
Going Dark Again: AI Bug Hunting and the Return of Backdoor Demands
Cryptographer Matthew Green argues that AI vulnerability hunting will make mainstream software far harder to hack — and push law enforcement and intelligence agencies back toward demanding backdoors.
In a blog post published on August 14, Johns Hopkins cryptographer Matthew Green argues that artificial intelligence is about to make mainstream software much harder to break into, with an uncomfortable side effect: U.S. law enforcement and intelligence agencies may "go dark," losing a large part of their surveillance capability for the first time since 2010.
From wiretaps to end-to-end encryption
Green traces the shift from the payphone wiretaps of the early 2000s to smartphones that store data as well as transmit it. Apple began encrypting iPhone storage with a key derived from the user's passcode in 2010, with Android following soon after, and added end-to-end encryption to iPhone messages in 2011. WhatsApp reached 600 million users by 2014 and nearly a billion by 2016, all with default end-to-end encrypted messaging and calls. In 2014 FBI Director James Comey announced the "Going Dark" initiative; in 2016 the bureau went to court to force Apple to unlock a shooter's iPhone. Apple refused, and an outside company broke into the phone instead — a pattern that held for a decade through commercial tools such as GrayKey and NSO Group's Pegasus.
The AI vulnerability era
That equilibrium is now under pressure. In April, Anthropic announced a model called Mythos that was unusually good at finding software vulnerabilities; the U.S. government briefly blocked its export, a move Green calls mostly pointless, since OpenAI and Chinese open-weight labs such as Z.ai and Moonshot have shown that vulnerability discovery will not remain a single-lab monopoly. Defenders are patching decades of bugs and rebuilding CI toolchains to run AI-based vulnerability scanning before code ever reaches a human. Green expects major software to run out of remotely exploitable bugs within roughly two years.
Why backdoor demands will return
For agencies that is a nightmare: the low-hanging vulnerability supply disappears, so demand for constructed, intentional backdoors becomes acute again, along with pressure on industry to re-architect systems for "exceptional access." Some governments will want such capabilities for spying on other governments, which Green doubts will work as well in the AI era. The worst outcome, he writes, is that new backdoors mainly weaken the systems of the countries that mandate them, handing foreign adversaries new ways to attack communications. He offers no plan, only the hope that this time the right choices get made.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.