AI News Feed
Market watch
Cybersecurity

AI Could Make Software Too Secure for Government Hacking, Professor Warns

Cryptography professor Matthew Green argues AI could make software too secure for governments to lawfully hack criminals' devices, possibly renewing backdoor calls.

Green, a longtime observer of the tension between government hacking and strong encryption, wrote that AI is likely to make software much more secure, potentially causing law enforcement and intelligence agencies to lose access to security flaws they rely on to surveil targets. He warned that the U.S. government in particular may lose access to vulnerabilities as companies patch an unprecedented volume of bugs.

The fear of "going dark" is not new. In 2014, then-FBI Director James Comey warned that encryption could block authorities from listening to calls or accessing device data. Since then, apps like Signal, WhatsApp and Apple's iMessage have rolled out end-to-end encryption, and Apple has encrypted devices by default, making it harder to break into iPhones protected by strong PINs.

As Green explains, governments have adapted by buying hacking tools and spyware instead of requiring backdoors, creating what he calls an "uneasy kind of truce." He now worries AI will disrupt this balance, and that governments could ask for backdoors again, making everyone's devices less secure by design.

Several experts offered mixed reactions to Green's argument. Luna Tong, a researcher who previously worked at two firms that develop exploits for governments, agreed, describing a "gold rush of bugs right now" but adding it is a temporary phenomenon. An anonymous researcher with over a decade in offensive security said AI could make human security researchers obsolete, and that defenders will eventually have the edge.

Paolo Stagno, chief technology officer at Crowdfense, a company that develops and sells zero-days to governments, said no state will throw away the possibility of surveillance. He called the current process of requiring governments to exploit security flaws the "most democratic system we have," but noted the status quo may not last if bugs become too hard to find.

However, three current and one former offensive security industry professionals disagreed. They argued that easy bugs will be easier to find, complex bugs that are more valuable for governments will not go away, and AI can actively assist researchers who sell bugs to government authorities. Hamid Kashfi, founder of offensive security firm DarkCell and an employee at AI cybersecurity startup Xbow, said that for every AI-found and reported bug, there are probably 20 that are not reported.

Two researchers who currently look for bugs for zero-day firms told TechCrunch they were less concerned about AI than about new security protections in modern devices that make them more difficult to hack. Eva Galperin, cybersecurity director at the Electronic Frontier Foundation and an expert on government spyware, said the offense has the advantage today.