Why “Lawful Access” For Encrypted Communications Is Just a Back Door with Better PR
In a recent blog post, child safety advocate John Carr argued that governments should have “lawful access” to end-to-end encrypted messages. He criticised the media for using the term “back door” and claimed it unfairly stokes fear. Carr believes strong encryption without government access is irresponsible and even dangerous. I disagree.
Carr’s argument assumes that encryption can be designed to work differently depending on who is using it. That’s not how maths or software works. If you build a tool that lets anyone decrypt private messages, that tool exists. Once it exists, it introduces a vulnerability that can’t be confined to “the good guys.” No one has invented a form of encryption that selectively fails only when a warrant is present.
Technology experts are not opposing lawful access because of ideology. Their position is based on mathematics. Literally. Once you introduce a flaw into a secure system, that system is no longer secure. You cannot build an exception that works safely for some without exposing everyone to risk. That is why every respected cryptographer has warned against this idea for decades.
Calling it something softer, like lawful access, doesn’t change what it is. It’s a back door. It’s a deliberate weakness built into a system that is supposed to be secure. Legal safeguards don’t fix this. Authoritarian regimes will demand access. Criminals will look for it. If a door exists, someone will try to walk through it.
We don’t ban kitchen knives because they can be used as weapons. We accept their value and deal with misuse through policing and the courts. Encryption is no different.
⛑️ Encrypted communications protect journalists, doctors, lawyers, business leaders, political dissidents, aid workers, survivors of abuse, elected officials, and ordinary people navigating a world of surveillance and coercion. Weakening that protection to help a few investigations puts everyone at greater risk.
This is not a privacy absolutist view. Over the past 15 years, I’ve worked with NCMEC, CEOP, the Thorn Project, the FBI, and the Department of Justice to strengthen child protection systems using data and technical insight that few have or want to possess. I’ve also worked with some of the earliest victims of online exploitation and trafficking. I understand the stakes. I also understand the technology. And what Carr proposes would make everyone less safe.
Carr is right about one thing. Privacy is not an absolute right. It’s a qualified one. But encryption is not about ideology or entitlement. It’s about making digital life safer for everyone. Whether or not society believes every person deserves absolute privacy is a question of politics. But from a technical perspective, there is no such thing as selective encryption. You cannot weaken it for the few without weakening it for all.
Security and privacy may sometimes seem in conflict, especially in policy debates. But the real question is not which one wins. It’s how we design systems that support both. Strong encryption does that. Weakening it may feel like a shortcut to justice, but it often removes the very protections that keep people safe.
There’s no technical way to break encryption for some and not others. Pretending otherwise is the real danger.
