Again, thank you all for being here.
I think we have a general tension in this law, as you've rightly pointed out, between the goal to be as safe as possible and the goal to respect privacy rights. We have to find the middle, where most people are comfortable. I don't think we'll ever find a situation where everybody agrees on the details of the bill, but I think we have to try to find that reasonable point.
We start from a premise that the bill is laudable in that it deals with some of the flaws in Bill C-2. The bill is really needed, in terms of law enforcement having access to information that technologically isn't dealt with under current law, but as everybody here said, there are concerns you have expressed.
I've noted a real discomfort with the idea of regulations. I would point out that there's a suspicion as to what's going to be in the regulations, and then we're hearing hypotheticals of what might be in the regulations or how orders might be used. Some people will trust the government and say that it will act reasonably, that the charter still applies and that there's still judicial oversight. Other people say that they won't trust it unless it's written in the bill. I get all that.
I also expressed concern about the interplay between systemic vulnerabilities and the orders. The way I read the bill, the company is exempt from having to do it if it creates a systemic vulnerability. I understand that we might need to look at the definition of systemic vulnerability. However, in an order, the company's obliged to carry out the order.
Mr. Geist, you talked about that issue. Could you express the way you would amend the bill to deal with that?