End-to-End Encryption (E2EE) - True Message Privacy
About 2 min read
End-to-end encryption (E2EE) is a communication method in which data is encrypted on the sender's device and decrypted only on the recipient's device. As long as the keys are managed and verified correctly, no intermediary, including the service provider, can read the contents of the communication, which is why it has been adopted in messaging apps and cloud storage as a means of protecting privacy. Its scope is not limited to messaging: in December 2022 Apple announced Advanced Data Protection for iCloud, an opt-in setting that extends E2EE to categories such as iCloud Backup.
Practical Application Scenarios
When sharing patient data with medical institutions, some organizations adopt a configuration based on E2EE-capable messaging. Because the data is not decrypted on the server side, insider misconduct at the cloud provider or a breach of the server alone does not reveal the message contents. On the other hand, a compromised device or a skipped key verification falls outside the scope of this protection, so device management and key verification need to be operated alongside it.
E2EE Flow
Historical Background
The concept of E2EE dates back to PGP (Pretty Good Privacy), developed by Phil Zimmermann in 1991. TextSecure v2, released in February 2014, adopted the Double Ratchet design that later came to be known collectively as the Signal protocol, and in April 2016 WhatsApp made E2EE the default for communication between users running the latest version of the app, spreading it widely among general consumers. As encryption technology became more widespread, LINE began offering Letter Sealing as an optional feature in August 2015, enabled it by default in its major environments in 2016, and since 2021 has had it enabled by default in all regions, with no way for users to turn it off manually.
How It Works and Practical Considerations
E2EE is built on public-key cryptography. Each user holds a pair of public and private keys, and the sender encrypts the message with the recipient's public key. Because the private key exists only on the recipient's device, the contents remain protected even if data is leaked on the server side. However, E2EE does not protect metadata (who sent what to whom and when). In addition, if the device itself is infected with malware, the decrypted data may be stolen.
Challenges of E2EE
Law enforcement agencies sometimes demand a "backdoor" into E2EE for criminal investigations, but the report "Keys Under Doormats," published in July 2015 by researchers at MIT CSAIL and other institutions, argued against such mechanisms on the grounds that any capability enabling decryption could also be exploited by attackers. For corporate compliance departments, an E2EE environment poses the challenge that employee communications cannot be audited. Protect your E2EE app accounts with a strong, unique password for each service, and combine this with secure password sharing to strengthen your security.
Was this article helpful?