Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

FTC Calls on Tech Firms to Resist Foreign Anti-Encryption Demands

Tech giants have received a letter from the FTC urging them not to weaken security and privacy at the request of foreign governments.

FTC encryption backdoor

The Federal Trade Commission (FTC) has sent letters to major tech companies in the United States, urging them to resist foreign governments’ demands to weaken encryption. 

The letters were sent by FTC Chairman Andrew Ferguson to Akamai, Alphabet (Google), Amazon, Apple, Cloudflare, Discord, GoDaddy, Meta, Microsoft, Signal, Snap, Slack, and X.

Ferguson told the companies that they might feel pressured to weaken data security and privacy protections at the request of foreign governments, or in response to their laws. The EU’s Digital Services Act and the UK’s Online Safety Act and Investigatory Powers Act were given as examples by the FTC chairman. 

The Investigatory Powers Act was recently cited by the British government as an argument for requesting that Apple provide backdoor access to encrypted data. The US announced last week that the UK had abandoned this demand.

However, the FTC wants to ensure that American tech companies don’t give in to such demands in the future.  

“I am concerned that these actions by foreign powers to impose censorship and weaken end-to-end encryption will erode Americans’ freedoms and subject them to myriad harms, such as surveillance by foreign governments and an increased risk of identity theft and fraud,” Ferguson said

Advertisement. Scroll to continue reading.

“I am also concerned that companies such as your own might attempt to simplify compliance with the laws, demands, or expected demands of foreign governments by censoring Americans or subjecting them to increased foreign surveillance even when the foreign government’s requests do not technically require that,” he added. 

The FTC official said global companies might be tempted to accept the demands made by foreign governments to simplify operations and compliance by using the same policies across jurisdictions.

However, Ferguson highlighted that companies have “independent obligations to American consumers under Section 5 of the Federal Trade Commission Act, which prohibits unfair or deceptive acts or practices in or affecting commerce”.

Specifically, if a company advertises secure communications but then uses weak encryption to comply with a foreign government’s demands, it can represent a violation of the FTC Act. 

The agency pointed out that it has brought dozens of cases against companies that failed to keep promises to protect consumer data.

Governments regularly call for the introduction of encryption backdoors, mainly arguing that they are needed to facilitate criminal investigations. The current Trump administration appears to oppose encryption backdoors, but the previous Trump administration did make such demands

However, privacy advocates and the cybersecurity industry have raised concerns that encryption backdoors implemented for good purposes can also be leveraged by criminals and foreign intelligence agencies, undermining the very security they are designed to protect. 

Related: Encryption Backdoors: The Security Practitioners’ View

Related: Fraud Losses Reached $12.5 Billion in 2024: FTC

Related: Order Out of Chaos – Using Chaos Theory Encryption to Protect OT and IoT

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

Quantum Secure Encryption has named Michael Massing as Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.