What is end-to-end encryption?
End-to-end encryption seals a message on your phone and opens it only on the phone of the person you wrote to. Learn how the keys work, what it still leaves exposed, and how to check it is on.
End-to-end encryption means a message is scrambled on the sender device and can be unscrambled only on the receiver device. The company carrying it holds no key, so it cannot read the content, and neither can the network or anyone tapping the line. It hides what you said. It does not hide who you wrote to or when.
Picture a locked metal box sent across town on a bus. The driver carries it the whole way. He can see the box, and he can see who handed it over and who is waiting for it. However, he cannot see what is inside, because he has no key.
Now picture a postcard on the same bus, and anyone who handles it can read it in a second.
Most messages used to travel like postcards. End-to-end encryption turns them into locked boxes, and the company that carries your message becomes a driver who cannot look inside.
What end-to-end encryption means
End-to-end encryption scrambles a message on the sender device and unscrambles it only on the receiver device. Therefore nobody in between can read it. That includes the app maker, the phone network, your internet provider and anyone who taps the wire.
Look closely at the phrase. The two “ends” are the two devices. They are not the two companies. The message is already sealed before it leaves your hand, and it stays sealed until it reaches the phone you sent it to.
Scrambled text on its own is useless, because its value lies in who holds the key. Therefore one question decides everything. Who has the key?
How it works, step by step
The maths is deep. However, the idea is simple.
- Your app makes two keys on your phone, and one is public and one is private.
- The public key is shared freely, and it can seal a message but it cannot open one.
- The private key stays on your phone, and it never leaves. It opens what the public key sealed.
- When you write to a friend, your app seals the message with their public key.
- The company carries the sealed message and stores it for a moment.
- Their phone opens it with the private key that only they hold.
Good apps go further, and they change keys often, sometimes for every single message. So a key stolen today does not open the chats you sent last year.
How to tell it apart from the padlock in your browser
The padlock in your address bar is encryption too, and it is a different kind. It protects the trip between your device and the company server. The company then opens the data and reads it, because it must.
There is a third kind called encryption at rest. Here files are scrambled while they sit on a disk, and that guards against a stolen hard drive. The company still holds the key.
| Kind | Who can read it | Common example |
|---|---|---|
| In transit | You and the company | The padlock on a website |
| At rest | The company | Files stored in the cloud |
| End to end | Only you and the person you wrote to | Private chat apps |
ONLY THE THIRD KIND KEEPS THE COMPANY OUT. Keep that difference in mind when a service says it uses encryption. Ask which kind.
What it hides, and what it does not
It hides the content. It does not hide the fact that you sent something.
The carrier still sees what is called metadata. That means your number, their number, the time, how often you write and how big the file was. Metadata alone can tell a story, because a call to a clinic at midnight says plenty without a word of content.
It also stops at the two ends, so consider what that means in practice.
- A person reading over your shoulder sees everything.
- Bad software on either phone sees everything.
- Anyone in a group chat can copy or forward your words.
- A screenshot leaves the app with no key needed.
- A chat backup saved to the cloud may not be sealed unless you switch that on.
That last point catches many people, so check your backup setting today. A sealed chat with an open backup is a locked door beside an open window.
Where you already meet it
Personal chats on WhatsApp are end-to-end encrypted by default, and so are chats on Signal. Messages between Apple devices are sealed in the same way. Several other chat apps offer it, sometimes only in a special mode you must turn on.
Video and voice calls in those apps are usually sealed as well. Ordinary SMS is not, and neither is a normal email, unless both sides set up extra tools.
This matters for anyone who handles the secrets of other people. Journalists, doctors, lawyers and human rights workers use it as a basic tool of the job. It is also part of the wider set of habits covered in our guide to what cybersecurity is.
How to check it is really on
Do not take the word of a marketing page, and check inside the app.
Open a chat and look for the security code, sometimes called a safety number. It is a long string, and often a QR code as well. Both people should see the same one.
Now compare it. Meet the person, or call them on a line you already trust, and read a few digits aloud. If the codes match, no one is sitting in the middle. If the code changes for no reason, ask why before you send anything sensitive.
Beware of one trick. A fake app or a fake login page can defeat all of this. Learn the signs in our guide to phishing, because attackers now go after the person rather than the maths.
Why the argument about it will not end
Governments in many countries want a way to read sealed messages during a serious crime case. Their case is easy to understand. Criminals use these apps too.
Engineers answer with a plain technical point. A special key for one government is still a key, and it can be stolen, copied or misused. A door built for one visitor opens for anyone who finds it.
There is a second change coming, and future quantum computers may break some of the maths used to swap keys today. So the main apps have begun adding newer maths built to survive that. You do not need to do anything, and it arrives in an update.
What to do this week
Move your private conversations into an app that seals messages by default. Then turn on an encrypted backup, or turn cloud backup off. Set messages to disappear in chats that hold money details or health details.
Finally, remember what encryption cannot do. It protects the message. It does not protect the device. Keep the phone updated and locked, and treat the sign-in to your accounts as the real front door, as any zero trust team would.
Just Out Tech explains new research in plain language. This article was drafted with AI assistance and checked by a human against the original source.
- End-to-end encryption keeps the keys on the two devices, which is why the app maker cannot read your messages even under a court order.
- End-to-end encryption still leaves metadata visible, so the carrier can see who you contacted, when and how often, even when the content is sealed.
- A cloud backup of an encrypted chat can sit open on a server, so anyone relying on sealed messages should switch on encrypted backup or turn backup off.
Questions people ask
Can WhatsApp or Signal read my messages?
Neither can read the content of personal chats, because the keys stay on the phones taking part. Both can still see metadata, such as the numbers involved and the timing. If you back up your chats to the cloud without turning on the encrypted backup option, the backup may be readable by the backup provider.
Is HTTPS the same as end-to-end encryption?
No. The padlock in a browser protects data on the trip between your device and the website server. The company running the website opens the data and reads it at the other end. End-to-end encryption means only the two people talking hold the keys.
Does end-to-end encryption protect me from hackers?
It protects the message while it travels, and it stops the service provider from reading it. It does nothing about a phone with bad software on it, a person looking over your shoulder, or a screenshot taken by someone in the chat. Device security is a separate job.
How can I check my chat is really encrypted?
Open the chat and look for a security code or safety number in the contact details. Compare it with the other person in a meeting or on a call you already trust. Matching codes mean no one is sitting between you. A code that changes without reason is worth asking about.