Two Think Minimum
Two Think Minimum

2025 TPI Aspen Forum: Privacy and Governmental Surveillance

2025 TPI Aspen Forum: Privacy and Governmental Surveillance by Technology Policy Institute

Featured Speakers

Technology Policy Institute Host

Topics Discussed

Episode Summary

Executive Summary: A panel at TPI Aspen examined how AI is reshaping cybersecurity and privacy policy, with a focus on encryption, child online safety, state privacy laws, and government surveillance. Speakers argued that strong encryption is essential for individual security and national resilience, while warning that backdoors, broad age-verification mandates, and fragmented state rules can weaken privacy, create honeypots of sensitive data, and burden businesses without meaningfully improving safety.

Main Topics: AI, cybersecurity, and privacy as a shared policy challenge (Priority: 5/5): The panel framed AI as both a defense tool and a source of new vulnerabilities, pushing cybersecurity and privacy to the center of tech policy and making surveillance concerns unavoidable. Salt Typhoon and the case for encryption (Priority: 5/5): Jeff Green described the PRC-linked intrusion into U.S. wireless infrastructure and used it to argue that encrypted communications are the most practical individual defense when networks are compromised. Backdoors, lawful access, and the anti-encryption debate (Priority: 5/5): The panel warned that government demands for exceptional access or master keys undermine security for everyone and often lead to less cooperation rather than more effective enforcement. Child online safety vs. privacy harms (Priority: 5/5): Jennifer Huddleston argued that many age-verification and parental-consent proposals create large-scale data collection, identity risks, and barriers for vulnerable users, while not reliably protecting kids. Federal privacy law and the state patchwork problem (Priority: 4/5): Speakers supported a national privacy framework to replace inconsistent state laws, noting consumer confusion, compliance burdens, and a patchwork that can stifle innovation. Cybersecurity regulation, critical infrastructure, and public-private coordination (Priority: 4/5): The panel discussed whether the federal government should set cybersecurity baselines for critical sectors while preserving flexible, standards-based approaches like NIST and information-sharing protections. Europe’s regulatory spillover and security risks (Priority: 4/5): The discussion criticized the UK, EU, and other European rules as potentially weakening encryption, device security, and browser protections, with global consequences for users and platforms.

Key Arguments: Encryption is not optional infrastructure; it is the core mechanism that protects consumer, business, and national-security data across communications, devices, and cloud services. The Salt Typhoon intrusion showed that adversaries can exploit telecom infrastructure without compromising user devices directly, making network-level encryption and hardening essential. Backdoors created for law enforcement, child safety, or intelligence access do not remain limited to good actors and create systemic vulnerabilities for criminals and foreign adversaries. Age verification and verifiable parental consent schemes often require collection of government IDs, biometrics, or parent-child identity data, creating large honeypots of sensitive information. State-by-state privacy rules create confusion for consumers and heavy compliance costs for businesses, especially small firms, while failing to match the interstate nature of the internet. A federal privacy framework is preferable to fragmented state laws, but cybersecurity should remain more standards-based and flexible rather than rigidly codified. Regulated sectors often have better security, so the federal government should still help set cybersecurity baselines for critical infrastructure and use purchasing power and standards to improve security. Europe’s DMA and related rules may unintentionally weaken security by mandating interoperability and changes that expose notifications, browser internals, or other sensitive pathways. Post-quantum cryptography planning must start now because deployment cycles are long and the transition may arrive faster than organizations expect. Data collected for safety purposes is itself a target, so privacy policy must account for breach risk, misuse, and the real-world harms to dissidents, whistleblowers, abuse survivors, and families.

Data Points: State consumer privacy frameworks: 19 to 26 - The panel estimated the number of U.S. states with their own consumer data privacy frameworks. Age verification data exposure: 4 billion apps - Huddleston described app-store-based age verification schemes as potentially forcing sensitive age data to be shared across billions of apps. Apps that are small businesses: 90% - Huddleston said most apps are small businesses, highlighting the compliance burden of age-verification mandates. Estimated compliance cost: $290 billion - Huddleston estimated that updating 4 billion apps at roughly $10,000 each would create a massive aggregate compliance burden. Parent concern about child privacy online: 90% - Green cited survey data suggesting most parents are concerned about protecting children’s privacy, identity, and safety online. Typical deployment time for a new encryption algorithm: 10 to 15 years - Green said NIST-related observations showed that deploying new cryptographic algorithms can take a decade or more. Mobile phishing share of attacks: 82% - Huddleston cited Zimperium data claiming most phishing attacks are mobile phishing.

Pivotal Quotes: "I’ve always viewed security and privacy as the flip side of the same coin." — Jeff Green: Green opened by linking the two topics and arguing for a pro-privacy security agenda. "There’s never been a back door created for the good guys that doesn’t get abused by the bad guys." — Jim Kohlenberger: Kohlenberger used this line to warn against government backdoors into encrypted systems. "Law is static, technology is dynamic." — Jennifer Huddleston: Huddleston explained why one-size-fits-all privacy rules can quickly become outdated and harmful.

Implications: Listeners should expect privacy, encryption, child-safety, and cyber policy to converge. The panel favors national privacy rules, flexible cybersecurity standards, and strong encryption over backdoors or broad data-collection mandates.

🔓 Sign Up for Unlimited Episode Search

About Two Think Minimum

Podcast of the Technology Policy Institute of Was…

View all episodes from Two Think Minimum