What is end-to-end encryption?¶
End-to-end encryption protects message content so that it is readable at authorised endpoints rather than by each system carrying it between them. The provider may transport encrypted data without possessing what it needs to turn that data back into readable content.
Encryption protects a route, not every copy¶
The sending endpoint encrypts the message and an authorised receiving endpoint decrypts it. The exact key management differs between services, but the important investigative distinction is between content in transit and content available at an endpoint.
Participants must be able to read the conversation. Readable material may therefore exist in application databases, notifications, exports, screenshots, attachments, linked devices or backups. Finding content on a phone does not show that the encryption was broken; the phone is one of the places where reading was intended.
Service records can remain available¶
Encryption of content does not necessarily conceal account registration, device links, sessions, group structure or message-delivery events. Those records may help establish timing and associations, although metadata is not the message and does not establish authorship by itself.
Preserve endpoints and account state before avoidable interaction changes synchronisation, message status or active sessions. Describe separately the readable content recovered, its source, and any provider-held event data.
The point to remember
End-to-end encryption can prevent a provider reading content in transit while leaving readable endpoint copies and non-content service records available as evidence.