EFF's "Encrypt It Already" Campaign Calls Out Tech Giants on Broken Promises
The Electronic Frontier Foundation dropped a campaign this week with a name that says it all: "Encrypt It Already." The target? Major tech companies who made big public promises about encrypting user data but somehow never got around to actually doing it.
This isn't about companies that never mentioned encryption. This is about the ones who announced plans, got the good press, then quietly let those commitments gather dust while users' data sits exposed.
The Real Problem: Opt-In Security
The EFF is pushing for something that should be obvious: security by default. Too many platforms still treat encryption like a premium feature that users have to hunt for in settings menus. Most people never enable it because they don't know it exists or don't understand why they need it.
During our penetration testing work at Electronic Arts, we saw this pattern constantly. Developers would build solid encryption capabilities, then bury them behind configuration flags or user preferences. The result? Maybe 5% of users actually got the protection.
Why Companies Drag Their Feet
Implementing encryption by default isn't just flipping a switch. It requires rethinking data flows, key management, and recovery processes. It can break existing integrations and complicate customer support.
At TUI, we learned that encryption changes everything about how you handle user data. Customer service can't just look up account details anymore. Analytics teams need new approaches. Legal departments worry about compliance investigations.
But here's the thing: these are engineering problems, not impossible barriers. Companies that treat security as an afterthought end up with bigger headaches later.
What This Means for Development Teams
If you're building web applications or mobile apps, this campaign should be a wake-up call. Encryption by default is becoming the expected standard, not a nice-to-have feature.
For web applications and APIs, this means:
- Data encryption at rest should be enabled from day one
- API communications need proper TLS configuration
- User authentication should include strong password requirements
- Sensitive data should never touch logs or analytics
For mobile development, it's about using the secure storage APIs that iOS and Android provide instead of rolling your own solutions or storing sensitive data in plain text.
The Swiss Enterprise Reality
Working with Swiss clients has taught us that encryption isn't optional in regulated industries. Financial services, healthcare, and government contractors expect security by default because their auditors and regulators demand it.
These organizations understand something that consumer tech companies are still learning: fixing security problems after launch is exponentially more expensive than building it right from the start.
When we review cloud infrastructure for enterprise clients, the first question is always about data encryption. Not whether it's available, but whether it's properly configured and enabled by default across all services.
Beyond the Campaign
The EFF's push matters because it creates public pressure for something that should happen anyway. But don't wait for campaigns to force your hand.
Audit your own systems. Check what data is sitting unencrypted. Look at your default configurations. Ask whether your users would be surprised to learn what security features they're missing.
If you're finding gaps between your security promises and actual implementation, that's exactly the problem this campaign is trying to solve. The difference is whether you fix it proactively or wait for external pressure to force the issue.
If that audit reveals more security gaps than you expected, let's talk about getting them fixed before they become bigger problems.