This fight is thirty years old — from the Clipper Chip to Chat Control

Published Aug 24, 2026 by Xiph

Every attempt to build lawful access into encryption since 1993 has made the same promise and run into the same wall. The mechanisms change. The mathematics doesn't.

On 16 April 1993, three months into the Clinton administration, the White House announced a new encryption standard for American telephones. It arrived on a tamper-resistant chip, used a cipher the National Security Agency refused to publish, and had one distinguishing feature: a copy of every key it generated would be held by the government, split between two escrow agencies and reassembled on production of a warrant.

It was called the Clipper Chip. Almost every argument you will hear this year about encryption, child safety and lawful access was made — for and against — in the three years that followed.

Australia legislated its version in 2018. Britain is fighting Apple over its version now. The EU has been arguing about Chat Control for four years. The engineering differs each time. The demand underneath does not — and neither does the answer the technical community keeps returning.

This fight is thirty years old — from the Clipper Chip to Chat Control

The flaw was never in the encryption

The design was genuinely clever. The chip ran a classified 80-bit cipher called Skipjack, when the commercial standard, DES, used 56 — so on paper, users were offered stronger encryption than they could otherwise buy. The catch sat in a small block of data sent at the start of every call: the Law Enforcement Access Field, or LEAF, carrying the session key encrypted under a key unique to that chip. Split that unit key between two escrow agents, hold it until a warrant arrives, and you have wiretapping that never touches the cipher.

Then, in mid-1994, AT&T Bell Labs researcher Matt Blaze published Protocol Failure in the Escrowed Encryption Standard. Blaze did not break Skipjack. He didn't need to. He found the LEAF was validated only by a 16-bit checksum — small enough that a modified device could generate values at random until one passed. Two such units could hold a conversation that was properly encrypted, looked legitimate to any Clipper device on the other end, and could not be decrypted by the escrow agents. Escrow became optional for the sophisticated user it was designed to catch, and stayed fully effective against everyone else.

Note the shape of that failure, because it recurs in every scheme since. The cryptography was sound. The access mechanism bolted to it was not. Exceptional access doesn't weaken the mathematics; it adds a second, messier system beside it — and that is where the bugs live. That, plus an industry that refused to buy it, killed Clipper by 1996.

The quieter front: making everyone's security worse on purpose

While Clipper failed loudly, a second policy did the real damage quietly. Through the 1990s, strong cryptography was classified in the United States as a munition, exported under the same regime as weapons systems. Software sold outside America had to be crippled by design: 40-bit symmetric keys, 512-bit RSA. Vendors, unwilling to maintain two codebases, shipped one product containing both the strong and the deliberately weakened "export-grade" ciphers, with the weak ones switched off.

The controls were relaxed from 1996 and gone by 2000. The weak code stayed in the world's software, dormant, for another fifteen years — until researchers disclosed FREAK in March 2015, which let an attacker sitting between a browser and a server force both ends back down to export-grade RSA and factor the key for about a hundred dollars of cloud compute. Two months later came Logjam, the same trick applied to Diffie-Hellman.

Australians should know where one of those detonations landed. During the 2015 NSW state election, iVote — then the largest online voting deployment ever attempted, with 280,000 ballots — loaded analytics code from a server vulnerable to FREAK. Vanessa Teague of the University of Melbourne and J. Alex Halderman of the University of Michigan showed that an attacker in the right network position could have altered votes while the voter's screen displayed exactly what they intended. Around 66,000 votes were cast before the Electoral Commission pulled the code. At least one seat was decided by a smaller margin than that.

Nobody in Washington in 1993 intended to expose an Australian election in 2015. That is the point. Deliberate weaknesses do not stay in the hands they were built for, and they do not expire when the policy does.

Australia had its own crypto war — and its own answer

We were not spectators. In 1996, the Attorney-General's Department commissioned a review of Australian encryption policy from Gerard Walsh, a former deputy director-general of ASIO — hardly a man who could be accused of being soft on interception.

Delivered on 10 October 1996, its central finding was that Australia should not follow the United States into key escrow, and that legislating on cryptography then had no compelling justification. It recommended targeted alternatives instead — compelled disclosure of keys under warrant, penalties for obstruction, authorised device access — under oversight.

What happened next is the memorable part. The report was listed for sale by the Australian Government Publishing Service in January 1997 and pulled three weeks later, after Electronic Frontiers Australia asked why nobody could actually buy it. EFA obtained a heavily redacted copy under FOI. In February 1999, libraries were sent a notice recalling their deposit copies and asking the National Library to delete the catalogue record.

Australia's own expert review, written by a career intelligence officer, reached the cryptographers' conclusion — and was withdrawn from circulation.

Why the arguments come back word for word

Compare the scripts across thirty years and the resemblance stops being amusing.

1993: the capability is only for law enforcement, access requires a warrant, and criminals will otherwise operate beyond the reach of the law.

2018: Australia's Assistance and Access Act passes in the final sitting days before Christmas, after a minister accuses the opposition of being willing to let terrorists and paedophiles continue their work. Labor drops its amendments for a promise to fix the Act in the new year. The Independent National Security Legislation Monitor later recommends 33 changes — chief among them that compulsory notices be authorised independently, rather than by the agency that wants them. That reform still has not been legislated.

2023–2026: the UK's Online Safety Act carries a power for Ofcom to require "accredited technology" to scan private messages. Ofcom finalised its guidance in May 2026 and has issued no notice, so the power simply waits. In Europe, Parliament voted 307–306 in March 2026 to let the interim Chat Control regime lapse; it expired in April, was revived in July when a rejection vote fell short of the majority required, and now runs to 2028. Each of these was argued, at least in part, on the ground of child safety.

The mechanism changes each time — key escrow, then compelled capability, then client-side scanning, then the silent extra participant in your group chat. The requirement never does: somebody who is not a participant in your conversation must be able to read it. Everything else is implementation detail.

The technical answer hasn't moved in three decades

In 1997, eleven senior cryptographers — Rivest, Diffie, Schneier, Blaze, Anderson and Neumann among them — published The Risks of Key Recovery, Key Escrow, and Trusted Third-Party Encryption, concluding that exceptional-access systems would be inherently less secure, more complex and more expensive than systems without them. In 2015 most of the same people reconvened, published Keys Under Doormats, and reached the same conclusion — adding that the damage would now be far worse, because the world had wired itself to encryption in the intervening twenty years. More than 500 researchers have since said the same of Chat Control.

Three findings have survived every round:

  • Complexity is the enemy of security. Blaze found his flaw in the bolt-on, not the cipher.

  • The mechanism cannot check who is using it. It cannot read a warrant. Once built, it is available to an insider, an intruder, or another government with paperwork of its own. Chinese operators inside the lawful-intercept systems US telcos were legally required to build — Salt Typhoon — is what that looks like.

  • You cannot scope it to one jurisdiction. A capability built for Canberra exists in Beijing and Moscow the moment it exists at all.

What this means for Australian organisations

None of this says investigators face no problem. They do. It says the mechanism matters more than the intention — and the useful questions have not changed since 1993. Who authorises the power: an independent decision-maker, or the agency that wants it? Is the purpose fixed in the Act, or extendable by ministerial instrument? Does it sunset? Can anyone check?

The export-controls era adds a practical lesson: weaknesses outlive the policies that created them, and the ratchet only turns one way.

  • Collect less. Data you never held cannot be compelled out of you, or stolen from you.

  • Know your exposure. The Assistance and Access Act's definition of a designated communications provider is broad. Decide now who would handle a notice, and where legal advice comes from.

  • Retire legacy cryptography deliberately, rather than waiting for the next FREAK to find it.

  • Treat platform choice as a security decision. Favour vendors with audited clients and key transparency.

A final word

The useful thing about a thirty-year record is that it is a record. This industry was told in 1993 that key escrow was safe; it wasn't. Told that export-grade ciphers were a contained compromise; they surfaced inside an Australian election twenty years later. Told in 2018 that compelled technical capability would be proportionate and independently overseen; those recommendations are still on a shelf.

Each new proposal insists the past isn't relevant: this one is targeted, the technology has moved on. The technology has. The problem hasn't. A door that opens for one set of hands is still a door.

Xiph Cyber has argued this case, and supplied the tools behind it, for a decade — hardened handsets, end-to-end encrypted communications, security keys and the consulting to deploy them properly. To talk about where your organisation sits under Australia's assistance and access regime, contact us at enquiries@xiphcyber.com.

Further reading


Posted in: Security