Encryption Faces an Existential Threat in Europe

Jan 3, 2023 7:00 AM

Encryption Faces an Existential Threat in Europe

The CEO of Proton says new competition laws have finally given him a voice in Brussels, even as he fights the EU’s anti-encryption campaign.

A man in a chair speaks on a stage

Photography: Stephen McCarthy/Getty Images

Andy Yen is positioning himself to be Europe’s answer to Google cofounder Larry Page. Like Google, Yen’s company Proton offers services including email, calendar, drive storage, and VPN, just with a privacy twist. All its products are encrypted. But unlike Google, nine-year-old Proton has had to try and grow its business in the shadow of the tech giants. That has been a huge disadvantage, says Yen, because companies like Google and Apple can exploit their dominance to nudge users to use their apps as well as their phones.

If a person buys a Google Android or Apple iPhone, they are offered a default email service, search engine, and calendar app. “The defaults just so happen to be the services that [these companies] themselves provide,” complained Yen in 2021. He was well aware that people favor convenience. “What we know from studies is that 95 percent of people will not change the defaults.”

But 2022 was the year the European Union finally took action. In March, the bloc’s lawmakers agreed on new rules designed to release the grip Big Tech has on European consumers and to help homegrown internet companies compete with American giants for customers. The Digital Markets Act will obligate companies that run phone operating systems to offer “choice screens” so users have more control over which services they use. Technically, the DMA went into force in November, although it may not take full effect until March 2024. Proton is headquartered in Geneva, Switzerland, which is not an EU member. But Yen thinks this law will help European companies, like Proton, finally have a voice in Brussels.

Europe’s momentum in rewriting the rules of the internet, however, is not all good for Proton, which has grown to 70 million accounts. The company is warily watching a wave of proposals in the UK and the EU that privacy advocates warn will threaten encryption, such as the UK’s Online Safety Bill and the EU’s proposals to combat child sexual abuse material. Yen spoke in October at WIRED’s business conference, WIRED Smarter. At the event, we talked about how he is thinking about the breakthroughs and concerns that are emerging out of Europe’s increasing focus on technology legislation. This interview has been edited for clarity and length.

WIRED: You’ve been a big advocate for Europe’s Digital Markets Act. Now that the new rules have passed, are you concerned about enforcement?

Andy Yen: I had a call earlier this year with Margrethe Vestager, who is the head of competition at the European Commission. And I can tell you, the political will to enforce this is there. You can see the fire inside her. She wanted to get it done.

But is political will the same as having the resources to force big tech companies to comply?

That's exactly the problem. The combined market cap of these big tech companies a couple months ago was $7 trillion, which is bigger than most European countries’ GDP.

Most Popular

That’s a lot of lawyers.

They [Big Tech] are throwing literally hundreds of millions of euros at this problem. And as much as Ms. Vestager is committed to fighting this, she is facing an uphill battle against enormous resources of entrenched powers. So it will be a tough fight. But what is making me very optimistic is that, for the first time, I'm seeing the commission reach out to small companies like Proton to really understand what the issue is and get to the heart of it.

It's a shift. Instead of just listening to whatever Big Tech’s consultants and lawyers are spewing out, they're taking time to talk to small companies and, for the first time—maybe ever—I feel like we have a voice in Brussels.

When did that shift happen? After the DMA was passed?

Just within the past year. I think it really shows a shift in the mindset in Brussels that has, so far, not yet happened in the US. In the US, the antitrust fight is much tougher.

What about other European regulation? I know there's a lot of concern about the legislation drafted by EU Home Affairs commissioner Ylva Johansson which proposes forcing encrypted platforms to carry out automated searches for child sexual abuse material. Is that something you think could affect you?

Of course, it could potentially impact us. There's also the Online Safety Bill here in the UK. It seems like it's coming back from the dead.

But if these things go through, there’s the risk that encryption will be demonized at a time where you're having breakthroughs in these other areas.

The problem with these legislations is they are written too broadly; they are trying to cover too many unrelated issues. I'll give you an example from the UK’s online safety debate. Part of its focus is content moderation on social media. But there's a difference between messaging on social media versus private messaging. The two things should be decoupled. So, no one is saying that there are no problems and that we shouldn't try to fix them. But I think we need to define clearly what we're trying to solve and how the remedy is geared toward the actual problem. Otherwise you come up with legislation which has a lot of unforeseen consequences.

That might be the case in the online safety bill in the UK, which is trying to tackle lots of different things. But the EU’s chat control proposal is very much arguing that encrypted messaging creates a space where there is a concern child abuse is taking place. How do you approach that debate? Because it is so emotional.

Typically, the purpose of legislation is to step in when markets don't create the right incentive structures to enforce an outcome that will be good for society, right? And if you look at the, let's say, the child sexual abuse control debate, is there any company in the world that is incentivized not to tackle this problem? I would say no. It's a huge problem from a PR standpoint, from a business standpoint. So Big Tech and small tech companies like Proton are already putting all the resources that we can into combating this issue. So given that is already the case, legislation perhaps isn't necessary because the incentives to tackle the problem are already there.

Most Popular

The second aspect is the focus on encryption. But is breaking encryption the only way to tackle this problem? I can tell you, it's not. There's many other technological ways to do this—by looking at patterns of behavior, for example. We need to always find the right balance. And for me, mandating that we undermine or weaken or break encryption, that's not the right balance. The way I tend to think about this is, for sure, privacy and encryption can be misused. This is unavoidable. But a world where privacy and encryption is forbidden already exists. Russia did this recently. China is doing this. North Korea does it. Iran does it. And I can tell you that people in those countries don't feel more secure. In a democratic society, we need to accept and defend privacy, even though there will be some negative externalities because the alternative, which is no privacy, is worse. We shouldn't strive to say we have the perfect solution that will eliminate 100 percent CSAM [child sexual abuse material], as objectionable as it is. Because if we do that, we're giving up so much more. This is the balance that needs to be struck.

You said companies like Proton are finally being listened to when it comes to competition policy. But how does the EU’s approach to CSAM compare? Do you feel like you’re being listened to on this issue?

It is a debate. The issue that I see here is that politicians feel pressure to confront the issue. They're getting pressure, also from law enforcement, to tackle the issue. But I think law enforcement is using this as a Trojan horse, they really want to [break encryption] for other purposes. At the same time, when I talk to people in Brussels, they say, “We're not trying to break encryption, we know encryption is very important.” And it's the typical issue where they need to show that they're doing something, they want to do something. But at the same time there is no easy, obvious solution to the problem. So they're kind of stuck.

How worried are you about theEU CSAM proposal? There's a lot of opposition to the idea. Do you think that it's going to pass or that it’s just too unpopular?

Actually, I'm quite concerned, because in the past this has come up, but it was wrapped around terrorism. But this time they’ve bundled it around child abuse, which is a very toxic topic. Due to the public debate, some of the people that would actually be standing against this will not be able to have a rational debate.

It’s much harder to get into the details, because lots of people don't even want to debate this issue—it’s very upsetting.

You want to have a nuanced discussion about it, and then the response is “think of the children.” It’s difficult to have a proper discussion about it. I think it would be bad for democracy if we don't have that debate. But it is a very clever packaging, for sure.

More Great WIRED Stories

More from WIRED

How Should You Cut Through the Noise of This Year’s Headlines?

WIRED's editor in chief reflects on a cacophonous year in Big Tech, crypto, and more, and predicts where 2023 may lead.

Gideon Lichfield

The WIRED Guide to 5G

Here’s everything you need to know about the spectrum, millimeter-wave technology, and what 5G means for you.

Klint Finley

Mastodon Is Hurtling Toward a Tipping Point

As the niche, decentralized social networking platform rises in popularity, it faces rising costs, culture shifts—and potential legal risks.

Amanda Hoover

Welcome to Digital Nomadland

A Portuguese island created a village for remote workers, promising community to the newcomers and prosperity to the locals—then delivered on neither.

Susana Ferreira

Tired, Filthy, and Overworked: Inside Amazon’s Holiday Rush

The retailer’s warehouses are flooded with packages. Workers say that means mandatory extra shifts and faster-paced work.

Anna Kramer

No One on Twitter Is Safe From Elon Musk

The entrepreneur says he's cracking down on doxing. Many see his account-blocking spree as self-serving.

Amanda Hoover

This Was the Year That Electric Vehicles Took Off

More EVs were sold in the first half of 2022 alone than any previous year—and there are signs the surge can continue.

Aarian Marshall

Does Meta’s Horizon Workrooms Deliver? Customers Say Yes … and No

Companies trialing the metaverse space say it’s kind of fun, but only in small doses.

Jeff Link

Credit belongs to : www.wired.com

Check Also

Don’t Count on Tesla’s Dojo Supercomputer to Jump-Start an AI Revolution

Will Knight Business Sep 14, 2023 12:00 PM Don't Count on Tesla's Dojo Supercomputer to …