Skip to main content
Book 07 · SecurityPage 13 of 50

End-to-End Encryption

E2EE

Updated 2 min read

Share this page

Send the link, quote the definition with a link back, or show it as a card on your own site.

https://softwaredictionary.org/terms/end-to-end-encryption

In short

End-to-end encryption (E2EE) encrypts messages on the sender's device so only the intended recipients can decrypt them, not even the service carrying them.

What is end-to-end encryption?

With ordinary encryption in transit, such as HTTPS, data is protected on the network but decrypted on the provider's servers, where it can be read, scanned or leaked. With end-to-end encryption, the keys exist only on the users' devices. The server stores and forwards ciphertext it can't read, so a breach of the server, or a request to the company, reveals no message content.

Modern messengers use the Signal Protocol, developed for the Signal app and adopted by WhatsApp for all its users in 2016 and by other apps since. It combines public-key cryptography to agree on keys with a ratchet that derives a new key for every message, so stealing one key doesn't expose past or future conversations, a property called forward secrecy.

E2EE also protects backups, files and video calls in some services, and password managers apply the same idea so the provider never sees your vault. Users can verify that they are talking to the right person by comparing safety numbers or scanning a code, which defeats a server that tries to swap in its own keys.

A common misconception is that end-to-end encryption hides everything. Metadata, such as who talks to whom, when and how often, is often still visible to the provider, and the messages are readable on the devices themselves, so malware or an unlocked phone exposes them. Cloud backups that aren't end-to-end encrypted can also undo the protection.

Key takeaways

  • E2EE lets only the communicating users decrypt messages.
  • Servers relay ciphertext they cannot read.
  • The Signal Protocol, used by Signal and WhatsApp, is the common standard.
  • Per-message keys give forward secrecy; safety numbers verify contacts.
  • Metadata stays visible, and compromised devices still expose messages.

Readers ask

What is the difference between end-to-end encryption and encryption in transit?

Encryption in transit, such as TLS, protects data between your device and the server, which then decrypts it. End-to-end encryption keeps data encrypted all the way to the recipient's device, so the server never sees the plaintext.

Is WhatsApp end-to-end encrypted?

Yes. WhatsApp has used the Signal Protocol for all messages and calls since 2016, so message content is end-to-end encrypted, though metadata and unencrypted cloud backups are separate matters.

What is forward secrecy?

A property where keys change constantly, so if one key is stolen it can't decrypt earlier messages. The Signal Protocol and modern TLS both provide it.

See also

Spotted a mistake or something missing on this page?Suggest an edit

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings