Toolkit by Bot&Partners / films / Encryption

Encryption

The word “encrypted” says little until you know who holds the key. The film follows one message from the device to the recipient and shows who can read it at each step.

Film · practicum “Security”

Wide version for a big screen

Worth watching first:

Keep scrolling

    As text

    The same as the films: every shot and its text. You can copy the text and give it to your own assistant along with your question.

    Encryption

    1. Follow the route of one message. From the device it travels over Wi-Fi and the provider's network to the service's server, and from there to the recipient. Without encryption the text is open to everyone along the way: the Wi-Fi owner, the provider and the service itself. Different kinds of encryption close it off from different parties.

    2. Channel encryption, familiar from the https mark, protects data on its way from the device to the server. The Wi-Fi owner and the provider see which site the connection is with, when, and how much data went through, but not the content. On the server this protection ends: the service receives the text in the clear.

    3. Encryption on the server means the data is stored on disks in encrypted form, and the service itself holds the key. This protects against the theft of a disk or a copy of the database. It does not protect against the service itself: the service can read the data and hand it over on a lawful demand, for example under a court order.

    4. With end-to-end encryption, as in Signal, the keys exist only on the devices of the two people talking. The server relays encrypted messages and cannot read them, even on demand. It still sees the metadata: who wrote to whom, when, and how much.

    5. Once the content is protected both in transit and on the server, the device itself becomes the weakest point. An unlocked phone shows everything, end-to-end encrypted chats included. That is why the screen lock and disk encryption - FileVault on a Mac, BitLocker on Windows - decide what a person who finds a lost laptop gets.

    6. People often expect more from a VPN than it gives. A VPN sends all traffic through an encrypted tunnel to its own server, so the Wi-Fi owner and the provider see only the tunnel. In exchange, the list of sites you visit becomes visible to the company that runs the VPN. The observer does not go away, it is replaced by one you chose yourself.

    7. All these cases come down to one rule: encryption protects against those who do not have the key and does not protect against whoever holds it. So the first thing to find out about any service or device is who has the key. This is usually described in the documentation, and the answer says more than the word “encrypted”.

    Next