What does end-to-end encryption mean for an investigator?¶
It is designed so communicating endpoints, rather than the provider carrying the data, can read message content.
Content and service metadata separate¶
Plain content may remain on sender, recipient and linked devices, notifications or backups. The provider may still hold registration, session, device, delivery, connection and security records even where it cannot decrypt messages.
Expand the evidence environment¶
Identify endpoint devices, accounts, recipients and backups and ask the provider precisely what non-content records exist. Encryption does not prevent screenshots, copies or compromise after display, nor identify the user.
Encrypted providers can still hold useful operational records.
Key takeaway
End-to-end encryption limits provider access to content, so combine endpoint evidence with provider-held account, device and timing records.