> I bet I could come up with an encryption scheme that allows decryption for warrant holders only, but the scheme to decrypt will be very onerous for the warrant holder and will require manual retrieval of air-gapped asymmetric keys and lengthy background checks to establish trust (i.e. is this person who they say they are and did the judge really grant a warrant, etc.).
Whilst in theory ideas like these work, they don't in practice.
When security is tightened, and oversight is made more difficult, we regularly see the players involved skirting the system because they're human and don't think that they're really doing anything wrong.
Stuxnet was a while ago, but pierced an air-gapped network through a means that... Shouldn't have been possible. It was possible because of the failure of the humans involved. A factor that can't be removed.
You would find keys being surreptitiously shared over insecure shares, and getting caught up in other data leaks. Two or more departments sharing keys between employees to save some time and effort. Or forgetting to shred a key securely once it has been accessed. It doesn't take long until everyone in the department ends up with a key - and then each of those is a weak point.
The NSA has had repeated problems with their processes being avoided and ignored by employees skirting oversight to stalk their ex's, by doing things like listening to their phone calls - which supposedly required a warrant. [0]
You can't trust the people involved.
Now, there's a very, very simple way to avoid all of these problems. Secure the data to the fewest number of people required. Placing the responsibility of keeping the keys secure with the direct stakeholders.
An end-to-end encrypted chat still has the possibility of keys being leaked. But only the people who will be directly impacted are involved. You don't need a large and complicated scheme, and it is dead simple to implement, comparatively. You only have to trust the people involved, not swathes of departments.
[0] https://en.wikipedia.org/wiki/LOVEINT