Learning Center
Encryption and identity
End-to-end encryption means only the sender and the intended recipients can read a message. Learn how public keys, digital signatures, MLS group encryption and forward secrecy work, and what encryption leaves visible.
Basics
What is end-to-end encryption?Only the sender and recipients hold the keys, whoever carries the message.→What are public and private keys?Two related keys, one shared and one secret, behind signatures and key agreement.→Encryption at rest vs in transitProtecting data on the move and data in storage, and what falls between.→What is a digital signature?Proof of who signed something and that it has not changed, and its limits.→How does end-to-end encryption work when there is no server?Key pairs, direct key exchange, and verifying keys when no directory exists.→
Keys and signatures
How do Ed25519 signatures work?Key generation, signing and verification in Ed25519, step by step.→What is X25519 key exchange?How two devices agree a secret in public, and what X25519 leaves to you.→What is a device key?One key pair per device, kept on the device, and what it can and cannot prove.→What is key rotation?Replacing keys on a schedule or after compromise, and why identity keys are harder.→What is a self-certifying identifier?Names derived from keys, checked by recomputing them, and what they cannot tell you.→What happens when a phone holding keys is lost?What a lost phone exposes, and how to cut its keys out of the system.→
Group encryption
How does MLS (Messaging Layer Security) work?Epochs, key packages, Commits and the ratchet tree, step by step.→MLS vs the Signal ProtocolPairwise ratchets against a shared group tree, and what each design trades away.→How does group encryption work?Pairwise fan-out, sender keys and MLS trees, and what joins and removals cost.→What is a key package in MLS?The signed, single-use bundle that lets someone add your device to a group.→What is a ratchet tree?The tree of keys that lets an MLS group change its secret cheaply.→What is forward secrecy?Why a key stolen tomorrow should not open the messages you sent yesterday.→What is post-compromise security?How a conversation becomes private again after a device's keys are stolen.→How do you use MLS (RFC 9420) for group messaging on mobile?What MLS handles, what your app must supply, and what changes on a phone.→
Threats and limits
How can a relay carry a message it cannot read?End-to-end encryption, authenticated encryption and sealed envelopes on untrusted relays.→What is metadata, and does encryption hide it?Who, when, how much and where, and what it takes to hide more than content.→Is Bluetooth's own encryption enough for private messages?Link encryption covers one hop between two paired devices, not the whole journey.→What can go wrong with encryption in a mesh messaging app?Impersonation, tampering, metadata, replay and weak group keys, and the standard fixes.→