Summary
Otmar Lendl’s core message is that lawful access to encrypted data cannot be “squared” by inventing cleverer cryptography alone: the conflict is a political, legal, operational, and sovereignty problem rooted in the fact that strong mathematics limits state power. He opens by framing the clash plainly. Law enforcement wants to wiretap suspects, read messages, and open devices to retrieve chat logs and files. Cybersecurity, by contrast, aims to ensure that private communications and encrypted laptops or phones remain unreadable to outsiders, including when devices are lost or stolen. Lendl situates the debate in a long history, citing the Clipper chip, the Crypto Wars, and “going dark,” then explains what is currently new: the European Commission’s effort to define a roadmap for lawful access while safeguarding cybersecurity and fundamental rights.
He then describes the EU process around this unresolved tension. DG Home represents the policing side, DG Connect the cybersecurity side, and the Commission’s documents effectively state that Europe wants decryption and lawful access without weakening security or rights. Lendl says an expert group was created to survey options, not to decide policy. Its job is to present possible approaches with pros and cons so that normal political processes can choose a path. He emphasizes that there will be no perfect solution for everything. After expecting to spend his time on post-quantum cryptography, MLS, Signal’s double ratchet, and other technical proposals, he concludes that this is “completely the wrong approach”: the issue is not solvable through different cryptography.
The most important analytical turn is his claim that encryption changes the hierarchy between state power and citizens. In the physical world, the state has a monopoly on violence: police can break into houses and safes, and the state can escalate force. In the virtual world, however, mathematics is above legislation; politicians cannot pass laws that override cryptographic reality. “Math beats police,” meaning well-implemented cryptography can prevent law enforcement from accessing data used by both ordinary citizens and criminals. Lendl explains that police therefore become creative, using unlocked-device seizures, sensor tricks, filming password entry, brute force attempts, backup searches, and social engineering. He notes that techniques warned about in the context of Russian actors targeting Signal accounts resemble techniques police may use as well.
Lendl then examines the rise of private exploit and access vendors as modern “mercenaries” for states, naming Cellebrite, GreyKey, XRY, NSO Group, Paragon, and Cytrox. He argues that relying on such companies is undesirable because it is expensive, creates sovereignty concerns, and raises abuse and oversight problems, citing Pegasus as an example of a bad track record. He acknowledges that police report a genuine operational need and that encryption can hinder investigations, but he challenges nostalgia for the “old good days” of wiretapping. The provided transcript closes as he explains why lawful-access design is hard in practice: over-the-top providers such as WhatsApp, Signal, and Telegram are built without geography in mind, users and servers cross borders, VPNs complicate jurisdiction, and any proposed solution must define not only what should work but also what must never work.
Key Topics
5 key topics from Otmar Lendl at ONE Conference. Thicker branches were mentioned more often in the talk.
Key Takeaways
- Separate cryptographic feasibility from legal and political trade-offs.
- Define explicitly which lawful-access cases must not work.
- Assess mercenary access vendors for cost, sovereignty, and abuse risk.
- Design policy for cross-border providers, users, servers, and warrants.
- Avoid assuming old telephone wiretap models transfer to encrypted services.
“The laws of mathematics or cryptography are higher in hierarchy than the laws that politicians can pass.”

Otmar Lendl
Up Next


Next in agenda
Be a better ally.
MAlso on cybersecurity
Police Hack and Pass-the-Cookie: No Crumbs, Full Access



Also on cryptography
