← Privacy Guides

Accounts & identity

End-to-end account protection: key-only sign-in and encrypted storage

For a targeted, well-resourced adversary: sign in only with a hardware security key, enrol in your provider's strongest program, and turn on end-to-end encryption for the data your accounts store — accepting that the provider can then no longer recover it for you.

  • High threat
  • Time 2 hours
  • Difficulty Advanced
  • Last verified

What this protects, and what it doesn't

Protects

  • Against a remote attacker who already has your password: key-only sign-in accepts only a FIDO2/WebAuthn credential bound to the real site, so there is no SMS or one-time code left to phish, intercept or relay.
  • Against a provider breach, insider or legal demand reaching your stored data: with provider-side end-to-end encryption such as Apple's Advanced Data Protection, the provider holds no key to the covered categories, so a copy taken from its servers stays unreadable.
  • Against takeover through a weak second factor: enrolling in the provider's highest program (such as Google's Advanced Protection Program) removes SMS and other fallbacks and tightens account recovery.

Does not protect

  • Data you share or sync to a service that is not end-to-end encrypted. Shared albums, "anyone with the link" items, and iCloud Mail, Contacts and Calendars stay readable to the provider, and anything you send to another person is only as private as their setup.
  • A compromised or unlocked device. Malware on, or physical access to, an unlocked phone or computer reaches your open sessions and local copies no matter how the data is stored on the server.
  • Lockout. Key-only sign-in and end-to-end encryption mean the provider often cannot let you back in or recover your data: lose your keys together with your recovery key or recovery contact and both the account and the data are gone for good.
  • Metadata and the existence of the accounts. Who you email, file names and sizes, and timing are not hidden by any of this.

Prerequisites

  • A finished threat model that places you at the High level, and the Level 1 "Passkeys and hardware security keys" guide already done.
  • At least two FIDO2 hardware security keys enrolled on every account that accepts them, each with a FIDO2 PIN set, plus a safe offline place for recovery keys and backup codes.
  • Up-to-date operating systems on every device, and — for Apple — two-factor authentication already on your Apple Account with all your devices updated.

Step by step

  1. Know when this tier is worth it

    This is the High-level account setup: it assumes a capable, motivated adversary who may phish you, buy your password from a leak, pressure a provider, or steal a device. It goes beyond the Level 2 recovery-hardening guide in two ways:

    • Key-only sign-in. You remove every fallback (SMS, authenticator codes, email links) and keep only hardware-security-key sign-in, so there is nothing left to phish or relay.
    • Provider-side end-to-end encryption of stored data. You switch the account into a mode where the provider itself cannot read or recover the data it stores for you.

    Both choices move risk from "someone breaks in" to "I lock myself out". Only take this tier once your threat model justifies it and you have working backups of your keys and recovery material.

  2. Make sign-in hardware-key only (no SMS or TOTP fallback)

    The strength of key-only sign-in is that it is the only way in. On each account, finish this order so you never lock yourself out mid-change:

    1. Register two FIDO2 security keys and set a PIN on each (one for daily use, one kept safe at home).
    2. Sign out and back in with each key to prove both work.
    3. Save or refresh the provider's one-time recovery/backup codes offline.
    4. Then remove the weaker factors: phone number (SMS), authenticator-app codes (TOTP) and email one-time codes, on every account that allows it.

    A passkey or security key is phishing-resistant because the browser binds it to one site's origin; a code you type is not. NIST SP 800-63B states that manually entered authenticator outputs do not bind the output to the session being authenticated, so they are not phishing-resistant, while a channel- or verifier-bound authenticator blocks an impostor verifier from relaying the sign-in. Removing the typed-code fallbacks is what closes that gap.

  3. Enrol the Google account in the Advanced Protection Program

    Google's Advanced Protection Program is its strongest account tier, intended for people at high risk of targeted attacks. It requires you to sign in with a passkey or a security key: someone who knows your username and password still cannot get in without the key. It also limits which apps can reach your data and adds stricter checks on downloads.

    Before you enrol, Google recommends ordering your security keys and adding a recovery email and phone number so you can get back in if you are locked out. Enrol from the program's page at landing.google.com/advancedprotection and follow the prompts to register your two keys.

    Enrolment tightens account recovery: if you lose your key and cannot sign in, you must submit a recovery request and it takes Google a few days to verify your identity. Keep a key with you whenever you might need to sign in on a new device.

  4. Turn on Advanced Data Protection for iCloud

    By default most iCloud data is encrypted with keys Apple also holds, so Apple can read it or hand it over. Advanced Data Protection raises the covered categories to end-to-end encryption, meaning Apple no longer has the keys. With it on, Apple lists end-to-end encryption for 25 data categories including iCloud Backup, iCloud Drive, Photos, Notes, Reminders, Safari bookmarks and Voice Memos.

    On iPhone or iPad: Settings → tap your name → iCloud → Advanced Data Protection → Turn on Advanced Data Protection. On a Mac: System Settings → your name → iCloud → Advanced Data Protection. Enabling it on one device turns it on for the whole account; your Apple Account must have two-factor authentication and every signed-in device must be updated, or Apple asks you to remove the out-of-date devices first.

    Apple requires you to set up at least one recovery method first (a recovery contact or a recovery key), because, as the page states, Apple does not have the keys needed to help you recover this data. Web access at iCloud.com is turned off by default when Advanced Data Protection is on.

  5. Harden the Microsoft account (passwordless sign-in)

    Microsoft has no consumer tier that end-to-end encrypts the data stored in a personal account the way Apple's Advanced Data Protection does, so here the hardening is on sign-in. First add a passkey — sign in at account.live.com/proofs/manage (Advanced security options), choose Add a new way to sign in or verify, then the passkey/security-key option, and save it on a security key.

    Then make the account passwordless: at account.live.com/proofs/manage/additional, under Passwordless account, select Turn on and follow the prompts. A removed password is one fewer secret an attacker can phish or reuse. You can reverse it later from the same screen with Turn off.

    Work or school accounts are governed by your organisation; ask your IT team which methods and programs they allow.

  6. Treat recovery keys and contacts as the whole ballgame

    End-to-end encryption moves the single point of failure from the provider to you. Because the provider cannot recover your data, your recovery key (a one-time code Apple generates) or recovery contact (a trusted person who can help you back in) is now the only path back. Lose your keys and your recovery material and the data is unrecoverable — Apple and Google both say so plainly.

    • Write the recovery key on paper and store two copies in separate safe locations; do not keep it only in the account it protects.
    • Choose a recovery contact you trust and can actually reach, and confirm the setup with them. For example, add "alice@example.com" as a recovery contact only after she agrees.
    • Store the hardware keys apart, and keep the provider's one-time backup codes offline as a last resort.
    • Twice a year, test a real sign-in with the backup key and check that your recovery key still matches.

    This is the deliberate trade-off of the whole guide: stronger confidentiality in exchange for higher lockout risk that only your own discipline manages.

  7. Know what end-to-end encryption still does not cover

    Even with everything above on, some data stays readable to the provider by design. Apple's own overview states that iCloud Mail does not use end-to-end encryption because of the need to interoperate with the global email system, and that Contacts and Calendars are built on the CalDAV and CardDAV standards and do not provide built-in support for end-to-end encryption. Shared content — iWork collaboration, Shared Albums, and anything shared with "anyone with the link" — is not end-to-end encrypted either, and certain metadata (modification dates, checksums, file types) stays under standard protection.

    So for the most sensitive material, do not rely on the account's encryption alone: keep it out of Mail/Contacts/Calendars, encrypt files yourself before they sync, and remember that anything you share is only as private as the recipient's own account.

Common mistakes

  • Removing SMS and authenticator fallbacks before both hardware keys are registered and tested, and locking yourself out mid-change.
  • Turning on Advanced Data Protection and then storing the recovery key only inside iCloud or in the same account it is meant to recover.
  • Enrolling in a program such as Google Advanced Protection with a single security key and no backup key, so one lost key means a multi-day recovery request.
  • Assuming end-to-end encryption covers everything, and continuing to keep sensitive notes in iCloud Mail, Contacts or a shared album.
  • Naming a recovery contact who is unreachable, untrustworthy, or who was never actually asked.

Going further

Pair this with device-level hardening: a strong device passcode, automatic lock, and on Apple devices the Stolen Device Protection and Lockdown Mode features for the highest-risk situations. Review which devices and sessions each account trusts and remove ones you no longer use. For passwords on the accounts that still cannot use passkeys, generate long random ones locally with the password generator. Re-check this guide when a provider changes its program or its list of end-to-end-encrypted categories.