What is end-to-end encryption, and how does it work?

End-to-end encryption keeps the keys on your devices, so even the service can't read your messages. How it works, how WhatsApp, Signal and Telegram differ, and what it means for leaks.

8 min read
On this page 8 sections
  1. How it works: the keys stay on the devices
  2. E2EE vs encryption in transit and at rest
  3. WhatsApp, Signal and Telegram compared
  4. How group chats stay end-to-end encrypted
  5. What E2EE means for reporting leaks
  6. Can video streaming be end-to-end encrypted?
  7. Key takeaways
  8. Frequently asked questions

End-to-end encryption (E2EE) means a message is encrypted on the sender's device and can be decrypted only on the recipient's device. The company running the service passes it along but cannot read it, because it never holds the keys. WhatsApp and Signal chats work this way by default, while many other services, including Telegram's ordinary chats, groups and channels, encrypt data only between your device and the company's servers, so the company can read it.

How it works: the keys stay on the devices

The idea is simple: only the two ends of a conversation ever hold the keys. Here is what happens when Priya sends Arjun a message on an end-to-end encrypted app:

  1. Each phone makes its own keys. When the app is installed, Arjun's phone creates a key pair. The private key never leaves the phone; the public key is uploaded to the service.

  2. Priya's app sets up a shared secret. It fetches Arjun's public keys and combines them with its own private keys in a Diffie-Hellman key exchange. Both phones end up with the same secret; the server, which only saw public keys, doesn't.

  3. The message is encrypted on Priya's phone with a key derived from that secret, and sent to the server as unreadable ciphertext.

  4. The server stores and forwards it, without being able to open it.

  5. Arjun's phone decrypts it with its own copy of the secret.

Good E2EE designs also keep changing the keys. In the Signal protocol, which WhatsApp uses, new keys are derived as the conversation goes on, so even if someone stole the keys from a phone today, they couldn't use them to read messages sent earlier.

There is one weak spot: how do you know the public key really came from Arjun and not from someone in the middle? Apps let you check. WhatsApp shows a QR code and a 60-digit security number for each chat; if the numbers match on both phones, nobody has swapped the keys.

E2EE vs encryption in transit and at rest

Many apps say they are "encrypted". The question is who can decrypt.

AspectEncryption in transitEncryption at restEnd-to-end encryption
Protects againstPeople on the network, such as a Wi-Fi owner or internet providerStolen disks, phones or backupsEveryone except sender and recipient, including the service itself
Can the service read your data?Yes, once it arrivesYes, it holds the keysNo
ExamplesHTTPS websites, most apps, Telegram's cloud chatsPhone storage, cloud databasesWhatsApp chats, Signal, Telegram's secret chats

These layers stack rather than compete; our guide to encryption at rest vs in transit covers the first two. One thing none of them hides is metadata: who talks to whom, when and how often can still be visible to the service.

WhatsApp, Signal and Telegram compared

ServiceOne-to-one chatsGroup chatsCan the company read messages?
WhatsAppEnd-to-end encrypted by defaultEnd-to-end encrypted by defaultNo, for chats between people
SignalEnd-to-end encrypted by defaultEnd-to-end encrypted by defaultNo
Telegram cloud chats (the default)Encrypted between your device and Telegram's serversSameYes, the keys are on Telegram's side
Telegram secret chatsEnd-to-end encrypted, on one device eachNot availableNo

A few details matter in practice:

  • WhatsApp builds on the Signal protocol, according to its encryption white paper (updated February 2026). The same paper says WhatsApp does not treat chats with businesses that use Meta's hosted Cloud API as end-to-end encrypted, so a chat with a company's WhatsApp account may not be.

  • Signal has added protection against future quantum computers, first when chats are set up (2023) and then in the ongoing key changes, which it announced in October 2025.

  • Telegram, according to its FAQ, uses server-client encryption for cloud chats, both private and group, and adds client-to-client encryption only in secret chats. Secret chats are started from one contact's profile and exist only on the devices where they were created. Telegram also offers end-to-end encrypted calls.

How group chats stay end-to-end encrypted

Encrypting every message separately for each of 200 members would be slow. WhatsApp uses an approach called Sender Keys:

  1. The first time you post in a group, your app creates a sender key.

  2. It sends that key to every member individually, through the one-to-one encrypted sessions described above.

  3. After that, each of your messages is encrypted once with your sender key and signed, and the server delivers the same ciphertext to everyone.

  4. When someone leaves the group, every member throws away their sender key and makes a new one, so the person who left can't read what comes next.

A newer standard, Messaging Layer Security (MLS), published by the IETF as RFC 9420 in July 2023, is designed to do the same job efficiently for very large groups.

Remember what group encryption does not do. Every member can read, forward and screenshot every message. E2EE protects a group from outsiders, including the platform, not from its own members.

What E2EE means for reporting leaks

Paid course videos and notes often leak into Telegram channels and WhatsApp groups. Encryption shapes what the platforms can do about it:

  • Telegram public channels are not end-to-end encrypted; they are part of Telegram's public platform. Telegram accepts copyright complaints about public channels, bots and sticker sets from the copyright owner or an authorised agent. For private chats and groups, its FAQ says: "We do not process any requests related to them." Our guide to reporting a Telegram channel covers the process.

  • WhatsApp groups are end-to-end encrypted, so WhatsApp can't scan them for leaked lectures. Action depends on a member reporting the group; see our guide to reporting WhatsApp groups.

This is why watermarks matter so much. Encryption hides a group's content from the platform, but not from its members, and a dynamic watermark carrying the buyer's name or phone number travels with every copy. One screenshot shared by any member can identify the account a leak came from. For students, the lesson is equally direct: sharing a paid course in an encrypted group doesn't hide it from the people in that group, and it doesn't make it legal.

Can video streaming be end-to-end encrypted?

Live calls can. WhatsApp's voice and video calls are end-to-end encrypted, and some meeting apps offer an E2EE mode. That mode comes with a trade-off: anything that needs the server to see the video, such as cloud recording, live streaming or automatic transcription, can't work, because the server never has the keys.

Recorded course videos are different. The institute's platform is the publisher, and it has to process each lecture, converting it into several qualities for different network speeds, before anyone watches. So the platform necessarily holds the original. Recorded lectures rely on other layers instead: encryption in transit and in storage, control over who can play them, and deterrence at the screen itself, because anything shown on a screen can be filmed. Our guide to what encryption is explains why that last gap exists.

Key takeaways

  • With end-to-end encryption, only the sender's and recipient's devices hold the keys; the service can't read the content.

  • WhatsApp and Signal encrypt chats end to end by default; Telegram does so only in one-to-one secret chats.

  • Groups use shared sender keys that are replaced whenever someone leaves.

  • E2EE protects against outsiders, not against members who forward or screenshot, so watermarks remain the way to trace leaks.

  • Recorded video can't be end-to-end encrypted in the messaging sense, so it needs encryption plus protection at the screen.

If leaked lectures are a problem for your institute, VidSafe from Upclass protects videos with VidSafe proprietary encryption, screen- and camera-recording detection, account-sharing prevention and PDF watermarking. It also adds visible and invisible watermarks that are extremely hard to remove, even after heavy re-encoding, so a leaked copy can be traced back to the account it came from.

Frequently asked questions

Does Telegram have end to end encryption?

Only in secret chats. Telegram's normal cloud chats, including groups and channels, are encrypted between your device and Telegram's servers, and Telegram holds the keys so your history syncs across devices. Secret chats are end-to-end encrypted, one-to-one only, and exist only on the devices where they were started. You have to start one deliberately from a contact's profile. Telegram's voice and video calls are also end-to-end encrypted.

How does end to end encryption work on WhatsApp?

WhatsApp uses the Signal protocol. Each of your devices creates its own keys, and only public keys go to WhatsApp's servers. When you message someone, your phone uses their public keys to set up a shared secret, encrypts the message, and sends ciphertext that the servers pass along but can't read. Keys keep changing as you chat, and you can verify a contact through a QR code or 60-digit number.

How does end to end encryption work in group chat?

In WhatsApp and similar apps, each sender creates a sender key and shares it privately with every group member through one-to-one encrypted sessions. Each message is then encrypted once with that key and delivered to all members by the server, which can't read it. When someone leaves, members replace their sender keys so the departed member can't read new messages. The newer MLS standard does this for very large groups.

What is end to end encryption backup?

It is a chat backup encrypted on your phone before it is uploaded to cloud storage such as Google Drive or iCloud, so neither the cloud provider nor the messaging company can read it. On WhatsApp it is optional: you protect the backup's key with a password, or keep a 64-digit key yourself. Without it, those cloud backups aren't covered by WhatsApp's end-to-end encryption.

Share this article

Looking for something else?

Talk to Us