Encryption Isn't Ending Online Investigations. It's Transforming Them.
Encryption has become one of the most divisive issues in child safety circles. And I mean genuinely divisive, not just the usual policy disagreements.
On one side, you have organizations and investigators who see encryption as a threat. Their argument: when platforms encrypt messages end-to-end, they lose the ability to scan for abuse material. No scanning means fewer CyberTipline reports. Fewer reports means more kids slipping through the cracks.
For groups that have spent decades building detection systems, watching those systems get shut out feels like a major step backward.
On the other side, you have privacy advocates, security researchers, and a growing number of child safety professionals who see encryption differently. Their argument: encryption protects vulnerable users (including abuse survivors, at-risk youth, and whistleblowers) from hackers, stalkers, and authoritarian surveillance. Weakening encryption to catch predators also weakens it for everyone else. And backdoors, once created, don't stay in the hands of the good guys.
Both sides genuinely care about protecting kids. That's what makes this so complicated.
So when TikTok announced a few weeks ago that it won't be adding end-to-end encryption to its direct messages, framing it as a safety decision, I paused.
Because here's what that framing obscures: not encrypting messages doesn't just mean TikTok can detect abuse. It also means TikTok (and potentially hackers, bad actors, or government requests) can access every private conversation on the platform.** For the millions of teenagers using TikTok DMs, that's a real vulnerability. **
The "we're keeping you safe" messaging sounds protective, but it's also a company choosing to retain access to user data rather than securing it.
The encryption debate isn't really about whether we care about kids. It's about which risks we're willing to accept, and who bears those risks.
I work with Internet Crimes Against Children investigators through the ICAC training program at Zero Abuse Project. And the reality of how these cases actually unfold is far more complex than either side of this debate often acknowledges.
It's also (I dare say) far more encouraging.
Where Investigations Actually Start
Most people assume child exploitation investigations begin with someone reading a suspicious message.
They don't.
Many investigations start with reports sent to the CyberTipline, operated by the National Center for Missing & Exploited Children. Tech companies send these reports when they detect suspected child sexual abuse material or exploitative behavior on their platforms.
In 2023, we saw 36 million reports. That went down to 20.5 million reports in 2024 (29.2 million incidents), with NCMEC attributing part of the decline to encryption adoption.
But here's what those reports usually contain. Not full chat transcripts. Instead, investigators get things like account identifiers, IP addresses, uploaded images or videos, timestamps, platform activity logs.
Digital fingerprints. Not private conversations.
The Evidence Trail That Actually Matters
Modern investigations rely on a web of signals, and platforms use multiple detection methods to identify exploitation before it escalates.
Hash matching is one foundational tool. A hash is essentially a digital fingerprint of an image or video. Organizations maintain databases of hashes tied to previously identified abuse material. When someone uploads a file, platforms compare it against those databases. Match found? The system flags it and generates a report.
But that's not the only detection happening. Platforms also scan conversations for keywords and patterns associated with grooming and trafficking. Tools like Thorn's Safer Predict use AI to identify text-based harms, including grooming, discussions of sextortion, and potential offline exploitation. Thorn's Natural Language Processing algorithms can analyze conversations on social media platforms, chat rooms, and messaging apps, looking for patterns of speech indicative of grooming tactics, such as attempts to isolate a child, pressure them into secret-keeping, or solicit explicit material. *Source: *NCACIA
This is how many CyberTipline reports were generated before end-to-end encryption entered the conversation. Platforms were reviewing message content, flagging suspicious language, and reporting it. That capability is what encryption affects most directly.
Then there's metadata. Information about communication rather than the communication itself. When accounts interacted. What devices were used. Where logins originated. How networks of users connect to each other. Even when message content is fully encrypted, these patterns can reveal entire networks of activity.
And in many cases, investigators recover evidence through device forensics. Examining phones and computers for cached files, deleted images, application data. The digital artifacts people leave behind.
The Part Nobody Talks About
Here's something rarely discussed in the public encryption debate:
Investigators often enter the conversations themselves.
In many exploitation cases, investigators conduct undercover operations, posing as minors online to identify offenders directly. When that happens, encryption becomes completely irrelevant. Because investigators are already participants in the communication.
Some of the most significant online exploitation cases in recent years? Built through exactly these kinds of operations.
What Encryption Actually Changes
This is why the encryption conversation inside law enforcement is more nuanced than headlines make it seem.
Some investigators worry that encrypted messaging could reduce the number of reports generated by tech platforms. That's a legitimate concern.
But others recognize something equally important. Strong encryption protects victims, investigators, and everyday users from hacking, surveillance, and data breaches.
What encryption actually removes is a shortcut. It forces investigators to rely more heavily on digital forensics, behavioral analysis, and technical investigative techniques. It raises the bar.
Meeting That Higher Bar
At Zero Abuse Project, this is exactly what our work focuses on. Helping investigators and prosecutors meet that higher bar.
ICAC cases today involve a rapidly evolving mix of technologies. Encrypted messaging platforms. Cryptocurrency payments. Cloud storage services. Anonymous online communities. AI-generated content.
Investigating these crimes requires training that goes far beyond traditional methods.
Through our ICAC training programs and digital investigation courses, we work with professionals across the country to develop the technical skills modern cases demand. Cloud forensic evidence. Cryptocurrency tracing. Open-source intelligence. The NOVA Tool that integrates multiple OSINT capabilities into one interface.
Because protecting children online increasingly depends on investigators who understand the technologies shaping the crimes themselves.
The Real Question
Encryption will continue to expand across the internet. That trend isn't reversing.
So the real question isn't whether encrypted platforms exist.
The real question is whether investigators have the tools and training to investigate crimes in an encrypted world. History tells me they do.
Every major technological shift (peer-to-peer networks, social media, encrypted apps) has required investigators to develop new skills and new methods. Each time, they've adapted.
Encryption doesn't end investigations. It pushes them to become smarter. And that's exactly what we're building toward.
_2025.png)