EFF warns trusted execution environments cannot match encryption security for AI in messaging
The Electronic Frontier Foundation argues that server-side TEEs, despite industry promises, remain fundamentally weaker than end-to-end encryption for protecting data sent to cloud servers for AI processing.
What to know
- EFF argues that trusted execution environments (TEEs) used by Apple, Google, and WhatsApp for cloud-side AI processing are fundamentally weaker than end-to-end encryption because they rely on engineering rather than mathematical guarantees.
- The analysis notes that while TEEs provide more security than processing data 'in the clear,' they have seen 'multiple cracks and hacks every year,' whereas encryption algorithms benefit from decades of collaborative mathematical research.
- EFF recommends that user devices should never automatically send private data to TEEs without explicit user control, despite industry claims about the security of implementations like Apple's Private Cloud Compute, Google's Private AI Compute, and WhatsApp's Private Processing.
“In practice, we've seen multiple cracks and hacks every year that show that it is possible to get at that data.”
EFF (Portnoy, Klosowski), Authors · EFF Deeplinks ↗
Electronic Frontier Foundation (EFF) Digital rights and privacy organizationErica Portnoy EFF authorThorin Klosowski EFF authorApple Tech companyGoogle Tech companyWhatsApp Messaging platform
How it unfolded 4 developments, newest first · click a bar or a number to jump articlesposts
-
4
EFF analysis detailedTEEs rely on engineering, not math; encryption algorithms have decades of study
A Hacker News post surfaced the full EFF article, which explains that the fundamental security difference is that encryption relies on mathematics proven by decades of collaborative research, whereas TEEs depend on engineering and have seen 'multiple cracks and hacks every year.' The article notes that users' devices should never automatically send data to TEEs.
“That's because while encryption relies on math, TEEs rely on engineering to provide their security. Standard encryption algorithms are created by years-long processes collaboratively produced by mathematicians around the world and are based on problems that have been studied for decades. The math is reliable, and there is no shortcut to…”
— EFF (Portnoy, Klosowski) - 1 day quiet
-
3
EFF reframes debate as companies seeking hardware protections for private AI processing
The EFF continued social amplification, framing the issue as a tension between companies' desire to use hardware security to process private user data for AI features versus the privacy cost of that approach.
“Companies want to use hardware protections in the cloud to process your private data for AI features. But how much security do you give up in the process?”
— EFF, Digital rights organization · source -
E
Companies want to use hardware protections in the cloud to process your private data for AI features. But how much security do you give up in the process? https://www. eff.org/deeplinks/2026/09/secu re-messaging-and-ai-remain-conflict-despite-promise-tees
-
-
2
EFF amplifies core finding on Mastodon: TEEs are fundamentally less secure than E2E encryption
The EFF's official Mastodon account shared the analysis, emphasizing the central claim that while TEEs may be adequate for some uses, they are inherently weaker security mechanisms than end-to-end encryption or local computation.
“While trusted execution environments in the cloud might be secure enough for many cases, they're fundamentally less secure than end-to-end encryption or local computation.”
— EFF -
E
While trusted execution environments in the cloud might be secure enough for many cases, they're fundamentally less secure than end-to-end encryption or local computation. https://www. eff.org/deeplinks/2026/09/secu re-messaging-and-ai-remain-conflict-despite-promise-tees
-
-
1
EFF publishes analysis of TEEs versus end-to-end encryption in messaging AI
The Electronic Frontier Foundation, through authors Erica Portnoy and Thorin Klosowski, published a detailed analysis examining whether trusted execution environments (TEEs) adequately protect private data when AI features require cloud-side computation in messaging platforms like Signal, WhatsApp, and encrypted RCS.
“Because of that, a user's device should never automatically send data to a TEE.”
— EFF (Portnoy, Klosowski), Authors · source -
first by EFF Deeplinks, 8d ago
-