People buy encrypted phones for the wrong reason and then trust them for the wrong things. The device does something real and worth having. It also leaves large categories of exposure completely untouched, and the gap between what it protects and what people assume it protects is where the damage happens.
What encryption actually covers
Two different protections get bundled under one word.
Encryption at rest protects the contents of the device when it is off or locked. On a modern phone with a strong passcode, this is genuinely strong. A stolen handset is, to an ordinary thief, an expensive brick.
Encryption in transit protects a message between two endpoints. End-to-end encrypted messaging means the operator carrying the message cannot read it, and neither can anyone intercepting the network path.
Both are worth having and both work. CISA’s Mobile Communications Best Practice Guidance, issued after cyber espionage activity targeting commercial telecommunications infrastructure, recommends end-to-end encrypted applications for text, voice and video calls precisely because the network layer could not be assumed safe.
What it does not cover
Metadata
This is the biggest misunderstanding. Encryption protects the content of a message. It does not hide that a message was sent, when, between which two accounts, how often, or from roughly where. CISA’s guidance gives specific attention to metadata precisely because details of who communicated with whom are themselves sensitive.
For an investigator, a protection detail, or an adversary, the pattern is frequently more useful than the content. Knowing that a chief executive exchanged forty messages with an attorney between 11 p.m. and 1 a.m. on a particular Tuesday is often enough. Nobody needs to read them.
The endpoints
Encryption protects the path. It cannot protect either end. If someone can see the screen, the encryption is irrelevant — and “someone” here includes a shoulder in an airport lounge, a camera behind a desk, and malware with screen-capture access. Every encrypted message is decrypted on arrival, by design, because otherwise the recipient could not read it.
Backups and cloud sync
The commonest real-world failure. Messages protected in transit and at rest on the device are copied to a cloud backup which is encrypted with a key the provider holds and can be compelled to produce. The chat is secure; the backup of the chat is not. This is routine in litigation and in criminal matters, and most users have never checked the setting.
The other person
Every conversation has at least two devices. Yours can be immaculate and it will not matter if the recipient screenshots the thread, backs up to an unprotected account, or hands over the handset. Encrypted communication is only as strong as the least careful participant.
Lawful process and physical access
A locked phone in a drawer is well protected. A phone unlocked in someone’s hand is not protected at all. Compelled unlocking, consent searches and simple observation all bypass cryptography entirely, because none of them attack it.
The other half of CISA’s advice, which is duller and more useful
The guidance does not stop at “use encrypted messaging”. The rest of it addresses the routes that actually get used.
- Do not rely on SMS for multi-factor authentication. Text messages are unencrypted in transit, which makes SMS codes a weak second factor. Use FIDO-based authentication instead.
- Set a PIN on the telecommunications account itself. This is the control against SIM swapping — where an attacker persuades the carrier to move the number to their device and thereby collects every SMS code sent to it. Almost nobody does this, and it defeats an attack that requires no technical skill at all.
- Use a password manager. Credential reuse remains a leading cause of account compromise.
- Keep the operating system and applications current. Unpatched devices are exploited through known vulnerabilities, not novel ones.
- Prefer business-grade VPN provision to consumer personal VPNs. A consumer VPN moves your traffic from a carrier you have a contract with to a company you know nothing about.
Read that list against the average “secure phone” purchase. The buyer paid for the first item and skipped the five that would have stopped the attack most likely to happen to them.
A note on devices sold as impossible to trace
Phones marketed as anonymous or impossible to trace deserve scepticism. Any device that connects to a mobile network registers with it. Any device that connects to Wi-Fi leaves records. Purchase, top-up and activation all generate data. A locked-down handset can raise the cost of surveillance considerably; it cannot remove the device from the networks it must use in order to be a phone.
Where the marketing claim is that content cannot be read, that may well be true. Where the claim extends to invisibility, it is not.
What a sensible posture looks like
For someone with a genuine exposure — a principal, an executive, a party to sensitive litigation — the sequence that helps is roughly this. Use an end-to-end encrypted application for anything sensitive, and agree that with the people on the other end. Turn off or properly protect the cloud backup of those conversations. Put a PIN on the carrier account. Move authentication off SMS. Keep the device patched. Assume metadata is visible and plan around it rather than pretending otherwise. And treat the physical device as the weak point it is, because it is the part an adversary can actually reach.
Honeybadger Solutions treats device and communications security as part of a wider protective picture rather than a product purchase. Where a device may already be compromised, or where the question is what a phone can be made to reveal, that is digital forensics. Where a principal’s exposure extends beyond the handset, it belongs with executive protection, and concerns about physical or technical monitoring are addressed through counter-surveillance.
The threat models these devices do and do not address
“Encrypted phone” covers several quite different products, and the confusion between them is where buyers get hurt. It is worth separating the threat models.
Interception in transit. Protecting a conversation from being captured as it crosses a network. Modern end-to-end encrypted messaging already addresses this well on ordinary devices, which is why this is rarely the reason to buy specialised hardware.
Device compromise. Protecting against malware on the handset itself. This is where hardened operating systems, reduced attack surface, sandboxing and rapid patching genuinely matter — and where an ordinary consumer phone running a normal app store is weakest.
Physical seizure. Protecting data if the device is taken. Full-disk encryption, a strong passphrase rather than a short PIN, and configurable wipe behaviour are the relevant controls.
Metadata exposure. Concealing who contacted whom, when, and from where. This is the hardest problem and the one most products address least. Content encryption does nothing about the fact that a connection occurred.
Before buying anything, decide which of these four is your actual concern. A device excellent at one may do nothing for another, and most marketing deliberately blurs the distinction.
The failures that have nothing to do with the phone
The recurring lesson from every publicised case involving secure communications platforms is that the cryptography was not the failure point. The failures were operational.
The other party’s device was compromised, so perfectly encrypted messages were read on arrival. Backups were enabled, so content synced in plaintext to a cloud account protected by a reused password. Screenshots were taken and shared. The platform’s operator held metadata and was compelled to produce it. Or the device was seized while unlocked, which defeats every protection at once.
The practical consequence is that a secure device is one component of a practice, not a product that confers security. Two people using ordinary phones with good discipline are frequently safer than two people with expensive hardware and none.
Metadata is the part almost nobody addresses
Content encryption hides what was said. It does not hide that a call occurred, between which accounts, for how long, at what time, or from what approximate location. In most investigations, that pattern is more useful than the content would have been — it establishes relationships, timing and movement.
Reducing metadata exposure requires different measures: minimising how long a device is associated with a location, shielding a device when it is not in use, separating identities across devices and accounts, and understanding what any platform you use retains and for how long. A provider’s retention policy is part of your security posture whether or not you have read it.
Legal considerations worth understanding before you buy
Using encryption is lawful. Several adjacent situations are more complicated, and it is better to know in advance.
Border crossings are the most common surprise: device inspection authority at a border is broader than it is elsewhere, and travellers have been asked to unlock devices. Policies differ for citizens and non-citizens, and refusing has different consequences for each. If you travel with sensitive material, the robust answer is usually not to carry it — travel with a clean device and retrieve what you need afterwards.
In litigation, encrypted communications that are within the scope of discovery are still discoverable. Using an ephemeral or self-deleting messaging platform once litigation is reasonably anticipated can create a spoliation problem substantially worse than the contents would have been, and courts have imposed serious sanctions for exactly this. If you are in or near a dispute, ask counsel before changing how you communicate.
Finally, be cautious about the market itself. Several heavily marketed “secure phone” networks have turned out to be operated or compromised by law enforcement, and their customers learned this at indictment. Products sold primarily on the promise of being untraceable attract that attention specifically.
Who genuinely benefits
Hardened devices make sense for a defined set of users: executives handling material that a competitor or a foreign interest would pay for; attorneys holding privileged communications in contentious matters; journalists protecting sources; investigators working cases with capable adversaries; and individuals facing a specific, identified threat such as a stalking situation.
For most people asking about them, the honest answer is that better practice on the device they already own delivers more: a long passphrase rather than a six-digit PIN, full-disk encryption enabled, automatic updates on, a minimal set of installed applications, multifactor authentication on every account, a reputable end-to-end encrypted messenger with backups disabled or separately encrypted, and a Faraday enclosure for the times when the device should not be reachable at all.
Evaluating a vendor
- What exactly is encrypted, and against whom? Data at rest, in transit, or both — and can the provider read anything?
- What metadata does the provider retain, and for how long? An answer of “none” should be supported by an explanation of how the system is designed, not merely asserted.
- Has the implementation been independently audited, and is the report available?
- How are security updates delivered, how quickly, and for how long is a device supported?
- What happens if the company ceases trading? A device dependent on a vendor’s servers becomes a paperweight.
- Is the underlying cryptography standard and open, or proprietary? Proprietary cryptography is a warning sign, not a feature.
If the concern is that a specific device may already be compromised, the right step is examination rather than replacement — our digital forensics team can establish what is actually on it.
Browse by topic
Security guard services · Private investigations · Cybersecurity · Digital forensics · Financial fraud investigation · Executive protection · All articles