Product1 distinct publisher3 min readPublished
Matthew Green argues AI patching will strand law enforcement without exploits to buy. Most practitioners TechCrunch asked think otherwise, and either way the thing a mandate reaches is your default configuration.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
The reason encryption stopped being an argument for most people is that nobody had to opt in. Signal, WhatsApp and Apple's iMessage pushed end-to-end encryption out to everyone at once, and Apple began encrypting device data by default, so a strong PIN was enough to keep an iPhone shut [4]. Users do not weigh a security setting the way a product team imagines; they inherit whatever ships as the default. A mandate is aimed at that inheritance, which is why the part of your product it touches is the configuration you ship to people who never open the privacy screen.
Green's case runs through supply rather than policy. He wrote that he is worried AI will make software much too secure, leaving the US government without flaws to use against targets it needs to surveil as vendors patch at volume [2]. Bugs are the currency of what he calls an uneasy truce, in which governments spent money on hacking tools and spyware instead of requiring backdoors [5], and his conclusion is that scarcity brings the backdoor request back [6]. The premise underneath is that LLMs are getting better and faster at finding vulnerabilities at scale, which proponents promise and some early data suggests [15].
That premise is the weak plank. The canvass TechCrunch ran produced one quantity: Hamid Kashfi of DarkCell, who also works at the AI security startup Xbow, estimates that for every AI-found bug reported there are probably 20 that are not [11]. Read literally, reported findings are roughly 5% of what AI turns up, one in twenty-one [13], which points away from Green rather than toward him, because a hidden discovery boom does not produce patched software. Count the practitioners quoted and four disagreed with Green against two who agreed [12]. Crowdfense's Paolo Stagno sits between them, calling the requirement that governments burn an exploit the most democratic system available while saying plainly that no state will throw away surveillance [9].
So the thing being pitched is AI-hardened software, and the thing being decided is where recoverable copies of user content live and who can be served an order for them. Two questions sort that. Can you produce a named user's content today without their device or passphrase? Would gaining that ability require new client code shipped through app store review?
If you already hold enough to be served, the answer to both is yes: you are the cheapest fallback already, and your request volume grows without any new law, though you also pay twice, since you can be asked but cannot comply quickly. If you hold nothing today, the answer to both is no, and that is where a mandate would actually change something, because escrow could be added server-side without users ever seeing it, which is exactly the capability a statute would name. The one version of this that gets argued in public rather than settled in a legal inbox is the case where compliance shows up in a release note.
The useful exercise is not forecasting bug supply, which the people who trade in bugs do not agree on [14]. It is writing the paragraph that answers what you would ship within 90 days if your largest market mandated access, and naming who signs it. A team that can write that paragraph is still choosing its own architecture. A team that cannot will implement whatever design the drafters had in mind.
Ranked by verification strength, evidence, and original report placement.
Green's conclusion is that governments could ask for backdoors again, making everyone's devices less secure by design.
TechCrunch asked several people to respond to Green's argument, from privacy and cybersecurity experts to hackers with experience developing hacking tools for governments; some agreed, some disagreed, and some saw it both ways.
Earlier in August, cryptography professor Matthew Green wrote a thread on X and a longer blog post that went viral within the cybersecurity community.
Green wrote "I'm concerned that AI is going to make software much too secure," warning that the U.S. government may lose access to security flaws it uses to hack targets it needs to surveil as companies patch an unprecedented volume of bugs.
The concept of "going dark" was popularized in 2014, when then-FBI director James Comey warned that encryption could hamper authorities from listening in on conversations or accessing data on devices.
Around 2014, apps including Signal, WhatsApp and Apple's iMessage rolled out end-to-end encryption to the masses, and Apple began making data on its devices encrypted by default, making it harder to break into iPhones protected by a strong PIN code or passphrase.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
US courts turn government hacking into a line item, starting with 2028 wiretap data1 distinct publisher
security
GTA VI leak: extortion leverage moves from the regulator to the fanbase1 distinct publisher
product
Google shipped AirDrop onto Pixel and Galaxy handsets without Apple's participation1 distinct publisher
build
The Crypto Wars Ended, And The Prize Went To Whoever Owns Your Endpoint1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named experts, no numbers
The people are real and mostly on the record — Crowdfense's CTO, DarkCell's founder, EFF's Eva Galperin, Luta Security's Katie Moussouris — and TechCrunch deliberately sought out voices that reject its premise. What none of them supply is a measurement. The claim the whole chain hangs from is stated as "proponents promise and some early data suggests," with no benchmark, patch-rate or bug count attached, and the one quantitative figure in the piece is a practitioner's "probably 20." Expert judgment is the evidence here, and it splits four to two.
Nothing shipped, nothing mandated
There is no deployment to score. No vendor released a tool, no agency disclosed a change in access, no legislature filed a backdoor bill. The nearest thing to a usage figure is Kashfi's twenty-to-one guess about unreported AI-found bugs, and a guess is not a measurement. Scoring adoption here would mean inventing it.
A viral thesis outrunning its data
Green's argument travelled through the security community before anyone had a number to check it against, and the vivid framing — software becoming too secure — is doing more work than the evidence underneath it. TechCrunch pulls the opposite way, hedging its own headline to "could" and giving the dissenters more column inches than the thesis, which keeps the overstatement modest rather than severe. The residual gap is the distance between a well-circulated hypothesis and the zero measurements offered in support of it.
Almost everyone quoted sells the answer
Work through the roster: Crowdfense makes its money selling zero-days to governments and its CTO defends the exploit market as the democratic option; Kashfi founded an offensive-security firm and draws a paycheck from an AI security startup, so both halves of the argument pay him; Tong came out of two exploit-development shops; Galperin argues from a digital-rights mandate; Moussouris runs a vulnerability-management business. TechCrunch names most of these interests plainly, which is why this reads as a disclosed conflict rather than a hidden one — but two of the researchers are anonymous with unnamed employers, and their stake is unauditable.
One canvass, one outlet, long horizon
We are confident about what was said and by whom; much less about whether it will happen. Everything traces to a single TechCrunch canvass, no one outside it has tested the claims, and the timeline the sources themselves offer stretches past the next presidential election — far enough out that the forecast cannot be checked for years. The reporting's internal disagreement is a strength for honesty and a limit on certainty.