If this gets approved and you're based in the UK, that's it. If you're based somewhere else are you safe or should you refuse to create accounts for people from the UK?
Let's have a show of hands of founders/folks with technical control, shall we? I for one will risk prison rather than put several hundred million consumers at risk, and will publish any such technical capability letter we receive.
They've already demonstrated with RIPA that they are perfectly willing to convict and sentence in these sorts of situations. Failure to disclose encryption passphrases can (and does) result in jail times of up to 2 years, or in cases which are deemed to have national security implications, 5 years. [1-3]
Talk on HN is comparatively cheap, and I suspect most people would reconsider their position when facing down the very real prospect of serving 5 years in HM Prison Belmarsh.
I'd take the odds on this. The number of people charged with failing to comply with a s. 49 notice is low (much lower than the number issued with them and whom don't comply). The number of people successfully charged is lower still. Some of the cases of successful convictions were also where people had admitted to having the key; your odds probably improve if you don't do this.
My understanding of s49 is that to convict you, the government has to prove that you had the ability to decrypt at _any time in the past_. If they do that, you can make a defence by showing that you _no longer do_. In other words, if the government shows you ever had the ability to decrypt, the burden of proof changes to you to show you no longer do. Pretty ridiculous.
It does mean that if you can make it patently obvious that you can't decrypt something, you have a good defence. One option therefore is to place control of decryption in the hands of not yourself, but a trusted agent outside the UK (or both, with both required to decrypt).
There may also be grounds for appeal in the ECourtHR, as there is precedent that the 'right to a fair trial' in the EConventionHR includes the right to remain silent, etc.
This is why I've been saying from day one that an Y Combinator focus on UK was the wrong move, because I expected the authoritarian mentality to only increase there over the next few years. The focus should've been on Germany, which at least has a strong Constitution (UK has none) and judges tend to be pro-privacy (although I imagine some data-mining/advertising startups would hate that).
Perhaps even more importantly, it's the people that care deeply about privacy there, too, and would protest obvious authoritarian moves by the government, while in the UK they seem to care almost as little about it as the Americans do.
Yes the German Government has been caught doing some nefarious stuff but if you compare the totality of what the UK government has been doing against what the German government has been doing, I'll take the German government every single time.
I say that as a UK citizen, also this is one of the areas where the EU has actually been really useful and I have a feeling we might leave in the referendum.
Germany has a strong constitution, yes, and an even stronger constitutional court... but: Take a look at poland and see how fast things can change.
It is frightening how fast a government can eviscerate the very foundations of democracy. This is even more appaling when you look at the fastest growing political power in Germany: The rightists from the AFD. I have no doubt that, what is happening right now in poland can happen in germany too, given enough time.
Piggybacking a bit here: would a startup based in the UK (as in, devs and managers live in the UK), but incorporated in the US (maybe through the new Stripe service), be held to this?
"7.14 Section 217(8) provides that obligations may be imposed on, and technical capability
notices given to, CSPs located outside the UK and may require things to be done or not
done outside the UK. Where a notice is to be given to a person outside the UK, the notice
may (in addition to electronic or other means of service) be given to the CSP:
-- By delivering it to the person’s principal office within the UK or, if the person does not have
an office in the UK, to any place in the UK where the person carries on business or
conducts activities; or
-- At an address in the UK specified by the person."
IANAL. International laws probably vary, but by having employees in a country, you may be subject to its laws.
For example, I am part owner of a Canadian company that sells an online service. If we hire US employees (developers), then we must collect sales tax and pay income tax for sales originating within the governing municipality.
Obviously, I am talking about US tax law, and your question is of a different nature, so the best thing to do is to contact a lawyer who has expertise in that area. I only offer my experience as evidence that the location of employees can impact the legal responsibilities of a foreign business.
The key issue, I think, is not what law-theoretically does and does not theoretically oblige you to comply with a jurisdiction, but the assets and people which are within reaching distance of the applicable government. Whether a service is accessible from the UK is irrelevant so long as you have no assets, no employees in the UK. Conversely, if you have assets or employees in the UK, you can expect them to be under threat of seizure or coercion, respectively.
I also don't think it's a safe assumption in any jurisdiction nowadays that the person who gets served with a notice will be an executive. It seems quite plausible to me that a front-line engineer could get served with a notice, and not even be allowed to tell an executive. Thus, even if your employees in the UK don't appear to have been coerced, this appearance could be deceiving.
There may be some limited countermeasures to this sort of thing, like regular audits of system configurations, etc. performed by a different group of people, and who will thus cry murder if they find any anomalies. This should work because the second group of people will not be the target of a notice, and thus not bound by its secrecy provisions. Possibly this group could do their auditing remotely, from outside the UK. Of course the in-UK group could, under coercion, rootkit the system to hide these changes, probably by being told to install government-issued software. Hmm...
What if you operate in UK and have an office there? So from the privacy conscious user perspective one would need to check that a company operating the specific website doesn't have anything do with UK, it's not very practical and makes GCHQ kinda happy.
It becomes interesting when a company operates in the UK, but does all its software development elsewhere. UK law can't compel foreign software developers not to talk about what they've been asked to do, so I don't really believe the law will be successful in keeping such monitoring secret.
Even more interesting is how this would work regarding open-source software. You can't keep such a backdoor secret in GPL'ed software and comply with the license, but a UK company couldn't release changes they'd made to comply with the law either. So if you suddenly see UK companies move away from GPL'ed software for no obvious reason, that may be a clue.
Whilst you can't compel foreign software developers not to talk about what they've been asked to do, there are probably a couple of ways this remains possible:
(a) Disclosure would likely result in liability for the executive officers and/or Company Directors, which might be contempt of court, or something more serious;
(b) Software developers working for Apple (an example) are likely under strict Non-Disclosure Agreements as part of their employment contracts, so the company served with such a request will likely make it clear to those responsible for technical implementation that it's covered by NDA.
Even in the case of (b) if a developer quits rather than implement the functionality, in many jurisdictions, the employer would have grounds to pursue a gag order.
If I quit a job at Apple over this, Apple might have to sue me for appearances sake, but my GoFundMe account would be quite fattened by the experience.