"Any law broadly limiting E2EE would thus have severe serious consequences for cybersecurity, commerce, and government operations," the Article warns.
Round 3: The current debate over end-to-end encryption
The new paper frames today's controversy as "Round 3" of the long-running Going Dark Debate. It says governments worldwide have proposed, and in some cases enacted, laws that would limit end-to-end encryption (E2EE) to enable law enforcement or national-security access. The Article defines E2EE in the strict sense: a mode of communication in which no entity between sender and recipient can read the plaintext.
Five technically distinct scenarios for how E2EE operates
One of the Article's central findings is descriptive and technical: it identifies five technically distinct scenarios for how E2EE operates in practice, and it stresses these scenarios have different implications for lawful access. The paper argues those scenarios create "a substantial gap between the assumption that E2EE categorically blocks lawful access and the reality of how communications are sent and received." In other words, the binary idea that encryption either entirely prevents lawful access or entirely allows it is, according to the Article, an oversimplification.
E2EE is embedded across the modern technology stack
The Article emphasizes that E2EE is not confined to consumer messaging. It documents that encryption is embedded throughout the modern technology stack — including Transport Layer Security (TLS), Secure Shell (SSH), Virtual Private Networks (VPNs), and Zero Trust Architecture. By locating E2EE across these layers, the Article argues that policy actions aimed at limiting E2EE would reach well beyond chat apps and into the foundations of networked systems.
Zero Trust Architecture and legal requirements in the U.S. and EU
The Article highlights a policy twist with operational consequences: Zero Trust Architecture is now legally required under U.S. and EU law. Because Zero Trust relies on strong cryptographic protections, the paper warns that broad limits on effective encryption would intersect with legally mandated cybersecurity practices, potentially creating conflicts between new restrictions and existing legal obligations to deploy Zero Trust approaches.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: The Article's mapping of five scenarios and the description of encryption across TLS, SSH, VPNs, and Zero Trust suggest engineers will need to parse which components can reasonably accommodate lawful-access demands without undermining system security. The paper implies technical nuance matters: implementations differ, and so will the consequences of any legal constraints.
- Policymakers and regulators: The Article urges caution. It revisits two lessons from an earlier phase of the debate — the "least trusted country problem" and the "golden age of surveillance" — and concludes those lessons remain true. The paper therefore frames new government claims for restricting effective encryption as deserving "great skepticism."
- Affected enterprises and procurement leaders: Because encryption extends into core protocols and architectures, enterprises that must comply with U.S. and EU legal requirements to implement Zero Trust could face real operational tradeoffs if laws were to restrict E2EE. The Article signals the risk that commerce and government operations could be disrupted by broad legal limits on encryption.
The Article ties these technical and policy threads into a larger judgment: the binary rhetoric of "going dark" obscures a complex reality. Encryption today is widespread, multifaceted, and legally entangled; proposals to curtail it will have ripple effects beyond the narrow target of messaging apps.
As the paper closes, it reiterates two enduring points from earlier rounds of the debate — the least trusted country problem and the golden age of surveillance — and concludes that claims for new restrictions on effective encryption deserve close scrutiny. The central question it leaves in plain terms is procedural as much as technical: how can lawmakers reconcile demands for lawful access with the fact that encryption is woven through protocols and legal obligations that sustain modern cybersecurity, commerce, and government operations?
https://www.schneier.com/blog/archives/2026/07/end-to-end-encryption-and-going-dark.html




