Experts estimate fewer than 10% of the world's 1.4B Android phones are encrypted, compared with 95% of iPhones
Jack Nicas / Wall Street Journal :
Context & Ripple Effects
The encryption gap lands in a market that is effectively a two-vendor duopoly — with 96.8% of new smartphones sold being iPhone or Android — so the contrast is stark: Apple controls both hardware and software and ships encryption on by default, while Google's open-licensing model leaves the decision to dozens of OEMs across 1.4 billion devices.
The estimate also compounds earlier findings about Android's security debt: researchers had already flagged 500M+ Android devices that may not fully wipe data after a factory reset, meaning a large share of the fleet was exposed at rest even before considering encryption.
First-order effects
- Roughly 90% of the world's 1.4B Android phones hold data readable without the user's passcode, while the same extraction on an iPhone fails against about 95% of devices — a direct asymmetry for anyone relying on a phone to protect messages, photos, and credentials.
Second-order effects
- Google is pushed toward OS-enforced defaults rather than optional settings, a path later visible in Android Nougat's file-based encryption and in the Android 9 policy that drove app network-traffic encryption from under 20% to 80% within a year (Google's own figures).
Third-order effects
- Security becomes a structural differentiator between vertically integrated platforms and licensed ones: as long as OEMs control updates — researchers found many don't install the security patches they claim to — Google's fleet-wide guarantees will trail Apple's, keeping encryption adoption tied to hardware refresh cycles rather than software releases.
The trend: Mobile encryption is shifting from an opt-in feature to an OS-enforced default, with Apple setting the benchmark and Google closing a multi-year gap through successive Android releases.