Absolutely, and I think that's one of the big issues with this bill.
With regard to the intentions of the bill, the bill is in two parts, and they do two very different things. One is about authorities, and the other is about capabilities.
If you look at clause 5 and the list of things that the Governor in Council can make regulations about, or clause 7 and ministerial orders, you see that they are written extremely broadly.
First, I would call your attention to the regulations that the Governor in Council may make. They include all the things in paragraphs 5(2)(a) through 5(2)(d), which means more than implicit granting of authority. Paragraph 5(2)(a) could include back doors, and paragraph 5(2)(b) could include back doors, because they can require the installation of devices on ESPs' infrastructure. There is nothing else in the bill that prevents that from happening, other than the goodwill of the minister and the goodwill of the intelligence commissioner, and that's that.
I am particularly very concerned about these secret orders, because the minister has the power to do any of the things that could be in a public regulation to any telco or any electronic service provider. At least the regulations are going to be published and will go through a process, and people can see them. However, secret orders can include back doors, because that certainly isn't precluded in the definition of “systemic vulnerability”, and it doesn't protect encryption in any meaningful sort of way.
If you take those two things together, the guardrails simply are not there. The only guardrail is the Charter of Rights and Freedoms, for which we'll have to have litigation in order to.... I'm afraid the government are setting themselves up for failure if they pass a bill that goes too far, a bill that violates the charter and that is going to be found to be unconstitutional. It's better to get it right.
