The latest WikiLeaks revelations included a reminder that there are revealing things that just can’t be encrypted As we say goodbye to privacy, some people are putting their faith in encryption. But there’s only so much that encryption can do.I’m not arguing that encryption is weak and in danger of being busted wide open. I’m not even arguing that companies such as Apple will reverse their stances and give up encryption keys to law enforcement.I’m simply observing that not everything can be encrypted, and the things that can’t be encrypted can reveal plenty about us. And even Apple has no problem giving law enforcement that kind of information.None of this is a secret, but it was underscored by an interesting email from an Apple executive that was included In batch of Clinton campaign emails that was released by WikiLeaks on Wednesday (Oct. 26). The intercepted email was sent on Dec. 20, 2015, from Lisa Jackson, Apple’s vice president of Environment, Policy and Social Initiatives (who reports directly to CEO Tim Cook), to Clinton campaign Chairman John Podesta. Podesta and Jackson once shared the same employer, when Podesta worked at the White House and Jackson was the administrator of the U.S. Environmental Protection Agency.Jackson wrote that Apple works “closely with authorities to comply with legal requests for data that have helped solve complex crimes. Thousands of times every month, we give governments information about Apple customers and devices, in response to warrants and other forms of legal process. We have a team that responds to those requests 24 hours a day. Strong encryption does not eliminate Apple’s ability to give law enforcement meta-data or any of a number of other very useful categories of data.” It’s a simple point that many people haven’t grasped. Encryption can protect the contents of an email message, but it can’t hide who sent the message and who received it. That can be valuable information. Say that law enforcement officials are interested in a particular encrypted email that a suspect sent. If it can learn from the suspect’s carrier who the recipient was, it might be able to seize that person’s phone and read the message free of encryption. No muss and no fuss.As for meta-data, it can show times, dates and even location. So, despite Apple proudly declaring that it protects its customers’ data no matter what, it is still giving the government a lot of information “thousands of times every month.”Add in self-leaking mobile apps — due to inadequate app testing, as Amazon just discovered — and you see how hard it has become to keep much of anything private. We are getting to the point where the only way to keep information secret is to hide it from our phones. Maybe we’ll all have to become like Jason Bourne or the characters on Breaking Bad, buying disposable phones, using them once and then ditching them.Sure, you’re not a meth dealer, so it’s not a problem, right? But let’s say that you plan to take a trip to secretly meet with a major competitor about a job. Do you really want to take along your company-issued smartphone and let it collect unencryptable geolocation datapoints as you go? Or use that phone to email the competitor? You can’t encrypt the email’s destination, so by the time you send four or five emails to the rival’s domain, you may find yourself in an awkward conversation with your boss.Yes, strong encryption, enterprise-grade VPNs and dark web-friendly browsers such as Tor can enhance privacy, but they don’t even come close to shielding all sensitive data from prying eyes.If you’ll excuse me now, I have some Dixie Cups and string to assemble. Related content news analysis Attackers breach US government agencies through ColdFusion flaw Both incidents targeted outdated and unpatched ColdFusion servers and exploited a known vulnerability. By Lucian Constantin Dec 06, 2023 5 mins Advanced Persistent Threats Advanced Persistent Threats Advanced Persistent Threats news BSIMM 14 finds rapid growth in automated security technology Embrace of a "shift everywhere" philosophy is driving a demand for automated, event-driven software security testing. By John P. Mello Jr. Dec 06, 2023 4 mins Application Security Network Security news Almost 50% of organizations plan to reduce cybersecurity headcounts: Survey While organizations are realizing the need for knowledgeable teams to address unknown threats, they are also looking to reduce their security headcount and infrastructure spending. By Gagandeep Kaur Dec 06, 2023 4 mins IT Jobs Security Practices feature 20 years of Patch Tuesday: it’s time to look outside the Windows when fixing vulnerabilities After two decades of regular and indispensable updates, it’s clear that security teams need take a more holistic approach to applying fixes far beyond the Microsoft ecosystem. By Susan Bradley Dec 06, 2023 6 mins Patch Management Software Threat and Vulnerability Management Windows Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe