Skip to content
Skip to main content
Mobile Devices & Apps Technical Explainer

What does end-to-end encryption mean for an investigator?

It is designed so communicating endpoints, rather than the provider carrying the data, can read message content.

Content and service metadata separate

Plain content may remain on sender, recipient and linked devices, notifications or backups. The provider may still hold registration, session, device, delivery, connection and security records even where it cannot decrypt messages.

Expand the evidence environment

Identify endpoint devices, accounts, recipients and backups and ask the provider precisely what non-content records exist. Encryption does not prevent screenshots, copies or compromise after display, nor identify the user.

Encrypted providers can still hold useful operational records.

Key takeaway

End-to-end encryption limits provider access to content, so combine endpoint evidence with provider-held account, device and timing records.

Reference: MDA-078Mobile Devices & Apps