HeadFlash

Topic · 80 stories

Encryption: end-to-end, laws and latest news

Updated · Edited by Marcin Rybak

In short

Encryption scrambles data so that only someone with the right key can read it, protecting files, messages and web connections. End-to-end encryption, the strongest form for messaging, means only the people in a conversation can read it, not even the service provider. In 2026 governments and tech firms are fighting over access to encrypted data, and police increasingly read messages by taking over linked devices rather than breaking ciphers.

What is encryption and what is end-to-end encryption

Encryption is the scrambling of data into a form nobody can read without the right key. An algorithm turns readable data into ciphertext, and only the matching key turns it back; the algorithm is public, so the secrecy of the key is what counts. With symmetric encryption the same key locks and unlocks. With asymmetric encryption, such as RSA, a public key locks and a private key unlocks. Data can be encrypted in transit over the web (HTTPS), at rest on a disk or in the cloud, and end to end between two people.

End-to-end encryption (E2EE) means only the people in a conversation can read it, not even the company running the service. Messenger’s Help Center (as of 10 October 2026) describes it as ensuring that only you and the people you communicate with can see or hear messages and calls, “no one else, not even Meta”. Meta says it is securing personal messages with E2EE by default, but chats with businesses and Marketplace chats are not covered, and anyone in the chat can still share a message. Google’s help page says RCS chats between Google Messages users are end-to-end encrypted, but SMS and MMS are not (as of 10 October 2026). For a comparison of apps see messaging apps privacy.

Signal’s answer to server-side risk is Automatic Key Verification. It lets users confirm that messages reach the right person without meeting in person, using a key transparency system with Cloudflare and Trail of Bits as independent auditors, and it addresses a man-in-the-middle swap of keys at Signal’s own servers.

The difference between encryption types is who holds the keys. Amazon’s Ring shows where the line runs. It announced an encryption system called TAKE in which keys rotate and Ring deletes its cloud copy after 24 hours. The EFF replied that it is not end-to-end encryption: keys reach the server whenever features need them, so the system is close to encryption at rest, where the provider holds the keys. Ring already offers a separate end-to-end option, but says it cannot provide features such as smart alerts and video search under it.

Encryption also fails through poor deployment. Hackers found an encryption key stored on a stolen Flock camera that unlocked a partition of media files, and NHS Blood and Transplant sent patient data over an unencrypted pager network.

Can police read encrypted messages

Yes, but usually by going around the encryption rather than through it. A Netzpolitik document shows that German police read messages by exploiting linked-device features. Customs officials logged into web clients of Telegram and WhatsApp with a suspect’s phone number, which can mean phishing a confirmation code or coaching someone to link a device. Signal uses QR codes that can be scanned without physical access. Testing began in late 2023, the strategy became permanent in August 2025, and it covers WhatsApp, Telegram, Threema and Signal. Users are advised to check active sessions and remove unrecognized devices.

Phones are the other route. Magnet Forensics, maker of GrayKey, has reportedly built a workaround for iPhone’s Inactivity Reboot, which restarts a phone after 72 hours without unlocking and returns it to the protected Before First Unlock state. Its GrayKey Preserve is said to hold phones in the weaker After First Unlock state through restarts. A separate piece explains why restarting your phone is one of the best privacy moves: in Before First Unlock files stay encrypted until you enter the passcode. It puts the automatic restart at 96 hours for iPhones and 72 for Android, so the sources differ on the iPhone figure.

Software on your own device can read messages as well. OpenAI’s plugin lets ChatGPT on Mac search Apple Messages; the person who installs it must consent, but others in the chat cannot know. OpenAI says it reads messages only when a request calls for it. Security expert Paul Walsh called it the worst privacy development he had seen in decades, and Proton recommends leaving it off.

What are encryption backdoors and where is the fight

A backdoor is a deliberately built way for authorities to reach encrypted data, and the biggest 2026 fight over one involves Apple in the UK. See also encryption backdoors and lawful access.

A secret Technical Capability Notice issued under the Investigatory Powers Act 2016 in January 2025 reportedly ordered Apple to give access to iCloud data protected by Advanced Data Protection, at first worldwide and later narrowed to UK citizens. Apple withdrew the feature for new UK users instead of complying, which left two tiers of iCloud encryption in the UK depending on whether a user enabled it in time. Apple says it has never built a backdoor. In September the tribunal heard a lawyer for Privacy International and Liberty call the policy of neither confirming nor denying the notice farcical, while the government’s counsel argued that abandoning it would damage national security.

UK public opinion is clear. In a Center for Democracy & Technology poll of 2,000 adults from April, only 12% supported secret orders for data access, and 93% said they have a right to private online conversations.

Canada is next. Access Now and other groups urged the EU to act against Canada’s Bill C-22, under which a Canadian minister could secretly order a European company to weaken a product used across the EU. In the EU the same conflict centres on message scanning, covered under Chat Control.

Can encryption be broken

Widely used encryption has not been broken, but 2026 brought records and attacks on narrow schemes. Anthropic engineer Stephen Weis factored RSA-896 with help from Claude, lifting the public record from 862 to 896 bits, 16 days after the previous one set with the Devin agent. Weis stated that no new algorithmic improvements were made and no deployed keys are threatened; RSA-1024 remains unfactored publicly.

More worrying are attacks on how RSA is used. Researchers including Nadia Heninger and Emmanuel Thomé forged 1024-bit RSA signatures without factoring the key, using a hardware security module as a signing oracle, and estimate such setups are 15 to 30 bits weaker than factoring suggests. Nadia Heninger’s team published a faster forgery attack on blind-signature RSA; it works only on blind or textbook RSA, not the padded RSA used almost everywhere, but affects Privacy Pass, used by Apple and Cloudflare. Some leaks sit outside the maths: InjectEave pulls audio from headphones at up to 30 meters because the leak comes from the analog path.

What is quantum encryption, and will quantum computers break encryption

“Quantum encryption” usually means post-quantum cryptography: algorithms built to resist quantum computers, such as ML-KEM and ML-DSA. Quantum key distribution is a separate, hardware-based technique that these stories do not cover. A quantum computer could threaten today’s public-key schemes, and the EU’s financial supervisors warned that Q-Day could arrive before quantum computers are commercially useful. The risk already exists as “harvest now, decrypt later”: data intercepted today can be decrypted later.

Governments are moving. The G7 cybersecurity group urged immediate preparation on 3 September, the NIS Cooperation Group recommends migration strategies by end-2026, and NIST’s draft recommends phasing out 112-bit ECDSA after 2030. Google’s March claim that breaking an elliptic-curve scheme needs 1,175 logical qubits rested on a flawed zero-knowledge proof that was corrected in April, and as of July the record estimate is under 100 logical qubits. In crypto, experts warn that more than $2 trillion is exposed, though Coinbase says Bitcoin’s core infrastructure is largely safe and the risk sits at the wallet level.

Products are starting to change. Surfshark added ML-DSA certificates to WireGuard, claiming the first full post-quantum implementation; by its count only AWS KMS and Google Cloud KMS among 15 major platforms have deployed ML-DSA.

HTTPS, TLS certificates and encrypted browsing

TLS certificates are about to expire much faster: Let’s Encrypt will cut lifetimes from 90 to 64 days on 10 February 2027, with opt-in testing from 14 October and 45-day defaults planned for 2028. Administrators on modern ACME clients with ARI will not notice; those with hardcoded or manual renewals must update.

The certificate system has weak spots. Google said attackers obtained counterfeit TLS certificates for Google domains by hijacking three country-code domains and passing domain-control checks. Chrome blocks the suspect certificates, but Google warns that browser action alone is not enough. Cloudflare plans quantum-safe TLS certificates for the first quarter of 2027. Android 17 is the first major mobile OS with built-in Encrypted Client Hello, which hides the site name from carriers, and it also lets carriers disable 2G by default.

Encryption and AI

AI providers encrypted reasoning tokens with one global key. Researchers from MATS Research, the ELLIS Institute Tübingen, the Max Planck Institute and Snyk found that Anthropic, OpenAI and Google use a single key for the whole ecosystem. Decoding 315,320 blocks from public repositories gave 182 credentials, including 62 live API keys and 33 passwords. The providers patched their servers, but session logs already public can still be decrypted.

Encryption is also being used to protect AI users. Google DeepMind keeps the keys to AI memory on the user’s device in its Private AI Compute platform, decrypting only inside a secure enclave, and the system passed an independent audit. Google also released HEIR, a compiler for homomorphic encryption, which allows computation on encrypted data.

What it means for you

  • Use a messenger with end-to-end encryption, and treat plain SMS as unencrypted.
  • Review the linked devices in your messenger and remove any you do not recognize. German police use exactly this route.
  • Restart your phone now and then: after a restart, files stay encrypted until you enter your passcode.
  • Do not enable AI integrations that read your chats without the other participants knowing.
  • If you run a website, automate certificate renewal. From February 2027 Let’s Encrypt certificates will last 64 days.

Still open: whether the UK will disclose its order to Apple, how Canada’s Bill C-22 ends after the Senate review expected as early as October, and when post-quantum TLS certificates reach mass deployment.

Key facts

  • Let's Encrypt will cut free TLS certificate lifetimes from 90 to 64 days on 10 February 2027. Opt-in testing starts 14 October, and 45-day defaults are planned for 2028. (source)
  • Attackers obtained counterfeit TLS certificates for Google and other large services by hijacking three country-code domains. It is unclear how many certificates were issued. (source)
  • German police read WhatsApp, Telegram, Threema and Signal messages by exploiting linked-device features, without breaking encryption. The strategy became permanent for all agents in August 2025. (source)
  • EU financial supervisors warned that Q-Day could arrive before quantum computers are commercially useful. The NIS Cooperation Group recommends a post-quantum migration strategy by end-2026. (source)
  • Stephen Weis factored RSA-896 with help from Claude, lifting the public record from 862 to 896 bits, 16 days after the previous one. He says no deployed keys are threatened. (source)
  • The Investigatory Powers Tribunal heard a challenge to the Home Office's refusal to confirm a secret order to Apple. Apple withdrew Advanced Data Protection for UK users rather than build a backdoor. (source)
  • Signal launched Automatic Key Verification, which detects key substitution at its servers. Cloudflare and Trail of Bits act as independent auditors. (source)
  • Anthropic, OpenAI and Google use one global key for AI reasoning tokens. From public repositories researchers recovered 182 credentials, including 62 live API keys. (source)

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Timeline

  1. Let’s Encrypt to Cut Certificate Lifetimes to 64 Days in February 2027 Security
  2. Surfshark adds ML-DSA certificates to WireGuard for post-quantum authentication Privacy
  3. Hackers obtain counterfeit TLS certificates for Google and other services Security
  4. German Police Read Encrypted Messages by Exploiting Linked Devices Privacy
  5. GrayKey Preserve Bypasses iPhone Inactivity Reboot, Report Says Privacy
  6. Why Restarting Your Phone Is One of the Best Privacy Moves Privacy
  7. Ethereum Foundation launches zkAPI for anonymous AI model payments Privacy
  8. Cloudflare plans quantum-safe TLS certificates for early 2027 Security
  9. Researchers publish Shielded Bitcoin design for private transfers Privacy
  10. New RSA forgery attack cuts blind-signature security levels Security
Show older (70 stories)
  1. EU Financial Supervisors Warn Q-Day Could Arrive Before Quantum Computing Is Commercially Useful Privacy
  2. 1024-bit RSA signatures forged without factoring the key Security
  3. Google DeepMind adds server-side memory with keys kept on user devices Privacy
  4. Apple’s UK Encryption Fight Exposes Two-Tier iCloud Protection Privacy
  5. Google Used Flawed Zero-Knowledge Proof for Quantum Encryption Claim Privacy
  6. InjectEave pulls audio from headphones at up to 30 meters, bypassing encryption Privacy
  7. RSA-896 factored with Claude as AI-assisted cryptanalysis sets second record in 16 days Privacy
  8. Apple and rights groups demand UK lift gag order on secret encryption backdoor Privacy
  9. Tribunal hears Home Office secrecy over Apple technical capability notice is farcical Privacy
  10. Hackers extract 1.6 million images from stolen Flock camera despite encryption claims Privacy
  11. Privacy groups ask EU to fight Canada’s Bill C-22 encryption powers Privacy
  12. Ring’s New TAKE Encryption Falls Short of End-to-End Privacy Privacy
  13. G7 warns crypto networks to prepare for post-quantum migration Privacy
  14. OpenAI Mac App Integration With iMessage Raises Encryption and Consent Concerns Privacy
  15. ChatGPT plugin can search Apple Messages, raising hidden-access concerns Privacy
  16. Poll: 93% of Brits Believe in Right to Private Online Conversations Privacy
  17. Privacy-Focused App Kibu Targets Military Customers with Device-to-Device Encryption Privacy
  18. Android 17 Hides Browsing Destinations From Carriers With ECH Support Security
  19. UK Public Overwhelmingly Opposes Secret Surveillance Orders, Poll Finds Privacy
  20. Ring Introduces TAKE Encryption, Limiting Data Available to Police Privacy
  21. Ring’s New Encryption System Limits Police Access to Video Footage Privacy
  22. Privacy in AI era demands identity-centric Zero Trust and confidential computing Privacy
  23. Google’s HEIR brings homomorphic encryption to private AI inference Privacy
  24. CRYPTO 2026 opens with record papers, post-quantum scrutiny, and Encrochat analysis Privacy
  25. More than $2 trillion in crypto assets at risk from quantum computing, industry urged to migrate Privacy
  26. NHS Blood and Transplant Admits Data Breach via Unencrypted Pagers Security
  27. AI Providers Share One Encryption Key, Researchers Decode 315K Reasoning Blocks Privacy
  28. Signal Launches Automatic Key Verification to Stop Server-Level Wiretapping Privacy
  29. Signal launches Automatic Key Verification with independent auditors to thwart man-in-the-middle attacks Security
  30. Russia’s State-Backed Max Messenger AI Tells Users to Switch to Telegram or Signal Privacy
  31. Most wearables lack transparency reports and end-to-end encryption, EFF finds Privacy
  32. Self-Destructing Phone Code Sparks Federal Case Against Atlanta Man Security
  33. Apple Files New Legal Challenge to UK Encrypted Data Demand Privacy
  34. Apple challenges UK government’s second iCloud encryption order Privacy
  35. Homematic IP Launches Six Cameras With Free Encrypted Cloud Storage Privacy
  36. Quantum Computing Race Threatens $470 Billion in Exposed Bitcoin Privacy
  37. EU Chat Control Talks Stall as Fifth Round Ends in Deadlock Privacy
  38. Anthropic’s Mythos model discovers cryptographic weaknesses in HAWK and AES AI
  39. EU Governments Confirm Interim Chat Control Regime, Excluding Encrypted Apps Privacy
  40. EU ‘Chat Control’ Legislation Stalled Over Mass Surveillance Concerns Privacy
  41. EU Extends Controversial Chat-Scanning Regime Until 2028, Excluding End-to-End Encryption Privacy
  42. EU Revives Voluntary Chat Scanning Law, Excluding Encrypted Messages Privacy
  43. EFF Finds Only Apple Encrypts Health Data on Wearables Privacy
  44. BitLocker Zero-Day CVE-2026-50661 Allows Physical Bypass of Encryption Security
  45. EU Parliament Passes Suspicionless Mass Scanning Until 2028 Privacy
  46. Cloudflare Ships Authentication Fix Against IPsec Downgrade Attack Surviving ML-KEM Security
  47. EU Parliament to Vote Again on Message-Scanning Extension Amid Privacy Concerns Privacy
  48. Independent Teams Surpass Google’s Quantum Cryptography Results AI
  49. Crowdsourced Effort Surpasses Google’s Quantum Circuit for Breaking 256-bit ECC Security
  50. Delta Chat Offers Decentralized, Anonymous Messaging Without Phone Number Privacy
  51. Microsoft Accelerates Quantum Security Timeline to 2029 Security
  52. Open-Source Notes App Notesnook Offers Strong Encryption but Lacks Key Features Privacy
  53. WhatsApp’s Username Feature Re-Ignites India’s Message Traceability Debate Privacy
  54. EU Faces ‘Double Threat’ to Encrypted Messaging as Campaign Relaunches Privacy
  55. Quantum Computing Race Could Break Encryption by 2028, US Executive Orders Signal Privacy
  56. Post-Quantum Cryptography: Cloudflare Sets 2029 Target as Federal Mandate Nears Privacy
  57. Canada Passes Controversial Bill C-22 Lawful Access Before Summer Break Privacy
  58. AMD Reinstates Memory Encryption in Consumer CPUs After User Outcry Privacy
  59. France Sets 2027 Deadline for Quantum-Resistant Encryption in Certified Products Privacy
  60. Singaporean Brothers Develop Encryption Based on Unsolvable Math Equations Privacy
  61. Canada’s Bill C-22 and C-34 Raise Alarm Over Online Surveillance and Encryption Privacy
  62. China’s Wukong Quantum Computer Runs PQC Shield Amid National Security Concerns Security
  63. Singapore Startup Brings Diophantine Equation Encryption to Market with LionGuard App Security
  64. Fraunhofer IPMS Unveils 4.1 Gb/s Quantum Random Number Generator for Data Centers Security
  65. France to Stop Certifying Non-Quantum Encryption by 2027 Privacy
  66. France to Phase Out Non-Quantum Encryption by 2027, Citing Growing Quantum Threats Security
  67. AMD Silently Disables Memory Encryption on Consumer Ryzen CPUs Privacy
  68. Signal Veterans Launch Encrypted Spaces to Bring End-to-End Encryption to Collaboration Apps Privacy
  69. Signal President Warns Company Will Leave UK If Forced to Weaken Encryption Privacy
  70. Signal Condemns UK Device-Scanning Proposal as Mass Surveillance Privacy

FAQ

What is end-to-end encryption?

End-to-end encryption means only you and the people you are communicating with can read or hear your messages and calls, and no one else, not even the service provider. Meta's Messenger help page describes it that way. It does not stop a participant from sharing a message, and it does not protect a message once an app or device reads it in plain text.

What is encryption?

Encryption is the scrambling of data into an unreadable form that only someone with the right key can reverse. It protects data on a disk or in the cloud, data travelling over the web (HTTPS) and messages in apps. Encrypting data at rest does not protect it from a provider that holds the keys itself.

How does encryption work?

An algorithm combines readable data (plaintext) with a secret key to produce unreadable ciphertext, and the matching key reverses the process. The algorithm is public; the secrecy of the key is what protects the data. Apps usually use an asymmetric key pair to agree on a key, then a symmetric key to encrypt the bulk of the data.

What is quantum encryption?

The term usually means post-quantum cryptography: algorithms designed to withstand attacks by quantum computers, such as ML-KEM for key exchange and ML-DSA for signatures. In 2026 Surfshark added ML-DSA to WireGuard and Cloudflare plans quantum-safe TLS certificates for the first quarter of 2027. Quantum key distribution is a different, hardware-based technique.

What is symmetric encryption?

Symmetric encryption uses the same secret key to encrypt and to decrypt. It is fast and is used for the bulk of the data in HTTPS and in messengers. Its weakness is key sharing: both sides need the key first, which is why asymmetric schemes such as RSA, with a public and a private key, are used to exchange it.

Can police read encrypted messages?

Yes, but usually without breaking the cipher. German customs officials logged into web clients of Telegram and WhatsApp with a suspect's phone number, and the tool GrayKey tries to bypass the iPhone's Inactivity Reboot. Checking your linked devices and restarting your phone are the simple defences the stories describe.