Encryption has pushed police away from intercepting messages in transit and towards hacking the devices at either end. That shift, often called the response to “going dark”, changes who holds power over software flaws and how oversight works.
Key takeaways
- “Going dark” is the argument that strong encryption and secure devices leave investigators unable to read evidence they would once have obtained through a wiretap or a seized filing cabinet.
- Because end-to-end encrypted traffic is unreadable in transit, agencies have increasingly turned to compromising endpoints — phones, laptops and accounts — rather than tapping the network between them.
- Law enforcement hacking depends on software vulnerabilities, which means state agencies have an institutional interest in flaws remaining unpatched for a period of time.
- Legal frameworks in most countries were written for search, seizure and interception, and map awkwardly onto remote intrusion into a device.
- The core disagreement is not whether investigators need any access, but how narrow, auditable and independently supervised that access should be.
What is actually happening
Two decades ago, most digital evidence sat somewhere an investigator with a warrant could reach: an unencrypted hard drive, a mail server, a telephone switch capable of duplicating a call. Communications providers were required, in many jurisdictions, to build interception capability into their networks, and that capability generally produced readable content.
Widespread deployment of transport encryption and then end-to-end encrypted messaging changed the picture. When a message is encrypted on the sender’s device and decrypted only on the recipient’s, an order served on the network operator or even on the messaging service typically yields metadata — who talked to whom, when, from where — but not the content. Full-disk encryption on phones produced a similar problem for seized hardware: possession of the device no longer guarantees access to what is on it.
The response has been to move the point of access. If the message cannot be read in transit, it can potentially be read at the endpoint, before encryption or after decryption. That means placing software on a target’s device, or otherwise defeating its protections. Different jurisdictions use different names for this: equipment interference, network investigative techniques, remote forensic software, lawful hacking. The underlying technique is the same, and it relies on the target’s system being exploitable.
Why this is being discussed now
The subject resurfaces cyclically rather than because of a single event. Several long-running pressures keep it live. Consumer platforms continue to expand default encryption, including in backups and cloud storage, narrowing what a legal request to a provider can return. At the same time, a commercial market has developed around forensic extraction tools and exploit brokerage, so hacking capability is no longer confined to the best-resourced intelligence agencies; smaller police forces can buy access to it.
Legislative proposals in several regions have repeatedly floated obligations that would require providers to scan content on devices, retain access to plaintext, or otherwise weaken encryption guarantees. Each proposal reopens the same debate, and technical communities respond with the same objection: an access mechanism cannot reliably be limited to authorised users. Hacking is frequently offered as the alternative that avoids weakening encryption for everybody — which is precisely why its own costs deserve scrutiny.
Background a newcomer needs
Three concepts do most of the work in this debate.
Encryption in transit protects data moving between systems. End-to-end encryption means only the endpoints hold the keys, so intermediaries — including the service provider — cannot read content even if compelled. Encryption at rest protects stored data, usually with a key derived from a passcode and held in dedicated hardware on the device.
Metadata is everything about a communication other than its content. It is generally far less protected, legally and technically, than content, and it is often highly informative. Arguments that investigators have “gone dark” are contested partly on the grounds that the volume of available metadata and cloud-stored data has grown enormously over the same period.
A vulnerability is a flaw that lets an attacker make software behave in ways it was not meant to; an exploit is a reliable technique for triggering it. Exploits that work against fully updated systems are scarce and valuable. When a government agency acquires one, it holds something that also works against every other user of that software until the flaw is fixed. Many governments operate some form of internal process to decide whether to disclose a flaw to the vendor or retain it for operational use; the criteria and outcomes of those processes are usually not public.
Who is affected, and how
Direct targets of an investigation are the obvious group, but the effects are broader.
Every user of a vulnerable product shares the risk created by an undisclosed flaw. A vulnerability retained for law enforcement purposes is not reserved; if another party discovers or steals it, the same flaw is available to criminals or hostile states. Historical incidents in which stockpiled offensive tooling has leaked are a recurring reference point in this argument.
People near a target are affected because intrusion into a phone or laptop is rarely surgical. A device holds messages from many correspondents, location history, photographs, health data and credentials for other accounts. Where a technique is deployed against a server or a website rather than an individual device, it may touch large numbers of visitors, only some of whom are under suspicion.
Defendants and courts are affected in a specific way. Evidence obtained by hacking is hard to test in the usual adversarial manner if the technique itself is treated as a protected secret. Defence experts may be unable to examine how software reached a device, what it did once there, or whether it could have altered data. This creates a tension between disclosure obligations and operational secrecy that courts in various countries have handled inconsistently.
Security researchers, vendors and the wider software supply chain are affected because the same market that supplies investigators also raises the price of vulnerabilities, changing incentives around disclosure.
Where informed people disagree
There is more agreement than the public argument suggests. Few technologists claim that serious crime should be uninvestigable; few investigators claim that encryption should be abolished outright. The disputes are about magnitude and control.
One dispute is empirical: how often encryption genuinely blocks an investigation that could not proceed by other means. Reliable numbers are scarce and definitions vary — a locked device counted as an obstacle may be opened later, or may be irrelevant to the case. Without consistent public reporting, both sides argue from limited data.
A second dispute is about whether hacking is the lesser evil. Its defenders note that it is targeted and leaves general-purpose encryption intact, unlike mandated backdoors. Critics reply that it institutionalises a state interest in insecure software, and that “targeted” describes the warrant rather than the technique.
A third dispute is about proportionality of scope. Remote access to a live device can yield far more than a traditional search: continuous monitoring, microphone and camera access, and material created after the order was issued. Whether existing warrant standards are adequate for that scale of intrusion, or whether a distinct legal category is required, is genuinely unsettled.
A fourth concerns transparency. Some argue that publishing techniques would render them useless; others that the absence of published statistics, judicial reasoning and audit results makes meaningful oversight impossible.
Practical implications
For ordinary users, the practical defence against endpoint compromise is unglamorous and largely identical to the defence against criminal malware: apply updates promptly, reduce the number of applications and services holding sensitive data, use hardened modes offered by mobile operating systems where the threat model warrants it, and understand that encrypted messaging does not protect a compromised device.
For organisations, the implication is that endpoint security and patch management carry a wider significance. The same flaw that enables a lawful intrusion in one country enables an unlawful one elsewhere.
For policymakers and vendors, the practical question is process: how vulnerability retention decisions are made and reviewed, what notification obligations exist after an operation concludes, how long retained data may be held, and what a court is entitled to know about the tool that produced the evidence.
What to watch next
Watch whether jurisdictions create explicit statutory regimes for device intrusion rather than stretching interception or search law to cover it, and what authorisation thresholds those regimes set. Watch how courts handle disclosure disputes over investigative software, since a consistent line on defence access would shape practice considerably. Watch whether governments publish more about vulnerability retention processes, including numbers rather than only criteria. Watch procurement: whether public bodies disclose which forensic and intrusion tools they buy, and under what conditions. Finally, watch platform architecture — moves towards encrypted backups, shorter data retention and hardware-backed key storage each shift what any legal process can obtain, and tend to trigger the next round of the debate.
Frequently asked questions
What does “going dark” actually mean?
It is a phrase used by law enforcement agencies to describe a perceived loss of access to evidence caused by widespread encryption. The claim is that communications and stored data that would once have been obtainable with a warrant are now unreadable, even when the legal authority to obtain them exists. Critics of the phrase argue it understates the volume of metadata, cloud data and device data still available to investigators.
Is law enforcement hacking legal?
It depends entirely on the jurisdiction. Some countries have passed explicit legislation authorising remote intrusion into devices under judicial or ministerial authorisation; others rely on general search, seizure or interception powers that predate the technique. The legality of any specific operation turns on the authorisation obtained, the scope of the order and the procedural safeguards applied, and these have been contested in courts in several countries.
How is hacking different from a backdoor in encryption?
A backdoor is a deliberate weakness built into a product, affecting every user of it by design. Hacking exploits an unintended flaw in a specific target’s system, leaving the product’s design intact. The distinction matters, but it is not absolute: exploiting flaws requires those flaws to persist, so the practice creates an ongoing state interest in software remaining vulnerable for at least some users.
Does encryption stop police from investigating crime?
Encryption limits one route to evidence. Investigators retain access to metadata, communications records, cloud-stored material, physical evidence, financial records, informants and traditional surveillance. How often encryption is decisive in preventing a case from proceeding is disputed, and public data on this is limited. The honest position is that encryption raises the cost and difficulty of some investigations without making them uniformly impossible.
Can ordinary people be affected by these techniques?
Yes, in two ways. Vulnerabilities retained rather than reported affect everyone using the affected software, because the same flaw can be found or stolen by others. Separately, intrusion operations can capture data belonging to people who are not suspects, including correspondents of a target or visitors to a compromised website. The extent of such collateral collection is generally not publicly reported.
What can I do to reduce my exposure?
The defences are the same as for criminal malware: install security updates quickly, remove software you do not use, be cautious with links and attachments, enable hardware-backed protections and enhanced security modes where your device offers them, and limit how much sensitive data accumulates on any single device. None of this defeats a well-resourced adversary, but it removes the easy routes that most tooling relies on.
Sources and further reading
- Published guidance and technical standards from national cybersecurity agencies, which describe endpoint hardening and vulnerability disclosure practice in general terms.
- Academic legal scholarship on lawful hacking and computer search, which examines how warrant law applies to remote intrusion.
- Reports from digital rights organisations analysing surveillance legislation and the commercial spyware market.
- Technical write-ups from platform security teams and independent researchers documenting device security architecture and exploit mitigation.
Surfaced from the hackernews signal “encryption and lawful hacking debate”. AI-assisted draft, editorially reviewed.

