On 3 December 2024, officials from the FBI and CISA recommended that people move to encrypted communications on their mobile devices, in response to the continuing intrusion at AT&T, Verizon, Lumen and other providers.
Read plainly: agencies of a government that requires carriers to maintain interception capability advised the public to adopt communications those carriers cannot hand over.
The Advice Is Correct, Which Is The Point
If an adversary is inside a carrier’s network, then anything the carrier can read, the adversary can read. End-to-end encryption removes the carrier from the equation, so it removes the adversary that is standing in the carrier.
It is straightforwardly the right advice for the threat. It is also an admission about the architecture: the recommended mitigation for a compromised carrier is not to fix the carrier but to route around it.
What It Concedes
That the intrusion could not be quickly evicted. Advice to change your own behaviour is what a defender issues when it cannot change the thing that is broken.
This corpus has recorded the same pattern from private organisations: a notification offering credit monitoring is the same shape, an action transferred to the affected party because the responsible party has nothing else to offer.
It Sits Directly Against The Position On Encryption
Law enforcement agencies in several countries have argued for years that end-to-end encryption impedes investigations and that providers should retain a means of access.
This desk records the tension rather than resolving it, because resolving it is a policy judgement and this is a corpus of incidents. What the incident establishes is narrow and hard to argue with: at the moment the interception architecture failed, the advice from the agencies that use it was to stop relying on it.
Based on the reported December 2024 guidance from FBI and CISA officials and contemporaneous coverage, listed below. Graded high: the advice is official and was widely reported. This file characterises the advice and the tension it sits in; it does not take a position on encryption policy, and no agency position beyond the reported guidance is attributed here. Corrections: corrections@forensicpost.com.