trueNetLab logo
EN
Privacy Is Security: Who Can We Still Trust?

Privacy Is Security: Who Can We Still Trust?

There is a moment in debates about surveillance that irritates me every time. Someone demands access to private messages. Terrorism, organized crime, or child protection is cited as the reason. Suddenly, those who reject such access are expected to explain why their privacy matters so much.

The question should go in the other direction: Why should the state be able to look into the conversations of people who are not suspected of anything?

I want children to be protected from abuse. I want human traffickers prosecuted and offenders convicted. That is precisely why the word security on a political presentation is not enough for me. I want to know which measure helps whom, what evidence supports it, and what price everyone else must pay.

I work with security every day and think about how we protect systems, connections, and data. Encryption is therefore not an abstract political idea to me. It is one of the foundations on which secure communication is built. When the same governments that require companies to improve security also demand weaknesses in that foundation, it does not add up for me.

Pavel Durov’s speech at the 2026 Oslo Freedom Forum and his conversation with Tucker Carlson, published in June 2025, touch on exactly this point. The Telegram founder describes how governments gradually restrict freedom and use justifications that few people want to oppose. His warning strikes a nerve. It also raises a more uncomfortable question: If we should not trust governments blindly, why should we do so with Apple, Telegram, or any other technology provider?

Privacy is part of our security. Anyone who weakens it must also answer for the insecurity that results.

Why private conversations need a protected space

A message to a partner, a photo for a doctor, a search for psychological help, or a discussion about an employer are ordinary parts of life. Nobody needs to possess a secret of public importance for that. We close the bathroom door even when we are doing nothing illegal inside.

Privacy allows us to voice unfinished thoughts, be wrong, and change our minds. Anyone who must assume that every statement is stored and later judged in another context will speak more cautiously. Sometimes they will say nothing at all. This loss is difficult to see in statistics, but that makes it no less real for a free society.

I can hardly blame people for not following the technical debate. Between work, family, and everyday life, there is little time for legislation and encryption protocols. Terms such as “voluntary detection,” “access to data,” or “safeguards” also sound harmless. The intrusion only becomes visible when we ask who is deciding voluntarily and whose data is being examined.

Politicians and manufacturers therefore share responsibility. They must explain in plain language what their proposals and products actually do. A friendly name is no substitute for that explanation.

Durov’s warning deserves attention and scrutiny

Durov speaks from personal experience of state pressure. At the same time, he speaks as an entrepreneur about his platform and about proceedings that affect him personally. Both facts belong in the assessment.

His arrest in France on August 24, 2024, is documented. The statement issued at the time by the Paris public prosecutor lists investigations that include alleged complicity in criminal offenses and refusal to cooperate with authorities. Durov disputes the allegations. His portrayal of himself as politically persecuted is no more an established fact than an investigative statement proves his guilt.

One part of the interview is particularly revealing. Carlson suggests that the arrest was intended to force Durov to hand over Telegram keys. Durov corrects him: no such demand had been made to him by the time of that conversation. This qualification must not disappear when the story is retold.

An example from his Oslo speech also needs context. Durov refers to British court documents that discuss platforms with influence over public discourse. In the judgment in Wikimedia v. the UK government, paragraph 49, the passage concerns special duties for Category 1 services. Child protection is addressed in other parts of the Online Safety Act. It cannot be read as an admission that child protection was merely a pretext for the entire law.

For me, this precision makes the criticism stronger. We do not need exaggerated claims to recognize problematic surveillance.

How encryption can be bypassed without breaking it

With end-to-end encryption, messages are protected so that the participating devices can decrypt them while the service carrying them should have no independent access to the plaintext. This differs from a connection that is only encrypted on its way to the server. In that case, the operator may be able to read the content even though nobody can intercept it in transit.

In my daily work, I never look at encryption in isolation. It protects connections, data on devices, and backups, but only while keys, endpoints, and access rights are also protected. That is exactly why the promise of a safe backdoor bothers me. In security, I try to eliminate extra access paths and unnecessary privileges. A backdoor does the opposite: it deliberately creates another route in and then declares that route controllable.

An access mechanism intentionally built for third parties changes this protection model. Even if it is reserved for court-authorized access, additional keys, software, or permissions must exist. These components can be attacked, abused, or opened to further purposes through changed rules. Legal authority is not a technical guarantee against unauthorized access.

Client-side scanning starts somewhere else. Content is examined on the device, for example before a message is encrypted and sent. Depending on the system, a match may then trigger a reporting process. Transport encryption can continue to work unchanged, while confidentiality from an additional inspection authority is still reduced.

It is like having somebody inspect a letter before it is sealed. The envelope remains closed on its journey. Anyone who describes only that part is still not telling the whole story.

Not every local image analysis is automatically surveillance. A filter that remains on the device and helps the user has different consequences from a mandatory scanner that reports to third parties. Purpose, control, data leaving the device, and the ability to opt out are decisive.

The “Bugs in our Pockets” study describes the risks of such scanning systems: additional attack surfaces, ways to evade detection, and the danger that searches will later be expanded to other content. The boundary between today’s search target and tomorrow’s then also depends on political decisions and software updates.

False positives add another problem. Matching known files is different from predicting whether a new image depicts abuse or a conversation involves grooming. With very large volumes of data, even a small error rate can affect many innocent people. A machine-generated match is neither proof of abuse nor a conviction.

Chat control: what was actually decided

Several European proposals are grouped under the term “chat control.” Anyone writing about them must distinguish between them. The following assessment reflects the situation as of September 7, 2026.

The previous interim rule for certain voluntary detection measures by communications providers expired on April 3, 2026. It returned to the legislative process in July. On July 23, the Council approved the version amended by Parliament, reinstating it until April 3, 2028.

“Voluntary” describes the provider’s decision to use such measures. It does not automatically mean that every individual user has explicitly consented.

One important detail is missing from the dramatic claim that the EU has simply reintroduced scanning of all encrypted chats. According to the Council’s announcement of the adopted version, communications through affected number-independent services are excluded where end-to-end encryption is, was, or is intended to be applied. This interim rule is therefore not a general order to scan every encrypted chat on every smartphone.

The parliamentary process still deserves attention. According to Parliament’s report on the July 9 vote, 314 members initially supported rejecting the Council’s position, 276 opposed rejection, and 17 abstained. That simple majority was not enough for a rejection at second reading, which required a majority of all members. Parliament then adopted amendments.

It is legitimate to criticize a system in which a majority of votes cast does not stop a proposal. The applicable majority rules and the amendments subsequently achieved are nevertheless part of the explanation. They do not substantiate the claim that all the absent members had simply left for vacation.

Negotiations on the permanent legal framework are continuing in parallel. The Council explicitly stresses that the exceptions now accepted do not prejudge its position in those negotiations. The dispute over the limits of detection and the protection of encrypted communications therefore remains open.

Criticism also comes from within European institutions. In its 2026 opinion on the extension, the European Data Protection Supervisor called for effective limits against general and indiscriminate scanning. “Brussels” is not a single actor with one opinion here.

When access itself requires an identity check

Age checks and access restrictions for social networks belong to the same debate. They create a separate risk: if every platform demands identity documents or permanently links proof of age to browsing behavior, more sensitive data accumulates. For people seeking help anonymously or expressing political criticism, access itself can become a barrier.

An age check does not technically have to mean revealing a person’s full identity to a website. The European Commission describes its age-verification concept as data-minimizing: a service should receive the necessary proof of age without learning the user’s identity. That is a relevant design goal whose actual implementation must be examined.

I am interested in the limits: Who issues the proof, who can track its use, how are people without suitable devices treated, and can the system later be used for additional access controls? Neither a privacy promise nor a reference to child protection answers those questions. Sweeping claims that every age check already amounts to a full identity requirement for the entire internet are no help either.

How many offenders have surveillance measures caught?

I want this question answered. But there is no credible single figure for “all surveillance.” A targeted wiretap, analysis of a seized server, a report from a platform provider, and precautionary scanning of everyone’s private messages are different measures.

There are documented investigative successes. On April 2, 2025, Europol reported 79 arrests and 39 children safeguarded in the operation against the Kidflix abuse platform. In July 2025, Europol reported 158 suspects arrested and 1,194 potential victims safeguarded in Operation Global Chain against human trafficking. These are agency figures at the time of reporting, not counts of final convictions and not an overall assessment of all surveillance measures.

These results deserve recognition. They do not prove that a mandatory scanner in the private messages of the entire population was necessary to achieve them. The success of a specific investigation does not provide blanket justification for every new power of access.

An older US example shows why independent review matters. The PCLOB examined the bulk collection of telephone records under Section 215. In its 2014 report, it found no instance of a threat to the United States in which the program had made a decisive difference to the outcome of a counterterrorism investigation. This finding concerns one specific program and cannot be applied to every form of law enforcement.

A useful assessment would show how many reports lead to actionable intelligence, identified victims, arrests, and ultimately convictions. It would account for false positives and duplicate reports, examine the additional benefit over targeted investigations, and ask whether authorities can process the information promptly at all.

The claim that criminals are never affected is also too absolute for me. Offenders make mistakes and are caught. Well-organized groups can, however, move to other communication channels and add their own encryption. European data protection authorities explicitly identify this evasion problem in their joint 2022 opinion.

That leaves an uncomfortable imbalance: the population bears a broad intrusion while adaptable offenders may evade it. Anyone demanding the measure must explain why its demonstrated benefit justifies that price.

Why trust in state power concerns me

Broad promises of security are especially difficult for me to accept in the face of war. When governments order or prolong military violence that harms civilians and children, demands for ever more access in the name of protecting them ring hollow. Pointing to a duty of the state is not enough to earn my trust.

I do not want to turn this into an equation in which one crime diminishes another. An abused child deserves protection regardless of what a government does elsewhere. But state power must face the same questions about responsibility, consequences, and oversight that it asks of others.

Even well-intentioned access will not always be administered by the same people. Governments change, laws expand, databases are repurposed, and employees can misuse access. A system must therefore impose limits even when those responsible do not act in a trustworthy way.

The fact that confidentiality is part of security is reflected even in recommendations from US security agencies. After telecommunications networks were compromised, CISA recommended consistent end-to-end encryption, including Signal, in its guidance on mobile communications. The same protection that can complicate an investigation also protects people from espionage.

Apple: real safeguards and a very successful promise

Apple’s 2016 conflict with the FBI was real. In the San Bernardino case, the company resisted a demand to create a modified version of iOS that would bypass certain safeguards on the seized iPhone. Tim Cook’s open letter documents that resistance.

I have used Apple products myself for many years. That is why this question interests me more than a simple contest between fans and critics. Every day, I rely on devices whose operating systems I cannot fully inspect. Apple’s decisions therefore have practical consequences for me, and a strong privacy image alone is not enough.

The letter also contains something often lost in the retelling: Apple said it had supplied data already in its possession in response to valid legal demands and had assisted investigators. Apple refused one particular technical intervention. It never made a general promise to provide no data to authorities.

For everyday use, a more concrete question is therefore more useful than “Can I trust Apple?”: Which data can Apple decrypt in my actual configuration?

According to Apple’s overview of iCloud data security, Apple holds the keys for several data categories under standard protection. The optional Advanced Data Protection extends end-to-end encryption to backups, photos, and iCloud Drive, among other categories. Mail, Contacts, and Calendars remain excluded, while certain metadata and sharing functions have their own limitations. Anyone enabling the stronger protection must also organize account recovery reliably.

A marketing line about privacy does not tell me which of these states is active on my device. That is where the difference between a brand promise and a verifiable decision begins.

These safeguards are described in Apple’s documentation, not established by my own audit of the operating system. I can inspect settings, app permissions, and account access. That is still far from controlling the complete implementation and every future software change.

The United Kingdom shows how strongly location can affect the available options. New users there can no longer enable Advanced Data Protection. According to Apple, categories protected with end-to-end encryption by default, along with iMessage and FaceTime, remain protected. This is not evidence of a secret universal key. It is a publicly documented loss of an additional protection option. We examined the background and affected iCloud data in detail in “UK Surveillance Policy Forces Apple to Abandon Encryption”.

My assessment is therefore this: Apple’s privacy protections are more than marketing, but marketing tells the most comfortable version of the story. A public dispute with the FBI is no substitute for checking cloud settings or for independent scrutiny. Nor does it guarantee how the company will respond to every future demand.

Developers and gag orders

In the Carlson interview, Durov claims that the US government could compel developers to install a backdoor secretly while preventing them from informing their employer. He uses the term “gag order” and points to Wikipedia. The relevant starting point is the Wikipedia article “Gag order”.

Such an order initially restricts the disclosure of certain information. By itself, it is not an authorization to manipulate any software at will. What assistance can be required and who may be informed depends on the specific legal basis and order.

National Security Letters are a related example. The provision in 18 U.S.C. § 2709 concerns certain subscriber and connection data and can impose secrecy under specified conditions. It also includes exceptions, such as for legal advice and people whose involvement is necessary to comply with the request, as well as judicial review. It does not establish a general duty for every developer to install a backdoor secretly.

Durov’s broad claim is therefore not proven by the Wikipedia reference alone. The underlying conflict of trust remains: when companies or employees must keep government demands secret, the public has only limited ability to assess how they handle them.

Apple is a US company. That legal jurisdiction belongs in the assessment. A different headquarters does not automatically solve the problem, particularly because major providers operate in multiple countries. I am more persuaded by an architecture that creates as little accessible data as possible than by the hope that a manufacturer will always have the right nationality.

Telegram also requires trust

Durov’s position on privacy must not be confused with the properties of his product. According to Telegram’s own FAQ, ordinary one-to-one and group chats are cloud chats. They use encryption between client and server. Additional end-to-end encryption is available only in separately initiated, device-specific Secret Chats between two people.

Opening an ordinary Telegram chat therefore does not automatically provide the same protection from the provider as a conversation encrypted end to end by default. Convenient access to chat history on several devices is part of Telegram’s design. It also changes whom we must trust.

Telegram’s privacy policy also allows IP addresses and phone numbers to be disclosed after legal review in response to qualifying official orders. That is not access to every conversation. It is also not a guarantee of anonymity.

I can share Durov’s warning about state surveillance and still prefer a messenger with end-to-end encryption enabled by default for confidential conversations. The same test should apply to Apple and Telegram: What does the technology prevent, and what does the operator merely promise?

Does Linux give us back control?

Linux can make a real difference. Open source permits independent inspection, modification, and a move to another provider. We can select services more deliberately and run a system that is less tightly bound to a single commercial account. Anyone who wants to explore that path can find the different approaches in our overview of Linux distributions.

Trust does not disappear, however. It is distributed among developers, package maintainers, software repositories, and the people who build updates. Browsers, firmware, hardware, and cloud services remain in the picture. The same documents in the same third-party cloud account do not gain different protection from that provider simply because the operating system changes.

The backdoor in XZ Utils 5.6.0 and 5.6.1, known as CVE-2024-3094, shows that open software can also be deliberately manipulated. Its discovery also demonstrates the value of independent investigation. “Anyone could look” becomes protection only when people actually do look and their findings have consequences.

Reproducible builds are another component. They are intended to make it possible to generate identical program files from the same source code under defined conditions. Independent parties can then examine whether distributed software corresponds to the published code. That does not prove that the code is free of defects, but it closes an important verification gap.

For me, Linux is therefore primarily a path to greater self-determination. Whether it is safer in daily use also depends on maintenance, hardware support, and configuration. A system whose updates are constantly postponed because managing it is overwhelming loses an important layer of protection.

And yes, convenience matters. Specialist software, device integration, and established workflows can make a move difficult. These costs are real. It is reasonable to test Linux in your own working life first and reduce dependencies gradually instead of treating every inconvenience as proof of technical superiority.

Smartphones leave an especially large remainder of trust

A smartphone brings together communications, camera, microphone, location, payments, and account recovery. At the same time, an ordinary user can hardly verify its entire software and hardware stack. Even an alternative operating system does not eliminate every dependency on chips, firmware, and cellular technology.

Encrypted messengers cannot fully protect a compromised endpoint. Citizen Lab documented BLASTPASS in 2023, an attack that could install Pegasus without user interaction on then-current iPhones. The vulnerabilities were subsequently patched. This case demonstrates a concrete risk; it proves neither that every iPhone can be read today nor that security measures are pointless.

Anyone who can read plaintext on the device does not need to break the messenger’s encryption protocol. Current software, a strong device passcode, careful app selection, and protected accounts therefore belong to the same security decision as the messenger. A more restrictive operating mode can also be useful for people at elevated risk.

Alternatives such as GrapheneOS expand the choices on supported devices. The project adds security hardening and optionally allows Google Play to run as ordinary restricted apps. It still depends on supported hardware and its security updates. Banking, work, and everyday apps must be checked before switching. This assessment is also based on documentation rather than my own comparative test.

A VPN does not solve these fundamental problems. It protects one part of the network connection and shifts trust to the VPN provider. It neither prevents scanning on the device nor makes a user who is signed in to a service invisible.

What I take away from this debate

I do not want to give up digital communication. I want to use it without treating every message as a possible future case file. I do not need a perfect manufacturer or a device I can control completely. I need understandable safeguards and the ability to limit dependencies.

In everyday life, that begins with using a messenger that enables end-to-end encryption by default for confidential conversations. Then it is worth checking backups: Where does a second copy go, who holds the keys, and how does recovery work? Fewer installed apps, sparingly granted permissions, shorter retention of unnecessary data, and timely updates reduce further risks. These choices do not solve everything, but they concretely change what others can learn about us.

I want the same precision in politics. Anyone demanding surveillance should demonstrate its additional benefit, disclose its errors, and accept independent oversight. Effective child protection also includes accessible support, prevention, help for victims, and investigative authorities able to process concrete leads. The discussion must not end with a desire for more data.

What concerns me in Durov’s warning is ultimately habituation. A far-reaching intrusion is introduced as an exception, extended, and eventually barely explained. That is why I want to discuss it early: factually enough to correct false claims and clearly enough not to accept every new power of access as technical progress.

This is my view as someone who works with security every day: I do not trust any technology blindly, but I also do not weaken functioning protection in advance. I examine what data is created, who holds the keys, and what access paths actually exist. We should apply exactly that standard to political demands as well.

My private conversations need no political justification. Anyone who wants to restrict their confidentiality does.

Until next time,
Joe

Sources