▶ 0:12:24Subcommittee will come to order. Without objection, the chair is authorized to declare recess at any time. We welcome everyone to today's hearing on the Cloud Act and Foreign Influence on Americans data. I now recognize the the gentleman from Texas, Mr. Nells, to lead us in the pledge of allegiance.
▶ 0:13:05Thank you, M. Thank you, Mr. Niels. I now recognize myself for an statement. I welcome my colleagues to this important hearing and welcome our our audience and our our witnesses today. I thank each of our witnesses for being here today with special recognition for one of our witnesses who flew all the way from the UK to testify today. Thank you.
▶ 0:13:29Given advances in technology and the heightened interconnectivity of the digital era, personal data, business information, and sensitive communications are sent, received, and stored all over the world. Often during an investigation, law enforcement needs to acquire this information from US companies. Until 2018, if this information was held in another country, for example, a data server in Ireland, it wasn't clear whether US law enforcement would be able to obtain it, even though it was requesting the data from a US company.
▶ 0:14:00In 2018, Congress passed the Clarifying Lawful Overseas Use of Data Act, or the Cloud Act, to address this gap in the law. Under the Cloud Act, US law enforcement, pursuant to a lawful court order, can obtain data held by US-based service providers, but stored outside of the United States.
▶ 0:14:18The Cloud Act also provides avenues for our allies to enter into bilateral agreements with the United States to sim similarly obtain their citizens data from these same service providers to assist with their own law enforcement investigations. Unfortunately, one of our closest allies, the United Kingdom, is taking advantage of its authorities under the Cloud Act and is attacking America's data security and privacy.
▶ 0:14:42In February of this year, the Washington Post reported that the UK had secretly ordered Apple to build a backdoor into its devices to enable UK law enforcement to a access to access a user's data stored on a cloud, including encrypted data. The Cloud Act requires that a country entering into a data access agreement with the United States have laws that include robust protections for privacy and civil liberties.
▶ 0:15:06The UK's order, however, threatens the privacy and security rights not only of those living in the UK, but of Apple users all over the world, including Americans. This order sets a dangerous precedent, and if not stopped now, could lead to future orders by other countries. The UK's investigatory powers act permits it to issue orders to tech companies compelling them to weaken encryption or halt security updates for users around the world.
▶ 0:15:32This broad extr territorial order highlights the tension between national security and individual rights. These interests are not mutually exclusive and it is possible to protect both national security and individual rights. Providing law enforcement with the tools to conduct investigations is a laudable important goal. But the UK seemingly emboldened by its agreement with the United States under the Cloud Act has issued an order that will affect people all over the world. And this is a step too far.
▶ 0:16:01Encryption is a critical tool to maintain the privacy and security of digital information and communications. Efforts to weaken or even break encryption makes us all less secure. The US UK relationship must be built on trust. If the UK is attempting to undermine this foundation of US cyber security, it is breaching that trust.
▶ 0:16:22If companies are forced to build back doors to encryption, that simultaneously opens a back door to privacy rights or an invasion of privacy rights and is impossible to limit a back door to just the good guys. Just last year, Chinese hackers known as Salt Typhoon penetrated lawfully mandated back doors, gaining access to wiretap systems used by US law enforcement. The hackers also were able to access the private data of President Trump and Vice President Vance.
▶ 0:16:49This attack is a clear example of the dangers of surveillance backd doors. This should concern everyone. I've long had concerns about the Cloud Act and the bilateral agreements it enables that could allow foreign governments to spy on Americans. Given the recent actions by the UK, I am concerned that the Cloud Act is failing to adequately protect the privacy and security of Americans. In the wake of the UK's order, I've called on this administration to act decisively to protect Americans communications.
▶ 0:17:17I continue to urge our government, including the Justice Department, to evaluate whether the Cloud Act and our agreement with the United Kingdom are working as intended. If they are not, we should re renegotiate the agreement to ensure that our rights are protected, and we should do so by invoking the 30-day termination clause. After years of senior US government officials pushing for weaker encryption and surveillance back doors, it seems the tide has shifted.
▶ 0:17:43Indeed, after the Salt Typhoon hack, our government publicly recommended the use of endto-end encrypted communications tools. Director of National Intelligence Tulsi Gabbard stated at her confirmation hearing that back doors lead down a dangerous path that can undermine Americans Fourth Amendment rights and civil liberties. This hearing provides an opportunity to build on the momentum toward greater respect for privacy and evaluate whether and what changes are needed to ensure Americans rights are protected.
▶ 0:18:10I am looking forward to hearing from our witnesses today and again thank you for being here and discussing how we can best move forward. I now recognize the ranking member, Mr. Rascin, for his opening statement. Mr. Chairman, thank you very much and welcome to our witnesses. I appreciate you being here with us. Uh, living in the digital age in America means that much of our connection with other people takes place over the internet.
▶ 0:18:38We message with friends and family and co-workers over our cell phone apps. We store documents in the cloud and we share materials over email. End-to-end encrypted services promise that no one, not Apple, not Google, not the government, federal, state or local can access the messages that we send. And these platforms are increasingly counted upon by users wishing for the privacy of a protected face-to-face conversation in the new era of technology that we inhabit.
▶ 0:19:08Imagine pulling out your phone, opening up an app you've been told is secure, and sending a message to a friend. Now, imagine learning that the app is not endtoend encrypted as promised. Instead, the government has ordered the service provider to make its security weaker so the government can demand access to your message. Imagine the government told the platform that they couldn't tell a soul about this arrangement. Well, that's exactly what the United Kingdom secretly ordered Apple to do recently. And that's the reason that we're here today.
▶ 0:19:39Requiring Apple to secretly build a so-called backdoor into its advanced data protection service would make users ant encrypted documents no longer secure. As expected, law enforcement officers, not just in the UK, but also in the US, could demand Apple produce users content and metadata from the cloud. And cyber criminals would be able to exploit this system weakness introduced by the backdoor to target Americans for espionage, consumer fraud, and ransomware.
▶ 0:20:09Backdoors to encrypted technology are not capable, as the chairman said, only of letting good guys in while keeping the bad guys out. Back doors are intentional designed weaknesses in an encrypted technologies mathematical formula. These design weaknesses can be exploited by foreign governments seeking to compromise our national security, steal our intellectual property, and monitor us in our daily lives and workplaces.
▶ 0:20:37Congress passed the cloud act in 2018 to allow for data sharing agreements between the US and countries that meet required standards. Through its negotiated agreement with the US, UK law enforcement can access non-encrypted data transmitted by US providers that is relevant to their law enforcement recommendations.
▶ 0:20:56While secret orders like the technical capability notice the home office placed on Apple have nothing to do with the data sharing agreement or the cloud act, they are only worthwhile to the UK because of the data that is made available through the agreement. I for one believe that the cloud act and the US UK data sharing agreement thus far have been beneficial both to US companies and to our country.
▶ 0:21:18But I also believe that forcing companies to circumvent their own encrypted services in the name of security is the beginning of a dangerous slippery slope. And I look forward to hearing from the witnesses as to what if anything we need to do to change to prevent future similar orders against other companies. Some argue that privacy is pass a yesterday's news. Cookies monitor which websites we click on.
▶ 0:21:43Our devices already track every step we take and data brokers take anonymized data and reidentify it in portfolios available to the highest bidder. But I disagree with the idea that privacy is no longer valuable or meaningful to the American citizenry in a country where visa holders are being detained simply for opinions they've expressed or an op-ed they wrote where criticism of the administration can result in a visit from the Secret Service.
▶ 0:22:10And where the staff of members of Congress can be arrested and handcuffed just for doing their jobs. American security from government intrusion has never been more urgent or important. The delusive ways new technology enables the government to spy on their citizens makes it even more important that Americans stand up to increases in state surveillance. Thomas Jefferson wrote in 1788 that the natural progress of things is for liberty to yield and for government to gain ground.
▶ 0:22:41Well, we have to resist that natural tendency. A week ago, the Trump administration announced it would hire Palunteer to consolidate Americans data into dossas on all US citizens. The plan to use Palanteer's foundry project to organize and analyze data across agencies into one big beautiful dossier is chilling.
▶ 0:23:02It's the beginning of an effort to create a national citizen database which would be vulnerable to manipulation not just by outside actors but by inside political actors from bank account numbers and student debt totals to medical claims and disability status.
▶ 0:23:19The administration today is taking information that was previously siloed into different categories as required under the law and using it to create one big beautiful surveillance apparatus that can be used to crush resistance to profile Americans and to silence disscent. We're here today to discuss the cloud act. I recognize this, but we should also recognize none of these issues exists in a vacuum. All government surveillance curtails all citizens liberties.
▶ 0:23:48It is not always immediate. Often it's a slow decay and erosion. But every chip in our civil liberties foundation brings us that much closer to a government that no longer has its foundational and necessary ideological checks against total control of the citiz citizenry.
▶ 0:24:05Surveillance databases like the one contemplated by the Trump administration should remain the stuff of science fiction and authoritarian governments not a reality for a country founded on the principles of democratic self-government and freedoms and rights for the people. In the case of the UK order, we can start with an easy first step. We don't need legislation to pass in the divided house or frozen Senate. The Trump DOJ can just do its job.
▶ 0:24:31The US should not sit idly by and watch the Home Office issue perhaps more secret orders against US companies. But thus far, that's exactly what the DOJ has done. I sincerely hope that we move uh quickly to change that. I thank Chairman Biggs and Chairman Jordan for holding a second bipartisan surveillance hearing and I look forward to working across the aisle with my friends as we prepare for the expiration of FISA section 702 next year. And I yield back to you, Mr. Chairman. Uh the gentleman yields back. Thank you. I now recognize the chairman of the full committee, Mr.
▶ 0:25:00Jordan for his opening statement. I just uh no opening statement. I just want to thank the chairman for uh for having this hearing. Thank our witnesses for being here and and appreciate the remarks by both the chairman and the ranking member on on this subject and the ranking members reference to the good the the work we have to do as 702 and the FISA comes up for reauthorization less than a year from now. With that, I would yield back to the chairman and again thank our witnesses for being here. I thank the chairman. Chairman yields back.
▶ 0:25:27Without objection, all other opening statements will be included in the record. And uh I'll now introduce today's witnesses. With us today is Professor Susan Landau. Miss Landau is a professor of cyber security and policy in the department of computer science at Tus University. Professor Landau's research focuses on privacy, surveillance, cyber security, and law.
▶ 0:25:49She has previously worked or held faculty appointments at Google Sun Micros Systemystems the worst worester worester worester I'm from Arizona man I don't that northeast yeah that northeast stuff who knows you know worester polytenic institute the University of Massachusetts Amherst Wesleian University the nationalmies of sciences engineering and medicine the national science foundation and the national institute of standards and technology welcome professor thank you for being Miss Carolyn
▶ 0:26:19Wilson Palo. Miss Wilson Palo is the legal director and general counsel at Privacy International, a nonprofit organization based in the UK. Miss Wilson Palo leads the organ organization's legal advocacy and advises its programs on legal strategy and risk. Prior to joining Privacy International, she was an attorney with Wilson, Sunini, Goodrich, and Rosati, where her practice focused on privacy and intellectual property. Thank you for joining us. Thanks for coming all this way, too. Mr.
▶ 0:26:47Richard Salgado is the founder of Salgado Strategies, a consulting firm that advises clients on geopolitical, cyber security, and surveillance issues. He also serves as a lecturer at both Harvard Law School and Stanford Law School. Mr. Salgado previously was the director of law enforcement and information security at Google for more than 13 years, worked on international security and law enforcement compliance at Yahoo, and served in the Department of Justice. Thank you, Mr. Salgado, for being with us. And Mr. Mr.
▶ 0:27:16Gregory Nojame Nojime. Okay. Mr. Nojime is a senior counsel and director of the secretary security and surveillance project at the center for democracy and technology, a nonprofit organization that advocates for civil rights and civil liberties in an increasingly digital world. He previously served as the associate director and chief legislative counsel of the ACLU's Washington office where he focused on the civil liberties implications of terrorism, national security and information privacy legislation.
▶ 0:27:46All of you we welcome. Thank you for being here today. We will begin now by swearing you in. Would you please rise and raise your right hand? Do each of you swear or affirm under penalty of perjury that the testimony you are about to give is true and correct to the best of your knowledge, information, and belief. So help you God. Let the record reflect that the witness witnesses have all answered in the affirmative. And you may now be seated. Thank you.
▶ 0:28:13I want you to know that uh we've read your I don't know I won't guarantee everybody, but I've read your statements and uh those will be entered into the record in their entirety. Accordingly, we ask that you summarize your testimony uh in five for in five minutes. And and at four minutes, the light should go yellow before you. And when it's almost five minutes, I I will just tap this little bit so you'll know it's time to kind of wrap up.
▶ 0:28:39And I don't want to I don't want to cut you off too much, but uh we we do want to remind you of that. So, we thank you so much uh for being here. And now, Professor Lander Landau, I recognize you for your five minutes. Thank you, Chairman Biggs, Ranking Member Rascin, and members of the committee for the opportunity to testify today. I have no need to remind you of the damage caused by Salt Typhoon, but I want to touch on the hackers access to the databases of wiretap targets.
▶ 0:29:06This enabled the Chinese government to learn which spies we had discovered. It appears to have been made easier by the technical requirements mandates imposed by the Communications Assistance for Law Enforcement Act. Introducing such access to complex systems and communication systems are complex systems increases vulnerabilities. At the same time, the salt typhoon hackers could not read communications sent through WhatsApp signal and or on Apple's network.
▶ 0:29:34These were endto-end encrypted as the chairman mentioned a form of cryptography in which as long as the communications device itself has not been hacked, only the sender and receiver can uh read the encrypted communication. We all use end-to-end encryption daily. You almost always use it when you visit a web page. You always do when you're sending credit card information. You use it on Signal, on WhatsApp, and multiple other applications.
▶ 0:29:59Apple's advanced data protection secures users files by treating them as end-to-end encrypted messages sent from the user to themselves. Files are delivered when the user downloads them. Meanwhile, they reside on the iCloud. Since only the user has the encryption key, the files cannot be decrypted while stored in the iCloud. Um, if it is a terrific form of security, if there is ever a breach of the iCloud, the user's data is secure. Who needs it? All of us.
▶ 0:30:28Journalists, human rights workers, members of civil society organizations, the latter are particularly targeted by Russia and China. remote workers, business people while traveling, members of your family um uh with files they'd like to keep private like healthcare proxies, wills, financial information, members of your staff, all of us. Around the time the US government loosened export controls on encryption back in 2000, the NSA began encouraging wider use of of strong encryption domestically.
▶ 0:30:58The FBI was less enthusiastic and began pressing about going dark, its increasing inability to understand communications, and later read files due to encryption. The issue came to head with the San Bernardino case involving a locked iPhone. Unable to open the device due to Apple's security protections, the FBI and DOJ sought to have Apple undo those protections. Doing so was not nearly as straightforward as the FBI sought to portray.
▶ 0:31:26requests for access were likely to be frequent and while information on obtaining access had to be stored for both legal and technical reasons. This created a serious security vulnerability and Apple refused to do it. The case ended by the way when uh an FBI consultant was able to unlock the device.
▶ 0:31:44The real point though is whether you're looking at Kalia, the 2016 fight over the locked iPhone or the purported app UK technical capability notice uh served on Apple, these attempts at mandating lawful access to be built into complex communication systems creates vulnerabilities in this this these systems that's dangerous for Americans and for US national security. Protecting the private data of Americans is a critical aspect of protecting US national security.
▶ 0:32:12This is because protecting the private communications of the CEO's son-in-law, the files of an American who has family working in China, the draft research papers of a graduate student in genomics who has not yet filed a patent on her work, is protecting both the individuals and the economic and national security of our nation.
▶ 0:32:31That's why former NSA directors Mike McConnell and Michael Hayden, former DHS Secretary Michael Churoff, former general c FBI general counsel Jim Baker, and multiple other national security and law enforcement leaders support widespread public use of end-to-end encryption.
▶ 0:32:46And it's why as the chairman mentioned the joint guidance of the governments of Australia, Canada, New Zealand and the United States post salt typhoon recommended that endto-end be encryption be used whenever possible and for communications traffic to be used to the maximal extent possible. By refusing to sign the UK is a real outlier. It's a it has become a forey statement. Apple's advanced data encryption protects people's data. It's an important and needed technology.
▶ 0:33:13I urge you to ensure that the UK's efforts to improve its own investigatory capabilities do not come at the at its expense. The technology that Apple developed protects our national security and the security and privacy of ordinary Americans. It should be widely used and widely available. Please ensure that it continues to be so. Thanks very much. Thank Thank you. Uh now I recognize uh you miss Wilson Palo and uh for your five minutes.
▶ 0:33:42Thank you, Chairman Biggs, Ranking Member Raskin, and members of the subcommittee. Thank you for the opportunity to testify today on behalf of Privacy International. I'm here to tell you about a troubling surveillance power that allows the United Kingdom's government to secretly order a US company to undermine the security, privacy, and free speech rights of Americans. Indeed, due to the global reach of US companies, these orders threaten the security, and fundamental rights of users worldwide.
▶ 0:34:08This power can be found in the UK's Technical Capability Notice Regime, which is part of the Investigatory Powers Act 2016. Under this law, the UK can order a telecommunication service provider to build or modify its systems so that in the future, the UK can access data on those systems through other lawful processes such as warrants authorizing the interception of content or overseas production orders permitted under the Cloud Act. More on that later.
▶ 0:34:36I've provided a more detailed description of these notices in my written statement, but in brief, the most salient aspects of them are that they are ill-defined, secret, and extr territorial. An American company subject to UK order cannot reveal even its existence to US officials and oversight bodies, much less users, investors, or anyone else who plays a crucial role in vetting the legality and wisdom of such notices. But why are we concerned about a UK surveillance power affecting American companies?
▶ 0:35:06Because these notices can be given to companies outside of the UK so long as the company offers, provides, or controls services used by people in the UK, this small nexus is sufficient for the UK to demand a company change its systems worldwide, affecting all of its users, whether in the UK, the US, or elsewhere. We are here today because in February, the Washington Post revealed that a US company, Apple, received a secret notice requiring it to undermine the security of its advanced data protection service.
▶ 0:35:35as Miss Land at Professor Lando has described which is an optional security feature for Apple's users providing end-to-end encryption of iCloud storage that only the iCloud user not Apple itself can unlock. The Washington Post reporting and the significant press follow-up have provided us with a potentially unique opportunity to have a public debate about a specific application of these types of orders because of their inherent secrecy.
▶ 0:36:00Seizing this opportunity, my organization, Privacy International, has filed a case challenging the notices regime at the UK's Investigatory Powers Tribunal, Apple, has filed a similar challenge. Privacy International is devoting significant resources to opposing the Apple order because it exemplifies the potential for the Nun regime to have far-reaching consequences that threaten our security and rights. That is because it appears that Apple has been ordered to deliberately weaken an end-to-end encrypted service.
▶ 0:36:28We are concerned that this means that these notices are now being used against encryption services and the UK will not stop with Apple. My understanding from technical experts including professor Lando is that it is technologically infeasible to have both effective endto-end encryption and mechanisms for third party access which the UK seeks to be demand seems to be demanding. That is because to enable such third party access creates an inherent vulnerability that can be exploited by bad actors including hostile states and criminal networks.
▶ 0:36:57That is why government security and privacy experts on both sides of the Atlantic, including in the US, the UK, and the EU, strongly recommend using end to-end encryption. If the UK government succeeds in maintaining this order against Apple, it is likely further such orders targeting endto-end encryption may follow. Other American companies, given their global reach, will be targets. Notices might also be used to force a company to do many other things that could undermine our security, such as sends false security updates or refrain from fixing a vulnerability in its systems.
▶ 0:37:27Considering the notices regime's significant impact on fundamental rights and American companies, questions have been raised about the interaction of these orders with the cloud act. In some ways, the notices regime and the cloud act operate independently of each other as the UK claims the ability to serve an order directly on a US company irrespective of the cloud act and the cloud act itself steers clear of encryption with the department of justice declaring the act encryption neutral.
▶ 0:37:53But once a US company is ordered to create a back door in its end encrypted services, the UK could then serve a production order on that company for information that would have been previously inaccessible, tying the notices regime and the cloud act back together. These secret orders also significantly impact fundamental rights such as privacy and freedom of speech. And the cloud act was intended to protect these rights as well as US companies. The only other country with a cloud act data access agreement, Australia, also has a technical capability notices regime.
▶ 0:38:22And the European Union, which is negotiating a data access agreement, has been considering measures that would undermine endto-end encryption. More countries, therefore, might soon be targeting US companies and undermining the security and privacy of their users worldwide while also taking advantage of cloud act processes. This squarely weighs the question of whether the cloud acts encryption neutrality is truly sustainable, which I suspect my fellow panelists are now eager to answer. Thank you. Thank you, Miss uh Wilson Palao.
▶ 0:38:50Uh now I'd like to turn to Mr. Salgado. You have five minutes for your testimony. Thank you, Mr. Congressman, and thank you, Chairman Biggs, Ranking Member McBath, Chairman Jordan, and Ranking Member Rascin for inviting me here today to participate in this hearing on these important issues and for your leadership on this. My name is Richard Salgado. The chairman summarized my uh more than 35 years of experience as a lawyer mostly dealing with government surveillance and network security issues.
▶ 0:39:20Uh it was almost exactly eight years ago that I testified about the need for changes that were ultimately included in the cloud act signed into law by President Trump in 2018. And I'm honored to be here again now that we've gained some experience with the act and the agreement that the UK entered pursuant to it. Even in these relatively early days, it's clear that the act provides a framework for advancing US interests and public safety.
▶ 0:39:47It underscores the importance of finalizing agreements with Canada and the European Union and beginning negotiations with other countries. Deeply concerning is the report by the Washington Post in February that the UK is secretly seeking to compel Apple to disable a global security feature in one of its products in order to expand its surveillance capabilities. But it also illustrates the value of the Cloud Act framework.
▶ 0:40:15When a foreign government coerces an American company to compromise or withhold security protections intended to safeguard users worldwide, the impact reaches everyone, including Americans. The harm is magnified when such mandates are imposed in closed secret proceedings with outcomes concealed.
▶ 0:40:36These actions threaten core US interests in cyber security and erode the global competitiveness of American technology providers in the light of serious competition from China. If there's still a real debate about whether security should yield to government surveillance, it doesn't belong behind closed doors in a foreign country. It shouldn't be settled in secret proceedings run by foreign officials and with outcomes unknown even to US government.
▶ 0:41:05The debate belongs in public before the United States Congress, led by officials elected by the American people, acting with the interests of this country at heart. It must be decided here, not there. Regardless of the outcome in the reported Apple matter, which we may never know, this experience reflects the broader threat of foreign efforts to covertly undermine the security of products and services offered by American companies.
▶ 0:41:36We are now tasked with identifying and implementing solutions. Fortunately, the cloud act provides an ideal framework for this. The cloud act provisions it issued today were enacted to address problems created by US blocking statutes. Before the act, US providers were broadly and presumptively barred from disclosing certain user data to foreign governments, even when the request came from a jurisdiction that respects human law, human rights, and the rule of law.
▶ 0:42:04And in a legitimate case, as a result, countries had to rely on diplomatic tools like mutual legal assistance treaties, which are often too slow in practice. Frustrated, some would resort to unilateral measures to circumvent US law, including tactics that undermine security. The Cloud Act addresses this by conditionally lifting the blocking statutes for any country that qualifies for and signs an executive agreement with the US.
▶ 0:42:30To qualify, a government must demonstrate respect for civil liberties and due process, among other requirements. Once an agreement is in place, a US provider may honor data requests from that country without risking running a foul of the blocking statutes. With a few surgical changes, the Cloud Act is well suited to address the UK's reported actions and similar moves by other foreign governments. I've outlined several improvements in my written testimony and will briefly summarize only a few here.
▶ 0:42:58First, the US government should press the UK to end its reported effort against Apple and commit to refraining from similar actions against other American companies. That commitment should be a contion for continued participation in the agreement. Second, Congress should amend the cloud act to declare cyber security a national interest that like free speech must be respected.
▶ 0:43:22Third, Congress should require that to qualify for an agreement, a foreign government must not impose surveillance or anti-security obligations on American companies. With these targeted changes and a few others, the act can better advance cyber security and help American companies continue offering trusted secured services worldwide. We should treat the lamentable US the UK episode as a lesson and improve the act. Too much is at stake otherwise.
▶ 0:43:51Thank you for the opportunity to discuss these issues. Yeah. Thank you, Mr. Salgado. Mr. Nojime, you have five minutes for your testimony. Thank you so much, acting chairman Tiffany, Ranking Member Rascin, members of the subcommittee. My name is Greg Nojime and I direct the security and surveillance project at the Center for Democracy and Technology. And I'm proud to say that our awesome intern class is here and showed up. Thank you for identifying yourselves. Welcome.
▶ 0:44:20Um, CDT is a nonprofit, nonpartisan organization and uh, as the chairman mentioned, we defend civil rights, civil liberties, and democratic values in the digital age. We're calling on Congress to act with the DOJ to protect privacy and security of Americans data against threats from countries that benefit from Cloud Act agreements.
▶ 0:44:42Congress enacted the Cloud Act in 2018 by tacking it on to the end of a 2,322page omnibus spending bill. It empowers the DOJ to enter into executive agreements without congressional approval with foreign countries through which the US providers can disclose user data from storage and in real time.
▶ 0:45:06Disclosures are made directly to foreign states under the laws of the foreign states and the US warrant requirement that would otherwise pertain does not apply. The UK has availed itself of this opportunity in spades, issuing over 20,000 demands under the cloud act. In contrast, the US has issued 63. The benefits of the agreement to the US, while real, are limited.
▶ 0:45:34Cloud Act agreements are supposed to preserve the privacy of Americans and of other people in the United States. The foreign country cannot target those people with cloud act orders. But things haven't quite worked out as Congress planned.
▶ 0:45:52Instead, the UK has ordered Apple, as the other witnesses have said, under the authority of UK law, not under the authority of the Cloud Act, to build in a backdoor to its encrypted cloud backup service so Apple can fulfill the UK's Cloud Act demands.
▶ 0:46:10If Apple had fully complied, it would have compromised the communication security of its users in the US and UK law, the TCN's are super extr territorial.
▶ 0:46:23The UK authorities can issue orders on companies headquartered outside the UK, order them to alter their equipment that is outside the UK so they can wiretap people who are outside the Um, we don't know how many other US providers have received one of these orders. if they have received one, they are gagged and can't say so. Other countries assert the authority to compel this type of provider assistance.
▶ 0:46:53Australia is the only other country to have a cloud act agreement. It has a similar law similar to the UK's, but it includes a vague exception that may protect encryption. Canada, which is negotiating cloud act agreement with the US right now, has a provision almost identical to the Australian law provision.
▶ 0:47:16Acting chairman Tiffany, if you are an iPhone user and you go to London and you try to back up your iMes um with the uh cloud backup service that Apple provides, you wouldn't be able to do it in encrypted form. The reason you wouldn't be able to do it is because Apple has withdrawn that service from the UK under the pressure of this order that it's received.
▶ 0:47:42The UK would have Apple withdraw the service worldwide or compromise its protections so that no matter where you went, even to your office next door in the Canon building, if you downloaded your IME messages, you wouldn't be able to protect them with encryption. This situation is intolerable. The DOJ and Congress should put an end to it by taking three steps.
▶ 0:48:05First, DOJ should invoke article 12.3 of the agreement and declare that it is ineffective with respect to cloud act orders issued to a provider that has received an order like the one served on Apple. Such a declaration would have immediate effect. DOJ should also persuade the UK to publicly withdraw the order to Apple so that under threat under threat of terminating the agreement unless the UK agrees.
▶ 0:48:34This has the benefit of a negotiated result with more predictable public effect that sends a message to other countries that seek cloud act agreements. Finally, Congress should back up the DOJ by amending the Cloud Act to prohibit cloud act agreements with countries whose laws or practices permit such orders and to require cloud act agreements that they explicitly prohibit such orders.
▶ 0:49:00We look forward to working with you on such solutions. Thank you, Mr. Nojime. We're now going to proceed under the fivem minute rule with questions. First of all, I'd like to recognize the gentleman from Texas, Mr. Dal. Thank you, Mr. Chairman. Uh, thank you to all the witnesses that are here today. I I want to start posing a question to all of you.
▶ 0:49:21Uh, in your opinion, does the Cloud Act and the executive agreements we have under it with the UK and Australia sufficiently protect American communications from foreign surveillance? And please explain why or why not. Mr. Salgado, I'll start with you, Mr. Salgado. Apologies. Uh, no they do not.
▶ 0:49:44Uh, and for for several reasons, but the primary one that I think the ill the UK matter exposes is that they don't do anything to dissuade a foreign government from imposing technical capabilities like we've seen in the UK, but a whole host of other uh potential efforts to undermine security back doors uh uh contaminated apps. There's a whole host of things that a creative investigator could come up with.
▶ 0:50:10all that undermine the security of American services and that would also compromise Americans data. Uh and the cloud act is a framework that we could use to protect that. I I agree with that. Um we're focused today on the security risks that the cloud act actually ins countries that have cloud act agreements to demand of US providers. But there's a lot of improvements that could be made to protect Americans.
▶ 0:50:40One improvement would be to make it so that the US providers could at least tell their government when they receive an order like the one served on Apple that this has happened. Apple is gagged not only from telling the world it received an order, it can't even tell its home country. You mentioned there were like 20,000 requests. 20,000 of these. We were at 63. Yeah. It's uh it's imbalanced. Yes, it's imbalanced. Thank you, Miss Wilson.
▶ 0:51:11I would agree with my fellow witnesses. I would just add and reemphasize that the cloud act is designed when engaging in executive agreements with these other countries to make sure that these countries have a surveillance regime that respects privacy and other rights. And clearly the UK is not following that here with the the TCN. Um the technical capability notice, it's obviously huge invasion into privacy. It's breaking all of our security by targeting endto-end encryption.
▶ 0:51:37It undermines our potential free speech rights because of the way that endto-end encryption can be used by so many to communicate um by opposition groups around the world, by human rights defenders and really tough circumstances. Uh so I'd say that the UK is not really in the spirit of the act at the moment. professor.
▶ 0:51:53So, um this is mostly a law and policy question, but I will pose a technical version of it, which is that in the 1990s, the US government proposed a encryption scheme for digital communications, uh digital voice communications in which the keys would be stored with two agencies of the federal government. This did not go over well. It didn't go over well with industry. It didn't go over well with foreign countries, and it didn't go over well with buyers. When AT&T implemented it, the product did not get bought.
▶ 0:52:20But now imagine that the UK requires that encryption use keys that that are stored with the UK government. As far as I can tell, and and the lawyers to my right can correct me if I'm wrong, but I don't see anything in the Cloud Act that would prohibit such a thing. And yet, of course, no American company, no American who has any private business would want to use encryption where the keys are stored with the UK government. Sure. Uh Mr.
▶ 0:52:47Salgado, does the cloud act or our agreements under it impose an undue or unfair burden on US companies? Why or why not? Uh I don't think they they impose an undue burden other than that the companies as as uh Mr. Noji pointed out are barred from disclosing these things that are coming to them. Uh and the cloud act isn't there to protect them from that and it is a good vehicle for that so that they could tell the US government.
▶ 0:53:15Uh and really Congress ought to have much more information than is provided through the current reporting mechanism. Yes. A and could the UK's this technical capability notice to Apple aggravate that burden? Uh it could uh and it and I think it has. I think you see uh the the situation with Apple where they seem unable to comment on this. Right. They're what happens if other countries now they'll follow suit with this. Yeah. It's that's the problem.
▶ 0:53:41it just continues with more and more and especially if it's if it goes unadressed by the US that just creates a an invitation to continue doing things. We got about 25 seconds left. Do you have any recommendations for future executive agreements or amendments to the cloud act to to lessen that burden on US companies? I do. There's several of them laid out in my witness testimony.
▶ 0:54:03But first and very simply, we should have a declaration in the agreement that uh network security and cyber security is an essential interest which is a diplomatic term of art just like free speech and some others. Uh that carries weight with it. Uh and we can also put some in the in the conditions to get an agreement some restrictions on the type of technical surveillance capabilities that partner countries would be allowed to provide among other changes. Thank you all for being here. I reserve. Gentleman yields.
▶ 0:54:32I now turn to the ranking member, Mr. Rascin, for his five minutes of question. Thank you, Mr. Chairman. Um, Mr. Noj, so wait, what is the argument on the other side? Like what is the UK's interest in doing this? And is there some other way to vindicate their interest other than the construction of the back door?
▶ 0:54:56I think their argument would be first I think they should be at this table and answering your questions, but I think that the argument should would be that um they need access to communications content in order to uh fight crimes and prevent crimes and that they would say um well our interest in getting access trumps the privacy interest of everybody in the world. That's what they would have to say. Yeah.
▶ 0:55:24Yeah, I mean to transpose it to the domestic context, it would mean that the government would have access to all of our private conversations, not just technologically, but in person, at a restaurant, um, walking in the park, right? Because there might be some information they want to get. You know, you you might have heard that some in law enforcement argue that they're going dark because of encryption. This is the golden age of surveillance.
▶ 0:55:53There's never been more human thought available to law enforcement agencies around the world in the history of mankind than today. Uh they get it from social media, they get it from data brokers, they get it from all kinds of sources. Um thank you, Professor Landau.
▶ 0:56:12Could you um take us through the salt typhoon hack on the telecom providers and show us um why that episode underscores the importance of creating strong security. Sure. So I none of the technical details have been released by the US government. So this is certain amount of speculation but we do know that the um the telecommunications network the phone network has some insecurities.
▶ 0:56:41But one of the important aspects of the phone network is that the way that the phone interoperate used a threat uh used a model of trust where each of the phone companies knew each other and there were few phone companies and that worked fine. We don't have few ISPs. We have thousands of ISPs.
▶ 0:56:59We have tens of thousands of ISPs and um way back when ISPs started carrying phone calls for example E91 911 voiceover IP and so on there was a requirement an appropriate requirement by the government to have the ISPs interrupt interconnect with the phone system so that when somebody dials a 911 emergency call the phone system can then locate where that person is.
▶ 0:57:24The problem is that ISPs as we all know the internet has great number of insecurities and so the hackers use the insecurities that are caused by that interconnection. At the technical level I don't know all the different pieces. Um so when you send a message when you text if you're texting over the phone line as opposed to texting via iMessage or a an app that encrypts if you're texting over the phone line then your message is not encrypted.
▶ 0:57:52Once the hackers were into the phone system, they could read texts. They could read they the Kala um centralized or more greatly centralized wiretaps. So it used to be wiretaps were done at the phone central office, you know, the office 5 miles down from my house or three miles down from my house. They're now more centralized. So a a city will have only a few Kalia sites.
▶ 0:58:16if you only have a few sites and you're in the phone system and and the hackers are in the phone system, they can more easily access it. So, there were all sorts of pieces that were not thought through carefully. Thank you very much. Uh, Ms. Wilson Po.
▶ 0:58:31Um so the uh so-called technical capability notice which is the euphemism I suppose for creating this gaping backdoor entryway into communications uh contained a provision that the order itself was secret.
▶ 0:58:52Um, and I wonder uh first of all, what purpose did that secrecy uh condition serve for the government? And what does that do to civil liberties and people's reasonable expectations of First, the purpose, and again, I'm speculating because the UK government also has maintained total secrecy around why this order exists. But they've got secrecy around secrecy. Yes.
▶ 0:59:22Secrecy around secrecy. Exactly. Um, but I think the UK's general idea is that, and this is actually not just in the case of TCN's, but certain other broader powers like interception, is that it really heavily tries to protect the technical capabilities that it has. And so by making this uh order entirely secret, it means that users others can't know whether or not there is a backdoor in in a service that is being targeted.
▶ 0:59:49And the UK would say that that's necessary, I think, for national security, but it completely undermines the ability of everyone else, including uh Congress, including oversight bodies around the world, including users and concerned civil rights advocates, so civil liberties advocates um from being able to question whether or not this is uh a a acceptable in violation of our privacy and security. Gentleman's time is expired. Thank you. Um, and I apologize.
▶ 1:00:18Um, I was having a vote in another committee that is like a mile away. I mean, so I had to go get do that vote. So I apologize for missing some of your testimony. I apologize for that. Now recognize the gentleman from Wisconsin, Mr. Tiffany, for his five minutes. And Mr. Chairman, I was happy to pinch hit. Um uh Miss uh Wilson PLO, one requirement of the cloud act to uh to enter these agreements is it has to be part of the convention on cyber crime.
▶ 1:00:48Is that correct? That's my understanding. Yes, I believe so. Although actually some of the other witnesses may be able to ask that answer that better than I could. Um with that being the case that convention also includes countries like Turkey and South Africa.
▶ 1:01:08Um while the concern is being uh most pointed towards the UK and perhaps appropriately so um Turkey and South Africa aren't exactly exemplars of uh protecting people's civil rights. Shouldn't we be concerned about this? um extending beyond the UK certainly.
▶ 1:01:33I mean I think one of the most concerning aspects of this technical capability notice regime is of course the UK claims to be able to serve the notice actually entirely outside of the cloud act provision. So even if a country like Turkey or South Africa um did or did not negotiate an agreement um with an executive agreement under the cloud act, if they had a similar regime in place um if as long as that's not blocked by the cloud act or some other US law provision, they similarly could serve these types of notices on
▶ 1:02:04US companies um and may have much less respect for rights as as you suggest. Mr. John, do you have a comment in regards to what I just asked in the comments here? So, I I think a lot could be done to ensure that the US doesn't enter into agreements with countries that don't respect the rule of law.
▶ 1:02:24Um, for example, the Cloud Act does not have a requirement that the US that the that the country's laws um require that there be even judicial authorization of surveillance. That seems like a very basic requirement and yet it's not in the Cloud Act.
▶ 1:02:40So, um it strikes me as I sit here and as we um once again see the um that we have spies amongst us from China and the surveillance that's gone on, a spy balloon that flew over our country a few years ago. I mean, are we uh whistling past the graveyard of China freedoms that aren't they the greatest threat here?
▶ 1:03:03I think that um China poses a huge cyber security threat to the United States and if countries like the UK can force our providers to disarm by removing encryption protection then we're more vulnerable to that kind of surveillance and that kind of attack.
▶ 1:03:23So, you're saying that um we would benefit by um amending the Cloud Act um to make sure that it's not abused by the UK, but perhaps other countries also. Is that what you're saying? Yeah. Think of it, think of it, think of the Cloud Act requirements in three buckets. There's the criteria that the country's laws and practices must meet. You could include a new one for protecting encryption.
▶ 1:03:48There are criteria that the agreement must include things that the agreement must say. The agreement uh right now the statute says that the agreement um has to be silent on encryption basically. It should say it has to protect encryption. Um and then there's requirements about what the orders can and can't do. So amendments in those three buckets could protect encryption. Salgado.
▶ 1:04:16Um, were you with Google in 2018 when the Cloud Act was uh enacted into law? I was. Yes. So, in reading your testimony, I get the impression that you were a strong advocate for the cloud act at that point. Is that right? That's true. And, uh, now coming to us saying it uh needs to be changed.
▶ 1:04:34Did you sense in 2018 that there should be um um that we should be really concerned uh that we were giving away too much with that cloud act in 2018? Did you have concerns at that time? I did. There there were some changes to the cloud act I would have liked to have seen or some provisions I would have liked to have seen added.
▶ 1:04:58uh there wasn't anything quite on the horizon that we have with the UK now, but yes, there were some things that I thought we could do better with the cloud act. It was pretty good as it was passed and it's been valuable, but it could use a tuneup. So, this is going to be a pointed question. It seems to me we have Google and Apple that are the subjects of this in particular Apple and we look at them in China and how they go about doing their business where they have basically in my terms they've capitulated to the communist Chinese government.
▶ 1:05:28How do we um how do you reconcile that as someone who's a former executive with Google? Uh I'm not sure I totally understand the question. Uh it may be direct better directed to somebody who's currently at Google who could explain that further. I'm sorry that the gentleman's time is expired. I yield. Thank you. Chair now recognizes the gentleman from North Carolina, Mr. KN. Thank you, Mr. Chairman. I appreciate the uh topic of today's important hearing to the witnesses.
▶ 1:05:57I enjoyed speaking with you briefly before the hearing and again thank you for making the trip uh to Washington to to discuss this important issue and and uh it's one that's largely unknown on a technical and a practical level to many in this country even in Congress and this issue is one that I assume uh will be abused by foreign governments andor criminal actors and hopefully there is a distinction still between those uh you take The UK
▶ 1:06:27for instance, a country with a proud history of protecting liberties, of respecting the rule of law, adhering to due process. Um, you know, bedrocks of western civilization. Uh, that country today has has protected and built a surveillance state. You know, they spy on their own citizens. They arrest people for posting various things online. They monitor their own citizens public communications and public posts.
▶ 1:06:53Um it's something that's quite concerning and uh under this particular u issue that we're discussing today. I do want to know just technically speaking, Miss Landau, can you just explain to us how the communications that are covered that we're discussing today? How are they collected? How are they stored? And then how can they be accessed in the future?
▶ 1:07:17So the current Google architecture says that if I have three devices that I've made um fit this advanced data protection that when I upload something when I upload something to the iCloud, it's essentially a message that I am going to send to myself because I might pick it up on another one of my devices and I've encrypted it end to end. All of my devices know the encryption key and I authenticate to the devices before I pull it down from the iCloud. So, it's sort of like it's just hanging out in the iCloud.
▶ 1:07:47Hanging out. Hanging out. Apple doesn't have the key. Nobody has the key. Just I have the key. And so, that's the protection for it. Is the UK seeking to collect the data of two parties who are exclusively in the UK or is it looking to protect? Okay. Explain. When they're in Well, I I think you're probably better set, Miss Pal. Yes. Uh, with this technical capability notice, they're seeking to open up a back door.
▶ 1:08:14So the option to collect data and then under other surveillance powers that they have they can collect um data from anyone in the world. Okay. So they have both outward facing powers and inward facing to the UK. And then hypothetically let's say in the future or present could federal law enforcement request information from a foreign country like the UK to receive communication files that involve American correspondents? Yes, I believe that is possible.
▶ 1:08:44Although I may defer that some to some of my other panelists who better understand the American regulations because I think there are some prohibitions. I'm not talking about regulations. I'm talking about practically practically speaking that that that uh action would be feasible. Correct. That's right. Because the UK absolutely will have Americans data in in the intelligence that it collects. So it could also be reasonable to assume this this this is a bypass of fourth amendment protections potentially if it was uh motivated by the wrong actors.
▶ 1:09:13Again it potentially could be uh in theory. There's the possibility. Now if I if I could add something here, may I? I was getting ready to Yeah. go to you. Yes, sir. So So um the the statute wouldn't permit the US to task the UK to listen in on an American. um that order would be illegal under the statute. Um but what happens is Americans communicate with people outside the United States all the time. It doesn't permit it, but it enables it.
▶ 1:09:40It it enables it through this kind of uh incidental collection. You're familiar with this through the 702 program. So if I'm talking to a foreigner abroad who's the target of the UK surveillance order served on Apple, um my communications will be collected as well. And then there's rules about when those communications can be shared back to the United States. Right. So let me let me follow up with that. You mentioned earlier this is the golden age of surveillance.
▶ 1:10:09Um what are ways that you believe the cloud act could be reformed to ensure that imminent threats are able to be identified and stopped without eroding the civil liberties protections that we're we're discussing. So, so I I think in addition to requiring that the foreign country have uh um judicial authorization that there ought to be a rule that people get notice when they've been surveiled.
▶ 1:10:33We have that rule in the United States and you don't get notice that happens before the investigation has finished. You get notice when it's done. Yeah. So, uh, I think that would go a long way and also transparency and the ability of providers to tell their own government that they've received an unlawful order. Sure. My time's expired. Mr. Chairman, I yield back.
▶ 1:10:56Gentleman yields back and uh I for entering into the record a letter from reform of government surveillance that without objection. So ordered and I now yield to the rank excuse me the chairman of the Thank you, Mr. Chair, Mr. Noj. Should the United States government have to get a warrant before they search the 702 database uh on an American? Absolutely. Yeah. And you were just there, didn't you?
▶ 1:11:19And this the issue we're talking about today, I think even underscores and highlights that reason because this, as you point out, United States government, we spy on foreigners all the time. Okay, fine. Good. I think that's that's that's appropriate. But they pick up all kinds of information on Americans and then that giant hay stack of information gets searched using Americans phone number, email address or name. If you're going to do that, go to a separate and equal branch of government, get a warrant, and show that you have a reason to do so.
▶ 1:11:50Yes, I think that's an essential reform and that Congress shouldn't reauthorize section 702 unless it achieves that reform. Well, we almost achieved it. Last last year, last Congress, we lost the vote 212 to 212. I'm hoping we win it this time. Mr. Salgado, do you think that's a a a good um change that we need to make? I think it's not only good, I think it's constitutionally mandated. It's also good public policy. No kidding. How about How about Miss Wilson Palo? Do you think so? Yes, I would agree. Professor, do you agree?
▶ 1:12:20Absolutely. Wow. This is amazing. This is amazing. We all think we should follow the Constitution and require a warrant if you're going to go search Americans data. So, I am hopeful. It's one one of the things that I think we can get bipartisan support on this committee and actually get it. We had it last Congress. Unfortunately, we didn't have quite the votes we needed. But th this issue just highlights it even more why that is necessary.
▶ 1:12:45So again, I want to thank you all for coming today and I would yield and I appreciate the gentleman from New York allowed me to go and the chairman for doing so and I'd yield back to the balance of my time to the chairman. Gentleman yields and I now recognize gentleman from New York, Mr. Goldman. Uh thank you very much, Mr. Chairman. Um I think you raised a very interesting point uh the Mr. Jordan, Chairman Jordan, um wanting to make sure that a warrant is obtained to search Americans data.
▶ 1:13:14So I recognize we're here focused on the Cloud Act and it's an important issue. I'm I don't dispute that. But in the times we're in, this seems quaint and intellectual. uh academic discussion.
▶ 1:13:30And in reality, what we're dealing with is an administration, current administration that is trying to uh uh cal categorize, gather and streamline data of Americans given with access by a private company. Now, let me explain a little bit and then I want to ask some questions.
▶ 1:13:58Uh many of you I'm sure have heard of Palunteer which is a uh a large data company uh has a lot of connections to uh Elon Musk to Doge. Uh and on on in March uh Donald Trump issued an executive order uh that would increase the sharing of all unclassified data between and among federal agencies.
▶ 1:14:21It directed agency heads to authorize and facilitate both the intra and inter agency sharing and consolidation of unclassified agency records. Now, a New York Times report uh in May outlined in great detail how the president has employed Palunteer to carry out this executive order uh essentially to merge all data from all different executive branch agencies into one single
▶ 1:14:53Now, it's unclear who would control that database, who would have access to it, what searches would be done. Uh, and there seemed to be no guard rails about Another New York Times article says that the administration that this database would have 314 different points of data about every American, literally every American,
▶ 1:15:23314 various categories of data will be consolidated into one database by a private company, Palunteer. Now, my colleagues on the other side of the aisle often express concern about government surveillance, about ensuring that we get search warrants in the context of 702, which is a a small universe of already obtained information that we know are communications
▶ 1:15:54with people of interest from uh of foreign nationalities. Here we just have every American's data put into a one database with no guidelines, no restrictions. We don't know what Palanteer is doing. We don't know what Doge is doing. We don't know what Elon Musk is doing.
▶ 1:16:16It essentially creates a one-stop shop for all Americans data, which as we're talking about cyber security, I'm sure you all agree that creates a tremendous cyber security risk if China or Russia were to hack this. Now, the chairman of this committee has said in the past, quote, "Congress has struggled the of this subcommittee, Mr. pigs.
▶ 1:16:41Congress has struggled for four years with a corrupt presidential administration, meaning the Biden administration that further expanded the opportunities for the government to spy on its So, is there I mean, there was nothing in the Biden administration that approximates this collection of data, this opportunity for the government to spy on its citizens.
▶ 1:17:07And I'm not even talking about breaking laws under the tax code and sharing tax information with immigration um enforcement agencies. Uh I'm not even talking about sharing uh you know tax the tax information or social security administration information. This is just every piece of data that is out there in the government's control consolidated with one uh one private company and one database.
▶ 1:17:36And so I would ask my friend Chairman Biggs to think about whether if you are truly worried about government surveillance, why are we not doing any oversight of Palunteer, its contracts with the government, its consolidation of all Americans personal information into one database and the cyber security risks.
▶ 1:18:02And I really hope in all seriousness that you will do oversight over that if you do truly care about government surveillance of citizens. And I yield Gentleman yields back. And um now I'm I yield myself five minutes. Mr. Chairman, could I um sorry to introduce two uh unanimous consent requests? Yeah. Thank you.
▶ 1:18:27Um, one is an April 9th, uh, 2025 New York Times article, uh, entitled, "Trump wants to merge government data. Here are 314 things it might know about you." You without objection. And the other one is a, uh, May 30th, uh, 2025 New York Times article, Trump taps palunteer to compile data on Americans. Without objection. Thank you. Thank you.
▶ 1:18:55Uh again, thanks to the the witnesses for being here and I'll yield myself now five minutes. Um so Mr. Salgado, in your in your written statement, you said one should take little solace in the provisions of the Cloud Act. First, they will still allow for incidental and in inadvertent collection of Americans data subject to certain minimization requirements. Can you expand on it for me, please? Sure. Uh we touched on that a little earlier uh in the hearing and specifically Mr.
▶ 1:19:25Nojime's reference to inadvertent and incidental collection where the UK can use the cloud act to obtain data from American companies uh and inadvertently or incidentally that data could include US persons data or data about people in the United States. There are some, as I mentioned in the written testimony, there are restrictions on the UK in its use and dissemination of that information and it has some minimization requirements, which is a phrase you may be familiar with from section 702 and FISA generally.
▶ 1:19:56So that's what I was referring to. That's what I thought you were you were referring to. And one of the things that I find interesting about that is uh having met with UK home office uh within the last 6 weeks I am concerned about their processes on on what they actually do and their transparency or lack of transparency um with these this incidentally collected data and that's part of the problem that we have with the 702 uh application as well.
▶ 1:20:25So uh Ms. Wilson Palo, you indicated um uh that you disagree that the UK's safeguards are as robust as they claim, but that is because the point is that is beside the point because your concern about TCN's is that once a back door has created states with far less stellar records on human rights such as Russia and China could seek similar access through legal process. You've talked about that a little bit. I'd like you to expand on that and then ask each of the members of the panel to also expand on that. Certainly.
▶ 1:20:55So once this back door is built, once end to end encryption is broken, any state using their legal process, no matter whether or not it is as white rights respecting as we would hope it would be, um can then ask Apple for access to this data because once it's broken, it's not just broken for the UK to access the data or for the US to access the data. Any country could request it and a lot of countries have surveillance regimes that would allow them to make these sort of requests. But it isn't just countries that would request, is it?
▶ 1:21:23It's also rogue actors that might be able to access those back doors as well. Right. That's exactly right. So rather than ask if each of you to expand on that, what I'm going to ask instead is do um my position would be that DOJ without immediate transparency and opening up of the process the TCN u that's going on with Apple uh that they immediately issue the 30-day termination notice. That's just my position.
▶ 1:21:50Is anybody there agree with me on the I think that would be a good tactic. Uh they could issue the notice. They say uh we're going to terminate in 30 days unless you withdraw this order to Apple. I think that makes a lot of sense. Yeah, it's leverage point. Yeah, professor. I I absolutely agree. Yeah. Anybody m Mr. Salgado? No, I I don't disagree with that at all. I think there's a lot of negotiating strategies here.
▶ 1:22:17This agreement is important to the UK and I think they would come to the table. Miss Wilson Bellow, I agree that this is an important moment to pressure the UK because if we don't push back now, then the UK may issue many more of these orders in the future entirely in secret and we won't know about them. Yeah, I think that's that's my point is that um it's hanging out there. We don't know enough about what's happening.
▶ 1:22:37We just there's this I think the legal term is of there's a penumbra of information out floating around out there that that we hear about but we need to nail it down and and really take action on it. So um the next the next step is and I'm going to ask each of you this and we have a minute left so you have about 15 seconds. What what two things do you think we need to do to uh improve the act? We'll start you Mr.
▶ 1:23:05Um, amended to make it so that no such order can be issued by another country that gets one of these agreements. Amended to make it so that a country can't get an agreement unless its laws prohibit such orders. Thank you, Mr. Salgado. Um, I would adopt uh Mr. Nojimes and add two more.
▶ 1:23:26One being that the providers be allowed to notify the US government when they receive orders under this act or technical capability notices and that Congress receive more frequent reporting from the Department of Justice on the operation of the acts that are in place. The oversight. Yes, Miss Wilson Pello. I would adopt Mr. Salgado and Mr. Nojime's recommendations. Thank you, professor. I would adopt all three recommendations. Um I would add that um as Mr.
▶ 1:23:55Salgado mentioned earlier cyber security and network security be part of the criteria in deciding whether or not to enter into an agreement. I don't disagree about privacy being fundamental and important but I think there's a really strong lever about cyber security and national sec network security that should be used. Thank you so much. Um we've exhausted our time which is a crying shame because there's so much more to to get at with this subject. I appreciate each of you and your testimony. It's important testimony. This is important.
▶ 1:24:26Here's the thing about Congress. If if there was a bunch of money on the table, this room would be filled uh and everybody be here. But but on this type of issue, which is actually critical to the country and national security, um you see what happens. It's it's a sad sad uh revelation about the United States Congress today. We appreciate all of you being here. Thank you so much. And we will undertake your recommendations and uh move forward with those very much. Thank you. We're We're