What is end-to-end encryption?
End-to-end encryption explained without jargon: how it works, what it protects, what it doesn't (metadata), and how to tell whether a messenger really uses it.
Frozen Chat Team · · 6 min read
“End-to-end encrypted” appears on the box of almost every messaging app now. It is one of the most important privacy protections you can have, and also one of the most misunderstood. This guide explains what it actually means, how it works, and the questions to ask before you trust an app that claims it.
The short answer
End-to-end encryption (E2EE) means a message is scrambled on the sender's device and can only be unscrambled on the recipient's device. Everything in between, including the company running the service, its servers, your Wi-Fi provider and your mobile carrier, only ever sees unreadable data. The “ends” are the devices of the people in the conversation, and only they hold the keys.
Encryption “in transit” is not the same thing
Most websites and apps use encryption in transit (the padlock in your browser, TLS). It protects data on the way between your device and the company's server. But at the server it is decrypted, so the company can read, store, scan or hand over the content. Many e-mail services and some messengers work like this: the connection is encrypted, but the provider holds the keys.
End-to-end encryption removes the provider from the trust chain. The server is only a post office for sealed envelopes it can't open. If the server is hacked, subpoenaed or run by someone curious, the message content is still protected.
How it works, in four steps
- Each device makes a key pair. A private key that never leaves the device, and a public key that can be shared with anyone.
- The devices agree on a shared secret. Using each other's public keys, two devices can compute the same secret without ever sending it. Someone watching the exchange can't work it out.
- Messages are encrypted with keys derived from that secret. Good protocols change the key for every message.
- The recipient decrypts with their own copy of the key. The server just passed along ciphertext.
The most widely used design is the Signal protocol. It adds the Double Ratchet, which turns the key forward with every message. That gives two valuable properties: forward secrecy (a key stolen today can't decrypt yesterday's messages) and post-compromise security (after a breach, the conversation heals once new keys are exchanged).
What about groups and calls?
Groups are harder, because many devices need to share keys efficiently and securely as people join and leave. The IETF standardised Messaging Layer Security (MLS) as RFC 9420 for exactly this. Calls are encrypted too: one-to-one calls typically use DTLS-SRTP with fingerprints checked through the encrypted chat, and group calls can use SFrame so that relays forward only encrypted media. Before you trust a messenger, check that groups and calls are covered, not just one-to-one text.
What end-to-end encryption doesn't protect
E2EE protects the content of messages. It does not automatically hide:
- Metadata: who you talk to, when, how often, from which IP address, and who is in your address book. A service can know all of this while never reading a word.
- Your identity, if the account is tied to a phone number or e-mail address.
- Backups, if your chat history is uploaded to a cloud without its own end-to-end encryption.
- Your device. If a phone is unlocked and compromised by malware, the attacker can read what you can read.
- The recipient. They can screenshot or forward anything you send.
That is why serious private messengers also try to minimise metadata: no phone numbers, sealed sender (the server isn't told who sent a message), no logs, and notifications without content.
How to verify you're talking to the right person
Encryption only helps if you are encrypting to the right key. If a server swapped in its own key, it could sit in the middle. Messengers defend against this with safety numbers (or security codes): a fingerprint of both people's keys you can compare in person or by scanning a QR code. If a contact's keys change unexpectedly, a good app warns you. For people who matter, compare them once.
Questions to ask any “encrypted” app
- Is end-to-end encryption on by default for every chat, or only an opt-in mode?
- Are group chats and calls end-to-end encrypted too?
- Which protocol does it use, and is it a published, well-studied design?
- What metadata does the server keep, and for how long?
- Does it need your phone number or upload your contacts?
- Are backups end-to-end encrypted?
- Can you verify contacts' keys?
How Frozen Chat does it
In Frozen Chat every chat, group, file and call is end-to-end encrypted by default. One-to-one chats use libsignal with post-quantum PQXDH keys, groups use MLS with a hybrid post-quantum suite, and calls use DTLS-SRTP and SFrame. To keep metadata small there is no phone number or e-mail, sealed sender is on, and servers keep no IP logs. Our security page lists what the server can and can't see, and our encrypted messenger page has the details. Curious about the quantum part? Read post-quantum encryption in messaging, explained.