By Glenn Fleishman
June 29, 2026 10:00 AM PT
My credit card number? Sure! It’s 4242 4242 4242 4242

We live in a modern, jet-set, hyper-fast world! When we want to buy something online, boom, zoom, we use our fingerprint or face to approve the transaction, so we can grab the next Segway outta here! We don’t have time to enter a credit card! And can we trust a webpage form? Pfeh!
All right, calm down, 1950s inner voice, it’s not that bad. Most of our transactions involving a payment card or other sensitive data can be safely handled over a secure web connection. Apple Pay in Safari is the highest standard, of course, because the payment process involves encrypted elements, and your card number isn’t disclosed to the merchant. The Wallet app in iOS and the Wallet features in iPadOS and macOS further let us automate the entry of numbers and identifiers on pages we trust.
That’s all for automated commerce. What about other scenarios where you need to provide information to someone, often a friend or a local business, in order to transfer money or conduct a transaction? How can you be sure no one else is snooping in?
Make a call
Voice is still one of the most secure means of providing data. The landline wired and cellular wireless networks may be fertile ground for government agencies, but if you need to read a credit-card number or provide a PIN, a call is often the safest way to do so. By voice, you can always have the other person verify details that you believe only they know, or you can verify details to them for the same.

Because we live in a cyberpunk dystopian future, I do have to add a proviso. AI-generated voices have been convincing for a couple of years now—long enough that you shouldn’t trust an incoming call from someone you think you know, and certainly not from a bank, credit-card company, or other financial institution. I mean, I wrote “How To Avoid AI Voice Impersonation and Similar Scams” in January 2024! I assume the state-of-the-art scam is even better.
(The biggest takeaway is analog, too. Set a family password that you demand from a family member who calls asking for money or to do some weird phone or computer set of instructions.1)
Unless recorded, voice calls also lack persistence, making them impossible to recover later. A real-time Bob needs to be either between Alice and Carol or doing an AI impression of Alice or Carol.
Use secure messaging
I could make the argument that using secure messaging carries even less risk than a voice call if you’ve had an ongoing messaging conversation with someone, so you know it’s really them. Are unsecured text messages being intercepted willy-nilly?2 No, but there is also something about sending plain text all over the cellular networks that gives me the willies, nillies aside.

Secure messaging systems include:
- iMessage: While iMessage has seen exploits, they’re government-grade ones. Its secure end-to-end infrastructure is creaky, but unbroken. There’s an extra detail I’ll mention below.
- RCS with encryption: Between Apple Messages on iOS 26.5 or later and an Android device with RCS encryption support, you have a similar level of end-to-end protection. Make sure you see RCS encryption in the text field, or it’s just plain text. You can also use RCS encryption between two capable Android devices—as if!
- Signal: The Signal app and ecosystem have the best end-to-end encryption, as it implements some of the most modern approaches to protecting older messages and current conversations available so far.
The extra note on iMessage is complicated. Briefly, if you use Messages in iCloud, an encryption key to retrieve those messages is included in an iCloud-based iPhone or iPad backup. With access to your Apple Account, someone could potentially retrieve your stored messages. However, if you enable iCloud’s Advanced Data Protection, the backup is encrypted and requires endpoint decryption using one of your devices, protecting the Messages in iCloud encryption key. This should be a worry only if someone manages to obtain your Apple Account, can activate a second factor, and the information you passed via Messages is so sensitive that someone would hunt to uncover it.
Avoid using SMS or MMS text messages (unencrypted plain text), unencrypted RCS (in-transit/at-rest encryption), or other messaging systems where you’re not sure how they handle data protection. WhatsApp can be used if you either have backups disabled or have enabled end-to-end encrypted backups.
Don’t use most collaborative tools
I know that I spend a lot of time in shared documents, whether Google Docs, Notes, Pages, or more esoteric apps or web apps. Most lack the highest level of protection. Shared Pages and Numbers files on iCloud Drive, as well as Google Docs, are encrypted in transit and at rest, and granting shared access is relatively easy (very easy in Google Docs). For iCloud Drive documents, this is true even with Advanced Data Protection enabled.
I’d be dubious about pasting my driver’s license or credit-card information into any of them that are shared with someone else. Ditto, don’t take a picture of your payment card or driver’s license and share it via a Shared Album in Photos, as it has the same issue.
There are two notable (heh) exceptions: if you and the other party or parties to a shared Notes entry or an iCloud Shared Photo Library all have Advanced Data Protection enabled, end-to-end encryption is used.
Consider the risk
As with all decisions around privacy, consider how at risk you and your data are, including voice as data. In most cases, ensuring a baseline level of encryption can be enough. Even when the app or server can “see” your unscrambled information, the transport between your device and the server and another person’s device is encrypted. Someone would have to break into the server to sniff data. If stored on the server, the baseline state would be encrypted at rest; however, the server operator would manage those encryption keys.
For peace of mind, if not strictly necessary, I’d encourage you to consider using end-to-end encryption when you can. It’s so easily available. For someone to crack your connection, they would need to obtain one of your devices and be able to unlock it. Otherwise, the path between you and someone else is effectively impregnable.
For further reading
I cover message security extensively in my book Take Control of FaceTime and Messages, which I recently updated to include the beta release of RCS encryption for Apple-to-Android communication.
For more on Wallet, I wrote an entire book on that seemingly simple app and set of features, Take Control of Apple Wallet. The book arose from the frustrations of finding where things in Wallet (and outside Wallet but related to it) lived.
On the security side of things, Take Control of Securing Your Apple Devices includes detailed advice on the ins and outs of physical security: how to ensure someone with access to your hardware can’t reach your data.
[Got a question for the column? You can email glenn@sixcolors.com or use /glenn in our subscriber-only Discord community.]
[Glenn Fleishman is a printing and comics historian, Jeopardy champion, and serial Kickstarterer. His current books in preparation, which you can pre-order, are Flong Time, No See, and That One Matt Bors Comic. Other books include Six Centuries of Type & Printing and How Comics Are Made.]
If you appreciate articles like this one, support us by becoming a Six Colors subscriber. Subscribers get access to an exclusive podcast, members-only stories, and a special community.