East York, ON

I mentioned the yellow vest movement, and I read a hateful comment that was an incitement to violence. There are many, obviously, that you can find across the Internet if you can bear to go to the comments sections.

We heard testimony from Michael Wernick that he was very concerned about violence in the upcoming election. Does it go beyond those sorts of online comments? Are there real, credible threat assessments, and should we be concerned that there is to be violence in the upcoming election?

4:55 p.m.

Deputy Chief, SIGINT, Communications Security Establishment

Dan Rogers

What I can say, from the national security and foreign intelligence perspective, is that, although a lot of what we've talked about today is in the cyberspace, of course we look for threats of all kinds that might be directed toward Canadians, whether that's terrorism, cyber-attacks or other types of malign foreign activity that we might see perpetrated against Canada or Canadians. In that space there are existing mechanisms. This isn't a new challenge for us. If we see those types of things, we'll report them. CSIS, the RCMP and others have the mandate to investigate those within Canada should they occur. The intelligence function that we and others will have will provide them with any information we see, so if it comes up we will be vigilant and we'll make sure they have that information.

Nathaniel Erskine-Smith Liberal Beaches—East York, ON

Mr. Sutherland, I don't know if you can speak to Mr. Wernick's comment and maybe give us a bit more detail. Is it based on just social media commentary and how nasty it tends to get or is there a real threat at issue here that the comments were in relation to?

Allen Sutherland Assistant Secretary to Cabinet, Machinery of Government and Democratic Institutions, Privy Council Office

I think Mr. Wernick was speaking from a personal view. He started his comments that way. I would say the worry that he expressed is one broadly shared by people who look at issues around social inclusion, not just in Canada but around the world.

Nathaniel Erskine-Smith Liberal Beaches—East York, ON

The last question I would have is with respect to digital education outreach initiatives. We know there's $7 million. An open question is how effective we can be in a short period of time to educate Canadians about misinformation or disinformation on the Internet. In the experience of the CSE, knowing that political actors like ourselves are a weak link, as it were, do you think the funds would be better spent to ensure that volunteers on our teams, our riding associations and those involved in campaigns, including ourselves, are doing everything we can to ensure we're not hacked and we're not vulnerable?

4:55 p.m.

Assistant Deputy Minister, Operations, Canadian Centre for Cyber Security, Communications Security Establishment

André Boucher

I will address a bit of that. The $7 million announced are incremental funds toward specific activities. I think we can't lose sight of the fact that we've actually started...even before the first “Cyber Threats To Canada's Democratic Process” report, we have engaged with all the participants who were mentioned in that report. The ongoing activity of making people aware and talking about prevention has been ongoing for years, and that's a significant investment.

4:55 p.m.

Conservative

The Chair Conservative Bob Zimmer

Thank you.

Next up, for seven minutes, is Mr. Kent.

5 p.m.

Conservative

Peter Kent Conservative Thornhill, ON

Thanks again to all of you for appearing again before us today.

Mr. Rogers and Mr. Boucher; you were last with us on October 18, I believe.

One of the questions I asked you had to do with how you would handle something like the Beyoncé play in the last federal election in the United States. A Russian entity or individual created a fake fan website for the well-known, popular star Beyoncé and attracted millions of followers with simple celebrity gossip, information, pictures and so forth. Then, a couple of days before the actual vote, this time bomb exploded with all sorts of statements and directions apparently from Beyoncé, which were intended, according to one of our previous witnesses, Dr. Ben Scott, to discourage black voters in the United States from participating in that election.

At the time, we talked theoretically. I don't want you to compromise or expose procedures and tactics, but I do want to talk about the capability of the intelligence community and this new panel to respond in the critical last few days or even final hours before an election to something like the Beyoncé play.