Skip to content
MDA-078 Mobile Devices & Apps

What does end-to-end encryption mean for an investigator?

End-to-end encryption means message content is protected so that only the communicating devices are intended to read it.

What this means

The provider may carry the encrypted data without being able to see the plain message content.

The content may still be visible on the sender’s device, the recipient’s device, linked devices, backups or notifications.

The provider may also hold account registration, device, connection, delivery, security and timing records.

The exact records vary by service.

End-to-end encryption protects content in transit and often on provider systems.

A recipient may take a screenshot.

A linked desktop session may hold a copy.

A notification preview may reveal part of the message.

A message may still have been sent through a shared, stolen or remotely accessed account.

What to check or do next

  • Ask precisely what records the service may hold and what evidence exists on devices and accounts.

Evidential limits

That does not mean the investigation has no evidential opportunities.

It does not automatically protect material once it is displayed, copied, backed up or stored on a device.

Do not assume that the provider can supply content.

Equally, do not assume encryption prevents all useful disclosure.

Encryption also does not identify the user.

The operational takeaway is: end-to-end encryption limits provider access to content, but it does not remove device, account, metadata and recipient-side evidence. Investigate the wider evidence environment rather than treating encryption as the end of the enquiry.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.