The silent extra participant — the "ghost" backdoor, explained

Published Aug 03, 2026 by Xiph

Most attacks on encrypted messaging arrive wearing boots. Ban the apps. Break the maths. Scan every message before it's sealed. The "ghost" proposal arrived wearing slippers — which is exactly why it's worth unpacking. Nobody breaks your encryption. Nobody cracks an algorithm. Law enforcement simply joins your conversation, invisibly, like crocodile clips on the copper phone lines of old. The padlock on your chat stays closed the whole time.

It sounds surgical. It's actually a demolition — just of a different load-bearing wall.

The silent extra participant — the "ghost" backdoor, explained

Where the ghost came from

In November 2018, two senior British intelligence officials — Ian Levy, technical director of the National Cyber Security Centre, and Crispin Robinson, GCHQ's technical director for cryptanalysis — published an essay on the US national security site Lawfare. Buried in its measured prose: it would be relatively easy for a provider to "silently add a law enforcement participant to a group chat or call". No weakened algorithms, no master keys — just suppress a notification or two on the target's device, and the encryption itself never gets touched. A virtual version, they suggested, of the crocodile clips police used on analogue phone lines for a century.

The timing matters for Australians. The essay appeared on 29 November 2018. One week later, our Parliament passed the Assistance and Access Act. Months earlier, Five Eyes ministers on the Gold Coast had declared that "privacy is not absolute" and put industry on notice. The ghost was never an idle thought bubble. It was the technical sketch behind a coordinated policy push — one Australia was arguably leading, not following.

How a ghost would actually work

To see the trick, you need to know the one job a messaging provider actually performs. In end-to-end encryption, your device holds a private key that never leaves it and publishes a matching public key. When you message someone, your app asks the provider's servers for their public keys and encrypts to them. The provider can't read the messages — but it makes the introductions. That key directory is the trust anchor of the whole system.

The directory is where the ghost lives. Under a ghost order, the provider quietly tells your app that your contact has one extra key — the agency's — and your app dutifully encrypts every message to both. Cryptographically, nothing is broken. Every message really is end-to-end encrypted — there are just three ends now, and you only know about two. Your private chat has silently become a group chat with a hidden member.

The second required change is the tell. Modern apps announce membership and key changes — the "security code changed" banner in WhatsApp, safety numbers in Signal, participant lists everywhere. A ghost only works if the app is also programmed to hide those alerts. So the proposal needs two alterations: a lie in the key server, and a lie in the interface. The maths stays intact. The truth doesn't.

The sleight of hand in "nobody's encryption is weakened"

Encryption does two jobs, not one. Confidentiality — outsiders can't read the content — is the famous half. The other is authentication: assurance that the keys involved belong to the people you think they do. Strip that out and confidentiality becomes decorative. A perfectly sealed envelope isn't much comfort if a stranger chose the address.

That's the case a coalition of 47 signatories — Apple, Google, Microsoft and WhatsApp among them, alongside civil society groups and cryptographers like Bruce Schneier and Phil Zimmermann — made in a May 2019 open letter to GCHQ. Their argument was blunt: the ghost requires providers to surreptitiously inject keys and suppress the notifications that would reveal them — to build deception into the product. Users rely on providers to confirm that participants in a conversation are "the people they think they are, and only those people". The ghost doesn't route around that trust; it weaponises it.

Three practical problems follow. First, the mechanism can't check warrants. Once a silent-add capability exists, it's a feature — available to a corrupt insider, a hacker who compromises the provider, or a less lovely government with paperwork of its own. We've watched this movie: China's Salt Typhoon operators burrowed into the lawful-intercept systems US telcos were required to build. The crocodile clips got stolen.

Second, a ghost mandate outlaws honesty as a product feature. Safety numbers, WhatsApp's key transparency, Apple's Contact Key Verification — these exist precisely to detect an uninvited key. A provider ordered to run ghosts must rip those features out or make them lie too. The UK has already laid track here: 2024 amendments to its Investigatory Powers Act require some companies to notify the Home Office before shipping security changes that could hamper lawful access.

Third, trust collapse is itself a security harm: if participant lists can be fictional, careful people drift to obscure tools or stop speaking freely — journalists, lawyers and abuse survivors first.

GCHQ called the ghost hypothetical, a starting point for discussion. It was never adopted by name. Never renounced either. Ideas like this don't die; they moult.

Same goal, different trapdoor

The ghost is distinct from client-side scanning, which we unpacked in our piece on the surveillance ratchet. Scanning inspects your content on your own device before it's encrypted. The ghost slips in through the identity layer after. Both are marketed as leaving encryption intact. Both defeat its point. They belong to the same family as the identity checkpoints creeping in through age verification: access by another name, a different trapdoor into the same room.

And the room is being actively renovated. The EU's ProtectEU strategy has produced a June 2025 roadmap on lawful access to data, an encryption technology roadmap promised for mid-2026, and next-generation decryption for Europol pencilled in from 2030. Sweden's 2025 lawful-access bill prompted Signal to threaten to leave the country. The UK's fight with Apple over encrypted iCloud backups grinds on. A ghost fits neatly into any of these frameworks as the targeted, proportionate option — which is exactly how it will be sold.

Australia may have legalised the ghost first

Here's the uncomfortable local angle. The Assistance and Access Act 2018 lets agencies issue escalating demands to designated communications providers — a definition broad enough to capture telcos, app developers and device makers, onshore and offshore — up to Technical Capability Notices that compel a company to build a new capability, with penalties in the millions for refusal.

The Act's celebrated safeguard is that no notice may require a "systemic weakness or systemic vulnerability". The catch: the ghost is practically designed to slip through that wording. It targets one conversation, one user. On the narrow reading the government has favoured, that's not systemic — and critics from the Law Council to global tech firms have argued since 2018 that a ghost-style capability is exactly what a Technical Capability Notice could demand. Successive reviews — the Independent National Security Legislation Monitor, then the Parliamentary Joint Committee on Intelligence and Security — recommended tighter definitions and independent authorisation. Years on, those recommendations are largely gathering dust.

Could we tell if it has ever happened? No. Notices are secret, disclosure is penalised, and transparency reporting gives bare counts. Add the Identify and Disrupt Act 2021, whose account takeover warrants let agencies not just join your conversation but become you, and the honest summary is: the legal plumbing for a ghost exists here, and the visibility to detect its use doesn't.

What you can do now

The encouraging part: ghosts are detectable in principle, because the countermeasures are identity checks.

For individuals:

  • Switch on security notifications. In WhatsApp: Settings → Account → Security notifications. You'll be told when a contact's security code changes.

  • Verify safety numbers for sensitive contacts. In Signal, compare safety numbers in person or over a different channel, and re-verify after any change.

  • Prefer apps with key transparency. WhatsApp's key transparency and Apple's Contact Key Verification let your device verify it received the same key as everyone else.

  • Take unexplained key-change alerts seriously. Usually it's a new phone. On a sensitive conversation, an unexplained change is worth a phone call to confirm.

  • Keep apps updated, and harden where it counts. Detection features ship in updates; an outdated client can't warn you. For genuinely high-risk work, a hardened handset and a vetted communications stack beat mainstream defaults.

For businesses:

  • Know your exposure under the Assistance and Access Act. If you build, carry or host communications in any form, you may be a designated communications provider. Decide before a notice arrives who may know, where legal advice comes from and what your disclosure limits are.

  • Treat platform choice as a security decision. Favour vendors with open, audited clients, published transparency reports and key transparency — and ask them directly how they would respond to a silent-add demand.

  • Verify high-stakes instructions out-of-band. Confirm payment and credential changes on a second channel. It defends against ghosts and everyday business email compromise alike.

  • Segment your most sensitive conversations. Keep them on a smaller, harder, vetted channel, and treat mainstream platforms as contested territory.

A final word

The ghost is, strangely, the most honest of all the backdoor proposals — because it states the requirement plainly: for the state to listen without breaking the maths, your apps must lie to you about who is in the room. Every access-by-another-name scheme carries that clause somewhere in the fine print. The ghost prints it on page one. "Nobody's encryption is weakened" is true, as far as it goes. It's your reasons for trusting it that get weakened.

If your organisation needs communications it can genuinely trust — hardened devices, secure messaging and calling, and advice on your obligations under Australia's assistance and access regime — talk to us at enquiries@xiphcyber.com.


Posted in: Security