Instagram has officially discontinued end-to-end encryption (E2EE) for direct messages effective immediately, bringing an end to this major update—which had been tested for years and was originally seen as a way to enhance privacy. Meta stated that the reason for rolling back this feature is that “very few users” adopted it, and the process for enabling it was too obscure: E2EE had to be manually enabled in every individual conversation and was buried deep within the chat settings, meaning most people were unaware it even existed.

Effective immediately, Meta has disabled end-to-end encryption for messages on Instagram.
Meta’s official statement is that if users need truly end-to-end encrypted communication, they can switch to WhatsApp. The company also emphasized that all Instagram users affected by this change will receive a notification instructing them to download any media and messages they wish to keep before the system is shut down, to avoid data loss.

The core concept of end-to-end encryption is that messages can only be decrypted by the sender and the recipient; even the platform itself cannot view the content, thereby effectively preventing access by hackers, law enforcement agencies, and even the service provider itself. Now that Instagram has abandoned this mechanism, future direct messages will revert to standard Transport Layer Security (TLS) encryption. This encryption ensures that data cannot be intercepted while being transmitted between devices and Meta’s servers, but since Meta holds the encryption keys, the platform can theoretically still read the content of all messages.

E2EE has long been the subject of a tug-of-war between privacy advocates and child safety organizations. The latter argue that end-to-end encryption allows criminals to operate within a “digital black box,” making it difficult for platforms to detect criminal activities such as child exploitation. A lawsuit previously filed by the New Mexico Attorney General revealed internal Meta documents from 2019: Monika Bickert, who was in charge of content policy at the time, warned her team that E2EE would undermine the company’s ability to detect cases of child sexual exploitation, going so far as to say, “Our company is about to do something bad; this is irresponsible.”

Against this backdrop, Instagram’s decision is not an isolated case. Two months ago, TikTok also publicly announced that it would never implement end-to-end encryption in direct messages, citing similar concerns regarding child safety. TikTok stated that, since its user base consists largely of young people, the platform must retain server-side readability so it can intervene and protect users when necessary—a stance that has been endorsed by several child safety advocacy groups. Like Instagram, TikTok currently uses only transport-layer encryption to secure messages during transmission.

Instagram’s decision to remove end-to-end encryption (E2EE) is bound to reignite the debate over the balance between “privacy” and “security.” For privacy-conscious users, this means the platform no longer offers truly private communication; but for those who advocate that the platform should actively intervene to protect vulnerable groups, this is a necessary adjustment. In any case, Meta’s decision to shift the primary responsibility for encrypted messaging to WhatsApp appears to signal that the company is realigning the positioning of its various product lines.
Source: KOCPC Chinese