Cybersecurity Experts Raise Alarms Over Bill C-22’s Potential Risks to Encryption and Public Safety

5 Min Read
⏱️ 4 min read

The Canadian government’s proposed Bill C-22, aimed at enhancing lawful access for law enforcement agencies, is facing fierce criticism from cybersecurity professionals. Experts argue that the legislation could inadvertently create significant vulnerabilities in digital systems, making them more susceptible to exploitation by cybercriminals. Among the voices of concern is Packetlabs, a reputable ethical hacking firm that has conducted security assessments for various high-profile clients, including governmental bodies and major corporations.

Concerns About Encryption Weakening

Bill C-22, currently under scrutiny by the House of Commons Public Safety Committee, mandates that telecommunications and internet service providers adjust their systems to facilitate surveillance measures for law enforcement and the Canadian Security Intelligence Service (CSIS). The government defends this initiative by asserting that Canada lags behind other G7 nations in establishing a lawful-access framework.

However, cybersecurity specialists warn that the bill’s provisions could lead to the weakening of encryption protocols. Richard Rogerson, CEO of Packetlabs and co-chair of the Cyber Security Council at the Canadian Chamber of Commerce, expressed his concerns, stating, “The concept of a ‘secure backdoor’ is fundamentally flawed. It demands engineers to open encrypted systems for law enforcement without compromising their security—something that is technically unattainable.”

Rogerson’s caution is underscored by the increasing sophistication of criminal hackers who could exploit any weaknesses introduced by such legislation.

Historical Context and Global Implications

The risks associated with Bill C-22 are not theoretical. A recent incident in the United States illustrates the potential consequences of similar legal frameworks. Following the implementation of its lawful access measures, a vast cyberattack attributed to the Salt Typhoon hacking group—reportedly linked to China—was executed. This group exploited legally mandated surveillance infrastructure to intercept sensitive communications, including those of prominent officials.

Natalie Campbell, senior director at the Internet Society, has echoed these sentiments, stating, “There’s no such thing as a backdoor that only ‘good guys’ can walk through.” She argues that the bill would not only compromise encryption but also position Canada as a prime target for cybercriminals.

Metadata Retention and Privacy Concerns

An additional point of contention in the debate surrounding Bill C-22 is its requirement for “core providers” to retain metadata for up to a year. While this data will not encompass direct communications like emails or texts, experts warn that the retention of metadata could present a lucrative target for hackers.

Kim Chandler McDonald, global vice president of the Cybersecurity Advisors Network, cautioned that the legislation could heighten systemic vulnerabilities across various digital platforms. Matt Hatfield, director of OpenMedia, emphasised the recklessness of mandating new security weaknesses while advanced AI tools are on the rise, capable of exploiting such vulnerabilities at unprecedented speeds.

Government’s Rebuttal

In response to the mounting criticism, Simon Lafortune, spokesperson for Public Safety Minister Gary Anandasangaree, asserted that the government “categorically rejects claims” that Bill C-22 would allow surveillance via everyday devices. He clarified that the legislation does not grant additional powers for indiscriminate access to private information and that any lawful access will still require appropriate legal authorisation, such as a court-issued warrant.

Why it Matters

The implications of Bill C-22 extend far beyond the realms of law enforcement and cybersecurity; they touch on the fundamental rights of Canadians to privacy and secure communications. As the government seeks to bolster its capabilities against increasingly sophisticated cyber threats, it must tread carefully to avoid creating new vulnerabilities that could endanger citizens rather than protect them. The ongoing discourse around this legislation serves as a crucial reminder that, in the realm of cybersecurity, the balance between safety and privacy is delicate and must be handled with the utmost care.

Share This Article
Covering federal politics and national policy from the heart of Ottawa.
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *

© 2026 The Update Desk. All rights reserved.
Terms of Service Privacy Policy