Facebook Messenger's end-to-end encryption not on by default because of inability to store keys in browsers and the firm's reluctance to make big UX changes
Privacy nerds got some good and some bad news on Friday, when Facebook became the latest major company to embrace encryption … Tweets: @moxie and @csoghoian Tweets: Moxie Marlinspike / @moxie : @csoghoian I think what they've deployed is a huge first step that we should congratulate them for. Christopher Soghoian / @csoghoian : Co-creator (@moxie) of crypto tech used by FB says they could have turned it on by default. http://motherboard.vice.com/ ... http://twitter.com/... Expand More For Next Unexpand More For Next
Context & Ripple Effects
This piece lands mid-arc in Facebook's slow walk toward private messaging: after June reports that an optional encrypted mode was planned, Wired confirmed days earlier that Messenger had begun testing opt-in end-to-end encryption with one-device visibility and self-destruct timers. What Motherboard adds is the why-not-default answer — browsers can't store the keys and Facebook won't absorb a major UX change.
The reaction splits the crypto community in the coverage itself: Moxie Marlinspike, whose Signal protocol underpins the deployment, calls it a huge first step worth congratulating, while Christopher Soghoian argues Facebook could have flipped the default anyway. Months later Facebook did finish the job at scale, rolling out Secret Conversations to all 900M+ users — still opt-in.
First-order effects
- Messenger users who want encryption must find and enable it per conversation, accepting single-device access and self-destruct timers, while every ordinary chat remains readable by Facebook for moderation, linking, and its ads business.
- The stated constraints hand Facebook a defensible public position: key storage in browsers is a real technical limit, letting it frame the non-default choice as engineering necessity rather than a decision to keep plaintext access.
Second-order effects
- Soghoian's claim that the default was a choice, not a constraint, keeps pressure on Facebook and sets the template critics will apply to every other platform that ships encryption as an opt-in extra.
- Rival messengers face a two-front comparison — against Signal's always-on default and against Facebook's reach — pushing them to decide whether to match the feature while copying the same convenient off-by-default posture.
Third-order effects
- If the pattern holds, end-to-end encryption becomes a checkbox feature across mainstream messaging rather than a structural commitment: platforms adopt the cryptography for credibility while preserving default plaintext for moderation, multi-device convenience, and data-driven monetization.
- That gap between capability and default becomes the durable battleground for regulators and privacy advocates — the argument shifts from whether platforms can encrypt to whether governments and users will accept defaults that leave most traffic unencrypted.
The trend: Major consumer messaging platforms are adopting Signal-style end-to-end encryption as opt-in add-ons rather than defaults, trading security posture for UX continuity and continued access to message data.