惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
T
Tailwind CSS Blog
博客园 - 三生石上(FineUI控件)
量子位
月光博客
月光博客
人人都是产品经理
人人都是产品经理
U
Unit 42
S
SegmentFault 最新的问题
M
MIT News - Artificial intelligence
H
Help Net Security
aimingoo的专栏
aimingoo的专栏
Microsoft Security Blog
Microsoft Security Blog
MyScale Blog
MyScale Blog
美团技术团队
P
Proofpoint News Feed
Apple Machine Learning Research
Apple Machine Learning Research
D
Docker
B
Blog
大猫的无限游戏
大猫的无限游戏
V
Visual Studio Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
G
Google Developers Blog

Robin Wilton – Internet Society

NDSS Symposium 2027 Heads to Seoul: Expanding Global Collaboration in Cybersecurity Research - Internet Society The NDSS Symposium 2026 Had a New Vibe—But Why? - Internet Society No Research, No Internet - Internet Society Take a Step Towards Privacy: Understanding Digital Footprints - Internet Society NDSS Symposium Showcases the Importance of Securing Your Connected Life - Internet Society How Do Surveillance Laws Impact the Economy? - Internet Society What Is a Man in the Middle (MITM) Attack? - Internet Society IoT Privacy for Policymakers: Solutions Need Informed Discussion - Internet Society Transparency, Fairness, and Respect: The Policy Brief on Responsible Data Handling - Internet Society Internet of Things Devices as a DDoS Vector - Internet Society CEOs and Encryption: The Questions You Need to Ask Your Experts - Internet Society Limited Time Only: Read our Springer/Nature Paper on Healthcare, Security, and Privacy - Internet Society Letter from Ethiopia: Can We Use Technology to Help Privacy Evolve? - Internet Society ROCA: Encryption vulnerability and what to do about it - Internet Society New Paper on Online Privacy in the Wake of Pervasive Surveillance Revelations - Internet Society Trust & Ethical Data Handling in the Healthcare Context | Internet Society Digital Identity: Evolving, or just cloning itself? - Internet Society Is Your Reputation Safe on the Blockchain? - Internet Society WhatsApp with the UK's new Information Commissioner? - Internet Society Is the UK Investigatory Powers Bill Fatally Flawed? Hey! Someone fragmented my Internet, and didn't even tell me.
Solving Crime Without Breaking Encryption - Internet Society
Adrian Wan, Robin Wilton · 2026-06-26 · via Robin Wilton – Internet Society

Solving Crime Without Breaking Encryption Thumbnail

Policymakers often face a dangerous dilemma: preserve privacy and security for everyone, or break encryption so law enforcement can catch criminals. This is a false choice.

Encryption is a fundamental technology that protects the confidentiality and integrity of data, communications, devices, and services. It is essential to a secure, trustworthy Internet.

Law enforcement agencies do not need to jeopardize the digital safety of billions of users to investigate crimes effectively.

We are living in the golden age of digital evidence. Agencies have access to more data today—location history, metadata, and transaction logs—than ever before. And breaking encryption—through backdoors, client-side scanning, or mandated access—introduces systemic vulnerabilities that criminals and hostile states will exploit, making the Internet less safe for everyone.

Infographic titled “Data access policy proposals and their impact on the open, globally connected, trustworthy, and secure Internet.” The graphic is divided into two sections. The upper green section, marked with a thumbs-up icon, is labeled “Does not interfere with the technical foundations of the Internet” and states that these approaches enable effective investigations without weakening encryption. It lists five recommended investigative methods: (1) User reporting, (2) Undercover investigation techniques, (3) Voluntary cooperation, (4) Analysis of metadata, and (5) Forensics on seized devices. Each item includes a brief description and a thumbs-up symbol. An upward arrow on the left indicates stronger protection of the Internet’s technical foundations. The lower red section, marked with a thumbs-down icon, is labeled “Interferes with the technical foundations of the Internet” and states that these approaches create systemic risks that can be exploited. It lists three measures: (6) Remote forensic software, (7) Client-side scanning, and (8) Mandated backdoors. Each item includes a brief description and a thumbs-down symbol. A downward red arrow on the left indicates increasing harm to the Internet’s technical foundations. The overall message is that some investigative techniques can support law enforcement while preserving encryption and Internet security, whereas others weaken encryption or create systemic vulnerabilities that undermine the Internet’s security and trustworthiness.

The Solution: Effective Tools (Support These)

Law enforcement agencies already have access to a broad and diverse investigative toolkit that does not require weakening encryption or undermining the technical foundations of the Internet.

Instead of demanding “magic keys” into encrypted data, governments and law enforcement should focus on these investigative methods:

  • User reporting: Law enforcement can often get important evidence directly from witnesses, victims, or cooperating individuals involved in criminal activity. Easy-to-use mechanisms for user-reported crime and for recovering digital evidence from devices can facilitate this process.
  • Undercover operations for covert and serious crimes, such as those against children: Traditional policing adapted for the digital age—such as infiltrating groups and using decoy accounts—remains the gold standard for catching predators.
  • Voluntary cooperation: Fast, reliable channels for platforms to share non-content data (login history, account activity) solve more crimes than mandated technical weaknesses.
  • Metadata analysis: Encryption protects content, not behavior. Investigators can build timelines, map criminal networks, and identify suspects using non-content data—who, when, where—without decrypting messages. (This measure does not imply a call for blanket collection and retention of any such information about every user.)
  • Digital forensics on seized devices: Accessing data physically stored on a suspect’s seized device is a targeted alternative to mass surveillance. It accesses evidence at the endpoint, leaving the secure “pipe” intact for the rest of the world.

The Red Zone: Dangerous Proposals (Reject These)

Some investigative techniques pose far greater risks to cybersecurity, human rights, and public trust than others. The risks that these intrusive measures pose vastly outweigh their speculative investigative benefits.

Governments and law enforcement should avoid relying on these methods of obtaining encrypted data:

  • Mandated backdoors: Backdoors intentionally insert weaknesses into software so that authorized parties, such as law enforcement, can access information. In reality, there is no such thing as a backdoor that only the “good guys” can use.
  • Client-side scanning: This method uses systems to scan content on a person’s device before it reaches a recipient, essentially turning user devices into surveillance tools.
  • Lawful access by design: This is a marketing term for systemic vulnerabilities. No system can provide exceptional access without weakening security.

Weakening encryption for anyone weakens it for everyone. When vulnerabilities exist, criminals, hostile states, and other malicious actors can exploit them.

These approaches create systemic risks, fail the tests of necessity and proportionality, and threaten the open, globally connected, secure, and trustworthy Internet. These harms are intrinsic and unavoidable.

Recommendations

Policies should strengthen, not weaken, encryption. Encryption is essential for maintaining the confidentiality, integrity, and authenticity of data and communications. It underpins a secure and trustworthy Internet and protects individuals, businesses, governments, and critical infrastructure.

Investigative measures must also be targeted, lawful, and limited to what is strictly necessary and proportionate to the seriousness of the crime. Measures that undermine the security of all users in order to investigate a limited number of cases fail this test and should not be pursued.

Policy and operational approaches should support a secure, trustworthy, and resilient Internet that protects data confidentiality, integrity, and availability. Maintaining strong cybersecurity across the digital ecosystem is essential for public safety, economic stability, and trust in digital services.

The Bottom Line

Protecting strong encryption is not an obstacle to public safety, child protection, or crime prevention. It is a prerequisite for all three, and a necessary component of a secure and trustworthy Internet.

Policymakers must stop looking towards security-eroding workarounds and instead start investing in the human and forensic capabilities that solve crime.

Want to learn more? Read our full report.

Image © Sasun Bughdaryan on Unsplash

Disclaimer: Viewpoints expressed in this post are those of the author and may or may not reflect official Internet Society positions.

Related Posts