Thank you so much for putting this question forward.
As drafted, the bill has a blanket secrecy provision that would essentially prevent us from being able to explain to our users that these changes were made and, if discovered, why they were made. This latter part is really important because, ultimately, our services are available around the world. This means there are security researchers, technical experts and journalists around the world who regularly decompile and reverse-engineer our products. Sometimes it's because they're trying to look for vulnerabilities and help us shore up our systems through bug bounty programs. Sometimes it's because they're trying to see if they can get any information on what our next product or feature releases will be. This happens with all companies like ours.
Ultimately, these kinds of changes will be discovered. It's not a question of “if”. As Rachel was saying, when it comes to the exploitation of a vulnerability, discoverability is a question of “when”. Providers would then be in a really significant conflict because users would completely lose trust in the security and privacy protections of our products.
