Evidence of meeting #39 for Public Safety and National Security in the 45th Parliament, 1st session. (The original version is on Parliament’s site, as are the minutes.) The winning word was data.

A video is available from Parliament.

On the agenda

Members speaking

Before the committee

Gary Anandasangaree  Minister of Public Safety
O'Gorman  President, Canada Border Services Agency
Deputy Commissioner Bryan Larkin  Royal Canadian Mounted Police
Pyke  Assistant Commissioner, Correctional Operations and Programs Sector, Correctional Service of Canada
Legault  Chief Financial Officer, Parole Board of Canada
Giles  Deputy Director, Policy, Canadian Security Intelligence Service
McCrorie  Vice-President, Intelligence and Enforcement, Canada Border Services Agency
Hazen  Chief Financial Officer, Royal Canadian Mounted Police
Bilodeau  Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness
Nashef  Director General, Policy, Planning and Accountability, Canadian Security Intelligence Service
Superintendent Richard Burchill  Director General, Technical Investigation Services, Royal Canadian Mounted Police
Wong  Acting General Counsel, Policy Sector, Department of Justice
Hiegel  Director General, National Security Policy Directorate, Department of Public Safety and Emergency Preparedness
Gibner  Deputy Assistant Deputy Minister, Policy Sector, Department of Justice

6:15 p.m.

Conservative

Rhonda Kirkland Conservative Oshawa, ON

No.

Voices

Oh, oh!

6:20 p.m.

Director General, Policy, Planning and Accountability, Canadian Security Intelligence Service

Ramzi Nashef

—just in the sense that there are a lot of layers to the question you just asked me.

In fact, not to challenge the premise, but it would be my view that we're not asking for a government-mandated access point. It would be, again, intercept-capable. That's the language we would use.

6:20 p.m.

Conservative

Rhonda Kirkland Conservative Oshawa, ON

Thank you. That helps me. That answers my question.

Would you agree, though, that any mechanism created for lawful access is inherently dual-use, so it could potentially be discovered or exploited outside authorized use?

6:20 p.m.

Director General, Policy, Planning and Accountability, Canadian Security Intelligence Service

Ramzi Nashef

There is no technical system by any means that is 100% foolproof by any stretch. The only small footnote I would give you there is that.... Well, I might leave it there, and I'll let you keep going.

6:20 p.m.

Conservative

Rhonda Kirkland Conservative Oshawa, ON

Okay. I may ask you about that footnote later.

Has CSIS assessed whether large-scale metadata retention creates a higher-value target for foreign intelligence services or cybercriminal groups?

6:20 p.m.

Director General, Policy, Planning and Accountability, Canadian Security Intelligence Service

Ramzi Nashef

It wouldn't necessarily be a CSIS assessment there. It would be a national security partner that would have the more centralized expertise on the cyber side. My short answer would be, yes, that's a thing that has been considered and thought through.

I would maybe offer my footnote now, because I teased it. I think the point I started with is the point I will start with again here, and then I'll finish with a second one. It is that, no, there is no technical system that is 100% foolproof by any stretch. We have heard what has been said here and take the point. I would say also, though, that you have a group of people who work in a national security community, whose fundamental ethos is to protect Canadians, Canadian systems and the critical infrastructure of this country.

6:20 p.m.

Conservative

Rhonda Kirkland Conservative Oshawa, ON

Perfect. That's understood. I'm coming from a place of helping Canadians understand this and helping them feel like they can trust it.

On a human level, one to one, when you're talking to anyone, they would feel like large-scale retention of metadata would be a higher-value target. Put yourself in the place of a bad guy. You're a bad guy—it's a higher-value target.

6:20 p.m.

Director General, Policy, Planning and Accountability, Canadian Security Intelligence Service

6:20 p.m.

Conservative

Rhonda Kirkland Conservative Oshawa, ON

Mr. Bilodeau, the public safety minister has mentioned that the metadata provision will be brought in line with U.S. law, but the American lawful access statute, CALEA, imposes no data retention requirement at all. It's an interception regime. It requires providers to be able to hand over communication under a warrant. It does not require them to stockpile metadata in advance on everyone, just in case. There's nothing in U.S. law resembling the up-to-a-year, suspicionless retention this bill contemplates.

Can you be specific on which U.S. statute he would be referring to that would get us up to date and in line with U.S. law?

6:20 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

I think that statement may have been corrected following the minister's remarks. What I understood it to mean, or what was said during that conversation, was really about bringing encryption in line with CALEA. It has specific language around end-to-end encryption and not being able to force providers to decrypt end-to-end encryption. That was the intent of that statement.

Rhonda Kirkland Conservative Oshawa, ON

That brings to mind, then, Mr. Caputo's question, because I'm finding myself, as many Canadians are, not as technical and not understanding. End-to-end encryption I understand. However, there are encrypted items on my cellphone right now that are not really end-to-end encryption so....

6:20 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

The distinction that the legislation makes is that if an electronic service provider does not have the capability to decrypt your data, because your device has encrypted the data on your phone and they don't have the key, so to speak, then the legislation can't force it, because the supplier or the provider does not have the capability to do it. There's a distinction based on where the data is encrypted.

6:20 p.m.

Conservative

Rhonda Kirkland Conservative Oshawa, ON

Would it—

The Chair Liberal Jean-Yves Duclos

Thank you, Ms. Kirkland. I'm so sorry.

We'll go to MP Housefather for five minutes, please.

Anthony Housefather Liberal Mount Royal, QC

Thank you very much, Mr. Chair.

I think this is a good opportunity for us because we have to prepare amendments to the bill. One amendment that I think is very important is the one that Ms. Kirkland was just talking about. It's with respect to encryption and bringing this into line with the U.S. statute to say that no company that doesn't have a key to the encryption has to create one or could be ordered to create one, under an order. I think that's very important, but another element that is important to look at in this bill is the systemic vulnerability issue, the definition of systemic vulnerability and its interplay with the orders.

I think it will be relatively simple to craft amendments to say, for example, that you can't be forced in an order to create a systemic vulnerability. I think we can create amendments to do this that would be very agreeable.

I have an issue with the definition of “systemic vulnerability”. This is what it says right now:

systemic vulnerability means a vulnerability in the electronic protections of an electronic service that creates a substantial risk that secure information could be accessed by a person who does not have any right or authority to do so.‍

A substantial risk is very high. It means it's not just any risk. It's not a plausible risk. It's not just a risk. It's not a material risk. It's not a real risk. It's not a credible risk. That's a lower threshold. It basically means that if somebody says, “I think there's a plausible risk that by doing this we will create a systemic vulnerability”, they could still be forced to do it.

I'm not satisfied with “substantial” risk. I understand that there may be a reason to not just remove the word “substantial” and put in “a” risk, because that would be any risk, irrespective of how immaterial it is. What word should I propose, or do you recommend that I propose, as an amendment?

For example, if I were to use “plausible” risk, what, then, do you believe would be the legal interpretation? How would that be viewed? What would be the effect?

6:25 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

That's a good question. I might ask my colleagues from the Department of Justice to weigh in. I'll give them an opportunity to think about it.

At the end of the day, substantial risk was used to strike that balance between providing a framework for lawful access and making sure we're not creating those systemic vulnerabilities. The last thing we want this legislation to be used for is to weaken this. As one of the previous witnesses said, we don't want to harm Canadian security writ large, whether it's through this or cybersecurity.

That's why I would add to Mr. Nashef's answer earlier that a lot of data is being retained now. Companies are used to doing this. They take a lot of precautions. Some of the firms have very good cybersecurity hygiene and take really important steps to protect that. We would expect that to continue under this lawful access regime, because some of the data might still be kept.

Anthony Housefather Liberal Mount Royal, QC

I agree, but then you're speaking to why we shouldn't be using the threshold of substantial risk. Substantial risk means you could be asking to do something. They could say, “I think there's a real risk here, a plausible risk”, and they're still forced to do it.

Coming back to my question, if I said “plausible” risk, what is the position of the Department of Justice on what that would mean? Would that make any change that would undermine the purpose of this legislation?

6:25 p.m.

Acting General Counsel, Policy Sector, Department of Justice

Normand Wong

Thank you for the question.

I don't know if I'll be of much assistance on this, Mr. Housefather. You have highlighted the fact that a variety of words can be used. I think you rightly point out that it will change the scale. At the end of the day, it's a policy decision, how this is decided, and it's the Minister of Public Safety's responsibility in that part of the act.

Anthony Housefather Liberal Mount Royal, QC

Since I only have one minute left, I'll just follow up on something from earlier.

I understand what the witnesses are saying; it's all very clear. I think we have to be responsible, but without requiring a company to do something that could plausibly create a risk, as the company mentioned.

So if you can't suggest another word, I'm going to continue to use the word “plausible”.

Mrs. DeBellefeuille, is “plausible” the right word in French?

Claude DeBellefeuille Bloc Beauharnois—Salaberry—Soulanges—Huntingdon, QC

Yes.

Anthony Housefather Liberal Mount Royal, QC

So, if I use this word, do you think it is going to create a legal issue by preventing the government from obtaining the information that police forces or others really need?

6:25 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

Mr. Chair, from a non-legal standpoint, that is, simply from a linguistic point of view, the words “plausible” and “un risque important” don't mean the same thing to me. The word “plausible” evokes the likelihood that something will occur, so the level of risk is much lower. It's not in the same category as a substantial risk. They might not be synonyms. I don't want to pull out my French dictionary, but these words don't necessarily belong in the same category.

Anthony Housefather Liberal Mount Royal, QC

It's not about whether or not they're in the same category, but rather about what they mean for the company. If we say that a risk is plausible, then it isn't substantial.

6:30 p.m.

Senior Assistant Deputy Minister, National Cyber Security Directorate, Department of Public Safety and Emergency Preparedness

Richard Bilodeau

A plausible risk could suggest the likelihood of it occurring, regardless of the risk level. I think it's up to you as parliamentarians to decide how you'd like to move forward. However, there is a difference between the two.