Nothing has changed on Instagram; Meta has always read your DMs

Since May 8th, Instagram stopped offering the option of direct messages (DMs) with end-to-end encryption (e2ee). The announcement was made quietly on a page in Meta’s help documentation, which reflects the importance of this feature within Instagram — close to zero. In reporting the news, however, the media did a poor job, stretching the truth or even resorting to misinformation, inflaming public opinion for no good reason.

I am the first to criticize Meta, which is why we must be careful with our accusations, lest we weaken the real arguments against it and its practices.

In the BBC News article, the headline (mis)informs: “Instagram privacy tech is turned off today – what does this mean for your DMs?” Even tech-focused sites like Brazilian TechTudo jumped on the bandwagon — “Meta can read your Instagram messages starting today; see what’s changed.”

Let’s set the record straight, starting with the most important point: it’s almost certain that none of your Instagram DMs have ever been end-to-end encrypted. The feature was never mandatory, as it is on WhatsApp. It was optional.

In 2019, Meta announced a major privacy-focused plan, including integrating all its messaging platforms and making them end-to-end encrypted by default, following WhatsApp’s example. With the benefit of hindsight (though this seemed obvious at the time), it was just a bluff by Mark Zuckerberg to dispel anti-monopoly concerns that were already swirling around the company at the time.

Meta began offering DMs with end-to-end encryption on Instagram starting in 2021, but with three caveats:

  1. It was in a testing phase.
  2. The feature wasn’t and never were available in all markets.
  3. Most importantly, it was always optional.

Unless you manually enabled end-to-end encryption before chatting with someone, your messages remained readable by Meta, just as they always were.

In standard mode — which everyone uses — messages are encrypted only in transit, that is, as they travel from your phone to Meta’s servers, and from there to the recipients’ phones. Furthermore, all conversations are stored on Meta’s servers and can be read by the company, its employees (unlikely), and bots and automated systems (which definitely happens). With e2ee, messages disappear from the servers and remain only on the users’ devices (the “ends” mentioned in “end-to-end encryption”).

That’s why, in my opinion, Meta’s low-key announcement was appropriate: because it was never something relevant to anyone. Most people don’t care about e2ee, and those who do don’t use Instagram (or anything from Meta) to discuss sensitive topics.

In fact, there are legitimate arguments against end-to-end encryption on Instagram. Two, in particular:

  1. Less flexibility in accessing messages on new devices. When switching phones, for example, simply logging into Instagram wouldn’t be enough to access your conversations, because they’d only be on the old phone. You know how much of a hassle it is to migrate your WhatsApp history to another phone, and that delay when loading messages on the web/desktop app? Well, that’s because of end-to-end encryption.
  2. Greater difficulty for authorities to obtain evidence from messages. With e2ee, Meta’s hands are tied when subpoenaed to provide conversations in ongoing criminal investigations, which is especially frustrating in cases of child abuse. Instagram is fertile ground for abusers, making it a valuable asset in combating them.

If the news that Meta started “reading your Instagram messages” as of May 8th shocked you, the truth is worse: Meta has *always* read your Instagram DMs.

***

PS: Telegram, which many tout as “the most secure messaging app,” works the same way Instagram did. There, end-to-end encryption is also optional and rarely used.

Subscribe to my newsletter

Follow me on Bluesky and Mastodon. Subscribe to push notifications and the RSS feed.