DEV Community

Cover image for The FBI's Own Advice Changed. Yours Probably Should Too.
Short Lived
Short Lived

Posted on

The FBI's Own Advice Changed. Yours Probably Should Too.

What changed and why

In December 2024, officials from the FBI and the Cybersecurity and Infrastructure Security Agency urged Americans to move away from regular text messages and phone calls, and toward end-to-end encrypted apps instead. The trigger was a discovery that a state-linked hacking group, tracked under the name Salt Typhoon, had been sitting inside the networks of major US telecom providers for an extended period, with access to real-time, unencrypted calls and texts as they traveled across carrier infrastructure.

A CISA official put the reasoning plainly on a press call. Encryption is your friend, whether it’s on text messaging or on voice communication, because even if an adversary intercepts the data, it stays unreadable. That’s a notable shift in tone. For years prior, the FBI had pushed for the opposite, arguing that strong encryption made it harder for law enforcement to investigate serious crimes. A telecom-wide breach large enough to expose senior officials’ own communications was apparently what it took to move the agency’s public position.


Why regular texting doesn’t offer this protection

Standard SMS text messages and regular phone calls travel across carrier networks with minimal encryption, which is exactly what made the Salt Typhoon intrusion so damaging. Apps like Signal, WhatsApp, and iMessage work differently. Messages are encrypted on your device before they ever leave it, and only decrypted on the recipient’s device, meaning the carrier, the app company itself, and anyone intercepting the connection in between all see nothing but scrambled data. This is a meaningfully different security model than “the company promises not to look”, which is what most unencrypted services actually offer.


The practical takeaway

If sensitive conversations, financial details, personal information, anything you’d rather not have exposed in a future breach, currently happen over regular text messages or unencrypted calls, switching that specific traffic to an end-to-end encrypted app closes off a real, demonstrated attack path, not a hypothetical one. One caveat worth knowing. Messages between an iPhone and a non-iPhone number typically fall back to standard SMS without a clear warning that protection has dropped, so it’s worth confirming the specific conversation is actually running through an encrypted channel rather than assuming it by default.

CISA’s guidance was aimed primarily at people considered high value targets for espionage, senior officials and similar roles, though the underlying vulnerability affects the same telecom infrastructure everyone uses. The core recommendation, prefer encrypted channels for anything sensitive, holds regardless of how likely any individual is to be personally targeted.


Reference

Federal Bureau of Investigation, “FBI Announces Joint Cybersecurity Advisory Related to Salt Typhoon.” https://www.fbi.gov/video-repository/salttyphoon082725.mp4/view

Support Me on Ko-fi

Top comments (0)