HomeGuidesEncrypted messaging without the myths

Encrypted messaging without the myths

Encrypted messaging is sold to us in two ways, and both of them are wrong. One version says that if you install the right app you become invisible. The other says encryption is pointless because the authorities can break it anyway. The truth sits between the two, and it is far more useful than either slogan.

This guide explains what end-to-end encryption actually protects, what it leaves wide open, and the handful of settings that make the real difference. You do not need to understand any mathematics.

What end-to-end actually means

When a message is end-to-end encrypted, it is locked on your device and unlocked on the recipient’s. The company running the service carries a sealed package it has no key to. If a court orders it to hand over the contents of your conversation, the honest answer is that it cannot, because it never had them.

That is a real protection, and it is the reason this kind of encryption has been argued over in parliaments for more than a decade. It is also narrower than most people assume.

The part nobody advertises: metadata

Encryption hides what you said. It does not hide that you said it. The service still knows which account contacted which account, at what time, how often, from roughly which location and from which device. That is metadata, and it is frequently more revealing than the words themselves.

Intelligence agencies have said for years that metadata alone tells them nearly everything they want to know about a person. One call to a clinic at two in the morning tells a story by itself, and no encryption anywhere hides the fact that the call happened.

Apps differ enormously here, and this is the comparison worth making. Some keep almost nothing — no contact list on their servers, no record of who messaged whom. Others keep a detailed map of your social connections because their business is built on it. Encrypting the message body has become common. Restraint about metadata has not.

What the well-known apps actually do

Signal encrypts everything by default, keeps very little on its servers and hides the sender’s identity from its own infrastructure where it can. It is paid for by a non-profit foundation rather than advertising, which is a useful thing to know when you wonder why an app is free.

WhatsApp also encrypts message contents by default, using the same underlying protocol, but it sits inside a company whose business is data, and it retains far more information about accounts, contacts and connections than Signal does.

Telegram is the biggest misunderstanding in this field. Its ordinary chats — the ones nearly everybody uses, including groups and channels — are not end-to-end encrypted. They are encrypted between your phone and Telegram’s servers, where the company itself can read them. Telegram does offer end-to-end “secret chats”, but you have to start one deliberately, they work only between two people, and they are not available everywhere in the app.

iMessage is end-to-end encrypted between Apple devices, but a conversation with an Android phone drops back to ordinary SMS, which has no protection at all. The colour of the bubble is doing more work than most users realise.

Facebook Messenger spent years without default encryption and has been switching it on for personal chats. The direction is right, and the history is a reminder that “encrypted” sometimes means “encrypted since last year”.

None of this is a ranking of virtue. It is a set of questions you can now ask about any app: is encryption on by default, who holds the keys, and what does the company keep besides the messages?

Backups are where encrypted chats go to die

This is the mistake that quietly undoes everything else. A chat can be perfectly encrypted in transit and then copied, in readable form, into a cloud backup that somebody else can open. If your backup is not locked with a key only you hold, the conversation exists in plain text somewhere, no matter which app you chose.

The fix is usually a single switch, buried in the app’s settings under backup or chat history, that turns on an encrypted backup and asks you to write down a password or a long recovery key. Do it once, keep the key somewhere physical, and the hole closes. Then check whether your phone’s own cloud backup includes messages, and whether the strongest protection available for that account is switched on.

The weakest link is a screen, not the maths

Nobody breaks modern encryption. They collect the text where it is already readable: on a device. An unlocked phone left on a table. A password reused from a site that leaked three years ago. A family tablet still signed in to the same account. A screenshot forwarded by the person you trusted. Spyware on a phone that has not been updated in two years. That is how conversations leak in practice.

So the boring measures matter more than the choice of app. A screen lock with a proper passcode rather than four digits. Automatic updates left on. A look through the app’s list of linked devices, where an old laptop is often still attached. Disappearing messages for conversations that do not need a permanent archive.

Verify the person, not just the app

Encryption protects a channel between two keys. It cannot tell you that the key at the other end belongs to the person you think it does. Serious apps let you check: a safety number, a security code, a QR code you scan while standing next to each other. Doing this once with the few people who matter most takes a minute and closes the one attack encryption cannot see.

If an app warns you that a contact’s security code has changed, it is not automatically sinister — people reinstall apps and replace phones. But it is worth one question in a different channel before you send anything sensitive.

Groups change the arithmetic

A group chat is only as private as its least careful member. Twenty people means twenty phones, twenty backup settings and twenty chances that somebody screenshots the conversation or leaves the group without really leaving. The encryption is intact; the confidentiality is not. For anything genuinely sensitive, a small group with a short retention setting beats a large group with good intentions.

A twenty-minute setup that covers most people

Choose one app that encrypts by default and use it for the conversations that matter, instead of trying to move your entire life at once. Turn on the encrypted backup and write the recovery key on paper. Set a real passcode and leave updates automatic. Switch on the app’s registration or account lock, so that nobody can claim your number by swapping a SIM card. Review your linked devices and remove anything you do not recognise. Enable disappearing messages where a permanent record serves no purpose. Verify security codes with two or three people. That is the whole list, and it puts you ahead of almost everybody.

Four myths, briefly

“Military-grade encryption” is a marketing phrase that means nothing in particular; ordinary apps use the same algorithms as banks and armies. A VPN does not encrypt your messages — it hides which network you are on from your internet provider, which is a different problem with a different guide. Deleting a message on your phone does not delete it from the other person’s phone, or from a backup. And an app being free is not proof that it sells your data: the useful question is who pays the bills, and honest projects answer it publicly.

What this doesn’t solve

Encryption does not make you anonymous. Your account is usually tied to a phone number, and the pattern of who you talk to stays visible to the service and, with a legal order, to others.

It does not protect you from the person you are talking to. Anything you send can be screenshotted, forwarded, quoted or simply read over a shoulder.

It does not survive a compromised device. If somebody controls the phone, they read the messages exactly as you do.

It does not stop an officer at a border or a police station from asking you to unlock the phone, and the rules on whether you have to comply differ enormously from country to country. That is a separate guide, and it is on the way.

And in a few places, using an encrypted app is itself treated as suspicious. Encryption protects content. It cannot protect you from a law written against it.

What it does do is remove the easiest form of bulk access to what you say. That is not everything. It is a great deal more than nothing, and it costs nothing to set up this afternoon.

Get the weekly briefing

Five things worth your attention — censorship, privacy, algorithms and digital rights. One email a week, no noise.

We’ll send you a confirmation email first. No tracking, no sharing, unsubscribe in one click. See our Privacy Policy.

Must Read

spot_img