Is end-to-end encryption really secure?
Thanks for asking.
In late April 2024, police chiefs from the UK's National Crime Agency and 32 European
countries issued a statement expressing their concerns about the use of end-to-end encryption
by instant messaging services like WhatsApp.
The statement recognised that end-to-end encryption protects users' personal data, but
emphasised that it also prevents authorities from identifying suspicious or illegal
activities, and as we'll get to in just a moment, encryption doesn't always guarantee
full privacy for users.
No doubt you'll have seen the term on services like WhatsApp and Zoom in the past.
Since the end of 2023, Messenger has also had end-to-end encryption.
It basically means that no one else can intercept or access your conversations.
When you hit send, your message is converted into an unreadable code during its journey
from server to server, and it only becomes readable again when it reaches your recipient's
device.
It's kind of like sending your messages in a secure envelope that only your recipient
can open.
Not entirely, in actual fact, end-to-end encryption doesn't mean everything is private.
Let's take the example of Meta's messaging servers, which are used for messages sent
via WhatsApp and Messenger.
They still have access to metadata, including information about who you've exchanged messages
with and when.
As 2021, WhatsApp has also required users to accept the collection of certain personal
data, such as their location, contact lists, and even photos, videos and audio shared via
the platform.
On the plus side, end-to-end encryption helps prevent some of your private information
from falling into the wrong hands.
Say you shared your address with a friend or family member via WhatsApp.
You wouldn't want scammers or other dangerous people having access to that information,
would you?
But police authorities say that the more widespread end-to-end encryption becomes, the harder
it will be for them to combat illegal activities and protect miners online.
Commenting on the Meta, National Crime Agency Director General Graham Bigger said, encryption
can be hugely beneficial, protecting users from a range of crimes, but the blunt and increasingly
widespread rollout by major tech companies' event-to-end encryption without sufficient
consideration for public safety is putting users in danger.
What's the best way to stay safe and secure then?
It's a pretty complex issue.
If you want to protect your conversations as much as possible, you should ideally avoid
saving your chat histories in the cloud and use applications that don't collect metadata
or rely on your phone number.
One example is Signal, which you may remember we ran an episode on a while back.
In short, balancing cybersecurity and privacy remains a challenge for now.
There you have it!
Now you know whether end-to-end encryption is really secure.
In under three minutes, we answer your questions and help you understand the true meaning behind
the trends, concepts and acronyms that are making headlines.
It's an along and you will really know for sure.