The Last of Us - Fighting the EU Surveillance Law Apocalypse

Svea Windwehr, Chloé Berthélémy

39th Chaos Communication Congress (39C3): Power Cycles · Day 3 · Saal Fuse

Overview

In "The Last of Us - Fighting the EU Surveillance Law Apocalypse," Svea Windwehr and Chloé Berthélémy of European Digital Rights (EDRI) deliver a stark warning about the escalating and often recycled surveillance agenda within the European Union. Framed as a battle against "zombies in an apocalypse," the talk dissects an "avalanche" of legislative proposals, many of which are revived iterations of past attempts to undermine privacy and data protection. The speakers emphasize that while the specific justifications may shift – from counter-terrorism to child sexual abuse – the underlying objective of enabling mass surveillance and weakening encryption remains constant.

Watch on YouTube

Visual summary for The Last of Us - Fighting the EU Surveillance Law Apocalypse by Svea Windwehr, Chloé Berthélémy
Visual summary for The Last of Us - Fighting the EU Surveillance Law Apocalypse by Svea Windwehr, Chloé Berthélémy

Key moments

  1. 0:00 Introduction to EU surveillance agenda and 'apocalypse' theme
  2. 1:20 The first crypto war: US Clipper Chip and its EU influence
  3. 3:00 EU gains competence; PNR and data retention emerge
  4. 4:50 Edward Snowden's revelations and the birth of GDPR
  5. 6:40 Proliferation of E2E encryption and the 'going dark' narrative
  6. 8:00 San Bernardino case: FBI vs. Apple in the new crypto war

The Last of Us - Fighting the EU Surveillance Law Apocalypse

Speakers: Svea Windwehr, Chloé Berthélémy

Conference: 39C3

YouTube: https://www.youtube.com/watch?v=pfVng5csqyk

Overview

In "The Last of Us - Fighting the EU Surveillance Law Apocalypse," Svea Windwehr and Chloé Berthélémy of European Digital Rights (EDRI) deliver a stark warning about the escalating and often recycled surveillance agenda within the European Union. Framed as a battle against "zombies in an apocalypse," the talk dissects an "avalanche" of legislative proposals, many of which are revived iterations of past attempts to undermine privacy and data protection. The speakers emphasize that while the specific justifications may shift – from counter-terrorism to child sexual abuse – the underlying objective of enabling mass surveillance and weakening encryption remains constant.

The presentation provides a crucial historical context, tracing the evolution of EU surveillance policies from the early "crypto wars" to the present day. It highlights key legislative milestones, judicial challenges, and the persistent efforts of law enforcement agencies to gain broader access to digital communications. Windwehr and Berthélémy argue that the current political climate, coupled with a shifting judicial landscape, necessitates a fundamental change in strategy for privacy advocates. The traditional reliance on legal challenges, while still important, is no longer sufficient; a robust, multi-faceted narrative battle supported by broad coalitions is now paramount to safeguarding fundamental rights in the digital age.

This talk is particularly significant for anyone concerned with digital rights, cybersecurity, and the future of privacy in Europe. It meticulously unpacks the complex interplay between technological advancements, political will, and legal frameworks, demonstrating how seemingly disparate proposals converge to create a comprehensive surveillance architecture. By exposing the historical patterns and future threats, Windwehr and Berthélémy empower the audience with the knowledge and actionable strategies needed to resist these encroaching measures and protect the foundational principles of secure and private communication.

Background

▶ Watch: Introduction to EU surveillance agenda and 'apocalypse' theme (0:00)

The speakers begin their historical overview in the 1990s, with the first crypto war in the United States, centered around the Clipper chip. Introduced in 1993 by the US National Security Agency (NSA), this chipset incorporated a built-in backdoor designed to allow law enforcement to decode intercepted voice and data transmissions using a key escrow technology. Although the Clipper chip's encryption was reportedly broken within a year, its underlying concept of mandated access deeply influenced EU policymakers, an idea that persists today. At this time, the EU’s competence in home affairs and security was nascent, largely remaining a member state domain.

The landscape shifted significantly in the 2000s, propelled by a series of terrorist attacks, including 9/11 and the Madrid and London bombings. This era saw the emergence of an international counter-terrorism agenda, providing the EU with the political momentum to gain more competence in justice and home affairs. This newfound authority led to the introduction of massive surveillance measures. The Passenger Name Records (PNR) directive, though initially rejected by the European Parliament, eventually became law in 2016, mandating the mass collection and algorithmic profiling of travelers' data. More critically, the Data Retention Directive, adopted in 2006, obliged telecommunication operators to generally and indiscriminately retain all user data.

The 2010s brought a brief "good time for privacy" thanks to Edward Snowden's revelations. His disclosures about the NSA's global surveillance programs sparked a major scandal, leading to significant legislative and political impacts. Crucially, the public outcry contributed to the adoption of the General Data Protection Regulation (GDPR) in the EU, which became a global standard for data protection. Snowden's revelations also fueled a surge in consumer demand for secure communication services, leading to the proliferation of end-to-end encryption (E2EE) in popular apps like WhatsApp and Viber. However, this progress was met with fierce pushback from law enforcement, epitomized by FBI General Counsel Vera Caproni's introduction of the "going dark" narrative. This framing suggested that E2EE was hindering law enforcement's ability to access crucial data, implying a natural right to such access despite the exponential increase in overall data creation and collection. The San Bernardino case in 2015, where the FBI attempted to compel Apple to unlock an iPhone, became a key illustrative example of this "new crypto war." By 2020, the Five Eyes intelligence alliance (Australia, New Zealand, UK, US, Canada) publicly lamented E2EE and called for measures to access encrypted data.

A pivotal moment occurred in 2014 when the European Court of Justice (ECJ), in the Digital Rights Ireland case, struck down the Data Retention Directive, declaring general and indiscriminate retention of traffic and location data contrary to EU law and fundamental rights. While a significant victory, its impact was blunted by member states largely ignoring the judgment, having already transposed the directive into national law. This initiated the "infamous data retention saga," leading to a decade of national litigation cases across Sweden, France, UK, Belgium, and Germany. Despite a rich jurisprudence from the ECJ setting limits, the European Commission, acting as the "guardian of the treaties," politically chose not to launch infringement procedures against non-compliant member states for a decade, allowing illegal data retention regimes to persist.

The 2020s introduced new police cooperation practices, exemplified by the dismantling of encrypted communication services like EncroChat and Sky ECC in 2020-2021, and later Matrix. These international operations, involving EU member states and the US, revealed a mass hacking approach, where communications data were obtained in a general and indiscriminate manner, bypassing individualized suspicion. Furthermore, a forum shopping tactic was employed, leveraging countries with the weakest legal protections (e.g., France) to perform the intrusive hacking, then laundering the collected data through international cooperation channels. Despite these "success stories," law enforcement, led by Europol's Executive Director Catherine De Bolle, continued to demand broader access, famously stating, "encryption unregulated is justice denied" and calling for a "front door" rather than a "backdoor" into encrypted communications.

This period also saw a shift in justification for surveillance, with child sexual abuse and exploitation increasingly replacing terrorism as the primary rationale. This led to a derogation of the e-Privacy Directive, allowing companies to scan for child sexual abuse imagery, and subsequently, the notorious Child Sexual Abuse Regulation (CSAR), widely known as "chat control." This proposal aimed to mandate client-side scanning capabilities for all private and encrypted communication service providers, scanning data on-device before encryption. While a recent positive development saw European member states move away from endorsing mandatory client-side scanning in their joint position for trilogue negotiations, the speakers warn that "check control was just the beginning," setting the stage for new, equally concerning proposals from the EU Commission.

Key Findings

▶ Watch: EU gains competence; PNR and data retention emerge (3:00)

The talk unveils several critical findings regarding the EU's persistent surveillance agenda and the evolving landscape of digital rights advocacy:

  • Recycled Surveillance Proposals: The EU is experiencing an "avalanche" of legislative proposals aimed at increasing surveillance, many of which are "recycled or enhanced" versions of previously failed or legally challenged ideas. This suggests a persistent, underlying drive for mass data access despite prior judicial setbacks.
  • Persistent "Going Dark" Narrative: Law enforcement, particularly Europol, continues to push the "going dark" narrative, arguing that encryption hinders their ability to fight crime. This framing is presented as highly successful, even though law enforcement has more data access than ever before in history, implying a perceived "natural right" to all data.
  • Shifting Justifications for Surveillance: The primary justification for undermining encryption has shifted from counter-terrorism in the 2000s and 2010s to child sexual abuse and exploitation in the 2020s. This new narrative is described as "nefarious" due to its emotional weight, making it harder to challenge proposals like client-side scanning.
  • ECJ's Evolving Stance on Data Retention: While the European Court of Justice (ECJ) initially struck down the Data Retention Directive as contrary to fundamental rights, its recent rulings (e.g., La Quadrature du Net, ADOP case) show a worrying "nuancing" of its position. The court appears increasingly swayed by arguments about "new forms of crimes" leading to "systematic impunity," potentially weakening previously held privacy requirements, particularly concerning the retention of source IP addresses. This indicates that the courts, traditionally strong allies for privacy advocates, may become less reliable.
  • Paradoxical "Lawful Access by Design": The EU Commission's new internal security strategy, "Protect EU," introduces "lawful access by design" as an approach to undermine encryption. This concept promises to provide a "front door" to encrypted data while simultaneously "preserving IT security, data protection, and human rights," a feat the speakers highlight as technically impossible and a form of "technocratic washing machine" to depoliticize a highly political issue.
  • Need for a Narrative Battle: Given the shifting judicial landscape and the persistent political will for surveillance, the speakers conclude that the fight for privacy is no longer primarily a legal battle but a "narrative battle." Advocates must move beyond solely relying on legal arguments and actively work to reframe the public discourse around privacy and data protection.
  • Importance of Broad Coalitions and New Engagement: Successful resistance, as demonstrated by the partial pushback against chat control, requires building "broad coalitions with unlikely partners" (e.g., child protection organizations, sex workers, trans people, youth) and inviting "more people to understand why this matter[s]." This involves articulating the relevance of privacy to diverse, often vulnerable, communities who are most affected by surveillance but least represented in policy spaces.
  • Early Intervention is Crucial: The current legislative phase for new data retention proposals and "lawful access by design" is at an early stage (public and policy debate), offering a critical window for advocacy. Laying the groundwork now through coalition building and narrative shaping is essential before proposals become entrenched in later legislative stages (Council, Parliament, trilogues).

Technical Deep Dive

▶ Watch: Edward Snowden's revelations and the birth of GDPR (4:50)

The talk delves into several technical and conceptual underpinnings of surveillance and encryption, spanning decades of conflict.

The historical context begins with the Clipper chip in 1993, a hardware-based encryption system developed by the US NSA. Its core technical feature was key escrow, where a unique encryption key for each device was split into two parts and held by two separate government agencies. This design inherently provided a backdoor allowing law enforcement to decrypt communications. Despite its rapid technical compromise, the concept of mandated access through key escrow profoundly influenced subsequent policy debates, particularly within the EU, where the idea of a "master key" or similar mechanism for law enforcement access persists.

In the 2000s, EU surveillance efforts gained technical breadth with measures like Passenger Name Records (PNR). This involved the massive collection of travelers' data, including booking information, contact details, and payment methods. The data was then subjected to algorithmic profiling to identify potential terrorist threats or serious crime suspects. This represented an early form of large-scale automated data analysis for security purposes. Concurrently, the Data Retention Directive (2006) mandated the general and indiscriminate retention by telecommunication operators of all their users' communications data, including traffic data (who communicated with whom, when, and where) and location data. This was a blanket requirement, applying to all citizens regardless of suspicion.

The 2010s saw the widespread adoption of end-to-end encryption (E2EE), a cryptographic method ensuring that only the communicating users can read the messages. Services like WhatsApp and Viber implemented E2EE by default, a significant technical barrier to traditional interception methods. This technical advancement directly led to law enforcement's "going dark" narrative, as it rendered real-time interception of message content much harder.

The 2020s brought new technical and tactical challenges. The operations against EncroChat and Sky ECC showcased a mass hacking approach. Instead of targeted interception, police forces engaged in bulk hacking, obtaining communications data from all users of these encrypted networks in a general and indiscriminate manner. This technical method bypassed the principle of individualized suspicion and fair trial rights, effectively catching "everybody in the fishing net." The data was often obtained by exploiting vulnerabilities in the modified devices themselves or the network infrastructure. These operations also involved forum shopping, a legal tactic where intrusive measures (like mass hacking) are carried out in a partner country with the "weakest legal protection," and the resulting data is then "laundered" through international cooperation channels, making its legality difficult to challenge in other jurisdictions.

The most recent and concerning technical proposal discussed is client-side scanning, as advanced in the "chat control" (Child Sexual Abuse Regulation) proposal. This technology would oblige service providers of private and encrypted communication to introduce capabilities to **scan private and confidential communication on the user's device before it is encrypted. The goal is to detect specific types of abusive material. Technically, this involves deploying a scanning agent or software on the user's device that examines content (e.g., images, text) locally. This approach is highly controversial because it inherently creates a major new security risk** by introducing a potential vulnerability point on every user device. Such a mechanism, once in place, could easily be expanded to scan for other types of content, effectively undermining the privacy and confidentiality of E2EE.

Further, the new "Protect EU" strategy introduces "lawful access by design." This concept, while vaguely defined, aims to develop "technical solutions that would enable law enforcement authorities to access encrypted data in a lawful manner while safeguarding cyber security and fundamental rights." The speakers highlight this as an inherent contradiction, as creating "front doors" or mandated access points fundamentally compromises the security properties of strong encryption. The EU Commission has convened an Expert Group for Technology Roadmap on Encryption to identify "potential technical options" that "might already exist or potentially could be developed in the future" to achieve this impossible feat. The terms of reference for this group explicitly seek to balance access with security, a balance that security experts widely consider unattainable.

Finally, the impending comeback of mass data retention is discussed. The new EU legislation is expected to focus on specific data categories like source IP addresses and port numbers, and potentially civic identity data collected by service providers. Critically, the scope of service providers is expected to be enlarged to cover over-the-top (OTT) providers (e.g., messenger services, email services) and potentially VPNs, which were not covered by previous directives. Member states are pushing for broad purposes for retention, including "all crimes committed in cyberspace or using information and communication technology," potentially going beyond the limits set by the ECJ for certain data categories. The German proposal, for example, suggests retention of IP addresses and port numbers for up to three months, covering OTT services. This represents a renewed push for indiscriminate data collection, extending its reach to modern communication platforms.

Demo / Proof of Concept

▶ Watch: Proliferation of E2E encryption and the 'going dark' narrative (6:40)

While the talk does not feature a traditional technical demonstration or a live proof of concept in the conventional sense, it powerfully leverages a video clip from Europol's Executive Director, Catherine De Bolle, as a "demonstration" of the opposing viewpoint's rhetoric and strategic messaging.

The video, which the speakers humorously note they "couldn't have made a better video" themselves, serves as a direct insight into how law enforcement frames the "going dark" problem and their proposed "solution." In the clip, De Bolle discusses the success stories of operations like Sky ECC, where "specialists...try to decrypt the communication and to enter into...the system" to "listen to everything." Crucially, she then articulates the demand for a "front door," stating, "our expectation from the law enforcement community is that we should be granted also access to the content on that information. So for me the hosting online providers should be forced in one way or another to provide us with the information we need for our investigative cases to be able to do our work in an efficient way. I am not asking for a back door. Nobody is asking for a back door. We want a front door."

This segment acts as a crucial "proof of concept" for the speakers' argument about the ongoing narrative battle. It vividly illustrates:

  • The "Going Dark" Framing: De Bolle reiterates concerns that encryption allows criminals to operate unchecked.
  • The Demand for Access: The explicit call for hosting online providers to be "forced" to provide access to "content" and "information."
  • The "Front Door" Euphemism: The deliberate linguistic shift from "backdoor" (which carries negative connotations of vulnerability) to "front door" (implying legitimate, lawful access), despite the underlying technical implications being similar in terms of undermining E2EE's security.

By showcasing this direct communication from a high-ranking law enforcement official, the speakers effectively demonstrate the sophisticated and often misleading public relations strategy employed by those advocating for increased surveillance, thereby reinforcing the urgent need for privacy advocates to counter this narrative effectively.

Defensive Implications

▶ Watch: San Bernardino case: FBI vs. Apple in the new crypto war (8:00)

The talk outlines critical defensive implications for digital rights advocates, shifting the focus from purely legal battles to a broader, more strategic engagement:

  1. Acknowledge the Shifting Judicial Landscape: The European Court of Justice (ECJ), once a reliable ally against mass surveillance, is beginning to "nuance its position" on data retention. Recent rulings show a willingness to accept certain forms of data retention under conditions, or for specific data categories like source IP addresses, even if it constitutes a "serious interference with fundamental rights." This means relying solely on litigation is now a "risky tool" and no longer a guaranteed political strategy for winning the overall fight. Defenders must understand that legal victories, while important, may become harder to achieve or more limited in scope.
  1. Prioritize the Narrative Battle: The core defensive strategy must shift from a legal one to a narrative battle. Law enforcement has successfully waged this battle for 30 years with terms like "going dark." Privacy advocates must develop compelling, accessible counter-narratives that explain why privacy and data protection matter to everyone, not just a niche technical community. This involves reframing complex issues like data retention (e.g., proposing "insecurity by design" instead of "lawful access by design") and highlighting the tangible benefits of privacy for ordinary citizens.
  1. Build Broad, Unlikely Coalitions: Resistance requires building alliances beyond traditional privacy circles. The success in pushing back against mandatory client-side scanning in chat control was attributed to forming "broad coalitions with unlikely partners," such as child protection organizations, sex workers, trans people, and youth groups. These partners bring diverse expertise, legitimacy, and the ability to articulate the impact of surveillance on vulnerable communities, which often lack representation in policy debates. This strategy moves beyond technical arguments to human-centered impacts.
  1. Engage New Communities and Translate Relevance: It is crucial to "invite more people to understand why this matter[s]." The assumption that everyone agrees mass surveillance is bad does not hold outside the privacy community. Advocates must actively reach out to and mobilize diverse groups, especially those most affected by surveillance but least involved in policy discussions. This requires translating technical and legal concepts into relatable terms, demonstrating the practical relevance of digital rights for their daily lives and security.
  1. Advocate for Targeted, Judicially Controlled Measures: While opposing mass surveillance, EDRI and similar organizations support a "quick freeze" approach or preservation orders. This means law enforcement could issue an order to a service provider to preserve existing data (not generate new data) based on reasonable grounds of individualized suspicion, within the context of a judicial proceeding, and for serious crimes, adhering to strict procedural safeguards. This provides a balance between legitimate law enforcement needs and fundamental rights, contrasting sharply with indiscriminate data retention.
  1. Early and Sustained Engagement in the Legislative Process: The current phase of EU legislative proposals (e.g., new data retention, lawful access by design) is at an early stage of "public debate" and "policy debate." This provides a critical window to "lay the ground early" by building connections and pushing back before proposals become entrenched. This involves actively participating in public consultations, lobbying Members of European Parliament (MEPs), and influencing the Council and trilogue negotiations.
  1. Mobilize Diverse Skills and Support Existing Networks: The fight requires a wide array of skills – technologists, lawyers, graphic designers, social media experts, and communicators. Everyone can contribute. Supporting organizations like EDRI and its member organizations (e.g., La Quadrature du Net, Bits of Freedom, Epicenter Works) through involvement, donations, or volunteering is essential, as these groups are on the front lines of advocacy in Brussels and across member states.

Key Takeaways

  • The EU is pushing an "avalanche" of recycled surveillance proposals, attempting to erode privacy and data protection under shifting justifications, currently focusing on child protection.
  • Law enforcement's "going dark" narrative, despite more data being available than ever, remains a powerful and successful rhetorical tool used to legitimize demands for pervasive access to encrypted data.
  • The European Court of Justice (ECJ) is showing signs of weakening its stance on mass data retention, making exclusive reliance on legal challenges a riskier strategy for privacy advocates.
  • The concept of "lawful access by design" (or a "front door" into encryption) is a dangerous paradox, technically impossible to implement without fundamentally undermining cybersecurity and fundamental rights.
  • The fight for digital rights must strategically shift from a primary focus on legal battles to a robust "narrative battle," building broad coalitions with diverse, sometimes unlikely, partners and engaging new communities to articulate the universal relevance of privacy.
  • Early intervention and sustained engagement in the EU legislative process, coupled with the mobilization of varied skills and support for advocacy organizations, are crucial for effectively resisting these encroaching surveillance measures.

About the Speaker(s)

Svea Windwehr is an expert in digital rights and policy, working to fight against mass surveillance and attacks on encryption within the European Union. Her work involves analyzing complex legislative proposals and developing strategies to protect fundamental rights. She is actively engaged in the narrative battle, seeking to reframe public perception of privacy and engage broader communities in advocacy efforts. Her insights often highlight the tension between digital policy and home affairs within political parties.

Chloé Berthélémy is a Senior Policy Advisor at European Digital Rights (EDRI), a network of civil and human rights organizations across Europe. Based in Brussels, she specializes in EU surveillance legislative proposals and initiatives, including data retention and encryption backdoors. Chloé has extensive experience in monitoring and challenging EU policies, engaging with institutions, and advocating for the respect of fundamental rights in the digital sphere. Her work includes analyzing legal precedents, such as the numerous ECJ rulings on data retention, and strategizing political responses to ensure EU law upholds privacy standards. Both speakers are deeply involved in the ongoing efforts to resist the EU's expanding surveillance agenda.

All talks from 39th Chaos Communication Congress (39C3): Power Cycles