<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: truksharoz</title>
    <description>The latest articles on DEV Community by truksharoz (@rsharoz).</description>
    <link>https://dev.to/rsharoz</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4042053%2F7a833c1d-e3f2-4660-8bd7-d1f663e182e4.jpg</url>
      <title>DEV Community: truksharoz</title>
      <link>https://dev.to/rsharoz</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/rsharoz"/>
    <language>en</language>
    <item>
      <title>Why End-to-End Encryption Isn't the Whole Privacy Story</title>
      <dc:creator>truksharoz</dc:creator>
      <pubDate>Thu, 23 Jul 2026 19:29:57 +0000</pubDate>
      <link>https://dev.to/rsharoz/why-end-to-end-encryption-isnt-the-whole-privacy-story-4h3m</link>
      <guid>https://dev.to/rsharoz/why-end-to-end-encryption-isnt-the-whole-privacy-story-4h3m</guid>
      <description>&lt;h2&gt;
  
  
  &lt;em&gt;By J DV. Independent security researcher exploring cybersecurity, privacy, and secure system design.&lt;/em&gt;
&lt;/h2&gt;




&lt;p&gt;People often assume that if a messaging app offers end-to-end encryption their conversations are completely private. Encryption is undoubtedly one of the strongest security technologies available today but privacy extends far beyond protecting the content of a message.&lt;/p&gt;

&lt;p&gt;Modern messaging platforms still generate metadata, rely on cloud infrastructure and interact with operating systems in ways that can expose information about users. This article explores why encryption alone is not enough examines the broader privacy challenges facing digital communication and discusses the principles that should guide the next generation of privacy-focused technologies.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;I. End-to-End Encryption Protects Messages, Not Everything&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;For years, end-to-end encryption (E2EE) has been presented as the gold standard for private communication. It ensures that only the sender and the intended recipient can read the contents of a message, preventing intermediaries from accessing it during transmission. This has significantly improved the security of modern messaging platforms and raised the baseline for protecting digital conversations. However, equating end-to-end encryption with complete privacy creates a misleading impression of how modern communication systems actually operate.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;II. Metadata Can Reveal More Than the Message Itself&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;While end-to-end encryption protects the contents of a message, it does not eliminate the digital traces created around every interaction. These traces, commonly known as metadata, include information such as who communicated with whom, when the communication occurred, how frequently it happened, and, in some cases, the approximate size or type of the exchanged data. Although metadata does not reveal the actual message, it can still provide a detailed picture of a person's communication patterns and relationships.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;III. Privacy Depends on the Entire Ecosystem, Not Just Encryption&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Modern communication does not take place in isolation. Every message exists within a broader ecosystem that includes operating systems, cloud services, notifications, backups, connected devices, and the servers responsible for delivering communications. While end-to-end encryption protects the contents of a message, messaging platforms still need to process certain metadata—such as routing information, timestamps, or other operational data—to provide their services. The type of metadata collected and how long it is retained varies between platforms, but users often assume that only they and their device know about their conversations. In reality, privacy depends not only on message encryption but also on how the surrounding ecosystem and service infrastructure handle communication data.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;IV. Privacy Ultimately Depends on Trust, Transparency, and Design&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Strong encryption creates a powerful barrier against attackers attempting to intercept the contents of a conversation during transmission. However, encryption alone does not define the entire privacy model of a messaging platform. Even services such as WhatsApp, Signal, Telegram, and other modern messaging platforms rely on server infrastructure to authenticate users, route messages, exchange encryption keys where applicable, and process operational metadata required for service delivery. Although end-to-end encryption is intended to prevent service providers from accessing message contents, the overall privacy experienced by users also depends on how each platform collects, processes, and retains metadata, manages its infrastructure, and handles user data outside the encrypted message itself. Evaluating privacy therefore requires examining the complete system rather than relying on a single security feature or marketing claim.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;V. Privacy Cannot Be Measured by Encryption Alone&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Once the limitations of end-to-end encryption are understood, the next step is to examine what actually defines a private communication system. Encryption is a critical security technology, but it represents only one layer of a much broader privacy architecture. A realistic evaluation of any messaging platform requires looking beyond encrypted message content and assessing how the entire system operates.&lt;/p&gt;

&lt;p&gt;A modern messaging platform can be evaluated across four fundamental layers.&lt;/p&gt;

&lt;p&gt;The first layer is message protection. End-to-end encryption ensures that the content of a conversation remains inaccessible to unauthorized third parties while it is being transmitted. This is the foundation of secure communication, but it protects only the message itself.&lt;/p&gt;

&lt;p&gt;The second layer is metadata handling. Every communication system generates operational information required to deliver messages. The amount of metadata collected, processed, and retained varies between platforms, making metadata protection an essential part of any privacy assessment.&lt;/p&gt;

&lt;p&gt;The third layer is infrastructure and service architecture. Communication depends on authentication systems, message routing, notifications, cloud services, backups, and other supporting infrastructure. The way these components are designed and managed has a direct impact on the overall privacy experienced by users.&lt;/p&gt;

&lt;p&gt;The fourth layer is user control and transparency. A privacy-focused platform should provide users with clear information about what data is collected, why it is processed, how long it is retained, and what controls users have over their own information. Transparency and user control are fundamental principles of trustworthy system design.&lt;/p&gt;

&lt;p&gt;Encryption remains one of the strongest security technologies available today, but it should not be mistaken for complete privacy. True privacy is achieved only when message protection, metadata management, infrastructure design, and user control work together as parts of a comprehensive security model.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;VI. How Server-Side Data Shapes the Privacy Model&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Many users assume that end-to-end encryption means only the sender and recipient are involved in every aspect of communication. In reality, modern messaging platforms—including WhatsApp, Telegram, Signal, and others—still rely on server-side infrastructure to authenticate users, route messages, synchronize devices, deliver notifications, and operate their services. Features such as contact discovery, account management, optional cloud services, and optional location sharing also depend on server-side systems to coordinate communication between users. As a result, platforms process operational information beyond the encrypted message itself. Depending on the platform's architecture, this may include account details, device information, connection records, timestamps, routing information, and other forms of metadata that support service operation, reliability, spam prevention, fraud detection, and performance monitoring. While end-to-end encryption protects message content, the surrounding communication ecosystem continues to play a significant role in how user data is handled and how privacy is ultimately experienced.&lt;/p&gt;

&lt;h2&gt;
  
  
  VII. If the Service Is Free, What Pays for the Infrastructure?
&lt;/h2&gt;

&lt;p&gt;Free messaging platforms often create the impression that private communication comes at no financial cost to the user. In reality, operating a global communication service requires significant resources, including data centers, servers, network bandwidth, cloud infrastructure, security operations, software development, and continuous maintenance. Every message delivered, every account authenticated, and every notification sent depends on infrastructure that must be funded.&lt;/p&gt;

&lt;p&gt;For this reason, every platform operates under a business model. Some rely on subscriptions, some on enterprise services, some on advertising, and others on investor funding or a combination of these approaches. In certain cases, user data, analytics, or aggregated usage insights may also contribute to advertising, product improvement, market research, or business decision-making, depending on the platform's policies and practices.&lt;/p&gt;

&lt;p&gt;This is why understanding how a platform funds its infrastructure is just as important as understanding its encryption model. Privacy is influenced not only by how messages are protected, but also by how user information is collected, processed, retained, and used within the platform's overall business and operational ecosystem.&lt;/p&gt;

&lt;h2&gt;
  
  
  VII. If the Service Is Free, What Pays for the Infrastructure?
&lt;/h2&gt;

&lt;p&gt;Free messaging platforms often create the impression that private communication comes at no financial cost to the user. Many users assume that because they are not paying for the service, there is nothing else to consider. In reality, operating a global communication platform requires enormous investment in data centers, servers, cloud infrastructure, network bandwidth, security operations, software engineering, and continuous maintenance. Every message delivered, every account authenticated, every notification sent, and every server request consumes infrastructure that must ultimately be funded.&lt;/p&gt;

&lt;p&gt;For this reason, every platform operates under a business model. Some rely on subscriptions, some on enterprise services, some on advertising, and others on investor funding or a combination of these approaches. Depending on the platform's policies and architecture, operational data, analytics, and aggregated usage information may also be used to improve products, measure user behavior, support market research, personalize services or advertising, and guide future business decisions. The extent to which this occurs differs between platforms.&lt;/p&gt;

&lt;p&gt;For users, this raises an important question: if a service appears to be free, what is actually funding the infrastructure behind it? Understanding a platform's business model is just as important as understanding its encryption model. Privacy is influenced not only by how messages are protected, but also by what information is collected outside the encrypted message, how it is processed, how long it is retained, and how transparently the platform explains these practices. These factors play a central role in determining the level of privacy users actually experience.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Sources&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Geopolitical Analysis &amp;amp; Digital Sovereignty&lt;/p&gt;

&lt;p&gt;Mathilde Pannier (IFRI) — Software Power: The Economic and Geopolitical Implications of Open Source Software&lt;br&gt;
&lt;a href="https://www.ifri.org/en/studies/software-power-economic-and-geopolitical-implications-open-source-software" rel="noopener noreferrer"&gt;https://www.ifri.org/en/studies/software-power-economic-and-geopolitical-implications-open-source-software&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Chatham House — Trump's AI Action Plan seeks customers, not partners&lt;br&gt;
&lt;a href="https://www.chathamhouse.org/2025/07/trumps-ai-action-plan-seeks-customers-not-partners" rel="noopener noreferrer"&gt;https://www.chathamhouse.org/2025/07/trumps-ai-action-plan-seeks-customers-not-partners&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Real Instituto Elcano — Can open source secure Europe's digital infrastructure?&lt;br&gt;
&lt;a href="https://www.realinstitutoelcano.org/en/analyses/can-open-source-secure-europes-digital-infrastructure/" rel="noopener noreferrer"&gt;https://www.realinstitutoelcano.org/en/analyses/can-open-source-secure-europes-digital-infrastructure/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Geopolitical Monitor — Distributed Risk: Open-Source Software as Strategic Infrastructure&lt;br&gt;
&lt;a href="https://www.geopoliticalmonitor.com/distributed-risk-open-source-software-as-strategic-infrastructure/" rel="noopener noreferrer"&gt;https://www.geopoliticalmonitor.com/distributed-risk-open-source-software-as-strategic-infrastructure/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;CSIS — Government Open Source Software Policies&lt;br&gt;
&lt;a href="https://www.csis.org/programs/strategic-technologies-program/resources/government-open-source-software-policies" rel="noopener noreferrer"&gt;https://www.csis.org/programs/strategic-technologies-program/resources/government-open-source-software-policies&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Open Source Governance, Sanctions &amp;amp; Dependency&lt;/p&gt;

&lt;p&gt;Software Freedom Conservancy — Linux banned Russian contributors. Does my FOSS project need to worry about U.S. sanctions?&lt;br&gt;
&lt;a href="https://sfconservancy.org/blog/2024/dec/12/linux-banned-russian-contributors-do-i-need-to/" rel="noopener noreferrer"&gt;https://sfconservancy.org/blog/2024/dec/12/linux-banned-russian-contributors-do-i-need-to/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Hackread — Linux Kernel Project Drops Russian Developers Amid US Sanctions Concerns&lt;br&gt;
&lt;a href="https://hackread.com/linux-kernel-project-drops-russian-developers-sanction/" rel="noopener noreferrer"&gt;https://hackread.com/linux-kernel-project-drops-russian-developers-sanction/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;TechCrunch — GitHub confirms it has blocked developers in Iran, Syria and Crimea&lt;br&gt;
&lt;a href="https://techcrunch.com/2019/07/29/github-ban-sanctioned-countries/" rel="noopener noreferrer"&gt;https://techcrunch.com/2019/07/29/github-ban-sanctioned-countries/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Felipe Contreras — The Linux Foundation is wrong about sanctions&lt;br&gt;
&lt;a href="https://felipec.wordpress.com/2024/10/26/linux-foundation-sanctions/" rel="noopener noreferrer"&gt;https://felipec.wordpress.com/2024/10/26/linux-foundation-sanctions/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Corporate Influence in Open Source&lt;/p&gt;

&lt;p&gt;The New Stack — Who Contributes to the Linux Kernel?&lt;br&gt;
&lt;a href="https://thenewstack.io/contributes-linux-kernel/" rel="noopener noreferrer"&gt;https://thenewstack.io/contributes-linux-kernel/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The Register — Who writes Linux and open source software?&lt;br&gt;
&lt;a href="https://www.theregister.com/2023/02/24/who_writes_open_source/" rel="noopener noreferrer"&gt;https://www.theregister.com/2023/02/24/who_writes_open_source/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Linux Foundation — Linux Kernel Development Reports&lt;br&gt;
&lt;a href="https://www.linuxfoundation.org/" rel="noopener noreferrer"&gt;https://www.linuxfoundation.org/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Software Supply Chain Security&lt;/p&gt;

&lt;p&gt;Andres Freund — Initial disclosure of the XZ Utils backdoor&lt;br&gt;
&lt;a href="https://www.openwall.com/lists/oss-security/2024/03/29/4" rel="noopener noreferrer"&gt;https://www.openwall.com/lists/oss-security/2024/03/29/4&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;CISA — CVE-2024-3094 XZ Utils Supply Chain Compromise Alert&lt;br&gt;
&lt;a href="https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094" rel="noopener noreferrer"&gt;https://www.cisa.gov/news-events/alerts/2024/03/29/reported-supply-chain-compromise-affecting-xz-utils-data-compression-library-cve-2024-3094&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Wiz Research — IngressNightmare in Kubernetes&lt;br&gt;
&lt;a href="https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities" rel="noopener noreferrer"&gt;https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Kubernetes Blog — Ingress-nginx CVE-2025-1974&lt;br&gt;
&lt;a href="https://kubernetes.io/blog/2025/03/24/ingress-nginx-cve-2025-1974/" rel="noopener noreferrer"&gt;https://kubernetes.io/blog/2025/03/24/ingress-nginx-cve-2025-1974/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Kubernetes Blog — Ingress NGINX Retirement Announcement&lt;br&gt;
&lt;a href="https://kubernetes.io/blog/2025/11/11/ingress-nginx-retirement/" rel="noopener noreferrer"&gt;https://kubernetes.io/blog/2025/11/11/ingress-nginx-retirement/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;China and Alternative Digital Ecosystems&lt;/p&gt;

&lt;p&gt;Jamestown Foundation — Open-Source Technology and PRC National Strategy&lt;br&gt;
&lt;a href="https://jamestown.org/program/open-source-technology-and-prc-national-strategy-part-i/" rel="noopener noreferrer"&gt;https://jamestown.org/program/open-source-technology-and-prc-national-strategy-part-i/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Rest of World — China wants to build an open-source ecosystem to rival GitHub&lt;br&gt;
&lt;a href="https://restofworld.org/2021/china-gitee-to-rival-github/" rel="noopener noreferrer"&gt;https://restofworld.org/2021/china-gitee-to-rival-github/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;European Commission — Open Source Software Country Intelligence Report: China&lt;br&gt;
&lt;a href="https://interoperable-europe.ec.europa.eu/sites/default/files/inline-files/OSS%20Country%20Intelligence%20Report%20China.pdf" rel="noopener noreferrer"&gt;https://interoperable-europe.ec.europa.eu/sites/default/files/inline-files/OSS%20Country%20Intelligence%20Report%20China.pdf&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  A Different Approach to Privacy-Focused Communication
&lt;/h2&gt;

&lt;p&gt;Traditional messaging systems often require centralized server-side infrastructure to authenticate users, route communication, synchronize devices, and provide additional services. This architecture can create operational data that must be processed and managed by the service provider.&lt;/p&gt;

&lt;p&gt;VeilComm was created around a different privacy approach: reducing unnecessary server-side data exposure by minimizing what information needs to be collected, stored, or retained. The objective is not only to protect message content through encryption, but also to rethink how communication systems handle metadata and operational information.&lt;/p&gt;

&lt;p&gt;Instead of building privacy around a single security layer, the approach focuses on limiting unnecessary data collection and reducing the amount of information that exists outside the user's control. By minimizing server-side data dependency, privacy risks associated with large-scale data storage, profiling, and unnecessary retention can be reduced.&lt;/p&gt;

&lt;p&gt;The goal is simple: a communication system should not require excessive access to user information in order to provide secure communication.&lt;/p&gt;




&lt;p&gt;&lt;strong&gt;Developer&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;VeilComm was conceived, designed, and developed by &lt;strong&gt;TurkSharoz (Sheroz)&lt;/strong&gt;. The project reflects an ongoing commitment to advancing practical privacy, secure communication, and user-controlled data protection through privacy-first engineering principles.&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>cybersecurity</category>
      <category>encryption</category>
      <category>community</category>
    </item>
    <item>
      <title>Building VeilComm: Rethinking Private Communication</title>
      <dc:creator>truksharoz</dc:creator>
      <pubDate>Wed, 22 Jul 2026 18:53:48 +0000</pubDate>
      <link>https://dev.to/rsharoz/building-veilcomm-rethinking-private-communication-41ja</link>
      <guid>https://dev.to/rsharoz/building-veilcomm-rethinking-private-communication-41ja</guid>
      <description>&lt;h1&gt;
  
  
  Building VeilComm
&lt;/h1&gt;

&lt;p&gt;After learning more about how messaging apps handle photos, backups, metadata, and forwarded content, I started asking a simple question:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can private messaging be designed differently?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;That question became the beginning of &lt;strong&gt;VeilComm&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why I Started VeilComm
&lt;/h2&gt;

&lt;p&gt;I wasn't trying to build another messaging app.&lt;/p&gt;

&lt;p&gt;I wanted to build something that gives people more control over their own data and make privacy the starting point instead of an afterthought.&lt;/p&gt;

&lt;p&gt;For me, privacy isn't only about encrypting messages. It's also about reducing who can access the information you share.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Idea Behind VeilComm
&lt;/h2&gt;

&lt;p&gt;VeilComm is built around three simple principles:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Collect less.&lt;/li&gt;
&lt;li&gt;Store less.&lt;/li&gt;
&lt;li&gt;Share less.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The less data that exists, the lower the risk of it being exposed.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Makes VeilComm Different
&lt;/h2&gt;

&lt;p&gt;VeilComm encrypts messages and files &lt;strong&gt;before they leave your device&lt;/strong&gt;. The encrypted content can then be shared through existing platforms such as WhatsApp, Signal, Telegram, email, or any other service that can transfer files or messages.&lt;/p&gt;

&lt;p&gt;Because the content is already encrypted before it is shared, the platform used for delivery does not have access to the original message or file contents. It only carries encrypted data.&lt;/p&gt;

&lt;p&gt;VeilComm is not trying to replace existing messaging apps. Instead, it adds an extra layer of privacy that works before your data is shared.&lt;/p&gt;

&lt;p&gt;The project also focuses on:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;End-to-end client-side encryption.&lt;/li&gt;
&lt;li&gt;Secure media and file encryption.&lt;/li&gt;
&lt;li&gt;Privacy-focused file handling.&lt;/li&gt;
&lt;li&gt;A simple interface that keeps privacy easy to use.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Every feature is designed with one goal in mind:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Give users more control over their own data without making secure communication complicated.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Still a Work in Progress
&lt;/h2&gt;

&lt;p&gt;VeilComm is still under development, and I'm continuing to improve it with every new feature and security improvement.&lt;/p&gt;

&lt;p&gt;In future articles, I'll explain how the encryption system works, why I chose this approach, and the engineering decisions behind building VeilComm.&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>ai</category>
      <category>metada</category>
      <category>security</category>
    </item>
    <item>
      <title>What Happens When You Send a Photo Through Most Messaging Apps?</title>
      <dc:creator>truksharoz</dc:creator>
      <pubDate>Wed, 22 Jul 2026 18:50:02 +0000</pubDate>
      <link>https://dev.to/rsharoz/what-happens-when-you-send-a-photo-through-most-messaging-apps-366o</link>
      <guid>https://dev.to/rsharoz/what-happens-when-you-send-a-photo-through-most-messaging-apps-366o</guid>
      <description>&lt;p&gt;Sending a photo feels simple. You choose an image, tap Send, and a few seconds later it appears on someone else's phone. Behind that simple action, however, several things may happen that most people never notice.&lt;/p&gt;

&lt;p&gt;It Starts on Your Device&lt;/p&gt;

&lt;p&gt;The photo already exists on your phone before you send it. Depending on your device settings, it may also be part of your gallery or included in local or cloud backups.&lt;/p&gt;

&lt;p&gt;Before the Photo Is Sent&lt;/p&gt;

&lt;p&gt;Most messaging apps prepare the image before sending it. They may reduce the file size, create a preview, or optimize it so it can be delivered faster. These steps happen automatically in the background.&lt;/p&gt;

&lt;p&gt;Sending the Photo&lt;/p&gt;

&lt;p&gt;If the app supports end-to-end encryption, the photo is encrypted before it leaves your device. This helps protect the image while it is traveling across the internet.&lt;/p&gt;

&lt;p&gt;After that, the message is routed through the app's delivery infrastructure until it reaches the recipient.&lt;/p&gt;

&lt;p&gt;After It Arrives&lt;/p&gt;

&lt;p&gt;Once the recipient opens the photo, it exists on their device. Depending on the app and their settings, it may also be saved to the phone's gallery or included in future backups.&lt;/p&gt;

&lt;p&gt;At this point, the recipient can also take a screenshot or forward the image to someone else. Encryption protects the photo while it is being transmitted, but it cannot control what happens after the recipient has access to it.&lt;/p&gt;

&lt;p&gt;Final Thoughts&lt;/p&gt;

&lt;p&gt;When we send a photo, we often think only about the moment we press Send. In reality, there can be several stages between your device and the recipient, and in some cases, multiple copies of the same image may exist over time.&lt;/p&gt;

&lt;p&gt;Understanding this process is an important part of understanding digital privacy.&lt;/p&gt;

&lt;p&gt;While researching these privacy challenges, I started building VeilComm to explore how private communication could give users more control over their data—not just while it's being transmitted, but throughout its entire lifecycle.&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>android</category>
      <category>cybersecurity</category>
      <category>security</category>
    </item>
    <item>
      <title>Why Private Messaging Isn't Really Private Anymore</title>
      <dc:creator>truksharoz</dc:creator>
      <pubDate>Wed, 22 Jul 2026 18:45:34 +0000</pubDate>
      <link>https://dev.to/rsharoz/why-private-messaging-isnt-really-private-anymore-5dla</link>
      <guid>https://dev.to/rsharoz/why-private-messaging-isnt-really-private-anymore-5dla</guid>
      <description>&lt;p&gt;We use messaging apps every day to share photos, videos, documents, voice notes, and even sensitive information like banking details, payment confirmations, passwords, and one-time verification codes. Because many apps advertise end-to-end encryption&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fliuprj2dyfpa7bq9mhzw.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fliuprj2dyfpa7bq9mhzw.png" alt=" " width="800" height="336"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Farckh2ptsaqze2zry5kv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Farckh2ptsaqze2zry5kv.png" alt=" " width="800" height="336"&gt;&lt;/a&gt; it's easy to believe that everything we send stays completely private.&lt;/p&gt;

&lt;p&gt;The reality is more complicated.&lt;/p&gt;

&lt;p&gt;Encryption protects the content of your messages while they're being transmitted but privacy doesn't end there. Metadata cloud backups screenshots forwarded media and stored copies can all affect how much of your personal information remains under your control.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Is Metadata?
&lt;/h2&gt;

&lt;p&gt;Your message may be encrypted but every conversation also creates metadata. This can include when a message was sent who communicated with whom how often conversations happen and what type of device is being used.&lt;/p&gt;

&lt;p&gt;Metadata usually doesn't reveal the content of your messages but it can still paint a surprisingly detailed picture of your habits and relationships.&lt;/p&gt;

&lt;h2&gt;
  
  
  Cloud Backups Can Become Another Copy
&lt;/h2&gt;

&lt;p&gt;Many messaging apps automatically back up chats and media to cloud storage.&lt;/p&gt;

&lt;p&gt;This is convenient if you lose your phone, but it also means another copy of your private data may exist outside your device. If those conversations include banking information, identity documents, or payment records, that sensitive data may also become part of those backups depending on your settings and the service you use.&lt;/p&gt;

&lt;h2&gt;
  
  
  Screenshots and Forwarded Media
&lt;/h2&gt;

&lt;p&gt;Even if a message is encrypted, nothing stops someone from taking a screenshot after opening it.&lt;/p&gt;

&lt;p&gt;The same is true for forwarded photos, documents, or videos. Once they leave the original conversation, you often lose control over where they go next. Encryption protects data while it's being transmitted, but it doesn't automatically prevent what happens after someone receives it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Thoughts
&lt;/h2&gt;

&lt;p&gt;Private messaging is about more than encrypting the content of a conversation. Metadata, cloud backups, screenshots, and forwarded media all play a role in how much control you actually have over your personal information. Understanding these privacy challenges is the first step toward making better choices about how we communicate online. In the next article we'll follow the journey of a single photo and explore what can happen after you press &lt;strong&gt;Send&lt;/strong&gt;.&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>android</category>
      <category>cybersecurity</category>
      <category>security</category>
    </item>
    <item>
      <title>Why Private Messaging Isn't Really Private Anymore</title>
      <dc:creator>truksharoz</dc:creator>
      <pubDate>Wed, 22 Jul 2026 18:39:27 +0000</pubDate>
      <link>https://dev.to/rsharoz/why-private-messaging-isnt-really-private-anymore-53c1</link>
      <guid>https://dev.to/rsharoz/why-private-messaging-isnt-really-private-anymore-53c1</guid>
      <description>&lt;p&gt;We use messaging apps every day to share photos, videos, documents, voice notes, and even sensitive information like banking details, payment confirmations, passwords, and one-time verification codes. Because many apps advertise end-to-end encryption&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fliuprj2dyfpa7bq9mhzw.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fliuprj2dyfpa7bq9mhzw.png" alt=" " width="800" height="336"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Farckh2ptsaqze2zry5kv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Farckh2ptsaqze2zry5kv.png" alt=" " width="800" height="336"&gt;&lt;/a&gt; it's easy to believe that everything we send stays completely private.&lt;/p&gt;

&lt;p&gt;The reality is more complicated.&lt;/p&gt;

&lt;p&gt;Encryption protects the content of your messages while they're being transmitted but privacy doesn't end there. Metadata cloud backups screenshots forwarded media and stored copies can all affect how much of your personal information remains under your control.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Is Metadata?
&lt;/h2&gt;

&lt;p&gt;Your message may be encrypted but every conversation also creates metadata. This can include when a message was sent who communicated with whom how often conversations happen and what type of device is being used.&lt;br&gt;
Metadata usually doesn't reveal the content of your messages but it can still paint a surprisingly detailed picture of your habits and relationships.&lt;/p&gt;

&lt;h2&gt;
  
  
  Cloud Backups Can Become Another Copy
&lt;/h2&gt;

&lt;p&gt;Many messaging apps automatically back up chats and media to cloud storage.&lt;/p&gt;

&lt;p&gt;This is convenient if you lose your phone, but it also means another copy of your private data may exist outside your device. If those conversations include banking information, identity documents, or payment records, that sensitive data may also become part of those backups depending on your settings and the service you use.&lt;/p&gt;

&lt;h2&gt;
  
  
  Screenshots and Forwarded Media
&lt;/h2&gt;

&lt;p&gt;Even if a message is encrypted, nothing stops someone from taking a screenshot after opening it.&lt;/p&gt;

&lt;p&gt;The same is true for forwarded photos, documents, or videos. Once they leave the original conversation, you often lose control over where they go next. Encryption protects data while it's being transmitted, but it doesn't automatically prevent what happens after someone receives it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Thoughts
&lt;/h2&gt;

&lt;p&gt;Private messaging is about more than encrypting the content of a conversation. Metadata, cloud backups, screenshots, and forwarded media all play a role in how much control you actually have over your personal information. Understanding these privacy challenges is the first step toward making better choices about how we communicate online. In the next article we'll follow the journey of a single photo and explore what can happen after you press &lt;strong&gt;Send&lt;/strong&gt;.&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>cybersecurity</category>
      <category>android</category>
      <category>secure</category>
    </item>
  </channel>
</rss>
