🟡 Medium | Source: Schneier on Security
A new academic paper revisits the long-running ‘Going Dark’ debate, tracing encryption policy from the 1990s Crypto Wars through to today’s controversies around end-to-end encryption (E2EE). It examines government efforts globally to mandate lawful access backdoors into E2EE systems and the technical and policy implications of doing so. This matters because proposed legislation in multiple jurisdictions could directly affect how cloud platforms and messaging services handle encrypted data.
Security Architect’s Take: Cloud security architects should monitor legislative developments in key jurisdictions — particularly the UK Online Safety Act and EU Chat Control proposals — and assess how any mandated lawful access requirements could affect their organisation’s E2EE implementations, data residency posture, and third-party messaging dependencies.
Original advisory: End-to-End Encryption and “Going Dark”