Earlier quoted context omitted.
The article also mentions this company's new product where additional security is possible because decryption requires data kept only by the customer. Perhaps that is the new way to go?
I was wondering about that, it is described as: "where rather than hold the data, it is split in two so CertiVox has one half and the user has the other, and law enforcement would need both to access the data." By data here, do they mean encryption key? If so then I'm not sure what splitting it in two does as you presumably have to join them together somewhere and GCHQ would presumably just attack wherever the comple…
Alice sends Bob stuff, via the company.
GCHQ sends RIPA requests to the company, which means that GCHQ get Alice's communications. Neither Alice nor Bob are aware.
So, a new scheme where Alice and the company need keys to decrypt means that GCHQ send RIPA requests to the company, and to Alice. Now Alice, and the company, are aware of the RIPA request. Bob isn't. But at least Alice can stop sending things to Bob.