A definition that encompasses the need to exclude any obligations that cause systemic vulnerabilities would need to take into account the multiplicity of ways and proposals that keep emerging for getting around encryption. Many of these don't compromise encryption directly, but try to get at it indirectly by circumventing it or bypassing it, yet still have the same impact in terms of the vulnerabilities that they ultimately create. The current definition doesn't capture all of these. It's limited in scope. I would also really encourage your committee to consider blocking that.
