Sang's Blog

The encryption paradox, when privacy enables crime

Trust in cloud providers has disappeared. This did not happen overnight. It has eroded over the years due to data breaches, secret surveillance programmes, advertising scandals and terms of service updates that have redefined ownership without permission. Google scanning emails for ad targeting: Microsoft has shared data with US intelligence under PRISM. Dropbox has accidentally granted full access to anyone with a link, and iCloud photos have leaked through credential-stuffing attacks. Each incident chipped away at the idea that your data is safe in someone else’s data centre. Today, that assumption barely exists.

Privacy-conscious users have responded predictably and rationally: they encrypt everything before it leaves their device. If the provider cannot read your data, they cannot misuse it. This logic has driven the rise of zero-knowledge cloud services such as Proton Drive, Filen, Tresorit and Mega, where the encryption keys stay on the client’s device and the server only sees ciphertext. It has also led to the adoption of tools such as Cryptomator and Rclone Crypt, which add an encryption layer to any cloud storage system, effectively rendering Google Drive or OneDrive as mere block storage. Users treat the cloud as an untrusted pipe. The cloud provider becomes a hard drive in the sky with no visibility into what it stores.

This is a legitimate and necessary response to a genuine problem. Privacy is a fundamental right, not a convenience feature. Journalists protecting sources, activists organising under repressive regimes, lawyers handling privileged documents and ordinary people who simply do not want their personal photos or financial records analysed by machine learning models all have good reasons to encrypt. The fact that they no longer trust cloud providers to honour their privacy commitments is the providers’ failure, not the users'.

However, there is an uncomfortable paradox that needs to be discussed. The same encryption technology that protects a journalist’s sources can also protect a criminal’s evidence. The same zero-knowledge architecture that stops a corporation from mining your family photos also stops law enforcement from identifying illegal content. This is not hypothetical. It lies at the heart of every debate about end-to-end encryption, from messaging apps to cloud storage. Encryption is a tool. It does not distinguish between a whistleblower and a terrorist. It protects both equally because it has no way to tell them apart.

The European Union is currently grappling with this exact issue. Proposed legislation aimed at combatting child sexual abuse material would require providers to scan encrypted content, but this would be technically impossible without breaking the encryption model. Providers either have the keys and can scan the content, or they do not have the keys and cannot scan it. There is no middle ground. Any backdoor, key escrow or client-side scanning mechanism creates a vulnerability that can be exploited by anyone who discovers it, not just the well-intentioned authorities it was designed for. The cryptography community has reached a consensus on this issue, and they are right: it is impossible to build a backdoor that only the good guys can use. Mathematics does not recognise jurisdiction.

The result is societal tension with no clear resolution. On the one hand, the right to private communication and storage protected by strong encryption is essential to a free society. Without it, dissidents, journalists and vulnerable people are exposed to surveillance and repression. However, the same encryption can also create spaces where illegal activity can flourish undetected. Child exploitation networks, terrorist coordination and financial fraud all move to encrypted channels precisely because they are opaque to outsiders. Criminals understand the technology as well as privacy advocates do.

This is not an argument against encryption. It is an argument for being honest about encryption. The privacy community sometimes suggests that the societal risks of universal encryption are either negligible or easily dismissed. They are not. When designing a system that renders stored data inaccessible to anyone — including law enforcement with a warrant — you are making a trade-off. You are choosing to protect the innocent at the cost of also protecting the guilty. That may be the right trade-off. In many cases, it clearly is. However, this decision should be made with eyes open, not under the pretence that there is no cost.

Cloud providers themselves are caught in the middle. In 2021, Apple attempted to implement client-side CSAM scanning, but abandoned the idea after facing significant opposition from privacy advocates and security researchers, who correctly identified the system as a surveillance mechanism disguised as a child protection measure. While the technical proposal — hash matching on-device before upload — was clever, the precedent it would set was dangerous. Once the infrastructure for client-side scanning of one category of content has been built, pressure to expand it to other categories becomes inevitable. Copyright enforcement. Political dissent. Religious blasphemy. The definition of illegal content varies by jurisdiction, so a scanning system built for one government’s definition could become a tool for enforcing the definitions of other governments. Apple understood this and backed down, but the underlying problem remains unsolved.

The tension is not going away. As more users move to encrypted services, the volume of unreadable data increases. Law enforcement will continue to demand access. Governments will continue to propose legislation mandating backdoors. Meanwhile, privacy advocates will continue to point out that it is mathematically impossible to restrict backdoors to legitimate use. The encryption debate is a permanent feature of digital society — it is not a temporary argument that can be won by either side.

So, what does this mean for the individual user? As with every difficult decision about technology, you must understand the trade-offs and make your own choice. Encrypting your cloud storage is a rational response to the collapse of trust in providers. It protects you from data mining, breaches, government overreach and the myriad small violations that come with storing your life on someone else’s computer. However, it also means that your data cannot be inspected under any circumstances — and this includes both innocent and guilty individuals. Accepting this is part of taking responsibility for your digital security.

The line between privacy and impunity is thin. It always has been. The lock on your front door keeps out both burglars and the police without a warrant. An envelope conceals both love letters and criminal conspiracies. Encryption is simply a digital manifestation of a principle that predates the internet: private spaces are vital for human dignity, even though they can be misused. The challenge is not to eliminate misuse by eliminating privacy. Rather, it is to build a society in which the benefits of privacy so clearly outweigh the costs that the trade-off is not even a question.

← Prev Post Next Post →