What is end-to-end encryption?
End-to-end encryption means only the people at each end can read a message. What that changes, what it leaves visible, and what to ask a provider.
End-to-end encryption means a message is encrypted on the sender’s device and can only be decrypted on the recipient’s device. The company that carries the message between them passes along data it cannot read.
Who holds the keys
Most online services encrypt your data on its way to them. Australia’s eSafety Commissioner calls this encryption in transit: information is protected as it travels from your device to the company’s servers. When it gets there the company decrypts it, so the company can read what you sent and its systems hold a readable copy.
End-to-end encryption moves the keys to the two ends. Content is made unreadable while it is still on the sender’s device, and it is decrypted only at its final destination. The service in the middle stores and forwards a scramble. If that service is broken into, the scramble is all there is to take.
Where you will meet it
Messaging apps are the common case. eSafety names iMessage, WhatsApp and Signal among the services that use it. The US Cybersecurity and Infrastructure Security Agency (CISA) points out some catches:
- Ordinary mobile calls and SMS text messages are not end-to-end encrypted.
- Both people need to be using the same app.
- iMessage is encrypted only between Apple devices. A message from an iPhone to another kind of phone is not.
Ordinary email is not in this group. The Office of the Australian Information Commissioner (OAIC) says email is not a secure form of communication, and that a business should have a procedure for sending personal information by email.
What it leaves visible
The content is protected, but the routing information is not. NIST’s definition says it remains visible, so the service can still see who is talking to whom.
Protection also ends at the device. A message is readable once it arrives, so an unlocked phone, or a signed-in account in the wrong hands, shows everything. eSafety describes end-to-end encryption as something that helps when it is combined with account authentication and other security measures.
What a business should ask
Many cloud services encrypt your data in transit and in storage with keys that the provider manages. Microsoft 365 does this, and offers separate options for customers who want to manage keys themselves. For most everyday work that arrangement is reasonable. OAIC suggests two questions for anything you keep with a provider: who is able to decrypt it, and whether some of it should be encrypted by you before it is sent.
For conversations that need more privacy, such as a client’s legal or health matters, pick a tool that states it is end-to-end encrypted and tell staff which tool that is. Otherwise people fall back on SMS or personal email.
End-to-end encryption looks after the message, and multi-factor authentication looks after the account that reads it. For help choosing and setting up the tools, see security best practices.
Sources
- End-to-end encryption trends and challenges: position statement (eSafety Commissioner) esafety.gov.au
- Glossary: end-to-end encryption (NIST Computer Security Resource Center) csrc.nist.gov
- How to communicate securely on your mobile device (CISA) cisa.gov
- Guide to securing personal information (Office of the Australian Information Commissioner) oaic.gov.au
- Encryption in Microsoft 365 (Microsoft Learn) learn.microsoft.com