Encrypt every message perfectly and an observer still learns who talks to whom, when, how often, and from where. Why metadata is frequently the more valuable intelligence, and what can and cannot be done about it.
Part 7 of 10 in Trust through mathematics
Michael Hayden – the only person to have run both the NSA and the CIA – told a 2014 debate at Johns Hopkins, “We kill people based on metadata.” The line was not a boast about breaking encryption. It was the opposite point: for a great many purposes, nobody needs to.
The earlier posts in this series looked at what encryption guarantees, and at who holds the keys. This one concerns everything those guarantees leave exposed: the data about the data. Who communicated with whom. When, how often, in what bursts, from which locations, on which devices, in messages of what size. Content encryption – even flawless, end-to-end, key-custody-correct encryption – conceals none of it.
Why The Envelope Beats The Letter
It is tempting to treat metadata as the lesser prize, the residue left once the content is locked away. For a serious analyst the relationship runs closer to the reverse, for three reasons.
The first is that metadata is structured. Content is ambiguous, idiomatic, multilingual, and expensive to interpret at scale; metadata arrives pre-formatted for analysis, in timestamps, identifiers, durations, and network addresses. Building a social graph from a million encrypted conversations is trivial. Extracting one from a million transcripts is a research project.
The second is that metadata does not lie well. People speak in irony and shorthand; their traffic patterns are artless. That a company’s general counsel exchanged forty messages with an insolvency practitioner across a single weekend says what it says, in any language, whatever the messages themselves contained.
The third is that metadata aggregates. One communication event reveals little. A year of them reveals an organisation’s structure, its decision cadence, its outside advisers, who actually talks to whom as against the org chart’s theory – and, when the pattern shifts, that something is under way. The demonstrations are not new. A Stanford study of telephone metadata from 546 volunteers inferred medical conditions, firearm ownership, and financial distress from the patterns alone, without a word of content. Traffic analysis is older still: navies were locating fleets from the rhythm of their wireless chatter a century ago, every message unread.
For an organisation the translation is direct. The metadata of an M&A advisory firm’s communications – which counterparties, at what cadence, with what sudden intensification – is the deal flow. Encrypting the messages protects the wording, which is often the least sensitive thing about them.
What “Encrypted” Platforms Still See
This is where the earlier questions – who operates the infrastructure, and who can be compelled to hand over what it holds – return with force. A platform’s end-to-end encryption for content can be entirely real whilst it observes, retains, and is legally obliged to disclose a great deal besides: account identifiers, usually phone numbers; contact graphs; group memberships; the timing and size of messages; IP addresses, and therefore locations; and device information.
The variation between platforms is wide, and largely absent from their marketing. Some have engineered hard against their own visibility through measures such as sealed sender, private contact discovery, and minimal retention. Published responses to legal demands can show how little a service is technically able to produce. Others retain rich metadata as a matter of architecture, and disclose it only in the quieter paragraphs of a privacy policy. The label “end-to-end encrypted” does not tell the two apart. Disclosure records and transparency reports do: what a platform proved able to produce under legal compulsion is the most candid documentation of its architecture that exists.
The structural point outlives any particular vendor: metadata visibility follows infrastructure custody. Whoever runs the servers sees the traffic patterns, whatever the encryption does to the payloads. The operator of a consumer platform sits inside every customer’s metadata perimeter by construction. Moving communications onto infrastructure the organisation controls itself – as we did with SemaFore, run deliberately on UK infrastructure with no third-party cloud in the data path – does not make metadata vanish. It changes who can see it: from a platform with its own commercial interests and legal exposures, to the organisation itself. For some, that distinction is academic. For others it is the whole question.
What Can Be Done
Metadata is harder to protect than content, for a structural reason: networks must route, and routing needs addresses. The mitigations are real but partial, and they stack.
The highest-leverage move is minimisation at the platform, since the strongest metadata protection is the data that never exists. Platforms differ enormously in what they generate and keep, so the platform for sensitive communications should be chosen on its metadata behaviour and who holds the infrastructure, not on the encryption badge.
Custody of the infrastructure follows the same logic: self-hosted or organisation-controlled deployment moves the observer problem inside the organisation’s own governance, where it belongs for the most sensitive traffic.
Traffic-analysis resistance attacks the problem head-on – onion routing, mix networks, padding, cover traffic – at a real cost in latency and bandwidth. These stay specialist tools, suited to particular threat models rather than general use, and conspicuous in their own right, which is itself a kind of metadata.
And there is behavioural discipline, the least technical mitigation and often the most effective: deciding which relationships and activities should not sit on a third party’s platform at all, and holding them elsewhere. No protocol substitutes for the judgement that some patterns are better never created.
What does not work is the common default – assuming the encryption badge covers the envelope as well as the letter.
The Boundary Question
Every security claim has a precise boundary, and the incidents tend to live just outside it. Content encryption’s boundary is unusually crisp: it protects what was said, and nothing about the saying of it. The discipline is to put the boundary question to any platform trusted with sensitive communication – if this operator disclosed everything it technically could, what would that reveal about us?
For most organisations the answer, drawn candidly, takes in their advisers, their counterparties, their internal rhythms, and the early signatures of everything they have not yet announced. It demands the same seriousness as the words themselves, and it is secured by architecture and custody, not by any badge on a download page.