Matthew Green argues — perhaps somewhat counter-intuitively — that as AI becomes better at finding vulnerabilities in software, the digital systems and services we use will become much more secure. So secure in fact, that they will become next to impossible to hack. As a result, law enforcement (and intelligence services) loose ‘lawful hacking’ as the only currently available method to get access to encrypted data stored on phones, or to listen in on encrypted communications. According to Green, everything is about to “go dark”. Is it? And does it matter?

Experts like Daniel Miessler or Bruce Schneier tend to agree that AI will benefit defenders more than attackers, in the long run. For smartphones in particular, the security appears to already have improved dramatically over the years. Rumour has it that law enforcement is so far unable to get access to smartphones running GrapheneOS (a hardened version of Android), or to the most recent Apple iPhones. They expect this to become the status quo in the near future.

For older Google Android and Apple iOS smartphones, law enforcement use commercial tools to hack into these devices. These (expensive) tools, sold by companies like Cellebrite, use zero-day vulnerabilities found in the software used on these devices. As the software improves, vulnerabilities become harder to find, and thus more expensive. And the expected end result is that soon it will become practically impossible to find vulnerabilities that can realistically be exploited to get access to any modern smartphone.

Personally, I never was a big fan of such ‘lawful hacking’. First and foremost because it offered a way to weasel ourselves out of the fundamental discussion whether law enforcement should have access to our data and communications, and if so, under which conditions. ‘We’, privacy advocates, could firmly pretend to protect the fundamental right to the privacy of our data and communications, while law enforcement was still able to get access, albeit not at a massive scale, and only by exploiting vulnerabilities that shouldn’t have been there to begin with. But also, as Steven Levy put it: “lawful hacking is techno-capitalism at its shadiest”. It creates perverse incentives to hoard vulnerabilities. To keep critical infrastructure vulnerable because patching them would reveal the existence of the vulnerability and hence destroy the capability to use it later against a target of choice. Or for insiders to secretly bury a trapdoor to later sell information on how to exploit them to the highest bidder. Also, it restricts the use of such vulnerabilities to only those law enforcement agencies that can afford to pay high costs for their exploit tools. And makes them critically dependent on their suppliers.

But does all this mean that everything is about to “go dark”, though?

In terms of law enforcement no longer being able to get access to encrypted data and encrypted communications: yes, absolutely. But looking at law enforcement capabilities more broadly, I beg to differ. The amount of data available to law enforcement is staggering. Even if they can no longer listen in to our communications or read our messages, the metadata (who we are talking to, when, how often, and how much) is still available to them. Law enforcement can track our locations, either through data brokers that in turn get their data form the location based services we use on our phones, or by asking the mobile network operators for the current location of our phones. Camera surveillance is increasing, especially as more and more people attach video doorbells like Amazon’s Ring next to their front door, or by people wearing Meta’s AI glasses. Perhaps the only caveat is this: metadata is mostly circumstantial evidence, that does not necessarily prove without any doubt that someone was indeed involved in perpetrating a crime. Access to data (e.g. pictures or video footage) or messages may be needed to seal a case.

Which means we should be having this fundamental discussion whether law enforcement should have access to our data and communications, and if so, under which conditions. I don’t think this is a problem. As Green himself already pointed out a decade ago:

It is highly unlikely that either extreme – total surveillance or total privacy – is good for our society.

But this is by no means an easy matter. I myself am a member of the European Commission Expert Group for a Technology Roadmap on Encryption discussing exactly that. The most fundamental problem: to strictly prevent any means of lawful access to become a tool for mass surveillance, and to prevent abuse (by non-democratic regimes) to harass individuals (minorities, vulnerable groups, political opponents, dissidents, or journalists, to name but a few).

In case you spot any errors on this page, please notify me!
Or, leave a comment.