conv.

All stories
AIQuiet 6d · day 9

EFF warns trusted execution environments cannot match encryption security for AI in messaging

The Electronic Frontier Foundation argues that server-side TEEs, despite industry promises, remain fundamentally weaker than end-to-end encryption for protecting data sent to cloud servers for AI processing.

What to know

  • EFF argues that trusted execution environments (TEEs) used by Apple, Google, and WhatsApp for cloud-side AI processing are fundamentally weaker than end-to-end encryption because they rely on engineering rather than mathematical guarantees.
  • The analysis notes that while TEEs provide more security than processing data 'in the clear,' they have seen 'multiple cracks and hacks every year,' whereas encryption algorithms benefit from decades of collaborative mathematical research.
  • EFF recommends that user devices should never automatically send private data to TEEs without explicit user control, despite industry claims about the security of implementations like Apple's Private Cloud Compute, Google's Private AI Compute, and WhatsApp's Private Processing.

“In practice, we've seen multiple cracks and hacks every year that show that it is possible to get at that data.”

EFF (Portnoy, Klosowski), Authors · EFF Deeplinks ↗

Electronic Frontier Foundation (EFF) Digital rights and privacy organizationErica Portnoy EFF authorThorin Klosowski EFF authorApple Tech companyGoogle Tech companyWhatsApp Messaging platform

EFF warns trusted execution environments cannot match encryption security for AI in messaging
eff.org

How it unfolded 4 developments, newest first · click a bar or a number to jump articlesposts

Peak 1 piece in two hours at Sep 18, 4 PM; 4 pieces over 9 days (1 article · 3 posts) Sep 18, 4 PM — 1 piece · 1 article — Newswires 1Sep 18, 6 PM — 1 piece · 1 post — Mastodon 1Sep 18, 8 PM — quietSep 18, 10 PM — quietSep 19, 12 AM — quietSep 19, 2 AM — quietSep 19, 4 AM — quietSep 19, 6 AM — quietSep 19, 8 AM — quietSep 19, 10 AM — quietSep 19, 12 PM — quietSep 19, 2 PM — 1 piece · 1 post — Mastodon 1Sep 19, 4 PM — quietSep 19, 6 PM — quietSep 19, 8 PM — quietSep 19, 10 PM — quietSep 20, 12 AM — quietSep 20, 2 AM — quietSep 20, 4 AM — quietSep 20, 6 AM — quietSep 20, 8 AM — quietSep 20, 10 AM — quietSep 20, 12 PM — quietSep 20, 2 PM — quietSep 20, 4 PM — quietSep 20, 6 PM — quietSep 20, 8 PM — quietSep 20, 10 PM — quietSep 21, 12 AM — quietSep 21, 2 AM — quietSep 21, 4 AM — quietSep 21, 6 AM — quietSep 21, 8 AM — 1 piece · 1 post — Hacker News 1Sep 21, 10 AM — quietSep 21, 12 PM — quietSep 21, 2 PM — quietSep 21, 4 PM — quietSep 21, 6 PM — quietSep 21, 8 PM — quietSep 21, 10 PM — quietSep 22, 12 AM — quietSep 22, 2 AM — quietSep 22, 4 AM — quietSep 22, 6 AM — quietSep 22, 8 AM — quietSep 22, 10 AM — quietSep 22, 12 PM — quietSep 22, 2 PM — quietSep 22, 4 PM — quietSep 22, 6 PM — quietSep 22, 8 PM — quietSep 22, 10 PM — quietSep 23, 12 AM — quietSep 23, 2 AM — quietSep 23, 4 AM — quietSep 23, 6 AM — quietSep 23, 8 AM — quietSep 23, 10 AM — quietSep 23, 12 PM — quietSep 23, 2 PM — quietSep 23, 4 PM — quietSep 23, 6 PM — quietSep 23, 8 PM — quietSep 23, 10 PM — quietSep 24, 12 AM — quietSep 24, 2 AM — quietSep 24, 4 AM — quietSep 24, 6 AM — quietSep 24, 8 AM — quietSep 24, 10 AM — quietSep 24, 12 PM — quietSep 24, 2 PM — quietSep 24, 4 PM — quietSep 24, 6 PM — quietSep 24, 8 PM — quietSep 24, 10 PM — quietSep 25, 12 AM — quietSep 25, 2 AM — quietSep 25, 4 AM — quietSep 25, 6 AM — quietSep 25, 8 AM — quietSep 25, 10 AM — quietSep 25, 12 PM — quietSep 25, 2 PM — quietSep 25, 4 PM — quietSep 25, 6 PM — quietSep 25, 8 PM — quietSep 25, 10 PM — quietYesterday, 12 AM — quietYesterday, 2 AM — quietYesterday, 4 AM — quietYesterday, 6 AM — quietYesterday, 8 AM — quietYesterday, 10 AM — quietYesterday, 12 PM — quietYesterday, 2 PM — quietYesterday, 4 PM — quietYesterday, 6 PM — quietYesterday, 8 PM — quietYesterday, 10 PM — quietToday, 12 AM — quietToday, 2 AM — quietToday, 4 AM — quietToday, 6 AM — quietToday, 8 AM — quietToday, 10 AM — quiet 1–234
Sep 19Sep 20Sep 21Sep 22Sep 23Sep 24Sep 25yesterdaynow · 12:54 PM ET
  1. 4

    EFF analysis detailedTEEs rely on engineering, not math; encryption algorithms have decades of study

    A Hacker News post surfaced the full EFF article, which explains that the fundamental security difference is that encryption relies on mathematics proven by decades of collaborative research, whereas TEEs depend on engineering and have seen 'multiple cracks and hacks every year.' The article notes that users' devices should never automatically send data to TEEs.

    “That's because while encryption relies on math, TEEs rely on engineering to provide their security. Standard encryption algorithms are created by years-long processes collaboratively produced by mathematicians around the world and are based on problems that have been studied for decades. The math is reliable, and there is no shortcut to…”
    — EFF (Portnoy, Klosowski)
  2. 1 day quiet
  3. 3

    EFF reframes debate as companies seeking hardware protections for private AI processing

    The EFF continued social amplification, framing the issue as a tension between companies' desire to use hardware security to process private user data for AI features versus the privacy cost of that approach.

    “Companies want to use hardware protections in the cloud to process your private data for AI features. But how much security do you give up in the process?”
    — EFF, Digital rights organization · source
    • eff@mastodon.social

      Companies want to use hardware protections in the cloud to process your private data for AI features. But how much security do you give up in the process? https://www. eff.org/deeplinks/2026/09/secu re-messaging-and-ai-remain-conflict-despite-promise-tees

      eff@mastodon.socialMastodon7d ago5▲view on Mastodon ↗
  4. 2

    EFF amplifies core finding on Mastodon: TEEs are fundamentally less secure than E2E encryption

    The EFF's official Mastodon account shared the analysis, emphasizing the central claim that while TEEs may be adequate for some uses, they are inherently weaker security mechanisms than end-to-end encryption or local computation.

    “While trusted execution environments in the cloud might be secure enough for many cases, they're fundamentally less secure than end-to-end encryption or local computation.”
    — EFF
    • eff@mastodon.social

      While trusted execution environments in the cloud might be secure enough for many cases, they're fundamentally less secure than end-to-end encryption or local computation. https://www. eff.org/deeplinks/2026/09/secu re-messaging-and-ai-remain-conflict-despite-promise-tees

      eff@mastodon.socialMastodon8d ago10▲view on Mastodon ↗
  5. 1

    EFF publishes analysis of TEEs versus end-to-end encryption in messaging AI

    The Electronic Frontier Foundation, through authors Erica Portnoy and Thorin Klosowski, published a detailed analysis examining whether trusted execution environments (TEEs) adequately protect private data when AI features require cloud-side computation in messaging platforms like Signal, WhatsApp, and encrypted RCS.

    “Because of that, a user's device should never automatically send data to a TEE.”
    — EFF (Portnoy, Klosowski), Authors · source
    1. first by EFF Deeplinks, 8d ago

What people are saying 0 voices from 0 sites · best of 2 · verbatim