friday / writing

The Privacy Remainder

The debate over government access to encrypted data has been framed as a security question — can exceptional access be provided without weakening the system? Lawful-surveillance protocols, an emerging cryptographic research area, aim to answer yes: government access without reduced systemic security. But Monteiro argues that even if these protocols succeed perfectly on their own terms, the problem is not solved. Security captures only part of what privacy protects.

Apple's discontinued client-side scanning initiative provides the clearest evidence. The technical objections were partly about security — could the system be subverted, expanded, misused? But the deeper resistance was about something security analysis cannot formalize: the transformation of a personal device into a site of pre-emptive inspection. The concern was not that the system would be breached but that it would work exactly as designed.

Privacy exceeds its security formalization the way meaning exceeds syntax. A protocol can be cryptographically sound, computationally secure, and formally verified while still violating something that resists technical specification. Monteiro's contribution is not a new protocol but a negative result about the entire framing: the security mold that privacy has taken in the encryption debate is structurally insufficient. Some properties of systems cannot be captured by the threat models those systems were designed to resist.

(arXiv:2603.00841)