Skip to content
The Cyber Security Place

Cryptography

The argument is no longer whether to encrypt

Encrypting the whole web was the clearest security win of the decade. It also blinded the people defending it, and every live argument now is about who gets to look.

Last reviewed August 30, 2026

Over 95% of web traffic is now encrypted, and more than 80% of attack traffic travels inside it — command-and-control callbacks and data leaving a company look identical to reading the news unless somebody decrypts. Few organisations fully inspect, because inspection means holding plaintext for everyone's banking too. Meanwhile the clock is running: harvest now, decrypt later is passive and undetectable, the first post-quantum standards landed in August 2024, national security systems must move by 2030 and today's public-key algorithms are to be disallowed by 2035. The transport layer already migrated — hybrid key agreement went from 2% to the majority of traffic in under two years, through defaults that nobody had to configure. What organisations run themselves has not.

Who can see what you are doing?

The question has no answer until it names a party. Between your browser and a site there are 7 of them, and each learns something different. Change the settings and watch where the knowledge disappears — and where it does not.

The scale runs 0 nothing, 1 that you connected somewhere, 2 which site, 3 which page, 4 everything, including what you sent.

What each party on the path learns, under four settings
Party on the pathNo HTTPSHTTPSHTTPS + encrypted DNSHTTPS + encrypted DNS + ECH
Other software on your deviceEverythingEverythingEverythingEverything
The network you are onEverythingWhich siteYou connectedYou connected
Your internet providerEverythingWhich siteYou connectedYou connected
Whoever answers your name lookupsWhich siteWhich siteNothingNothing
Your employer's inspection proxyEverythingEverythingEverythingEverything
The delivery network in front of the siteEverythingEverythingEverythingEverything
The site itselfEverythingEverythingEverythingEverything
No HTTPS
The request travels as text anybody on the path can read.
HTTPS
The contents are encrypted. The name of the site is still announced in the clear as the connection opens.
HTTPS + encrypted DNS
The lookup that turns a name into an address no longer happens in the open.
HTTPS + encrypted DNS + ECH
The site name is encrypted too, so what remains visible is an address shared with many sites.
Other software on your device
Anything already running with your permissions, including an extension you installed and forgot. Encryption is applied after this point and removed before it. Nothing on this list is affected by any of the three settings.
The network you are on
The café, the hotel, the airport, or whoever else runs the access point. The classic argument for a VPN on public networks. Once HTTPS is universal it buys much less than it used to.
Your internet provider
The company that connects you, and in several countries whoever legally obliges them to keep records. The remaining signal is the address you talked to. On shared hosting that address serves thousands of sites; on a dedicated one it names a single organisation.
Whoever answers your name lookups
By default your provider; often a large public resolver instead. Encrypting the lookup does not delete it. It moves it from your provider to whoever you chose instead, who now has the full list.
Your employer's inspection proxy
Present only where a company installs its own certificate on the machine. It works by being a deliberate interception with your device's consent, so no transport setting hides anything from it. This is why the row is unchanged across all four.
The delivery network in front of the site
The company most large sites put between themselves and the internet. It terminates the encryption in order to serve you, which makes it a party to the conversation rather than an eavesdropper on it. Very few people count it.
The site itself
The service you meant to reach. Encryption protects the journey, never the destination. Everything you send arrives readable, which is the entire point of sending it.

4 of the 7 see exactly the same thing under every setting: other software on your device, your employer's inspection proxy, the delivery network in front of the site, the site itself.

The shape of it is the finding. Knowledge only falls away in the middle of the journey. 4 of the 7 parties are completely unaffected by every setting, because encryption is applied after the first of them and removed before the last. Even with all three protections in place, 3 parties still read everything you send. That is not a flaw in the design; it is what the design is for. But it means "encrypted" answers a narrower question than the word suggests in ordinary conversation.

The win that created the blind spot

For most of the last decade the security profession campaigned, correctly, for encryption everywhere. Certificates became free and automatic, browsers began marking plain connections as unsafe, and search rankings rewarded the change. It worked. Over ninety-five per cent of web traffic is now encrypted, and the class of attack that depended on reading traffic in transit has largely stopped being worth writing about.

The same change removed the defender's oldest source of information. A network that could once be watched for a file arriving, a credential leaving or a machine reporting to somewhere it should not, now sees an opaque flow and the fact that it happened. Reporting puts more than eighty per cent of attack traffic inside encrypted tunnels. A callback to an attacker's server and a request for a news article are, without decryption, the same event: two scrambled payloads of similar size. The archive noticed this early — Malware Authors Making a Payday Off Encryption argued it while the campaign was still being won.

This is worth stating carefully, because it is regularly misused. It is not an argument against encryption, and the people making it in bad faith usually want something else. Encryption is neutral about whom it protects; making it universal was correct precisely because the alternative protected nobody. What follows is narrower and duller: the visibility that used to arrive for free now has to be bought, and the price is a decision about interception that organisations are entitled to weigh rather than assume.

Should an employer read encrypted traffic?

The mechanism is worth understanding before the ethics. An inspection proxy works by installing the organisation's own certificate authority on the machine, so the device is told to trust connections the proxy has terminated. Nothing is broken; the device has been instructed to accept a deliberate interception. That is why no transport-level setting hides anything from it, and why it appears in the table above unchanged across every configuration.

The security argument for doing it is straightforward: without it a firewall is waving through most modern malware, most command-and-control traffic and most exfiltration. The argument against is equally concrete. The organisation now holds a copy of everything staff do on that machine, including personal banking, medical appointments and job applications, and the proxy becomes a single system holding plaintext for the entire company — an unusually attractive target with an unusually quiet failure mode.

The arrangement that survives contact with reality has three parts. Categories that are never decrypted, defined by destination — finance, health, legal — and enforced rather than promised. A plain statement to staff that inspection happens, on what devices, and with what exclusions, because discovering it later destroys more trust than the control is worth. And the recognition that the proxy is now among the most sensitive systems in the estate, to be protected accordingly.

Two developments are narrowing the technique. Certificate pinning makes some applications refuse a substituted certificate outright, so parts of the traffic cannot be inspected without breaking the application. And Encrypted Client Hello removes the site name from the last place it was visible, which was the signal most selective decryption policies used to decide what to leave alone. Both push toward the same conclusion: the answer to "what is happening on my network" is migrating from the network to the endpoint, and organisations whose visibility plan lives entirely in the middle are running out of road.

Where the settings actually help

The same 7 parties, drawn as how much each learns under the four settings. Longer means they know more.

Other software on your deviceThe network you are onYour internet providerWhoever answers your name loo…Your employer's inspection pr…The delivery network in front…The site itselfNo HTTPSHTTPSHTTPS + encr…HTTPS + encr…

Each added setting buys something and the gains are uneven: HTTPS improves 2 of them, HTTPS + encrypted DNS improves 3 of them. The rows that never move are the two ends of the journey, and no amount of transport security will change them. If the concern is the site itself, or software running on your own machine, this entire family of controls is addressing a different problem.

The argument about lawful access

The archive carries 71 entries on this and the shape of the debate has not moved in a decade, which is itself informative. Governments observe, accurately, that end-to-end encryption puts some communications beyond a warrant that would otherwise be honoured. Technologists reply, also accurately, that a mechanism for authorised reading is a capability rather than a permission.

The technical claim is narrower than it is usually reported. Nobody argues that a lawful access mechanism cannot be built — one can, and several designs exist. The argument is that its existence creates a key, that a key is a thing which can be stolen, compelled in a different jurisdiction, or used by a future government with different intentions, and that the same mechanism protects the messages of everybody who is not under investigation. The disagreement is about whether that risk is acceptable, not about whether it is real.

What has changed is the tactics rather than the positions. Direct proposals to weaken the mathematics have largely given way to proposals that inspect messages on the device before they are encrypted, which is not a cryptographic question at all and raises a different set of objections. Anyone following this should watch for the substitution, because a proposal described as leaving encryption intact may be doing exactly that while addressing the same underlying aim. The earliest entry here, 63 in favor of encryption backdoors to respond to national security threats, rehearses arguments still being made.

The part that decides whom you are talking to

Scrambling a conversation is worthless if you are scrambling it with an impostor. The half of the system that establishes identity is the certificate, and it depends on a chain of trust that almost nobody examines: a browser ships with a list of authorities it will believe, any one of them can vouch for any name, and a certificate issued in error by a single authority anywhere in the world is accepted everywhere.

That arrangement has been repaired in ways worth knowing about. Certificate transparency requires issuance to be logged publicly, so a domain owner can discover that somebody obtained a certificate for their name — a mechanism that has caught real misissuance and that costs nothing to monitor. Automated issuance made certificates free and short-lived, which removed both the commercial argument for going without and the long window during which a stolen private key stayed useful. Lifetimes have been shortening steadily since, on the reasoning that revocation has never worked reliably and expiry always does.

Short lifetimes bring their own hazard, and it is the one that actually takes sites down. An expired certificate is among the most common causes of self-inflicted outage in this field, it happens overwhelmingly to internal systems and appliances that automation never reached, and it tends to occur at whatever hour the renewal was originally performed years earlier by somebody who has left. An inventory of certificates with expiry dates is a mundane document that prevents a recurring and entirely predictable failure.

Inside an organisation the trust question reappears in a different form. Every machine with an inspection proxy has been given an extra authority it will believe, which means whoever controls that authority can impersonate any site to any of those machines. That is the intended behaviour and it is also a standing capability that deserves the same protection as any other master key — a point that tends to be missed because the proxy is filed as a network appliance rather than as a certificate authority, which is what it is.

What happens when the mathematics changes?

The archive mentions quantum computing 24 times, almost all of it speculative. The situation in 2026 is considerably more concrete, and the concrete part is not a machine — it is a set of deadlines.

The first post-quantum standards were finalised in August 2024. The deprecation timeline that accompanies them calls for today's public-key algorithms to be disallowed across those standards by 2035, and national security systems in the United States are required to have moved by 2030. Estimates for a large organisation migrating everything it runs range from five to fifteen years, which means the deadlines and the effort are the same size — a rare and uncomfortable alignment.

The threat that makes the schedule urgent is passive. Harvest now, decrypt later means copying encrypted traffic today and keeping it until it can be read. It leaves no trace, cannot be detected, and is presumed to be under way against anything worth the storage. The consequence is that a decision about secrecy is being made now for data whose confidentiality requirement is measured in decades: medical records, state material, industrial designs, anything whose worth outlives the cipher protecting it.

The encouraging half of the story is how much has already happened without anyone doing anything. Hybrid key agreement went from roughly two per cent of connections in early 2024 to the majority of web traffic in under two years, delivered through browser and content network defaults. Most engineers did not notice, which is what a successful migration looks like. The work that remains is everything an organisation operates itself — its own servers, its own applications, its own long-lived certificates, and the embedded equipment whose firmware nobody can change — and none of that migrates through somebody else's default.

What does encrypting stored data protect against?

Everything above concerns data in motion. Data sitting still is a separate problem with a separate answer, and conflating the two is the most common confusion in this subject — including in the sentence "the data was encrypted", which is offered after breaches to mean anything from a great deal to almost nothing.

Full-disk encryption protects against a specific and narrow event: somebody taking the physical machine while it is switched off. It is genuinely valuable, it should be on everywhere, and it does nothing whatsoever once the machine is running and the volume is mounted — which is the state a laptop is in when malware is stealing from it. A stolen laptop is protected. A compromised laptop is not.

Database encryption at rest works the same way and is oversold in the same way. The storage layer is encrypted so that somebody obtaining the underlying disks or a raw backup file learns nothing. An application with valid credentials reads plaintext, because that is the entire purpose of the arrangement, and almost every breach of a database happens through the application rather than through the disks. Attackers rarely steal drives from data centres. They log in.

Field-level encryption is where the protection starts biting, because the data stays unreadable until something with the right key decrypts a specific value. That narrows what an intruder gains and it costs real functionality: you cannot easily search, sort or index what you cannot read, which is why it tends to be applied to a handful of fields rather than everywhere. The design question is which values would cause harm if they escaped, and it is a business question rather than a technical one.

The practical test cuts through most of the marketing. Ask where the key is. If the key lives on the same machine, in the same account, or in the same cloud project as the data it protects, then whoever reaches the data reaches the key, and the encryption is protecting against theft of the hardware and nothing else. That is a legitimate thing to protect against and it is not what the phrase "encrypted at rest" is usually taken to mean when it appears in a breach notification.

What is actually worth doing

Take the defaults. The single highest-value action available in 2026 is to run current versions of things, because the transport migration is arriving through updates and an estate that is current is receiving it for free. An organisation three protocol versions behind is not just missing performance; it is opted out of the largest cryptographic migration in history without having decided anything.

Find the keys. The most common encryption failure in practice has never been broken mathematics — it is a private key committed to a repository by mistake, a certificate nobody can find the owner of, and the credential in a configuration file that has outlived three people. An inventory of where keys live, what they protect and when they expire is worth more than any algorithm choice, and it is the prerequisite for a migration that will otherwise be impossible to plan.

Sort data by how long it must stay secret. This is the specific piece of work the quantum timeline demands and it is not technical: a list of what the organisation holds whose confidentiality requirement outlasts the deadlines. For most companies that list is short, which is good news, and for a few it is the whole business, which is worth discovering now rather than in 2034.

Common questions

Is HTTPS enough to keep my browsing private?

Private from whom is the question that has to come first. It hides the contents from anyone on the path, which is most of the people the word usually means, and hides nothing from the destination, from a delivery network in front of it, from software already running on your own machine, or from an employer that installed its own certificate.

What percentage of web traffic is encrypted now?

Over 95% in 2026, which is the outcome of a deliberate decade-long push and one of the clearest security wins of the period. It also means that visibility into what is happening on a network now requires a deliberate decision to decrypt, where it used to be the default state of affairs.

Does encryption help attackers?

It helps everybody equally, which in practice means it helps whoever was previously being watched. Reporting puts more than 80% of attack traffic inside encrypted connections, where a callback and a news article are indistinguishable without decryption.

Should we decrypt and inspect traffic at work?

It carries real costs. The organisation ends up holding a copy of everything staff do, so it needs enforced exclusions and a policy people are told about, and the proxy becomes a single point holding plaintext for the whole company.

What is Encrypted Client Hello?

The last widely visible piece of a connection was the name of the site you were opening, announced in the clear so shared hosting could route you. ECH encrypts it, leaving observers with an address that may serve thousands of sites. It closes a long-standing gap and it removes the signal most network filtering was built on.

Are encryption backdoors technically possible?

A mechanism that lets an authorised party read messages is straightforward to build. The difficulty is that it is a capability rather than a permission: once the mechanism exists it can be used by whoever obtains the key, a court order in another jurisdiction, or found by somebody who was not meant to have it. The disagreement is not really about mathematics.

What is 'harvest now, decrypt later'?

Copying encrypted traffic today on the expectation of reading it once the mathematics changes. It is passive, it leaves no trace, and it is presumed to be under way. The practical consequence is that anything with a secrecy requirement measured in decades — medical records, state material, industrial designs — is already exposed to a decision made now.

When do current encryption algorithms stop being safe?

No date can be given honestly, which is why standards bodies published deadlines instead: the first post-quantum standards were finalised in August 2024, United States national security systems must move by 2030, and today's public-key algorithms are to be disallowed by 2035.

Has anyone actually migrated to post-quantum cryptography?

The transport layer largely has, and most people did not notice. Hybrid key agreement went from roughly 2% of connections in early 2024 to the majority of web traffic in under two years, delivered through browser and content network defaults. What has not migrated is everything organisations run themselves, where estimates for full migration run from five to fifteen years.

Is a VPN worth paying for?

It moves the party who can watch you from the network you are on to the company selling the service, which is an improvement only if you trust them more. In an era where nearly everything is already encrypted, the older argument about public Wi-Fi buys much less than it did. The genuine uses are hiding your address from sites and reaching a network you are entitled to use.

Does encryption satisfy data protection obligations?

It is named in most regimes as a measure that can reduce what a breach requires you to do, and it is not a blanket exemption. Encrypted data whose keys were also taken is not protected, and the question a regulator asks is whether the specific data was rendered unintelligible to the specific party who obtained it.

What should a small organisation actually do about encryption?

Very little that is exotic. Use current defaults everywhere, which now means the modern protocol version and hybrid key agreement without configuring anything. Encrypt what is stored, especially on devices that leave the building. And know where your keys are, because the most common encryption failure in practice is not broken mathematics but a key sitting in a repository.

Encryption and privacy in the archive

766 entries, of which 299 mention encryption, 407 privacy and 23 end-to-end messaging.