Getting started

The metadata problem

Encryption hides content, not behaviour. What networks still reveal, and why it matters.

End-to-end encryption solved one problem very well: an observer can no longer read your messages. It did not stop the observer from learning almost everything else.

What still leaks

Every packet has to be delivered somewhere. To get it there, today's networks expose information that is never encrypted, because the infrastructure itself needs it.

SignalVisible toWhat it reveals
IP addressesISPs, Wi-Fi operators, servers, transit networksRough location, organisation, household
TimingAnyone on the pathWhen you are active and who responds to whom
Volume and sizeAnyone on the pathType of activity: a call, a file, a page load
RoutesNetwork operatorsWhich services and regions you talk to
Long-lived identifiersService operatorsA single thread linking months of activity
Infrastructure relationshipsHosting and cloud providersWhich servers belong together and who runs them

Why it matters

One piece of metadata is rarely sensitive. Collected over time it becomes a social graph, a daily schedule and a list of interests. That can be enough to identify a person without reading a single message.

  • Correlation. Matching traffic that enters and leaves a network by timing and size links two ends of a conversation.
  • Persistence. A fixed address or account ID turns separate sessions into one long history.
  • Static infrastructure. Servers that never move can be found, mapped and watched once, then observed indefinitely.

Where existing tools stop

Encrypted messengers
Protect message content, but usually depend on central servers that see who is talking to whom and when.
Conventional VPNs
Move trust from your ISP to one provider. That provider sees everything, through a fixed server with a fixed address.
Onion routing
Strong path privacy, but relays are long-lived and publicly listed, which makes the network itself easier to map and observe.