End-to-End Encryption
E2EE
- In Turkish
- Uçtan Uca Şifreleme
In short
End-to-end encryption (E2EE) encrypts messages on the sender's device so only the intended recipients can decrypt them, not even the service carrying them.
What is end-to-end encryption?
With ordinary encryption in transit, such as HTTPS, data is protected on the network but decrypted on the provider's servers, where it can be read, scanned or leaked. With end-to-end encryption, the keys exist only on the users' devices. The server stores and forwards ciphertext it can't read, so a breach of the server, or a request to the company, reveals no message content.
Modern messengers use the Signal Protocol, developed for the Signal app and adopted by WhatsApp for all its users in 2016 and by other apps since. It combines public-key cryptography to agree on keys with a ratchet that derives a new key for every message, so stealing one key doesn't expose past or future conversations, a property called forward secrecy.
E2EE also protects backups, files and video calls in some services, and password managers apply the same idea so the provider never sees your vault. Users can verify that they are talking to the right person by comparing safety numbers or scanning a code, which defeats a server that tries to swap in its own keys.
A common misconception is that end-to-end encryption hides everything. Metadata, such as who talks to whom, when and how often, is often still visible to the provider, and the messages are readable on the devices themselves, so malware or an unlocked phone exposes them. Cloud backups that aren't end-to-end encrypted can also undo the protection.
Key takeaways
- E2EE lets only the communicating users decrypt messages.
- Servers relay ciphertext they cannot read.
- The Signal Protocol, used by Signal and WhatsApp, is the common standard.
- Per-message keys give forward secrecy; safety numbers verify contacts.
- Metadata stays visible, and compromised devices still expose messages.
Readers ask
What is the difference between end-to-end encryption and encryption in transit?
Encryption in transit, such as TLS, protects data between your device and the server, which then decrypts it. End-to-end encryption keeps data encrypted all the way to the recipient's device, so the server never sees the plaintext.
Is WhatsApp end-to-end encrypted?
Yes. WhatsApp has used the Signal Protocol for all messages and calls since 2016, so message content is end-to-end encrypted, though metadata and unencrypted cloud backups are separate matters.
What is forward secrecy?
A property where keys change constantly, so if one key is stolen it can't decrypt earlier messages. The Signal Protocol and modern TLS both provide it.
See also
- EncryptionSecurity, p. 12Encryption is the process of scrambling data with a key so that only someone holding the correct key can turn it back into its original, readable form.
- Public-Key CryptographySecurity, p. 30Public-key cryptography is a method that uses a pair of linked keys, a public key anyone can see and a private key kept secret, to encrypt and sign data.
- Symmetric EncryptionSecurity, p. 44Symmetric encryption uses the same secret key to encrypt and decrypt data; it is fast, so it protects most stored and transmitted data, usually with AES.
- TLSSecurity, p. 45TLS is the cryptographic protocol that encrypts data sent over a network and verifies the server's identity, securing HTTPS, email, and many other connections.
- Man-in-the-Middle AttackSecurity, p. 21A man-in-the-middle attack happens when an attacker secretly relays, and may alter, messages between two parties who think they are talking directly.
- Digital SignatureSecurity, p. 11A digital signature is a cryptographic value made with a private key that proves who produced a message or file and that it hasn't changed since it was signed.
Spotted a mistake or something missing on this page?Suggest an edit