Build1 distinct publisher3 min readUpdated
Matthew Green's argument is that backdoors lost and lawful access still won, by moving to device exploitation. That relocates the defender's problem from protocol design to fleet integrity.
The Engineer · Build desk
Compiled by The EngineerSomething wrong?How this is made
Cryptography engineer Matthew Green's essay "Going Dark, and the era of law enforcement hacking" reached the Hacker News front page with 179 points and 109 comments [1]. The argument, as relayed in a dev.to summary of it, is that encryption won the wiretap debate and that the win simply moved the fight to the endpoint, which is the one layer most organisations manage worst [2][3].
For decades agencies framed end-to-end encryption as a "going dark" problem and asked for exceptional access: warranted decryption built into the product, pushed by the FBI, DOJ and intelligence agencies elsewhere [4]. The cryptography community's answer was close to unanimous, and it has not changed: a weakness reserved for the good guys is not a buildable artefact, because criminals and foreign services eventually use the same door [5]. Green's claim, per the summary, is that law enforcement quietly stopped fighting that battle because it found a substitute [6].
The substitute is mechanical rather than clever. Traffic is encrypted in transit and decrypted on the handset, so the handset is the weak link [7]. The summary lists four properties that make this attractive to an agency: it works against any encryption without standards fights or vendor negotiation [8]; it is targeted per device rather than population-wide [9]; it is warrant-based and, in that view, increasingly treated as constitutional [10]; and it is effective, with modern spyware able to compromise fully patched devices [11].
There is a supply chain behind that. NSO Group in Israel makes Pegasus, which can remotely compromise iOS and Android [12]; Cytrox in North Macedonia makes Predator, used by governments worldwide [13]; Intellexa in Greece is described as an alliance of surveillance companies [14]; FinFisher in Germany was among the earliest [15]. That is four vendors across four national jurisdictions, which is why export control is a slow instrument here [16]. The Pegasus Project investigation found NSO clients using Pegasus against journalists, activists and political opponents in dozens of countries [17].
The asymmetry that matters to operators is legal, not technical. US wiretapping requires a Title III warrant with strict minimisation procedures [18], while device hacking often proceeds under Rule 41 of the Federal Rules of Criminal Procedure, which carries fewer safeguards [19]. There is no statutory framework specific to government hacking [20], no requirement to disclose vulnerabilities discovered in the course of it, and no clear rule on what happens to data taken off a compromised device [21]. No amount of protocol review fixes that.
The market prices the shift plainly enough. Zero-day brokers pay $2 to $3 million for iOS zero-click exploits [22], alongside government acquisition programmes such as the US vulnerability equities process [23] and AI-assisted vulnerability discovery [24]. The defensive column is entirely endpoint work: iOS Lockdown Mode, Android's enhanced sandboxing, Secure Enclave and Titan M, memory-safe languages in kernel code, and mitigations including PAC, BTI and MTE [25]. Not one of those is a wire-level control [26].
One tension in the source is worth naming, because it decides budgets. The same post says spyware compromises fully patched devices [11] and that most spyware exploits known vulnerabilities, making patching the first line of defence [27]. Both can hold across a tiered market, but they imply different spending: patch latency and Lockdown Mode for the broad case, and a different order of paranoia for staff who are individually worth a seven-figure exploit.
Worth watching: whether any statutory framework for government hacking appears, whether zero-click prices move as mitigations land, and whether exploit provenance starts surfacing in discovery.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
The essay argues we are entering a new surveillance era in which encryption has won the debate over wiretaps.
Law enforcement's response to encryption, per the essay, is to hack devices instead of intercepting communications.
Green's essay argues law enforcement has quietly given up on the backdoor fight and found a better alternative.
Endpoint hacking works with any encryption, requiring no weakening of standards and no fight with technology companies.
Endpoint hacking is targeted: specific devices are compromised rather than encryption being broken for everyone.
In law enforcement's view the approach is legal, with warrant-based device hacking increasingly seen as constitutional.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single secondary retelling, no primary artefacts
Everything in the cluster comes from one dev.to post that paraphrases Matthew Green's essay without linking or quoting it. No statute text, court record, vendor disclosure, forensic report, CVE or broker price list is cited for any empirical claim, and the post contradicts itself on whether patched devices can be compromised. The mechanism claim (plaintext on the endpoint) is self-evident and the defender inventory is verifiable common knowledge, which keeps the score above floor.
No adoption or deployment measurement available
The supplied source contains no release, deployment, procurement, incident-count, install-base or usage-disclosure datum that could be measured. The spyware industry is called 'booming' and Predator is called 'used by governments worldwide' with no counts, contracts or dates; likewise no figures on Lockdown Mode enablement or patch compliance. The only quantities present are Hacker News engagement numbers, which measure discussion of the essay rather than adoption of anything.
Sweeping conclusions outrun the cited support
The framing is decisive - the crypto wars are over, 'going dark' was always a misdirection, agencies have quietly abandoned backdoors, spyware defeats fully patched devices - while the underlying support is one unlinked paraphrase with zero primary artefacts and a self-contradiction on patch efficacy. The direction of the argument is plausible and the endpoint mechanism is sound, so the gap is moderate overstatement rather than fabrication; the practical defence advice is notably more measured than the headline framing.
Engagement-driven aggregation, no disclosed commercial stake
The sole item is a personal dev.to post that repackages a front-page Hacker News discussion, an incentive structure that rewards decisive framing and traffic over verification, and which explains the unlinked paraphrase and the definitive closing line. Offsetting this, the author has no visible vendor, agency or product interest, names no sponsor, and sells nothing; the advice given (patch, Lockdown Mode, hardware keys) is generic rather than steering to a paid offering.
Low: one publisher, one item, unverifiable relay
Confidence is limited by structure rather than by disagreement: a single publisher, a single item, no corroboration, no primary link, and an internal contradiction on a central capability claim. Confidence is not lower because the durable part of the argument - plaintext lives on the endpoint, and the named defences are all endpoint-resident - is checkable on its face and is unlikely to be reversed by better sourcing.
invest
Apple moved its spyware warnings to the Lock Screen. Your incident alerts are still in email.1 distinct publisher
security
The EncroChat "national security secret" was exploit code sitting on GitHub1 distinct publisher
security
A North Korean IT worker got hired by a federal agency. Vetting is a security control now.1 distinct publisher
invest
Washington licenses private hacking, and hands the contractor the liability1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 14, 2026