Tech Behind ThingsHow the ordinary machinery actually works

Data & Privacy

Backups Are The Weak Point In An Encrypted System

A conversation protected end to end stops being protected the moment either device saves a copy somewhere the provider can read.

Individual using a VPN application on a laptop at a desk in a modern office setting.
Photograph by Dan Nelson via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

Encrypted messaging protects data in transit so thoroughly that attacking it is impractical. The copies at either end are frequently protected far less.

The guarantee ends at the device

End-to-end encryption ensures only the participating devices hold the keys. Once a message is decrypted for display, it is ordinary data on that device.

Anything the device then does with it, including saving it to a backup, happens outside the protocol's protection.

The encryption was never broken. The plaintext was simply handed to something else and stored under different rules.

Cloud backups are often encrypted to the provider

Device backups are typically encrypted, but with keys the provider holds so that access can be restored to a user who has forgotten everything.

That design is a deliberate trade for recoverability, and it means the provider can produce the contents when compelled or when breached.

An encrypted conversation backed up this way is readable by a party the participants never included in it. The protocol's guarantee remains intact and has been routed around rather than defeated.

One participant decides for everyone

A conversation involves at least two devices, and each independently chooses its backup settings.

Somebody who has locked their own backups gains nothing if the person they are talking to has not, since both hold the same messages.

This asymmetry is invisible in the interface. Nothing indicates how the other end stores what it has received, and no setting on one device can constrain the other.

Key-protected backups shift the failure mode

Services increasingly offer backups encrypted with a key held only by the user, protected by a password or a long recovery code.

The provider then stores an unreadable archive, and losing the key means losing the archive with no route to recovery.

Whether that is preferable depends entirely on what is being protected against, and it is the rare setting where the safer option is also the more fragile one.

The pattern extends well beyond messaging

Encrypted notes synchronised to a general backup, password vaults exported for safekeeping and encrypted drives imaged while unlocked all reproduce the same error.

In each case protection was applied at one layer and the data was copied out at another where it did not apply. The copy is usually made by a process whose job is reliability rather than confidentiality.

Assessing this means asking where else the data exists, since an encrypted store is only as private as the least protected copy of its contents.

Questions readers ask

What happens if I lose my phone?

If your passkeys synchronise, they are available after signing into your platform account on a new device. If not, you need the recovery path.

Is a passkey the same as biometric login?

No. The biometric unlocks the key locally. Your fingerprint or face is never sent to the site and is not the credential itself.

Data & Privacysecurityauthenticationcryptographyaccounts
Mikkel Aas
Editor, Tech Behind Things

Mikkel edits Tech Behind Things and has taken apart more devices than he has successfully reassembled.

Also by Mikkel Aas