Not saying this is a good idea, though.
Not saying this is a good idea, though.
Also: We know how CSS, BluRay Master Keys, TSA Keys and other various signing keys fared in the wild.
Note that banning E2EE implies banning encrypted p2p communications entirely. E2EE is a concept that applies only to centralized comms providers where all messages go through a server.
Practically speaking, it's impossible to ban every encrypted protocol (TLS, SSH, ...). It's also (probably) impossible to ban IP communications that don't have an "approved server" participating.
However, comms providers / social networks to date at least manage, authenticate, and introduce users at the serverside. Fully distributed projects have problems with spam. So governments would have to ban comms providers from "allowing" their clients to talk to each other directly and not via the backend. That's a hefty technological restriction, which would block a wide range of protocols (webrtc/SIP, torrents, probably a bunch of other Very Important things I'm not thinking of right now).
Some examples are the code signing keys of most major desktop and mobile operating system vendors, the package signing keys of major Linux distributions, the SSL private keys of most banks and major e-commerce sites, and the certificate signing keys of most SSL certificate issuers.
It’s unreasonable to believe only the government will have access.
Just like it was impossible for the Titanic to sink.
Include privacy or civil rights civilian organizations among the shareholders, such as the ACLU, so that there is an outside check.
If you choose a sufficient and diverse enough set of shareholders, you can reduce the chances that someone could compromise or coerce enough of them to gain access to the government key to less than 1 in N, where N is arbitrarily large. Chose N so that this is less likely than simply brute forcing the key.
Instead we'd see 'ongoing' authorizations on the level of an investigation, a person or team, or a whole sub-organization (modulo clearance / position in that organization). And so you'd have copies of the complete key going around.
But getting Congress (or whatever is equivalent outside the US) to pass an E2E+G law that allows it to be done in such a way seems unlikely. They will go for a way that allows broad use.
[1] You could make it a per-device key, generated on the device itself. The device makes the Shamir secret sharing shares, encrypts them with the public keys of the shareholders, and periodically includes those includes those in the chat metadata.
To decrypt a chat, the government needs to record it, get the encrypted shares out of the chat metadata, get each shareholder to use that shareholder's private key to decrypt their share and then contribute that share for recovery of the actual chat key for that chat.
If they want to decrypt a chat from another device, they'd have to do that all over again for that device.