Thank you, Chairperson and members of the committee.
I am Udbhav Tiwari, vice-president of strategy and global affairs at Signal.
Signal is a non-profit. We make the world's most widely used, truly private messaging app, and the encryption protocol we built, the Signal protocol, is the gold standard that much of the industry beyond us relies on. It is essential for providing the core infrastructure for the fundamental human right to privacy.
Those who depend on us and on this technology are regularly subjected to surveillance around the world. However, it is vital for us to recognize that it is because of how we operate, at the frontier of global cybersecurity, that we understand intimately how technical architecture protects human safety and how easily badly drafted laws can dismantle these critical protections.
In its current form, Bill C-22 would convert the everyday tools Canadians rely on into a sprawling, insecure surveillance apparatus. To be up front, Signal will not build infrastructure into our service, and we will also not build surveillance into our service. If we are ever forced to choose between betraying the people who rely on us and leaving a market, we will leave.
One fact shapes everything I will say: Signal collects almost no data about our users, by design. It is this property that leads us to enjoy the reputation we have, including among Canadians. Bill C-22 could force us to rewrite our code, dismantle our robust privacy architectures and design surveillance into our systems. Let me give you three concrete pictures of how chilling such a proposition is.
First is undermining encryption. Bill C-22 creates an open-ended power to compel a company to re-engineer its own service to enable government access. We have seen where this leads. We know it is never one device. Once you build a mechanism to break your own protections, that mechanism exists, and it can be identified and exploited by anyone with the time and resources to do so. As security experts have warned for over 30 years, there is no back door that only the good guys can walk through.
Second is deliberately engineering weaknesses. This is the provision that should alarm anyone who relies on the safety of private messaging and on technical services more broadly. The powers in this bill are broad enough to compel a service like Signal to sell out our users, to do things like silently create hidden accounts and slip them into private group conversations, to manufacture a participant the other members cannot see, and to do the same to other apps, services and infrastructure.
Third is forced metadata retention. As we've established, we built Signal to retain as close to no data as possible. This includes intimate metadata. Bill C-22 would let the government compel us to construct the very surveillance apparatus we have refused to build, in order to log who is talking to whom, when and from where, for up to a year. Do not let the word “metadata” reassure you. Metadata is the 2 a.m. phone call, the clinic you contacted, the lawyer you retained, the organizer you met and the journalist you trusted. In aggregate, it reveals as much, if not more, about individuals as content—often more. A mandate to retain it would build a goldmine of intimate data where none exists today, sitting ready for any foreign adversary or criminal who breaches it. Mathematics does not care about executive intent. A back door built for the good guys is simply a vulnerability waiting for the bad guys to find.
None of this is hypothetical. Australia passed a similar regime in 2018, which required over 150 amendments before it could pass, and Australia's own Parliamentary Joint Committee on Human Rights found it incompatible with the rights to privacy and free expression. Under it, the definition of a “covered provider” stretched to fast food chains and shopping mall Wi-Fi. We've seen similar things play out with Apple and iCloud in the United Kingdom, and the Salt Typhoon hack in the United States as well, both of which have been covered in great detail by others testifying before this committee.
Let me end with what genuine reform of the law would require. To update this bill for the technical realities of our current era, part 2 of C-22 should be withdrawn. Its core defects cannot be repaired with targeted amendments.
If withdrawal is not politically feasible, as much as it is the right course of action, then the following safeguards should be considered non-negotiable for any amendments that improve these provisions.
The first is prior judicial authorization. Any order to alter a security system must be approved in advance by a court and not imposed—
