Mr. Chair, members of the committee, I appear before you today on behalf of Crypto Québec.
When I last appeared before this committee, as part of the consultations on Bill C‑8, I concluded by saying that the Quebec model increased overall security by harmonizing security and privacy protections, and that the government should draw inspiration from this approach, which has already proven to be effective.
However, today we find ourselves faced with a bill that many information security professionals in the country and abroad, as well as several technology organizations, consider fairly dangerous. These are organizations whose applications are used daily by a very large number of elected Canadian officials as well as law enforcement. I am notably thinking of Signal from the Signal Foundation, which is threatening to leave the country if this bill is passed, so as not to weaken the encryption of its application.
In our opinion, this bill should be withdrawn and completely rethought. The basic premise of this bill is flawed.
Bill C‑22 is based on a premise that has never been rigorously publicly demonstrated, which is that encryption is the main threat to public safety in Canada today. There is no evidence of that.
We've heard anecdotes from certain police forces and intelligence agencies, but we've never seen any empirical, public evidence that encryption is the greatest threat to Canada's national security.
On the contrary, it has been shown that the more data that is collected, the greater the risk of data leaks, without any real improvement in security.
To that effect, in the U.S., just a few years ago, it was demonstrated by The Washington Post that the FBI had massively overestimated the number of investigations allegedly blocked by encryption. These figures were then used publicly to justify the expansion of surveillance powers. We should not repeat the same mistake in Canada.
While we're being told about encryption being the problem, the actual public reports from the Canadian intelligence agencies, such as those from NSICOP, primarily tell us about foreign interference, deficient resources and the opaque expansion of the national security apparatus. The problem is thereby pretty clear. There's a lack of human, technical and financial resources as well as an excessive increase in data collection powers without any real oversight capacity. Bill C-22 addresses none of that.
Encryption is not the heart of this crisis; it is the solution.
Despite this, Bill C‑22 proposes nothing less than the creation of a permanent digital monitoring infrastructure. It would be an infrastructure in which service providers could be forced to keep more data, maintain technical access capabilities, respond to secret orders, and participate in extraction processes, even though the word “oversight” appears exactly zero times in the text of the bill.
The bill also makes no specific reference to robust democratic checks and balances. This is extremely concerning. A healthy democracy is founded on privacy, freedom of association, confidentiality of communications, and spaces where citizens can discuss and criticize power without fear of permanent structural monitoring.
To Albertans and Quebeckers alike, I say this. No federal government should ever possess expanded structural surveillance capabilities in a context where major democratic and constitutional debates may one day oppose Ottawa and the provinces.
Canada's history reminds us that national security tools can sometimes extend beyond external threats and affect domestic political movements. That's precisely why stellar democratic guardrails are needed.
It is also important to note that if this bill passes in its current form, all the efforts made in terms of digital sovereignty in Quebec will become null and void.
Protecting democracy in Canada requires strong institutions that balance security and privacy with robust oversight, checks and balances. Bill C-22, unfortunately, gives the impression that the main threat to Canada is becoming increasingly internal rather than external. We all know this is a slippery slope for a liberal democracy.
In closing, we believe that the Canadian Parliament should not adopt such a fundamentally transformative bill based on unfounded assumptions, fears or premises that have not been publicly demonstrated. There is no back door that is only used by the good guys. The history of cybersecurity shows us precisely the opposite.
Since the likelihood of potential abuses and their effects are too great, we are calling for Bill C‑22 to be withdrawn in its entirety.
Thank you.
