End-to-end encryption
What this criterion guarantees: Your messages are encrypted before they leave your device, and only those who hold the keys they were encrypted for can read them. You still need to make sure that those keys really belong to your correspondents (that is what the End-to-end authentication criterion is about).
Without it: Anyone with access to the server (operator, hacker, authority) can read all conversations in full.
At a glance
• Olvid — ✅ Good
• Signal — ✅ Good
• WhatsApp — ✅ Good
• Telegram — ❌ Poor
• Matrix-based — 🟠 Partial
• SimpleX — ✅ Good
• Threema — ✅ Good
In instant messaging, encryption is what guarantees the confidentiality of the data sent to a contact (messages, attachments, etc.). This protection is essential because of the inherent insecurity of the communication networks the data travels through. These networks include many intermediate devices that cannot necessarily be trusted.
Encryption can only be called “end-to-end” if the following conditions are all met:
- the data is encrypted on the sender’s device, before it is transmitted over the network;
- the data remains encrypted throughout its journey;
- decryption happens only on the recipient’s device.
How does end-to-end encryption work?
In practice, each user has a pair of cryptographic keys: a public key and a private key. The two are inseparable and are generated locally, on the user’s device, typically when the profile is created. The public key is meant to be shared with the user’s contacts, whereas the private key must remain strictly confidential.
Although implementations vary from one messaging app to the next, the principle is always the same:
- the recipient’s public key (shared with their contacts) is used to encrypt the messages addressed to them;
- only their private key (which they alone hold) can decrypt them.
Anyone without that private key, including the operator of the messaging service, is therefore unable to access the content of the communications.
How are these keys used in practice?
Most of the time, the public and private keys are not used to encrypt each message directly. They allow the two parties to agree on a shared secret (remotely, yet without ever sending it over the network). From this shared secret, the application derives the keys that actually encrypt and authenticate each message. This is known as authenticated encryption: it protects both the confidentiality of the message (nobody else can read it) and its integrity (nobody can alter it or forge one). Some solutions renew these keys with every message, immediately destroying the previous one: this is called ratcheting. It guarantees a property known as “forward secrecy.” This property is the cryptographic guarantee of a genuine right to be forgotten: if both parties delete a message, it becomes permanently unrecoverable. Even an adversary who had recorded all the encrypted traffic, and who later managed to compromise both devices and extract their keys, could not reconstruct the deleted messages: the keys used to encrypt them have been destroyed and no longer exist anywhere.
The role of the relay server
The vast majority of messaging apps rely on a relay server whose role is to deliver messages to users’ devices. This server is what makes asynchronous communication possible: a sent message is first transmitted to the server, which stores it until the recipient’s device comes to retrieve it.
End-to-end encryption protects users from any malicious behavior by this server: since it has no way to decrypt or alter the messages it carries, it is reduced to the role of a “pass-through” and plays no part in the security of the communications. As far as the confidentiality of the exchanges is concerned, knowing who controls this server therefore matters no more than knowing who controls the routers and cables the messages pass through: end-to-end encryption makes the question moot. The server nevertheless remains necessary for delivering messages, and therefore for the availability of the service.
End-to-end or point-to-point encryption?
It is important to distinguish between:
- end-to-end encryption (a prerequisite for a messaging app to be called “secure”);
- point-to-point encryption, where the data is decrypted on a relay server before being re-encrypted and forwarded to the recipient.
Unlike end-to-end encryption, point-to-point encryption does not protect the exchanges from a prying server: the server has access to every conversation of every user. The service operator, any server administrator, or any adversary who manages to take control of it can then wipe out the confidentiality of the exchanges entirely.
Point-to-point encryption is nonetheless fundamental in some cases. For example, when you log in to your bank’s website, the connection between your device and your bank’s servers is secured with TLSarchived, which is a point-to-point encryption protocol. In that situation, it is perfectly normal: the information you are trying to obtain is known to the server from the start.
A technology that can no longer be ignored
End-to-end encryption is not a recent innovation: its adoption by the general public owes a great deal to the Signal protocol, which WhatsApp adopted in 2016archived for all of its conversations, bringing end-to-end encryption to billions of users all at once. Messaging apps such as Messages (Apple) and Signal itself have also helped popularize it. Some solutions moreover offer a documented, open source implementation, which allows their security to be independently verified. Today, integrating this technology into a messaging app has become common practice and is technically well mastered. Tools that do not implement it therefore cannot claim to offer an acceptable level of security. This is the case with Telegram, whose FAQarchived nevertheless states: “Telegram is a messaging app with a focus on speed and security”. That claim is somewhat overstated, since end-to-end encryption is not enabled by default for one-to-one chats and remains unavailable for group chats. A gap that is hard to reconcile with a claim to security.
Applying this criterion
To earn a ✅Good, a messaging app must end-to-end encrypt all communications (messages, attachments, and audio/video calls where available), in every type of chat (including group chats), without this being optional and without users being able to disable it (deliberately or by mistake). This is what we mean by systematic end-to-end encryption. When this encryption is not guaranteed everywhere but is the default behavior of the main clients for private conversations, as on Matrix, the messaging app gets a 🟠Partial. When it is merely an option to turn on, or is even absent from some types of chat, as on Telegram, it gets a ❌Poor.
End-to-end encryption is not enough to guarantee the confidentiality of communications
The wording on some messaging apps’ websites sometimes suggests that end-to-end encryption alone is enough to protect communications from third parties, including the operator of the solution. WhatsApp’s FAQ on end-to-end encryptionarchived, for example, reads: “WhatsApp has no ability to see the content of messages […]”. While end-to-end encryption is indeed a necessary condition, it is not a sufficient one. The reason: encryption is only meaningful if you can first authenticate the person you are talking to. We discuss this point in detail in the criterion dedicated to end-to-end authentication.