Privacy

What "end-to-end encrypted" promises, and what it leaves out

End-to-end encryption keeps the service itself from reading your messages. It doesn't hide who you talk to, protect an unlocked phone, or cover backups unless you turn that on.

"End-to-end encrypted" appears on messaging apps, cloud storage and video calls. It's a real and valuable protection, but it promises one specific thing, and the gaps around it are where most privacy problems actually happen.

The promise

With end-to-end encryption, a message is encrypted on your device and can only be decrypted on the devices of the people you send it to. The keys live on those devices. The company running the service relays the scrambled message but can't read it. Neither can anyone who breaks into its servers or demands the data from it.

Without end-to-end encryption, a message is usually still encrypted on its way to the server, but the company decrypts it there and can read, scan or hand it over.

What it doesn't cover

Who you talk to, and when

Encryption protects the content of a message. The service may still see who sent it to whom, when, how often and from where. This information, called metadata, can reveal a great deal on its own. How much a service keeps varies widely. Signal, for example, built a feature called sealed sender so that its servers don't learn who sent a message. Most services don't go that far.

Your backups

Many apps back up your chat history to a cloud service, and the backup may not be end-to-end encrypted even when the chats are.

  • WhatsApp offers end-to-end encrypted backups, but you have to switch them on in the backup settings.
  • Apple encrypts many iCloud categories end to end by default, and more of them, including device backups, only if you turn on Advanced Data Protection, available since iOS 16.2. Even then, Apple lists iCloud Mail, Contacts and Calendars as not end-to-end encrypted, because they have to work with standard email and calendar systems.

If your backup isn't end-to-end encrypted, your messages are only as private as that backup.

The devices at each end

Encryption ends at the screen. Anyone holding your unlocked phone, malware on it, or the person you're writing to can read, screenshot or forward what you send. "End-to-end" says nothing about the ends themselves.

Whether you're talking to the right person

The app trusts that the keys it received really belong to your contact. Good apps let you check: Signal calls it a safety number and WhatsApp a security code. You compare it in person or over another channel. For most conversations this is overkill. For a sensitive one, it's the step that turns "encrypted" into "encrypted to the right person".

A quick checklist

  • Prefer apps that encrypt end to end by default, not only in an optional "secret chat" mode.
  • Turn on encrypted backups where they exist, or turn backups off for the chats that matter.
  • Use a screen lock, and keep your phone's software up to date.
  • Use disappearing messages for conversations you don't need to keep.
  • For a sensitive contact, verify their safety number or security code once.

End-to-end encryption is one of the best protections you can have. It's also a precise one: it keeps the company out of your messages, and leaves the rest to you.

No comments yet