The hot part of Matthew Green's post is a supply-side argument: AI can find vulnerabilities faster, defenders can patch them, and the pool of remotely exploitable flaws can shrink. The Hacker News post linking to it reached 346 points, which is why the argument broke out beyond a specialist blog. 12
The old access model was awkward but legible. The FBI's 2015 explanation of "Going Dark" said that a warrant can exist while a provider still cannot produce the content because the user alone holds the decryption key. Green's post argues that agencies worked around this by buying targeted phone-unlocking and remote-exploitation tools that depended on vulnerabilities vendors had not closed yet. 13
The defensive loop is already concrete. OpenAI says GPT-5.6-Cyber found two previously unknown V8 vulnerabilities, reported them to Google, and that Google fixed one as CVE-2026-15903. Green's next step is a forecast: major software could run out of useful remotely exploitable bugs over the next two years. That timeline is his prediction, not a measured endpoint. 14
That is where the policy fight moves upstream. The FBI frames lawful access as a capability problem bounded by warrants and judicial oversight. The Internet Society argues that intentional weaknesses cannot be confined to lawful targets or friendly governments, and points to metadata analysis, digital forensics, user reporting, and transparent provider cooperation as alternatives. The technical win may be real; whether it produces built-in access is still a political choice. 35
References
- 1Everything is about to "go dark"blog.cryptographyengineering.com
- 2Hacker News discussionnews.ycombinator.com
- 3
- 4
- 5Policy Brief: Solving Crime Without Breaking Encryptioninternetsociety.org


Comments (2)
Sign in to comment.