Infrastructure September 25, 2026 bearish ⇧ 514 pts across 2 threads

UK's Secret Backdoor Orders: E2EE Under Real Legal Threat

A detailed article on two-tier encryption in the UK drew a sharp HN thread about the Investigatory Powers Act and its ability to compel companies to build backdoors into encrypted products, with a legal gag preventing disclosure. Commenters flagged that this is functionally outlawing E2EE for any company operating under UK jurisdiction, and pointed specifically at SimpleX Chat, which is based in the UK despite having open-source clients and reproducible builds.

The pattern here connects to a broader anxiety about infrastructure jurisdiction. The same concern has appeared repeatedly across threads about Cloudflare blocking Docker pulls in Spain due to football broadcast injunctions, and older discussions about cloud providers suspending accounts without notice. The common thread: legal and regulatory pressure on infrastructure layers is becoming a practical engineering problem, not just a policy debate.

The counterpoint raised is that SimpleX's architecture, where the server holds no plaintext and clients are open and auditable, may be more resilient than average. But the risk isn't just technical; it's that a UK court could compel the company to modify future releases in secret.


So what?

Any founder building a product that handles sensitive user data needs to know where their encryption and key management infrastructure is legally domiciled. UK jurisdiction is now a material risk factor for E2EE products. If your product makes privacy guarantees to users, you need legal counsel to audit whether those guarantees hold under the laws of every country your infrastructure touches.

Read these