Saltar al contenido principal
en/blog/chat-control/research/chat-control-y-key-escrow/

Chat Control + Key Escrow — The historical pattern that always fails

By Xscriptor — Óscar Preciado6 min read
TechnologyPrivacyHistoryConnectionsResearchkey escrowClipper ChipCALEAUK IPAsurveillanceencryptionhistoryChat ControlXscriptorÓscar Preciado
Chat Control + Key Escrow — The historical pattern that always fails

Those who do not know history are condemned to repeat it. Those who know it are condemned to watch others repeat it.



The Chat Control proposal is not the first time a government has attempted to establish a mechanism for accessing encrypted communications. The history of key escrow is long, recurrent and always ends the same way: technical failure, political withdrawal, or implementation that is never used.

This document surveys the most significant attempts and extracts the lessons that apply directly to Chat Control.

Clipper Chip (1993-1996, USA)

The most famous attempt and the one that established the pattern for all others.

What it was

The US government, through the NSA, developed a cryptographic chip called Clipper that would be installed in all telephones and communication devices. The chip used an algorithm called Skipjack (classified, initially secret) and implemented mandatory key escrow: encryption keys were deposited with two government agencies.

Clipper encrypted call:
    A ←[Skipjack, key K]→ B

    K is split into two parts:
    K₁ → deposited with the Department of Commerce
    K₂ → deposited with the Department of Treasury

    With a court order: the two agencies deliver K₁ + K₂
    → K is reconstructed → The call is decrypted

Why it failed

Problem Manifestation
Cryptanalysis Matt Blaze discovered a vulnerability that allowed bypassing key escrow without being detected
Public pressure Massive campaigns by civil rights organizations and technology companies
Market rejection No company voluntarily adopted Clipper. The industry united around PGP, SSL and other open standards
Algorithm secrecy That Skipjack was classified generated absolute distrust. When declassified, design weaknesses were found

Lesson for Chat Control: an access mechanism that can be technically bypassed is worse than having no mechanism (it creates a false sense of security). And a secret mechanism is unacceptable.

CALEA (1994-2024, USA)

The Communications Assistance for Law Enforcement Act requires telecommunications companies to design their systems to allow legal interception.

Evolution

1994: Original CALEA — Traditional telephony only
2001: Post-9/11 — Expansion to VoIP and broadband
2015: The FCC extends CALEA to messaging services
2020-present: Debate on including E2EE within CALEA's scope

Lessons

CALEA has demonstrated that expansion is inevitable. Every decade, the scope extends to new technologies. What started as a law for analog telephones today covers VoIP, messaging, and there is debate about whether it should cover end-to-end encryption.

Lesson for Chat Control: the same expansive logic that CALEA has followed will apply to CSAR. Today it is CSAM; tomorrow it will be terrorism; the day after it will be any serious crime.

UK Investigatory Powers Act (2016, United Kingdom)

Known as the Snooper's Charter, this law grants the British government extremely broad powers to intercept communications, including the ability to demand the surrender of encryption keys or technical assistance to bypass encryption.

The confrontation

Actor Position
British government We need access to fight terrorism and serious crime
WhatsApp We will not implement backdoors. We prefer to leave the market
Signal We do not have the technical ability to grant access. It is mathematically impossible
Apple We explicitly refuse to create backdoors. iMessage will not have scanning
Academics Open letter signed by hundreds of cryptographers: there is no secure way to do it

The outcome

The law was passed (2016). But companies did not yield. The British government has not issued any order requiring Signal or WhatsApp to compromise their encryption. The law is, in practice, a permanent threat that has not been executed.

Lesson for Chat Control: passing a law does not mean companies will comply. If the law requires the impossible (scanning encrypted content without breaking encryption), companies can:

  1. Not comply (assuming the legal cost)
  2. Leave the market
  3. Remove E2EE (worsening security for all users)

None of these options is good for the stated goals of the law.

Australia — Assistance and Access Act (2018)

Australia went further than the United Kingdom: the law allows authorities to demand technical assistance to access encrypted communications, including the creation of security weaknesses in products.

The Signal case

The Australian Director-General of Security explicitly asked Signal to implement an access capability. Signal refused. The law theoretically allows forcing Signal, but doing so would require:

  1. A specific court order
  2. Demonstrating that the measure is proportionate
  3. Accepting that Signal can make public that it has received an order

No such order has been executed.

Lesson for Chat Control: laws that require the technically impossible create a legal theater: the law exists, but cannot be applied because compliance would destroy the product's security. The result is the worst of both worlds: the threat is present, but protection does not improve.

The recurring structure

All these attempts share the same structure:

1. A government identifies a threat (terrorism, CSAM, crime)
2. Proposes a mechanism for accessing encrypted communications
3. The technical community demonstrates the mechanism is insecure or unfeasible
4. The government insists: "this time is different"
5. The law is passed (or attempted)
6. Companies refuse to implement the mechanism
7. The law remains in legal limbo: it exists but is not enforced
8. Over time, a new version is attempted (return to step 1)

Chat Control is step 8 of this sequence, which started with Clipper Chip in 1993. The technology has changed; the structure has not.

Why they all fail

There is an underlying reason that explains why all key escrow attempts have failed and why Chat Control will fail in the same way:


Key escrow is not a technical problem. It is a trust problem.


There is no entity in the world that is simultaneously:

  • Competent to safeguard millions of keys without leaks
  • Trustworthy not to expand its use beyond what is authorized
  • Resistant to coercion from other governments
  • Transparent so that citizens can verify its actions
  • Efficient in managing the volume of requests from a mass system

Not even the NSA (with all its resources) could safeguard Clipper's keys without creating vulnerabilities. Not even the British government has been able to demonstrate that its access system would be proportionate. Not even the European Commission has been able to explain how it would prevent the expansion of scanning to other categories of crimes.

The history of key escrow is the history of a broken promise repeated every 10-15 years. Each generation of legislators rediscovers the idea, believes this time will be different, and collides with the same mathematical reality: encryption does not distinguish between legitimate and illegitimate uses of access. It only distinguishes between who has the key and who does not.


Related documents: