Endtoend encryption protects the message. The part that…

End-to-end encryption protects the message. The part that gives you away is still in the open.

Every few months there's another round of "use Signal, it's end-to-end encrypted," and as far as it goes that's fine advice. But it quietly moves the whole argument to the one place encryption is strongest and away from the place it barely touches: metadata.

The content of a message is the letter. Who you talked to, when, how often, for how long, from where — that's the envelope, and almost nothing encrypts the envelope. Nobody needs to read your messages to learn that you called a divorce lawyer, then a clinic, then went quiet for three days. The pattern is the information. The content is often the least interesting part of it.

What gets me is the framing. "Is it end-to-end encrypted?" has become the entire checklist, and services lean into it because it's a box they can honestly tick while still logging every connection. Signal is the rare one that actually tried to shrink metadata — sealed sender, no contact graph sitting on the server — and even they can't undo the fact that a message left one place and arrived at another at a knowable time.

I don't think the takeaway is doom. It's that "encrypted" got quietly equated with "private," and those aren't the same claim. Encryption hides what you said. Privacy would also mean hiding that you said anything, to whom, and when — and almost nothing on offer does the second half.

Is there any consumer tool that actually protects the envelope and not just the letter, or is metadata just the standing price of using a network somebody else runs?

0 replies