# Security of encrypted messaging apps (e.g., WhatsApp, Signal)

**URL:** <https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622>\
**Category:** Factual Questions\
**Created:** [December 11, 2025, 9:31pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622 "2025-12-11T21:31:23Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [December 11, 2025, 9:31pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/1 "2025-12-11T21:31:23Z")

</div>

These apps encrypt data for transmission. But how common is, really, it to attempt to intercept data in motion? Even if the messages were in plain text, how commonly has that occurred? All the hacking I’ve ever heard of is either breaking into databases (data at rest) or hacking into a device (e.g., Pegasus). I would think it would be fairly easy to target an individual if you wanted to. You go right to the device and see everything in plain text.

---

<div class="post-metadata">

**Author:** ![Humbagger](https://avatars.discourse-cdn.com/v4/letter/h/db5fbb/32.png) [@Humbagger](https://boards.straightdope.com/u/Humbagger)\
**Post date:** [December 11, 2025, 9:55pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/2 "2025-12-11T21:55:26Z")

</div>

> [@CookingWithGas](#):
>
> But how common is, really, it to attempt to intercept data in motion? Even if the messages were in plain text, how commonly has that occurred?

You may have heard of something called the NSA running programs called PRISM and Upstream. You may have heard the name Snowden.

If not, here’s the short version:

Yes, the NSA did go right to the large Internet providers and basically said, “Send ALL your data traffic to us. But don’t tell anyone in any way about it.”

They later decided that it’s easier to just put wire taps on major fiber optic backbones.

You can probably imagine that the US might not be the only country with an agency like that.

---

<div class="post-metadata">

**Author:** ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)\
**Post date:** [December 11, 2025, 10:22pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/3 "2025-12-11T22:22:15Z")

</div>

Yeah, end-to-end encryption is most often (but not always) to protect against state agencies. It is also useful for when you don’t want the provider itself (e.g. WhatsApp/Meta) to be able to read your messages.

It’s also not uncommon for many devices these days to be encrypted themselves (Bitlocker on Windows, FileVault on Macs, various implementations on phones), and often using their own hardware encryption chips.

If you truly care about security, you would want all parts of the chain to be encrypted, with nobody except the two communicating people/devices able to decrypt it, and only while their devices are unlocked (after which it will re-encrypt). In practice very few people need strong security like that, but it’s also easy and cheap enough these days it’s more or less automatic.

An example of what happens when you don’t: In the 2010s, before Google made HTTPS the default, it was easy to hijack the Facebook sessions of anyone else on the same wifi: [Firesheep - Wikipedia](https://en.wikipedia.org/wiki/Firesheep)

---

<div class="post-metadata">

**Author:** ![md-2000](https://avatars.discourse-cdn.com/v4/letter/m/9d8465/32.png) [@md-2000](https://boards.straightdope.com/u/md-2000)\
**Post date:** [December 11, 2025, 11:56pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/4 "2025-12-11T23:56:15Z")

</div>

The trick is to intercept the data in transit. As mentioned, those with access to the transmission - or the power to compell access - can and have intercepted transmissions. But then, most transmissions will be encrypted nowadays. I presume simple SMS text messages are not, but every other situation where you connect to a server (i.e. message transits through a server) the message is encrypted by detault. Even email downloads are encrypted for most servers.

The next logical question is - how secure is that encryption? That’s something everyone would like to know, and the NSA would not like you to know. There are two problems - can encryption be broken in real time, and can it be eventually broken? Because, allegations are the NSA (and likely others) keep large data stores of relevant messages they hope to eventually decrypt. Mathematicians dealing in cryptography claim most ciphers are effectively impossible to decrypt, absent any significant flaw in the algorithm design. (which happens sometimes).

However, at this time it seems the simpler solution is to tap the phone with a software hack - it requires less time trcacking down the data path, and no need to install interception on the data, less need to filter gigabytes and Terabytes of data…

> **[Pegasus (spyware)](https://en.wikipedia.org/wiki/Pegasus_(spyware))**
>
> Pegasus is spyware developed by the Israeli cyber-arms company NSO Group that is designed to be covertly and remotely installed on mobile phones running iOS and Android. While NSO Group markets Pegasus as a product for fighting crime and terrorism, governments around the world have routinely used the spyware to surveil journalists, lawyers, political dissidents, and human rights activists. The sale of Pegasus licenses to foreign governments must be approved by the Israeli Ministry of Defens As ...

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [December 12, 2025, 12:15am UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/5 "2025-12-12T00:15:26Z")

</div>

> [@md-2000](#):
>
> Mathematicians dealing in cryptography claim most ciphers are effectively impossible to decrypt, absent any significant flaw in the algorithm design. (which happens sometimes).

Well, we think so, at least. Nobody knows of a quick factorization algorithm, for instance, and everyone thinks that it’s impossible, but nobody’s ever actually proven it.

---

<div class="post-metadata">

**Author:** ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)\
**Post date:** [December 12, 2025, 12:28am UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/6 "2025-12-12T00:28:35Z")

</div>

> [@CookingWithGas](#):
>
> But how common is, really, it to attempt to intercept data in motion?

Oh, one more example that comes to mind… in the old days (like 2010s and before), it used to be common for some organizations like universities or companies to run stateful packet inspection firewalls that can look at unencrypted traffic and selectively filter or block it based on its content. (Sometimes those work on encrypted traffic too by analyzing its shapes and headers and destinations and such, even if it can’t see the content.)

Really anybody on the same network with a “[promiscuous mode](https://en.wikipedia.org/wiki/Promiscuous_mode)” network card can see everyone else’s unencrypted traffic and reconstruct it with a free tool like [Wireshark](https://www.wireshark.org/). So in an org, all the other students/coworkers’ traffic would be visible to such a person, whether they were a sysadmin, a developer, or a malicious guest.

I _think_ this is still generally true of networks today that don’t practice “client isolation” to keep clients apart. But it’s also much less important now because most transports (like HTTPS) and apps (like WhatsApp) are encrypted by default.

You can also use such tools to monitor the unencrypted traffic of _local_ apps (like a competitor’s app you’re trying to reverse engineer, or a game you’re trying to cheat in). If the app itself does the encryption, then it’s more difficult… you have to find and rip out the private key from memory first, which is quite a bit harder than just running Wireshark.

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [December 12, 2025, 1:26am UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/7 "2025-12-12T01:26:04Z")

</div>

> [@Humbagger](#):
>
> “Send ALL your data traffic to us. But don’t tell anyone in any way about it.”

My understanding of that program was that they were providing transaction metadata, not message content. That is, who is calling whom, from where to where, and when.

---

<div class="post-metadata">

**Author:** ![echoreply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/echoreply/32/3641_2.png) [@echoreply](https://boards.straightdope.com/u/echoreply)\
**Post date:** [December 12, 2025, 1:30am UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/8 "2025-12-12T01:30:37Z")

</div>

> [@CookingWithGas](#):
>
> how common is, really, it to attempt to intercept data in motion?

Much less now days, because almost everything is encrypted for transmission. Really though, it can be anyone trying to do the interception, for a state level actor (perhaps not even _your_ state) who has infiltrated a major Internet interconnect point, to your techy friend whose WiFi you use at their house.

Probably the currently most dangerous interception happening now days is SMS. The old telecom protocols and systems are not even secure a little bit. This is why SMS as a second factor is considered poor (still much better than no second factor).

It’s also important to distinguish encrypted in transit (like HTTPS) and end-to-end encrypted, like Signal. End-to-end means that the unencrypted data only lives at the two end points. It is not readable anyplace in the middle. Encrypted in transit is like this website. This message was encrypted while transmitted to Discourse, and is encrypted while transmitted to you (the reader), but is also stored unencrypted at Discourse.

---

<div class="post-metadata">

**Author:** ![Duckster](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/duckster/32/1244_2.png) [@Duckster](https://boards.straightdope.com/u/Duckster)\
**Post date:** [December 12, 2025, 1:57am UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/9 "2025-12-12T01:57:19Z")

</div>

Sometimes it’s not about intercepting the message. Sometimes it’s about intercepting the messenger.

Stingray. Confirmed to be used by ICE to track people.

> **[Stingray phone tracker](https://en.wikipedia.org/wiki/Stingray_phone_tracker)**
>
> The StingRay is an IMSI-catcher, a cellular phone surveillance device, manufactured by Harris Corporation. Initially developed for the military and intelligence community, the StingRay and similar Harris devices are in widespread use by local and state law enforcement agencies across Canada, the United States, and in the United Kingdom. Stingray has also become a generic name to describe these kinds of devices.
> The StingRay is an IMSI-catcher with both passive (digital analyzer) and active (cell...

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [December 12, 2025, 1:00pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/10 "2025-12-12T13:00:48Z")

</div>

> [@Reply](#):
>
> Yeah, end-to-end encryption is most often (but not always) to protect against state agencies. It is also useful for when you don’t want the provider itself (e.g. WhatsApp/Meta) to be able to read your messages.

Which latter sentence really has two parts:

1. I don’t want e.g. Meta to read my messages to feed their algorithms or train their AIs. Or satisfy the prurient curiosity of their bored IT workers.

2. I don’t want e.g. Meta to be able to comply with a lawful (or increasingly unlawful) subpoena for my messages. If all they have is encrypted gibberish they can’t decrypt, I’m that much safer from overweening government. Maybe NSA can decrypt that stuff and maybe not. But if Meta has it in plain text, and hands it over when told, that sure makes government trawling efforts a lot easier.

---

<div class="post-metadata">

**Author:** ![FinsToTheLeft](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/finstotheleft/32/2930_2.png) [@FinsToTheLeft](https://boards.straightdope.com/u/FinsToTheLeft)\
**Post date:** [December 12, 2025, 1:25pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/11 "2025-12-12T13:25:37Z")

</div>

> [@Reply](#):
>
> Really anybody on the same network with a “[promiscuous mode](https://en.wikipedia.org/wiki/Promiscuous_mode)” network card can see everyone else’s unencrypted traffic and reconstruct it with a free tool like [Wireshark](https://www.wireshark.org/).

This hasn’t really been a thing for Ethernet since we replaced hubs with switches. A switch only forwards packets to the port corresponding to the MAC address of the destination.

If you have control of a managed switch, you likely have the ability to setup a port as a mirror to capture the traffic sent to another port. This is why physical security of network infrastructure is important.

---

<div class="post-metadata">

**Author:** ![scudsucker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scudsucker/32/14101_2.png) [@scudsucker](https://boards.straightdope.com/u/scudsucker)\
**Post date:** [December 12, 2025, 1:40pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/12 "2025-12-12T13:40:30Z")

</div>

> [@Reply](#):
>
> Yeah, end-to-end encryption is most often (but not always) to protect against state agencies. It is also useful for when you don’t want the provider itself (e.g. WhatsApp/Meta) to be able to read your messages.

I’ve done financial software interfaces, similar to PayPal (I am a software developer) and wow, security can get complicated. I can’t talk about WhatsApp/Meta/etc, but I can certainly say multilevel encryption is currently next to impossible to beat today.

Even when quantum computers come on line… someone will generate an encryption scheme they cannot beat.

That said, I don’t know or care about Meta (all my Facebook accounts are fake names) and if your NSA wants to read my bitter WhatsApp messages to my ex-wife for their amusement, I wish them all the happiness I wish her.

---

<div class="post-metadata">

**Author:** ![DPRK](https://avatars.discourse-cdn.com/v4/letter/d/4491bb/32.png) [@DPRK](https://boards.straightdope.com/u/DPRK)\
**Post date:** [December 12, 2025, 2:24pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/13 "2025-12-12T14:24:07Z")

</div>

I have seen people physically sniff everyone’s traffic off an Ethernet network, and it was not the NSA or Facebook spies doing it.

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [December 12, 2025, 4:01pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/14 "2025-12-12T16:01:02Z")

</div>

Who is “everyone”?

---

<div class="post-metadata">

**Author:** ![FinsToTheLeft](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/finstotheleft/32/2930_2.png) [@FinsToTheLeft](https://boards.straightdope.com/u/FinsToTheLeft)\
**Post date:** [December 12, 2025, 4:20pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/15 "2025-12-12T16:20:14Z")

</div>

> [@DPRK](#):
>
> I have seen people physically sniff everyone’s traffic off an Ethernet network, and it was not the NSA or Facebook spies doing it.

Very little traffic is not unicast. Unless you are looking for ARP traffic or DHCP requests, you really won’t see much without being attached to the source or target interface.

---

<div class="post-metadata">

**Author:** ![echoreply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/echoreply/32/3641_2.png) [@echoreply](https://boards.straightdope.com/u/echoreply)\
**Post date:** [December 12, 2025, 4:45pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/16 "2025-12-12T16:45:11Z")

</div>

> [@scudsucker](#):
>
> Even when quantum computers come on line… someone will generate an encryption scheme they cannot beat.

[Post-quantum cryptography](https://en.wikipedia.org/wiki/Post-quantum_cryptography) is already here and in use. There are active projects to add appropriate mechanisms to TLS (HTTPS, for encrypting web traffic), and they are available in some places.

Current versions of SSH will complain when the other end of the connection is not using quantum safe cryptography.

> [@FinsToTheLeft](#):
>
> you really won’t see much without being attached to the source or target interface

There are ways to turn switches into hubs by overflowing their arp tables, and other methods. Putting your packet logger on the router is a good way to capture Internet bound traffic.

In my experience of occasionally running a temporary network for about 150 users from all over the world, in 30 years we’ve gone from unencrypted POP3 logins being the norm, to now, when I don’t even bother to run a web caching proxy to improve performance. There is essentially zero http traffic to cache; it is all https.

---

<div class="post-metadata">

**Author:** ![FinsToTheLeft](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/finstotheleft/32/2930_2.png) [@FinsToTheLeft](https://boards.straightdope.com/u/FinsToTheLeft)\
**Post date:** [December 12, 2025, 4:53pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/17 "2025-12-12T16:53:38Z")

</div>

> [@echoreply](#):
>
> There are ways to turn switches into hubs by overflowing their arp tables, and other methods. Putting your packet logger on the router is a good way to capture Internet bound traffic.

I agree, either you use an exploit or you are authorized to access the router or switch and capture the traffic. The reality is that 99.9% of what you capture is going to be ARP, DHCP, DNS, and TLS encrypted traffic.

I’m like you, started in this game in the 90s. I remember setting up my first VPN over ISDN so we could pass internal email with Exchange 5.0 between our Toronto, Ottawa, and Sydney Australia offices. The days of setting up a caching proxy to limit the traffic to Yahoo News is long gone.

---

<div class="post-metadata">

**Author:** ![scudsucker](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/scudsucker/32/14101_2.png) [@scudsucker](https://boards.straightdope.com/u/scudsucker)\
**Post date:** [December 12, 2025, 4:56pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/18 "2025-12-12T16:56:17Z")

</div>

Yeah, I’m a nerd, I know how to use Wireshark.

> [@FinsToTheLeft](#):
>
> either you use an exploit or you are authorized to access the router or switch and capture the traffic. The reality is that 99.9% of what you capture is going to be ARP, DHCP, DNS, and TLS encrypted traffic.

---

<div class="post-metadata">

**Author:** ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)\
**Post date:** [December 12, 2025, 4:57pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/19 "2025-12-12T16:57:33Z")

</div>

> [@FinsToTheLeft](#):
>
> The days of setting up a caching proxy to limit the traffic to Yahoo News is long gone.

Only to be replaced by the One Big Caching Proxy in the Sky, aka Cloudflare. Now everything is fast and secure, but when there’s a problem, half the world goes dark…

---

<div class="post-metadata">

**Author:** ![FinsToTheLeft](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/finstotheleft/32/2930_2.png) [@FinsToTheLeft](https://boards.straightdope.com/u/FinsToTheLeft)\
**Post date:** [December 12, 2025, 6:01pm UTC](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622/20 "2025-12-12T18:01:08Z")

</div>

> [@Reply](#):
>
> Only to be replaced by the One Big Caching Proxy in the Sky, aka Cloudflare. Now everything is fast and secure, but when there’s a problem, half the world goes dark…

The first rule of Cloudflare is that no one talks about Cloudflare!

[Next page](https://boards.straightdope.com/t/security-of-encrypted-messaging-apps-e-g-whatsapp-signal/1025622.md?page=2)
