Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

California Quietly Drops Bill Requiring Phone Decryption

The California Assembly Bill 1681 was quietly dropped this week without a vote. The bill would have authorized $2,500 penalties for phone manufacturers and operating system providers if they do not comply with court orders to decrypt phones. In effect, it would force phone providers to include a backdoor or face repeated fines.

The California Assembly Bill 1681 was quietly dropped this week without a vote. The bill would have authorized $2,500 penalties for phone manufacturers and operating system providers if they do not comply with court orders to decrypt phones. In effect, it would force phone providers to include a backdoor or face repeated fines.

Assemblyman Jim Cooper had claimed it was simply wrong that a search warrant could allow law enforcement agencies to search homes, but not necessarily phones. “I’m not concerned about terrorism. The federal investigators deal with that,” he said, but “local law enforcement deals with cases every day and they cannot access this information.”

The bill had faced opposition from civil liberties organizations such as the EFF, the tech industry including Apple and Google, and business representation including the California Chamber of Commerce and the California Bankers Association.

The original bill introduced in January had specifically required that all phones sold in California should, at the point of sale, have the technical ability to be unlocked and decrypted. This was later amended to a requirement to obey court orders.

“The bill, both before and after it was amended, posed a serious threat to smartphone security,” wrote the EFF in a blog post Wednesday. “It would have forced companies to dedicate resources to finding ways to defeat their own encryption or insert backdoors to facilitate decryption. As a result, the bill would have essentially prohibited companies from offering full disk encryption for their phones.”

This echoed the industry view. “Fundamentally weakening the security of smartphones in the way AB 1681 envisions not only doesn’t make us safer, it actually makes us less safe,” warned Internet Association lobbyist Robert Callahan (reported in the Sacramento Bee), who called encryption “an incredibly important tool in today’s interconnected, Internet-enabled world to keep data secure.”

The practicality of such a bill also needs to be questioned. Phone manufacturers would need to abandon the security of encryption altogether. Manufacturing two versions, one for California and one for the rest of the world, is neither feasible nor effective. Customers would just purchase phones across state lines or via the internet – leaving the manufacturer still open to legal sanctions in California.

For such a requirement to work, it would need to be not merely nationwide, but ultimately worldwide. It is worth remembering that compulsory breach disclosure laws in America started in California and were then copied by other states.

Advertisement. Scroll to continue reading.

However, this defeat in California can be seen as a win for encryption and the tech companies that provide encryption throughout the country.

“The tech industry was very helpful in killing this bill. It would be bad for business and bad for their customers – which is all of us,” EFF’s Rebecca Jeschke told SecurityWeek. “We certainly hope that this will make it easier to protect encryption from misguided efforts to break it.”

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Artificial Intelligence

Two of humanity’s greatest drivers, greed and curiosity, will push AI development forward. Our only hope is that we can control it.

Malware & Threats

Apple’s cat-and-mouse struggles with zero-day exploits on its flagship iOS platform is showing no signs of slowing down.

Mobile & Wireless

Samsung smartphone users warned about CVE-2023-21492, an ASLR bypass vulnerability exploited in the wild, likely by a spyware vendor.

Mobile & Wireless

Infonetics Research has shared excerpts from its Mobile Device Security Client Software market size and forecasts report, which tracks enterprise and consumer security client...

Fraud & Identity Theft

A team of researchers has demonstrated a new attack method that affects iPhone owners who use Apple Pay and Visa payment cards. The vulnerabilities...

Cybercrime

Daniel Kelley was just 18 years old when he was arrested and charged on thirty counts – most infamously for the 2015 hack of...

Cybercrime

No one combatting cybercrime knows everything, but everyone in the battle has some intelligence to contribute to the larger knowledge base.