Communication Under Surveillance
Why end-to-end encryption is more than a privacy feature — and why control over our private communication has become one of the most important security questions of the digital age.
We write messages, send photos, make video calls, store documents in the cloud, and manage our entire lives through smartphones. In the process, an enormous amount of personal information is generated: private messages, photos and videos, location information, contacts, voice and video calls, business communication, health information, political views, passwords and credentials, financial information, personal documents, and movement and connection data.
A large share of this communication is now transmitted encrypted. With genuine end-to-end encryption (E2EE), a message is meant to be protected so that only the sender and the intended recipient can read its content. But this very principle is increasingly at the centre of a political and technical dispute.
Under the term "chat control," various legislative proposals and measures are being discussed that would require providers of communication services to detect certain illegal content, or grant them the corresponding capability to do so.
This is exactly what politicians, data protection authorities, security researchers, scientists, civil rights organisations, and technology companies are currently arguing about. And this discussion doesn't only concern criminals. It concerns every single person who owns a smartphone.
What is chat control?
"Chat control" is not the official name of a single technical procedure. The term is used mainly by critics and in the public debate. At its centre is the European legislation to prevent and combat child sexual abuse online, often referred to as CSAR (Child Sexual Abuse Regulation). Among other things, it concerns how online services can or should detect, report, and remove depictions of child sexual abuse.
The stated goal is fundamentally understandable: children must be protected from sexual abuse. The dispute begins with the question of which technical means may be used for that. Because if a system is meant to automatically analyse private messages, some technical way of examining those messages has to be created somewhere. And that is exactly where the fundamental tension arises: privacy and end-to-end encryption on one side, automated content control on the other.
Why end-to-end encryption matters so much
End-to-end encryption, put simply, means: sender → encrypted message → recipient. The message is encrypted on the sender's device, the service transports encrypted data, and the recipient's device decrypts it. The provider is not supposed to have access to the plaintext. With Signal, for example, messages and calls are end-to-end encrypted by default. Signal explicitly states that, as a result, the service itself has no access to the content of messages and calls.
That is not merely a convenience feature. Encryption protects, among other things:
- private conversations
- corporate communication
- trade secrets
- journalistic sources
- medical information
- attorney-client communication
- personal relationships
- political communication
- credentials
- sensitive documents
Encryption doesn't only protect "secrets"
A common misconception goes: "If you have nothing to hide, you don't need encryption." That's wrong, both technically and socially. After all, you don't lock your front door because you're committing a crime behind it. Privacy is a protective function. A doctor must be able to communicate confidentially with a patient, a journalist must be able to protect their source, a company must be able to transmit trade secrets, a lawyer must be able to communicate with their client, a citizen must be able to exchange political views, and a victim of domestic violence must be able to seek help without the abuser being able to read along.
Encryption therefore doesn't only protect secrets from the state. It protects people from:
- criminals
- hackers
- extortionists
- stalkers
- corporations
- data brokers
- foreign states
- intelligence services
- compromised networks
and, depending on the legal framework, from unnecessary state surveillance as well.
The central technical problem
The most important technical question is: how can an encrypted chat be examined automatically without undermining the protection encryption provides? If a message is genuinely meant to be accessible only to sender and recipient, a central server normally can't simply analyse its content. So the analysis has to be moved to a different point.
One option is client-side scanning, or on-device scanning: the message or file is examined on the user's device — analysis on the smartphone, then a decision of "unremarkable" or "match", only afterwards encryption and transmission. That way, the central encryption doesn't necessarily need to be mathematically "cracked". But: the plaintext must be analysable before it is encrypted. And that is exactly why many security researchers see this as a fundamental intrusion into the security model of end-to-end encryption.
The perhaps bigger risk factor: scope creep
Suppose a technical infrastructure can search for a specific category of illegal content today. What stops it from being used for other categories tomorrow? This problem is called function creep, or scope creep. An infrastructure originally created for a narrowly defined purpose can later be expanded.
Today: child abuse. Tomorrow, possibly: terrorism. Later: copyright infringement. Later still: disinformation. Or: politically unwelcome content. The specific path isn't inevitable. But the technical possibility can be created. And that is exactly why the architecture is decisive.
Encryption doesn't automatically protect against surveillance
Here too, one has to be very precise. End-to-end encryption mainly protects the content of communication. It doesn't automatically protect against every form of surveillance. There is, for example:
- metadata
- IP addresses
- timestamps
- phone numbers
- device information
- location information
- connection data
- contact relationships
- push notifications
- account information
A surprisingly detailed movement and relationship profile can emerge from this alone.
Encryption against the attacker — but security of the device
Another decisive point: the best encryption doesn't help much if your device is compromised. If an attacker gets direct access to your smartphone, they may be able to read data before it's encrypted, or after it's decrypted. That's why device security matters just as much as messenger encryption.
There is an important difference between targeted and mass surveillance
Targeted surveillance
A specific suspect is the focus, based on a legal procedure.
Mass analysis
A technical system fundamentally examines the communication of a very large number of unsuspected people.
These two approaches are very different, both from a security and a societal standpoint. With targeted measures, a concrete suspicion and a legal basis can exist. With mass automated analysis, by contrast, a large volume of unsuspected communication is processed in the first place. That very question of proportionality is a central point of criticism.
Surveillance and espionage: the international context
Europe is not the only region where encrypted communication is under pressure. Worldwide, states are trying to obtain communication data, regulate encryption, analyse metadata, expand surveillance powers, and require platforms to cooperate. The problem is international. Because weakening a technology in Europe may well not stay confined to Europe. Technologies get deployed globally.
The future of privacy may be decided on the device
The classic idea is: "my message gets encrypted on my device." In the future, the decisive question could instead be: "what is my own device allowed to know and analyse about me?" Because modern smartphones can recognise speech, recognise faces, classify images, analyse text, recognise behaviour, determine location, analyse contacts, and process biometric data. The smartphone is therefore no longer just a communication device. It is a permanent sensor for your own life.
How users can protect their communication today
The good news: there is already a lot you can do today – that applies to choosing a messenger and securing your own device, as well as to how you handle files.
ℹ️ Files such as PDFs, photos, or backups should be encrypted too. A widespread weak point here isn't the encryption itself, but the transfer path: when people share a file, they often upload it unencrypted to a provider that stores a copy of it.
Our Vault encrypts files directly in the browser and only relays them as a data stream, without storing them itself.
🔗 Related: data minimization often starts at sign-up. If you'd rather not register with your main phone number or email address, the PRO6SELLER shop offers temporary SMS and email verifications – see our articles Virtual & Temporary Phone Numbers and Temporary Email Addresses.
To see how commercially collected location data is already being used for surveillance purposes, independent of any chat-control debate, read our article Fog Reveal & Location Tracking.