Encryption Won the Backdoor War. Governments Just Started Hacking Instead.
The encryption backdoor debate is over, and the cryptographers won. Signal still works. WhatsApp servers still can’t read your messages. Apple never built the FBI its magic key. So why does the privacy picture look worse than it did in 2016?
Because governments stopped asking for the front door. Johns Hopkins cryptographer Matthew Green has been making this point for years, and it keeps getting more relevant: when you refuse to hand over the keys, the people who wanted them go buy a crowbar instead.
Where “Going Dark” Came From
Going Dark was the FBI’s framing, pushed hard starting in the early 2010s. The argument: communications volume is exploding, but lawful intercept capability is collapsing. Get a warrant, serve it, and receive… encrypted noise.
The trigger was default device encryption. Apple shipped iOS 8 in 2014 with a design where Apple itself couldn’t extract data from a locked phone. Google followed. WhatsApp flipped end-to-end encryption on for its entire user base in 2016. The Signal Protocol became the de facto industry standard around the same time.
From law enforcement’s chair, a wall had appeared overnight. The ask that followed was exceptional access: build a special key that opens only for a valid warrant.
Why Cryptographers Said No
The technical answer from Green and his colleagues has been consistent for a decade: that key cannot exist.
The reason is boring and absolute. Math does not check ID. There is no cryptographic construction for a door that opens for good guys and stays shut for everyone else. If a key exists, it can be stolen, copied, leaked, subpoenaed, or extracted under duress. The property you want — “only for the righteous” — is a legal category, not a mathematical one.
In 2015, Green and fourteen other prominent security researchers published “Keys Under Doormats,” which laid this out formally. The title is the argument: hiding a spare key under the mat works right up until someone else checks under the mat.
The empirical record backs it up. The Athens Affair is the canonical case — from 2004 to 2005, lawful-intercept functionality built into a Greek carrier’s switching equipment was compromised, and roughly 100 people were wiretapped, including the prime minister. The surveillance channel built for the state got used by someone else entirely, and to this day the attribution remains contested.
Twenty years later, same story, bigger scale. Salt Typhoon, disclosed in 2024, involved a Chinese-linked group penetrating US telecom infrastructure — including, per reporting, the systems used for lawful intercept. The wiretap system got wiretapped.
The policy takeaway landed hard: build a backdoor, and a foreign intelligence service will eventually walk through it. That argument won.
So Governments Found Another Route
San Bernardino, 2016. The FBI went to court to compel Apple to build a tool that would unlock a specific iPhone. Apple refused. Everyone braced for a landmark ruling on whether the government can conscript engineers into writing code.
The ruling never came. The FBI withdrew — because it had bought a working exploit from a third party.
That single moment previewed the next decade. Why fight a constitutional battle to force the door open when you can pay a vendor to find a crack in the wall?
What followed is a functioning industry. NSO Group’s Pegasus achieved zero-click iPhone compromise — no tap, no link, no user action. The 2021 Pegasus Project, a consortium investigation, surfaced a leaked list of roughly 50,000 phone numbers flagged as potential targets. Journalists. Human rights lawyers. Opposition politicians. Heads of state.
Then came the rest of the market: Candiru in Israel, Hacking Team in Italy, Intellexa and its Predator toolkit more recently. The US Commerce Department added NSO Group and Candiru to the Entity List in 2021. The Biden administration signed an executive order in 2023 restricting federal use of commercial spyware. Apple sued NSO Group in 2021 and shipped Lockdown Mode for high-risk users.
You don’t get export controls, lawsuits, and executive orders aimed at a market that doesn’t exist. That’s Green’s point. The space where the backdoor debate used to be is now occupied by a government hacking industry with real revenue and real customers.
Is Hacking Better or Worse Than a Backdoor?
Here’s where it gets genuinely contested, and the counterargument deserves a fair hearing.
A backdoor weakens every user simultaneously. Targeted device exploitation weakens one device at a time. Legal scholars and policy researchers have argued in print that government hacking is the less invasive option precisely because it doesn’t degrade the security of the whole system. On a narrow reading, that’s correct.
The Green-aligned rebuttal runs on three tracks.
Vulnerabilities are not consumable. For an agency to use a zero-day, that bug must stay unpatched. That puts law enforcement’s operational interest in direct conflict with every other user of the same software. The exploit only works because you are still vulnerable. The government’s capability is literally built out of your exposure.
Oversight is dramatically weaker. The backdoor fight was, whatever else you think of it, public. Congress held hearings. Courts issued opinions. Reporters covered it. Exploit procurement hides inside contracts and classified budget lines. What was purchased, against how many targets it was deployed, whether anyone reviewed it — largely unverifiable from outside.
Proliferation is structural. The vulnerability market has no borders. The same vendors selling to democracies sell to authoritarian governments, and the Pegasus record shows this repeatedly. “A capability only our government will have” is not a thing that survives contact with a commercial supply chain.
Reasonable people split here between “targeted access is legitimate in principle” and “it will be abused in practice, every time.” The practical record leans hard toward the second. Most of the documented deployments over the past decade were not narrow criminal investigations. They were journalists, dissidents, and activists.
The 2026 Front Lines
The fight isn’t over. It changed shape.
In the EU, the child sexual abuse material regulation — Chat Control, colloquially — has been stalled for years, and the core dispute is client-side scanning: inspect content on the device, before encryption applies. Technically elegant, since the crypto stays intact. Green and other researchers argue it’s a backdoor with extra steps. The unanswered questions are governance ones: who controls the hash list, and what stops it from growing beyond CSAM once the scanning infrastructure ships on two billion phones?
The UK wrote comparable powers into the Online Safety Act. Signal and WhatsApp have both said publicly they would exit the UK market rather than comply. In early 2025, reporting revealed the UK had demanded access to encrypted iCloud backups; Apple’s response was to withdraw Advanced Data Protection from UK users entirely rather than build the capability.
And now AI is in the mix. Automated vulnerability discovery cuts the cost of finding exploitable bugs — which expands supply. Defenders get the same tools, so the net effect is genuinely unclear. What is clear: capabilities that once required nation-state budgets are drifting toward a much lower price floor. That changes who gets to play.
What to Actually Watch
The encryption held. Signal is still safe. WhatsApp messages still aren’t readable server-side. The math did its job.
The endpoint is the problem. Perfect transport encryption is irrelevant if the device rendering the plaintext is compromised. That’s not a cryptography failure. It’s a systems failure, and it’s much harder to fix with a protocol.
Which means the question worth arguing about in 2026 is not “should we protect encryption.” That’s settled. It’s “how do we govern government hacking.” Who authorizes a deployment, and under what standard? Is the target count ever disclosed after the fact? When does an agency have to tell a vendor about a bug it’s sitting on? The US has a Vulnerabilities Equities Process on paper, and its actual bite has been disputed since the day it was published.
One more thing worth noting. This debate has been conducted almost entirely on US and EU terms, with US and EU institutions as the assumed check. Most countries have neither the export-control leverage nor the adversarial press corps that made Pegasus a scandal instead of a routine procurement. If the oversight model only works where the vendors are headquartered, it isn’t an oversight model.
We won the technical fight and lost the ground it was fought over. So which failure mode is actually worse — a backdoor that makes everyone slightly weaker, or targeted hacking that breaks a few people completely while nobody can see who chose them?
Deepen your perspective
Comments
Loading comments...