What Is a Cookie? (No, Not That Kind – The Website Kind)
By Ken Hollow, the man who had to explain to a fox spirit that the “accept all cookies” button is not an invitation to baked…

By Ken Hollow, the man who had to explain to a fox spirit that “encrypted” does not mean the message is written in a secret fox language, though she seemed genuinely disappointed by this
“Ken. WhatsApp says my messages are end-to-end encrypted.”
“Good. That means only you and the person you’re messaging can read them.”
“Not even WhatsApp can read them?”
“Not even WhatsApp.”
“Then how does WhatsApp work if it can’t read the messages it’s delivering?”
That’s actually an excellent question, and the answer is the most interesting part of how modern encryption works. Here’s what end-to-end encryption actually means, how it functions, and which apps genuinely have it versus those that use the phrase loosely.
End-to-end encryption means your message is scrambled on your device before it’s sent, and can only be unscrambled by the recipient’s device. The app company acts as a delivery service that carries a sealed envelope — they can see that a message was sent, and who sent it to whom, but not what’s inside. Truly end-to-end encrypted apps cannot read your messages even if a government demands they do, because they don’t have the key.
Encryption is the process of scrambling information using a mathematical key so that only someone with the correct key can unscramble it. Think of it like a padlock where only you and the recipient have a copy of the key — anyone who intercepts the locked box sees only the box, not what’s inside.
In standard (non-end-to-end) encryption, the app company holds one of the keys. Your message is encrypted between you and their servers, then decrypted by the server, then re-encrypted between the server and the recipient. The server sees the plain text message in the middle of that process. This means the company can read your messages — and can be compelled by courts or governments to provide them.
In end-to-end encryption, the keys exist only on the devices at each end of the conversation — your phone and your recipient’s phone. The server in the middle never has the key. It delivers an envelope it cannot open. The company genuinely cannot read your messages, not because they’ve chosen not to, but because they mathematically cannot — they don’t have what’s needed to decrypt them.
“So WhatsApp is the postal service and the message is in a locked box, and WhatsApp doesn’t have a key?” — Exactly. They can see the box, the sender’s address, and the recipient’s address. Not what’s in the box. “And they couldn’t open it even if someone official asked them to?” Correct — they’d hand over the locked box with no ability to open it themselves. “That’s a very good system.” It’s the correct approach for private communication.
| App | End-to-End Encrypted? | Notes |
|---|---|---|
| Signal | Yes — always, by default | The gold standard. Open-source protocol audited by security researchers. No metadata collection beyond phone number. |
| Yes — messages and calls | Uses the Signal protocol for message content. However, Meta collects substantial metadata: who you talk to, when, how often, your location, device info. | |
| iMessage | Yes — when both parties use iMessage (blue bubbles) | Green bubbles = SMS, which is NOT encrypted. iCloud backup of messages can be accessed by Apple unless you enable Advanced Data Protection. |
| Telegram | Only in “Secret Chats” | Regular Telegram chats are NOT end-to-end encrypted — Telegram holds the keys and can read them. Secret Chats are E2E but not the default. |
| Facebook Messenger | Only in “End-to-end encrypted” chats | Like Telegram, regular chats are not E2E encrypted. Must opt in to encrypted chats specifically. |
| Google Messages (Android) | Yes — when both parties use RCS | RCS between Android users is E2E encrypted. SMS fallback is not. |
| Gmail / Outlook | No | Email is not end-to-end encrypted by default. The provider can read your emails. For encrypted email, you’d need a service like ProtonMail. |
| Snapchat | Partially | Some messages are encrypted in transit, but Snapchat has the ability to access content in some circumstances. Not true E2E. |
End-to-end encryption protects the content of your messages. It does not necessarily protect metadata — information about the message rather than the message itself.
Metadata includes: who you communicated with, when, how often, for how long, your approximate location, your device, and your IP address. This information can be enormously revealing even without the message content. Intelligence agencies have famously argued that metadata tells them more than content in many cases.
Signal collects virtually no metadata — it knows your phone number and the last time you used the app, and that’s essentially it. WhatsApp encrypts message content but collects extensive metadata for Meta’s advertising and analytics infrastructure. These are meaningfully different privacy postures, even though both use the Signal protocol for message encryption.
Encryption protects messages in transit and at rest on the server. It doesn’t protect you from:
Someone with physical access to your unlocked phone. If someone picks up your phone while it’s unlocked, they can read every message. Encryption is about the transmission, not what’s visible on your screen.
The other person in the conversation. The message is decrypted on their device. If their phone is compromised, or if they screenshot and share the conversation, encryption provides no protection against that.
Malware on your device. If your phone has spyware installed, it can capture messages before they’re encrypted or after they’re decrypted. Keep your software updated — this is the main defence.
For deeper security across all your online activities, two-factor authentication on your accounts and a VPN on public networks address different parts of the threat landscape that encryption alone doesn’t cover.
“So WhatsApp can’t read what I say, but it knows I spoke to you, when, how long, and roughly where I was?” — Correct. “That’s a lot of information for someone who claims not to be reading my messages.” It is. The contents are private. The pattern of your communication is not. “I’m switching to Signal.” That’s the logical conclusion. “I’ll tell everyone I know to switch too.” That’s also how Signal spreads. It requires everyone to be on it, which is the only real limitation.
End-to-end encryption means your message is scrambled on your device and can only be unscrambled by the recipient’s device — the company delivering it never has the key to read it. Signal is the gold standard: fully encrypted, minimal metadata, open-source. WhatsApp uses strong encryption (Signal’s protocol) but collects significant metadata for Meta. iMessage is encrypted but only for blue bubbles (other iPhone users) — green bubbles (SMS) are not. Telegram and Facebook Messenger are NOT end-to-end encrypted by default — you have to opt into “Secret Chats” specifically. Email (Gmail, Outlook) is not encrypted. Encryption protects content in transit, not from someone with your unlocked phone, malware on your device, or the other person sharing what you sent.
Hi. I’m Ken. I run Two Second Solutions, a one-man agency that somehow landed a fox spirit influencer as a client. I drink too much coffee, blog when I need to vent, and regularly update my résumé just in case she sets the office on fire again. I’m not crying — it’s just spell residue.
By Ken Hollow, the man who had to explain to a fox spirit that the “accept all cookies” button is not an invitation to baked…
By Ken Hollow, the man who told a fox spirit to “clear her cache” and had to explain that he wasn’t deleting the internet “Ken.…
By Ken Hollow, the man who had to clarify to a fox spirit that 5G is a cellular network standard and not, as she suspected,…