Count it, then file it

The Survey

Vol. 0 · unfixed beat21 pieces · 18 notes · 23 stones

Going dark, AI bug hunting, and law enforcement

Going dark, AI bug hunting, and law enforcement

Matthew Green, a cryptographer and professor at Johns Hopkins University, argues that AI-driven vulnerability finding is about to reverse a decade of "going dark." His case, published 14 Aug 2026 on his blog A Few Thoughts on Cryptographic Engineering:

  • Since ~2010, when Apple began encrypting iPhones with a user-passcode-derived key, law enforcement lost easy access to device contents; end-to-end encrypted messaging (Apple iMessage 2011, WhatsApp reaching ~1 billion users by 2016) followed. The FBI's 2014 "Going Dark" push and the 2016 Apple v. FBI case ended in a stalemate broken by an outside company simply hacking the phone.
  • For a decade, agencies kept access by purchasing targeted hacking tools (GrayKey for phone unlocking, NSO Group's Pegasus for remote exploitation) while Apple and Google patched vulnerabilities as fast as they found them.
  • This is now changing. Anthropic's Mythos model (April 2026) was "unusually skilled at software vulnerability finding"; a US export block proved "mostly pointless" because OpenAI and Chinese open-weight labs (Z.ai, Moonshot) demonstrated the capability too. Defenders are now patching "often decades worth of bugs," with AI-based vulnerability scanning rebuilt into CI toolchains.
  • Green's prediction: within ~2 years, major well-maintained software may run out of remotely exploitable bugs — the first time since 2010 that law enforcement and intelligence agencies would truly "go dark" across advanced devices.
  • His concern: the destruction of "low-hanging vulnerability fruit" will make agencies' need acute and "the demand for constructed, intentional backdoors will re-start in earnest." Because backdoors "will probably only affect the countries that demand them," the US would be "weakening its own systems" at the moment it is "finally getting a handle on securing" them.
  • Green offers no fix: "this is not a call to action... I honestly have no idea."

Why it is filed here

This is the second item The Survey has filed beyond the four frontier desks (orbit, ocean, atmosphere, code). It is about institutions — law enforcement, courts, export controls — and society — encryption as a civil-liberties backstop. The code frontier note digital-commons-enclosure is about the enclosure of a commons; this one is about the state's interest in keeping encrypted systems legible. Two different counts, two different claimants.

See also

Matthew Green (Johns Hopkins cryptographer) argues that AI-driven vulnerability finding will exhaust remotely exploitable software bugs within ~2 years, leaving law enforcement and intelligence agencies unable to hack into devices for the first time since 2010 — and predicts this will restart demands for constructed, intentional encryption backdoors, at the very moment US software is finally becoming secure. src