惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Schneier on Security
博客园_首页
量子位
博客园 - 司徒正美
S
SegmentFault 最新的问题
J
Java Code Geeks
小众软件
小众软件
博客园 - 【当耐特】
The Register - Security
The Register - Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Microsoft Azure Blog
Microsoft Azure Blog
G
Google Developers Blog
Blog — PlanetScale
Blog — PlanetScale
T
Tailwind CSS Blog
博客园 - Franky
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
G
GRAHAM CLULEY
Cyberwarzone
Cyberwarzone
腾讯CDC
Apple Machine Learning Research
Apple Machine Learning Research
V
Visual Studio Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Hacker News
The Hacker News
aimingoo的专栏
aimingoo的专栏
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
Scott Helme
Scott Helme
L
LINUX DO - 热门话题
F
Full Disclosure
D
DataBreaches.Net
Martin Fowler
Martin Fowler
Cisco Talos Blog
Cisco Talos Blog
L
LINUX DO - 最新话题
云风的 BLOG
云风的 BLOG
C
Check Point Blog
T
Threatpost
Google DeepMind News
Google DeepMind News
WordPress大学
WordPress大学
W
WeLiveSecurity
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
有赞技术团队
有赞技术团队
Hugging Face - Blog
Hugging Face - Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
L
Lohrmann on Cybersecurity
Last Week in AI
Last Week in AI
T
Tor Project blog
T
Troy Hunt's Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
Security Affairs
SecWiki News
SecWiki News

Lobsters

Lunacy | Red Vice CIFSwitch: a non-universal Linux local root vulnerability RIPE NCC session fixation: poaching logins with an Atlas probe GNOME 2.20 but its Web Components Agentic Search for Context Engineering – Leonie Monigatti Garnix is shutting down [not OC] akashina.tngl.sh/jjc Concerning Emacs (and Jazz) Nitpicking the shell history scene in ‘Tron: Legacy’ What's cooking on SourceHut? Q2 2026 The tenth OpenPGP email summit Package managers that package package managers Clojure on Fennel part three: parsing WordPress at 23 Finding Miscompiles for Fun, Not Profit GitHub - creusot-rs/creusot: Creusot helps you prove your Rust code is correct. Announcing Rust 1.96.0 | Rust Blog A Love Letter to Neovim sqlite AGENTS.md Am I a Bad Friend? CSS vs. JavaScript • Josh W. Comeau Erlang Ecosystem Foundation - Supporting the BEAM community A brief note about slot access cost in Common Lisp Keyboard latency probe Rethinking the GNOME clipboard issues Back to the Building Blocks’ Building Blocks Tech Notes: Theseus: translating win32 to wasm Fast is better than slow Content-addressed Rust builds (or, what kache actually caches) Intent to Prototype: Embedding API 5 PostgreSQL locking behaviors that trip people up okmij.org Stop advertising in your commits! | AksDev GitHub - mplsllc/macsurf: A modern web browser for Classic Mac OS 9 PowerPC. Real CSS3, ES5 JavaScript, native HTTPS — built with CodeWarrior on the Carbon API. Introducing DoomBench - Can Your Data Stack Run DOOM? What are some of your favourite developer tools? Building a Scalable Ingestion Pipeline with Temporal (Part 1) Converting shallow Git bundles into normal repositories Are you a member of any professional associations? What is a harmonic? An interactive comic about additive synthesis How Virtual Tables Work in the Itanium C++ ABI Using SwiftUI to Build a Mac-assed App in 2026 Rust (and Slint) on a jailbroken Kindle. ~jack/lambda-on-lambda - Serverless Haskell on AWS - sourcehut git Human proof for FOSS contributions Extremely simple internet radio controlled via IRC Announcing BABLR Splitting Konsole views from Helix to run tools | AksDev GitHub - yugr/rust-slides Serving files over HTTP three ways: synchronous, epoll, and io_uring update docs with information about building with build.py (#979) · astral-sh/python-build-standalone@c9c40c5 A Simple Makefile Tutorial On C extensions, portability, and alternative compilers Switching to Colemak | Pedro Alves Just How Bad Was The Intel IAPX432? Nix's Substituter List Is Not a Routing Table Accelerating copy_if using SIMD Lambda on Lambda: Serverless Haskell on AWS | Blog Announcing feed-repeat v1.0 Scaling Akvorado BMP RIB with sharding EYG news: A host of CLI improvements, new guides and new effects The social contract of writing JS Crossword C array types are weird; and related topics Flatpak will depend on systemd – OSnews Migrating from Go to Rust | corrode Rust Consulting A portentous reunion Vivado Licensing Options How my minimal, memory-safe Go rsync steers clear of vulnerabilities the entropy layer of a wavelet codec, on its own GitHub - nferhat/fht-compositor: A dynamic tiling Wayland compositor. Debian SE Linux and PinTheft Does bulk memmove speed up std::remove_if? (No.) 声明式部分更新 | Blog | Chrome for Developers Fully in-browser container builds Dianne Skoll's Web Site - Remind The Architecture of Open Source Applications (Volume 1)Berkeley DB Pardon MIE? - ironPeak Blog “Long-Term Support” doesn’t mean what you think Jira IS Turing-Complete May I recommend thinking of Emacs as your Fortress of Solitude hershey Floodgap Gopher-HTTP gateway gopher://thelambdalab.xyz/1cuneiforth/ HP QuickWeb, Singular And Pointless That one time I used Go panics for flow control A new suite of modern tools coming for editing and publishing RFCs From the Tabletop… The Digital Antiquarian Building a Host-Tuned GCC to Make GCC Compile Faster Are we self-sovereign PKI yet? Claw Patrol: an open-source security firewall for agents | Deno Revised^7 Report on Scheme, Large: Procedural Fascicle Draft is now public A Network Allow-List Won't Stop Exfiltration — André Graf From AFSK to Goertzel – µArt.cz Software For My New Home Server Introducing Neptune: Direct3D virtualization for QEMU AI Agent Bankrupted Their Operator While Trying to Scan DN42 - Lan Tian @ Blog mimalloc: A new, high-performance, scalable memory allocator for the modern era Making wl_shm fast The Soul of Maintaining a New Machine - Third Draft | Books in Progress What is Git made of?
Canada’s Bill C-22 and the security cost of collecting more data
Avery Pennarun · 2026-05-27 · via Lobsters

Tailscale was founded in Canada. We’re a Canadian company that serves users and customers all over the world.

That’s why we’re paying close attention to Bill C-22, Canada’s proposed Lawful Access Act, 2026. The bill is Canadian, but the issue is a global trend. Governments around the world are trying to update lawful access rules for the Internet era. Some of those efforts are reasonable. Some go too far, especially when they push companies to retain more data, build surveillance capabilities, or make secure systems easier to access by design.

Bill C-22 is part of that larger pattern. It would affect Canadian companies like Tailscale. It would affect any company serving people in Canada. More broadly, it affects the privacy and security expectations of everyone who relies on modern encrypted services.

Police and intelligence agencies need tools to investigate serious crimes. Sometimes that means asking service providers for records. When a request is specific, lawful, and authorized by a court, providers should respond with data they actually have.

Bill C-22 goes beyond that and the wording is worrying.

What Bill C-22 would change

The bill would create a lawful access framework for “electronic service providers.” That definition is broad. It covers services that create, store, process, transmit, receive, or make available digital information, including services provided to people in Canada or by companies doing business here. It might sound like that's just traditional phone companies or ISPs. But no: it's a large part of the modern Internet.

Under the bill, “core providers” could be required to develop, assess, test, and maintain technical capabilities for government access. They could also be required to install, use, operate, or maintain equipment that enables government access to information. The bill also allows regulations requiring retention of categories of metadata, including transmission data, for up to one year.

Governments worldwide have spent years pushing for lower data retention in the name of user privacy, starting with the GDPR. This kind of mandatory data retention is the exact opposite, giving tech companies a reason to maintain all kinds of personal information they shouldn't, in the name of compliance.

That should concern anyone who cares about security and privacy. At Tailscale, we’re concerned too.

What Tailscale’s VPN does and doesn’t collect

Tailscale’s VPN is not an anonymity service. We’re an identity-aware network for secure connectivity. We know the information needed to run our service: accounts, devices, the IP addresses those devices connect from, operating systems, connection state, and some basic connection information. That’s how NAT traversal, reliability, abuse prevention, and support work.

But there are important things the product doesn't do.

Tailscale's VPN doesn't inspect customer traffic. Nor does it log browsing activity, or public DNS queries, or the contents of communications. Traffic inside a tailnet is encrypted end-to-end with WireGuard, and customer private keys never leave customer devices. Even our relay servers don’t have the keys needed to decrypt what they carry.

That isn’t a policy preference we can casually reverse. It’s how the product is built. Tailscale’s VPN is open source, so people don’t have to take our word for it: the code that handles encrypted connections is available to inspect. Taking extreme technical care about privacy is what makes Tailscale, a Canadian product, so loved by users worldwide.

Bill C-22 risks turning data minimization from a security virtue into a compliance problem.

There’s a big difference between preserving data for a specific investigation and requiring providers to collect or retain data in bulk because it might be useful later. The first can be targeted and accountable. The second changes the design incentives for every service in scope.

Once a law requires a company to retain more metadata, the company now has a new database. That database needs access controls, audit logs, backups, operators, retention systems, legal processes, and incident response plans. It becomes part of the attack surface. It becomes a temptation for theft or misuse.

The safest database is the one you never created.

This isn’t an abstract concern. Security systems are strongest when they collect less, expose less, and make sensitive access paths unnecessary. Laws that require the opposite create long-term risk. They may be intended for lawful use, but the systems they require add to the attack surface like any other system. They too must be protected from improper permissions, bugs, and attackers.

Tailscale complies with lawful, specific requests for data we have. That’s not controversial. But we oppose laws that would pressure secure services to collect more data, retain more metadata, weaken encryption, or build access systems that create new targets.

How Bill C-22 should change

Canada should be a great place to build secure infrastructure that protects consumers. Bill C-22, as written, moves in the wrong direction.

The good news is that this is fixable. Parliament can preserve targeted lawful access for serious investigations without forcing secure services to collect more data, weaken their architecture, or create new places for attackers to aim.

At minimum, Bill C-22 should be amended to:

  • Remove any requirement to build access tools for hypothetical future lawful access requests. Lawful access should be tied to specific investigations, specific accounts, and specific legal authorization. The law should not require building surveillance tools to enable law enforcement access without a specific case need.
  • Remove or sharply limit broad metadata retention. Providers should not be required to collect or retain data they otherwise would not need. Preservation orders should be targeted, not speculative.
  • Narrow the scope. Secure software services should not be casually swept into rules designed for telecom infrastructure. The bill should be absolutely explicit about who is covered and why.
  • Protect encryption and secure architecture explicitly. Technical capability requirements should not impair security.The law should prohibit compelled weakening of encryption, key escrow, client-side spyware, or product changes that undermine security guarantees.
  • Allow transparency reporting. Providers should be able to disclose aggregate information about government requests, orders, and compliance obligations.
  • Protect vulnerability disclosure. No law should prevent a provider from disclosing, reporting, or fixing security vulnerabilities.
  • Add independent oversight and sunset clauses. Extraordinary powers should be reviewed by independent bodies and expire unless Parliament renews them after evidence-based review.

If you live in Canada and care about privacy, contact your Member of Parliament.

If you don’t live in Canada: the same debate is happening in many countries, with different bill numbers and slightly different wording. Our principle is the same: secure services should not be redesigned to make government surveillance easier.

Canada doesn’t need to choose between public safety and secure infrastructure. Companies can comply with lawful, specific requests without making everyone’s systems easier to attack. Canada can be the country that security and AI companies choose to build in, but only if our laws protect both security and rights.

Build guardrails for lawful investigations. Don’t build backdoors into infrastructure everyone depends on.