WhatsApp has activated end-to-end encryption by default for messages and calls among more than one billion users, turning the world’s largest mobile messaging service into a communications network whose content the company says it cannot read.

The change covers individual and group chats, photographs, videos, files, voice notes and calls when participants use current versions of the application. Encryption keys are generated and stored on users’ devices, meaning WhatsApp’s servers transport scrambled information but do not possess the keys needed to turn it back into readable content.

“The idea is simple: when you send a message, the only person who can read it is the person or group chat that you send that message to,” co-founders Jan Koum and Brian Acton wrote in the company’s announcement Tuesday. They said the protection applies against cybercriminals, hackers, oppressive regimes and WhatsApp itself.

The deployment completes an engineering project conducted with Open Whisper Systems, the nonprofit software group behind the Signal encrypted-messaging application. Its Signal Protocol now protects WhatsApp conversations across Android, iPhone, Windows Phone, BlackBerry and older Nokia platforms, provided that both sides of a communication have updated software.

Encryption becomes a default, not a specialty

End-to-end encryption has long been available through security-focused tools, but WhatsApp’s scale changes its reach. The service passed one billion monthly users earlier this year, giving a cryptographic protection once associated with experts and activists to families, businesses and social groups in scores of countries without asking them to switch it on.

Open Whisper Systems said Tuesday that the integration now covers every message and call between users running current clients. Work began with encrypted Android text messages in 2014 and expanded progressively to other platforms and forms of communication.

The protocol uses a series of changing cryptographic keys rather than one permanent secret. New keys are derived as a conversation proceeds, a design known as ratcheting. That provides “forward secrecy”: obtaining a current key should not expose earlier messages. It also allows people whose phones are temporarily offline to receive encrypted messages later, a practical necessity for mobile communications.

Users can verify a conversation by comparing a long numeric security code or scanning a QR code displayed on each phone. Security researcher Bruce Schneier noted in a technical response to the rollout that this verification gives WhatsApp users a way to confirm a contact’s key, addressing a weakness in systems where users must simply trust the service’s directory.

The system is designed to make encryption invisible during ordinary use. That convenience is as important as the mathematics. Privacy tools often fail to achieve broad adoption because they demand that people manage keys or understand unfamiliar warnings. WhatsApp puts the stronger protection beneath a familiar interface and tells users about it with a notice inside each conversation.

What the protection does—and does not—cover

When end-to-end encryption works as designed, a wiretap on WhatsApp’s servers cannot reveal the content of messages or calls. A government can demand stored account records, and a network operator can observe that a connection occurred, but the conversation itself should remain unreadable without access to one of the participating devices.

The Electronic Frontier Foundation praised the design in its April 7 examination, highlighting the protocol’s forward secrecy and the company’s release of a technical white paper. The group also cautioned that closed applications cannot be inspected as fully as open-source software and that users still must trust WhatsApp to deliver the code it describes.

Encryption does not protect an unlocked or compromised phone. Malware, physical access, screenshots or a conversation partner who copies a message can expose content after it reaches an endpoint. It also does not make users anonymous: phone numbers, contact relationships, times and other account information may remain visible to the service even when message content is encrypted.

Nor is every exchange instantly protected if a participant runs an older version. The company’s notice indicates when a conversation has become end-to-end encrypted. A TechCrunch account of the rollout emphasized that the protection spans all supported mobile platforms, an unusually broad deployment for a system with many different clients.

The law-enforcement collision

The announcement comes one week after the Justice Department withdrew its case seeking to force Apple to help unlock an iPhone used by one of the San Bernardino attackers. The FBI accessed that device through a third party, avoiding a ruling on whether a company can be compelled to undermine its own security.

WhatsApp presents a related problem on a much larger scale. If the company truly lacks the keys, it cannot comply with a court order demanding readable message content. Reuters reported Tuesday that the service would no longer have the capability to read customers’ messages even when approached by law enforcement.

Officials argue that impenetrable communications can shield terrorists, organized criminals and child exploiters. Technology companies answer that adding exceptional access for authorities creates a weakness that hostile governments and criminals may also exploit. Cryptographic systems cannot reliably distinguish a court-authorized investigator from an attacker who obtains the same technical capability.

The conflict is already international. A Facebook executive was detained briefly in Brazil last month after authorities said WhatsApp failed to provide messages in a criminal investigation. WhatsApp maintained that it did not possess the requested content. Stronger universal encryption makes that inability a property of the service’s design rather than a discretionary policy.

The Guardian’s account connected Koum’s commitment to privacy with his childhood in Soviet-era Ukraine, where he has said fear of surveillance shaped family conversations. WhatsApp’s public position is therefore both technical and philosophical: private speech should be protected by default, including where governments reject that premise.

A billion-user security experiment

Deploying encryption at this scale carries operational risks. Users replace phones, reinstall applications and change numbers; groups add and remove participants; and unreliable networks interrupt key exchanges. The protocol must preserve confidentiality without making ordinary communication brittle.

It also concentrates responsibility in a company owned by Facebook. WhatsApp’s encryption code is based on an open protocol, but most of the application is not open for independent inspection. Users must trust the company’s implementation, update process and handling of unencrypted account data.

Still, the shift establishes a powerful new baseline. An ABC News report on the announcement noted that every message, photo, video or file is now protected by default for current users. That removes the most common reason encryption fails: people never turn it on.

The practical consequence will be felt far beyond WhatsApp. Competitors will face pressure to offer comparable protection, governments will confront more communications they cannot readily intercept, and consumers may begin to regard private messaging as an ordinary feature rather than an expert option. With one software update, end-to-end encryption has moved from the edge of the Internet to its mass-market center.