BlackBerry dismisses claim that Netherlands Forensic Institute cracked its device encryption, suggesting user error or third-party apps may be involved
BlackBerry Devices: Secure As They Have Always Been — There have been recent media reports that police-affiliated groups in the Netherlands …
Context & Ripple Effects
Five days after the [[a:863306|Netherlands Forensic Institute claimed it could read encrypted emails on PGP-equipped BlackBerrys]], BlackBerry has issued a formal denial, attributing any access to user error or third-party apps rather than a break in its own cryptography. The company's entire premium positioning — with governments and enterprises — rests on that distinction.
The dispute lands mid-arc for a vendor already repositioning around security services: weeks later BlackBerry would buy UK firm Encription to build a cybersecurity consulting unit, and months after that, [[a:867919|court documents would reveal Canadian police had held BlackBerry's global encryption key since 2010]] — a disclosure that reframes exactly this kind of vendor denial.
First-order effects
- BlackBerry's government and enterprise buyers must decide whether the NFI finding or the company's user-error explanation better describes their exposure, making this denial a direct defense of the security brand that underpins its BES licensing business.
- Dutch investigators retain their claimed method for reading PGP BlackBerry email regardless of the denial, so law-enforcement access questions shift from 'can they?' to 'how did they?'
Second-order effects
- Rival secure-device makers can market against the ambiguity, while BlackBerry's counter-move is to deepen services credibility — the Encription consulting acquisition converts a reputational fight into a revenue line.
- If forensic agencies conclude vendor denials are unreliable, procurement shifts toward independently audited or self-destructing hardware approaches like the Boeing Black device BlackBerry was helping build with its enterprise service.
Third-order effects
- The pattern here — vendor denies a crack, later records show long-standing key access — points toward a structural credibility gap between marketed encryption and state access, one that resurfaces in BlackBerry's own later handling of the critical QNX flaw disclosed only after talks with CISA.
- Sustained distrust of vendor assurances pushes encryption verification toward third parties: auditors, courts, and regulators become the arbiters of security claims rather than the vendors themselves.
The trend: Encryption assurance is shifting from vendor-marketed guarantees toward externally verified trust, as forensic capabilities and court disclosures repeatedly contradict official denials.