Skip to content
HN On Hacker News ↗

Bill C-22 Is a Mess of the Government’s Own Making

▲ 17 points 4 comments by ethanplant 3mo ago HN discussion ↗

Pangram verdict · v3.3

We believe that this document is primarily human-written, with some AI-generated and AI-assisted content detected

29 %

AI likelihood · overall

Mixed
74% human-written 15% AI-generated
SEGMENTS · HUMAN 4 of 5
SEGMENTS · AI 1 of 5
WORD COUNT 1,833
PEAK AI % 77% · §1
Analyzed
May 29
backend: pangram/v3.3
Segments scanned
5 windows
avg 367 words each
Distribution
74 / 15%
human / AI fraction
Verdict
Mixed
Pangram v3.3

Article text · 1,833 words · 5 segments analyzed

Human AI-generated
§1 AI · 77%

The government’s lawful access bill is no longer merely controversial. It is badly designed, badly explained, badly consulted, and now being rushed anyway. May 27, 2026 · 19 min read

"A mess of the government's own making." Those were the words used by Canadian digital policy expert Michael Geist following Tuesday's committee meeting regarding Bill C-22. And it's honestly the most generous way to describe what's happening. The government introduced a sweeping lawful access bill. Experts warned that it was overly broad, vague, and technically risky. Major technology companies warned it could undermine encryption and secure systems. Civil liberties groups warned about surveillance powers. Privacy lawyers warned about the rule of law. A House of Commons petition calling for the bill's withdrawal surged into thousands of signatures almost immediately. Committee hearings became chaotic. Opposition MPs argued they didn't have enough information. The Privacy Commissioner's recommendations were apparently not distributed in advance. The government then accused critics of spreading misinformation, while simultaneously making misleading comments that needed to be walked back within hours. This is not how a serious government should be handling a serious bill. The government's basic defence has been that people are misunderstanding Bill C-22. We are told it doesn't require backdoors. We're told it does not create new lawful access authorities. We're told it's about modernization, public safety, and ensuring police and intelligence agencies can obtain information under existing legal authorities. That might be more convincing if the people objecting were confused. But they are not. The coalition objecting to this bill includes privacy experts, civil liberties groups, digital rights organizations, major technology companies, VPN providers, legal scholars, software developers, and ordinary Canadians who have taken the time to read what the bill actually says. At some point, the problem is not that everyone is misunderstanding the bill. The problem is the bill. The government keeps answering the wrong question The government's major defence is that Bill C-22 doesn't require backdoors.

Bill C-22 would not create "backdoors" and weakening of cybersecurity

The Canadian Centre for Cyber Security defines a "back door" as a hidden mechanism that bypasses security controls.

§2 Human · 20%

Bill C-22 does not require ESPs to create "backdoors" to their systems or the weaken electronic protections, including encryption.

Bill C-22 does not alter the existing responsibility of ESPs to protect their networks from hacking or other unauthorized access. The Government of Canada will be required, by law, to consult impacted ESPs, both in the making of regulations and the issuance of Ministerial Orders, and take into account the potential impact on cost, cybersecurity and privacy protections.

But that doesn't answer the concern. The concern is not only whether the bill uses the term "backdoor" or explicitly orders a company to bypass encryption. The concern raised by tech providers is whether the bill creates legal pressure for companies to retain data, preserve access capability, avoid deploying stronger encryption, build technical interfaces, comply with ministerial orders, or redesign systems so future access remains possible. That is the heart of this debate. Modern secure systems are increasingly designed such that even the provider cannot access user content, encryption keys, logs, or other sensitive data. End-to-end encryption, zero-knowledge storage, and no-logs services are not loopholes designed to protect criminals. They're the basic foundation modern secure systems are built on. If a provider does not have access to data, it cannot leak it, misuse it, hand it over by mistake, expose it to insiders, or lose it in a breach. A government can say they're not asking for a backdoor. But, if the practical effect of the law is to make providers preserve access capability that would not otherwise exist, the architecture still resembles a backdoor.

§3 Human · 7%

Apple's stark warning In front of the Standing Committee on Public Safety and National Security, Apple gave the government a warning it should not be able to ignore.

"As you know, this may be one of the last times we're permitted to discuss the consequences of this legislation publicly."

That line should hang over this entire debate. Apple continued,

"That's because of the bill's secrecy provisions which forbid companies like Apple from even discussing the orders we receive with our users or the public."

That is an extraordinary, and unsettling thing for a company to have to say to Parliament. The government wants Canadians to trust that Bill C-22 will not be used to undermine encryption or secure systems. But, if companies can receive technical access orders and then be forbidden from telling users or the public about those orders, the government's reassurance becomes impossible to verify. It is one thing for the government to say, today, in public, that it does not intend to require backdoors or systemic vulnerabilities. It is another thing entirely to pass a law that may later prevent the affected companies from publicly explaining what they've been ordered to do. If the government's answer is "trust us" and the bill's secrecy provisions make it nearly impossible to check whether that trust has been earned, the bill has a serious democratic legitimacy problem. It also matters who delivered that warning. Apple's representative, Erik Neuenschwander is Apple's Senior Director of User Privacy and Child Safety. He is also a former software engineer. Erik is not just a PR spokesperson sent to repeat corporate talking points. He understands this reality deeply. He is the exact sort of person Parliament should listen to on a bill that touches encryption, privacy architecture, and technical access obligations. Parliament should have a very difficult time dismissing a senior privacy engineer telling them that this may be the last time his company is allowed to speak publicly on the consequences of legislation. The government's bizarre response In response, the government seemed to decide that one of its best strategies was to press Apple on whether it has ever supported lawful access legislation elsewhere:

"Has Apple ever gone before a Parliamentary committee or submitted a parliamentary brief a submission to a national parliament on a lawful access regime that Apple actually supported?" - Anthony Housefather

Michael Geist took to X and summarized it well:

When government thinks its best approach is to target Apple - have you ever supported a lawful access bill anywhere? -

§4 Human · 4%

you know they’ve lost the plot. Opportunity for real questions about privacy risks for millions of Canadians under Bill C-22 lost with strange line of questions.

Apple's position is really not difficult to understand. They'll happily comply with lawful requests for information they actually have. They will never support legislation that requires them to weaken security, preserve access they do not have, or redesign systems around government access. The government seems to want to collapse every objection into a refusal to support lawful access, but the serious critics aren't saying police should never obtain digital evidence. They're arguing lawful access must not require insecure architecture, suspicionless metadata retention, secret orders, or compelled redesign of systems where provider access doesn't exist. Pressing Apple on whether it has supported lawful access laws elsewhere misses the point so badly that it becomes almost clarifying.

Despite claims by the government to the contrary, metadata retention is not a routine feature of lawful access. The United States does not have a general mandatory data-retention law. The European Union's Data Retention Directive was struck down by the courts in 2014, with later European cases continuing to reject general and indiscriminate retention of communications data. Canada needs to be especially cautious because Canadian law has already recognized that this information can be private. In R. v. Spencer, the Supreme Court of Canada recognized a privacy interest in subscriber information. R. v. Bykovets later affirmed this view as the Court held that an IP address can attract a reasonable expectation of privacy under section 8 of the Charter. The government cannot wave away metadata retention by arguing it's "not content". It can't make the argument metadata is "just phone book information". Canadian constitutional law already moved past this idea. Metadata can be the key that links a person to their online activity.

The government now appears to be looking for amendments. According to CBC News, the public safety minister has said the government will propose changes "to ensure there's clarity on what encryption is", and to better define metadata in the legislation. The problem with Bill C-22 is not merely that the words "encryption", "metadata", or "systemic vulnerability" need to be better defined. The problem is that the bill creates a power to require broad metadata retention in the first place. If the government wants to protect encryption, it should not merely define encryption.

§5 Human · 7%

It should explicitly prohibit compelled weakening, bypassing, redesign, removal, or non-deployment of encryption and other privacy-preserving protections. If the government wishes to address metadata concerns, it should not merely define metadata more precisely. It should remove the suspicionless metadata retention power. At minimum, any preservation obligation should be targeted to a specific person, account, device, identifier, or investigation; based on individualized suspicion; authorized by a judge; time-limited; no broader than necessary; and subject to deletion once no longer required. The consultation problem is now part of the story The government's position looks even weaker now that the consultation story is beginning to unravel. The National Post reported that the government did not widely consult on the metadata retention aspect. The article's headline was deliberately blunt:

Government never consulted widely on contentious part of police search powers bill

The article continues with a quote from Murray Rankin, former chair of the National Security and Intelligence Review Agency and a lead consultant for the government on the bill,

"You know this business about the metadata, it never came up in our conversations. In my work, it never came up."

That is an incredibly damning quote. The metadata retention powers are one of the central problems with the bill, and if they were not properly tested with privacy experts, technical experts, civil liberties groups, providers, and the Privacy Commissioner, then something has gone seriously wrong with the process. And when the process is bad on a bill this technically sensitive and consequential, people are right to be alarmed. The government cannot accuse everyone else of misunderstanding a framework it apparently failed to properly explain, consult on, or stress-test before trying to legislate it. The committee problem itself is unraveling Geist summarized Tuesday's meeting of the committee bluntly:

What an embarrassment at Bill C-22 SECU hearing. Despite Liberal MPs admitting confusion, government trying to rush the bill through. CPC MPs call for more meetings and ability to hear from officials before submitting amendments. Meeting runs out of time before decision is made.

This is not a healthy committee process. If Liberal MPs are acknowledging confusion about the bill’s application, and Conservative MPs are asking how amendments can be submitted before hearing properly from officials, the answer should not be to rush ahead. The answer should be to slow down, to hear from officials, to ensure members actually understand the bill before they're expected to amend it.