Why Device Encryption Matters
Smartphones and laptops hold an enormous amount of personal data: email, photos, passwords, and financial information. Losing a device or having one stolen can happen to anyone, and if an unencrypted device ends up in someone else's hands, everything stored on it can be read with little effort.
Device encryption protects data at rest by keeping it unreadable without the correct credentials. Even if the device is stolen, as long as it is powered off or locked, an attacker cannot simply pull out the storage and read its contents directly. Conversely, the only thing encryption protects is data in its stored state. It cannot prevent information from being taken off a screen that is already signed in, nor can it help once someone knows the correct passcode.
How Encryption Works
Device encryption commonly relies on AES (Advanced Encryption Standard). AES is a symmetric-key cipher standardized by the U.S. National Institute of Standards and Technology (NIST) as FIPS 197. It defines three key lengths, 128, 192, and 256 bits, and which one is used by default varies by operating system and device generation.
The point worth remembering is that real-world protection is decided not by the algorithm itself but by how the key is guarded. The key that encrypts your storage is protected by your passcode or password together with the security chip inside the device. In other words, if you only set a simple four-digit passcode, the way in stays open on that side no matter how strong the cipher is.
Full Disk Encryption
Full disk encryption (FDE) encrypts the entire storage volume. Everything is covered, including the operating system, applications, and user data. Authentication at startup or sign-in releases the encryption key, and from then on decryption and encryption happen automatically on every read and write. The contents of the disk are never rewritten back as plaintext, so the stored data remains encrypted even after you authenticate.
File-Based Encryption
File-based encryption (FBE) encrypts each file with a different key. Its advantage is that certain functions, such as alarms and incoming-call notifications, can run after a restart even before the device has been unlocked for the first time. On Android, this method became available in version 7.0 and later.
Encryption Features by OS
Windows BitLocker
Drive encryption on Windows is split into two features with different names. Confusing the two leads to the familiar complaint that "BitLocker isn't on my PC."
- BitLocker is a feature of the Pro, Enterprise, and Education editions, and it can be controlled in detail from "BitLocker Drive Encryption" in Control Panel
- The Home edition has no BitLocker management screen, but on devices that meet the requirements a simplified "Device encryption" feature is available. You operate it from Settings, then "Privacy & security," then "Device encryption"
- Protecting the key in cooperation with a TPM (Trusted Platform Module) is the standard configuration, but BitLocker also lets you choose a configuration that skips the TPM and requires a PIN, a password, or a USB key at startup
- On Windows 11 24H2 and later, "Device encryption" is enabled by default on cleanly installed systems. Because your drive may be encrypted without you realizing it, check where your recovery key is stored first
- "Device encryption" is turned on when you sign in with a Microsoft account or a work account, and the recovery key is escrowed to that account. If you use only a local account, it is not enabled automatically, so you need to check the setting yourself
- Keep your recovery key in your Microsoft account, on a USB drive, or printed out and stored somewhere safe
- If you lose the recovery key, you may permanently lose access to your data
macOS FileVault
FileVault is the full disk encryption feature built into macOS.
- You can turn it on from System Settings, then "Privacy & Security," then "FileVault"
- You can choose whether to store the recovery key in your iCloud account or record and keep it yourself. It is shown as 24 alphanumeric characters, so take care not to make a mistake if you write it down
- On a Mac with Apple silicon or a T2 chip, the storage itself is encrypted even with FileVault turned off. In that state, however, the key is protected only by information held inside the device, which is why turning FileVault on and tying the key to the user's password is meaningful
iOS Encryption
On an iOS device, Data Protection (encryption) is enabled automatically the moment you set a passcode.
- Encryption and decryption are handled by dedicated hardware circuitry. The key length depends on the generation of the chip inside: 256 bits on A14 / M1 and later, and 128 bits on A9 through A13
- The Secure Enclave, a dedicated security processor, protects the encryption keys and blocks brute-force attacks
- Setting a passcode of six or more digits, or an alphanumeric password, strengthens the encryption
- If you enable the "Erase Data" option, the device erases its data automatically after 10 failed passcode attempts
Android Encryption
Encryption on Android devices uses different methods depending on the version.
- Older generations used full disk encryption to encrypt the whole storage volume, and on Android 6 (Marshmallow) devices that met a certain level of cryptographic performance were required to have it enabled by the time initial setup finished
- File-based encryption (FBE) became available in Android 7 (Nougat) and later, and it is the method used from Android 10 onward, the version from which full disk encryption is no longer allowed on new devices
- You can check the encryption status under Settings, then "Security." Item names and menu depth differ by manufacturer and model
- Encrypting an SD card may require a separate setting - be sure to include data saved on an SD card in what you protect
Combine this with privacy settings on your smartphone to strengthen mobile device security comprehensively.
Important Considerations
Device encryption is a strong safeguard, but it is not a cure-all. Keep the following points in mind.
Back Up Your Recovery Key
The BitLocker or FileVault recovery key is your last resort when you can no longer get into your device. If you lose it, you lock yourself out of your own data as well. Keep the recovery key somewhere safe and separate from the device. Managing recovery keys is an important part of password management.
Performance Impact
Because dedicated instructions and circuitry take on the work of encryption and decryption, a slowdown you can actually feel is unlikely. Dedicated AES instructions arrived on Intel with the 2010 Westmere generation (AES-NI), and on ARM they were provided as the cryptographic extension of ARMv8-A, announced in 2011. Most PCs and smartphones designed after that carry this support. On older or inexpensive equipment without encryption support, on the other hand, the processing load can show up in day-to-day use.
Limitations of Encryption
Encryption is effective at protecting data while the device is locked. Once the device is unlocked, however, it cannot protect data from malware or unauthorized access. It is important to combine encryption with cloud storage security and anti-malware measures to build layered defenses.
Summary: Protect Your Device Data with Encryption
Device encryption is the foundation you build on when preparing for loss or theft. Turn on the encryption feature that ships with your operating system, and store the recovery key safely. Beyond encryption, protecting the network path matters too.
Check your connection's security score with IP Check-san, and look at the risk of information leaking over the network as well as on the device itself.
Related Glossary Terms
Frequently Asked Questions
Is smartphone encryption enabled by default?
On iPhone, Data Protection (encryption) is enabled the moment you set a passcode. Android uses file-based encryption, and it is the method used from Android 10 onward, the version from which full disk encryption is no longer allowed on new devices. On older devices you may need to enable it manually. You can check the status under Settings, then Security.
Does encryption slow my smartphone down?
Because dedicated instructions and circuitry take on the work of encryption and decryption, a slowdown you can actually feel is unlikely. Dedicated AES instructions arrived on Intel with the 2010 Westmere generation (AES-NI) and on ARM with ARMv8-A, announced in 2011, and most devices designed after that carry this support. On older or inexpensive equipment without encryption support, the processing load can show up in day-to-day use.