At the initiative of the federal government, the German Bundestag has incorporated new surveillance regulations—barely recognizable from the outside—into another law. Using a tactic akin to that of the Trojan Horse, it has effectively slipped a new version of the federal Trojan into this law. Under this law, public prosecutors and the police will in the future be able, among other things, to exploit security vulnerabilities in the software of electronic devices in order, for example, to intercept communications via smartphones or tablets at the source and to access the contents of these devices.
This amendment to the law appears to have been ill-considered, as it was evidently drafted not only in secret but also without the input of data protection and IT security experts. The main danger it poses to the information society is that identified security vulnerabilities may no longer be disclosed and fixed, but instead exploited in secret for surveillance purposes—and, worse still, could fall into the hands of authoritarian states or even criminals. Thwarting terrorists in particular is certainly a priority, but this must be achieved through socially acceptable methods, which, in the view of data protection and IT security experts, undoubtedly exist (see, for example, www.stiftung-nv.de or www.forum-privatheit.de).
As early as 2008, the Federal Constitutional Court imposed very strict limits on the use of federal Trojans (see here). It is therefore foreseeable that this legislative initiative will also end up in Karlsruhe and will likely be struck down again by the judges there. This makes the attempt to hide this Trojan as a Trojan within another law all the more surprising.
Source: www.udis.de