How to Share Sensitive Information Securely over the Internet

At some point, most of our communications shifted from analog to digital: letters and phone calls became emails, texts, and video calls. With analog methods, we could generally assume that our private communications would remain private. Few people were going to steam open a letter or wiretap a phone line. The Internet changed that—digital communications, if not properly protected, can be intercepted in bulk far more easily.

Not all everyday communications require strict privacy. Most of us prefer privacy, of course—few people want their dinner plans published for the world to see—but there are typically no consequences of exposure greater than mild embarrassment (McDonald’s again?). But even ordinary people regularly need to share information that could damage their relationships, finances, or careers if it fell into the wrong hands.

Passwords are the most obvious example because their entire point is secrecy. But other sensitive data includes credit card details, bank account numbers, tax documents, retirement planning materials, and health-related information. When you need to share such data, how do you do it securely?

Data at Rest and in Transit

Before exploring specific solutions, you need to think about how information is protected when it’s in transit between systems and when it’s stored somewhere:

In transit: To prevent eavesdropping, focus on communication channels that are encrypted between you and the destination:

  • Between your app and a server: Nearly all Internet-enabled apps, including all Web browsers, use SSL/TLS to protect their connections to servers. A lock icon in a Web browser’s address bar indicates HTTPS encryption, or you can look for https at the start of a website’s URL.
  • End-to-end encryption: Even better is end-to-end encryption, which ensures that not even the service provider can decrypt your traffic. iMessage (blue-bubble conversations), WhatsApp, and Signal provide end-to-end encryption protection (though WhatsApp archives are readable by other Meta apps). SMS messages are not encrypted at all, and RCS conversations only support encryption with the latest Apple and Google updates, plus carrier support. Both SMS and RCS appear as green-bubble conversations.

At rest: Stored data—whether on your computer, at remote email servers, or in the cloud—needs protection too. Two approaches help:

  • Per-file encryption: Encrypt data before sending so even if an attacker figures out how to access the file, it can’t be decrypted without a password. Send the password through a completely different communication channel (called “out-of-band”)—for example, share an encrypted file via email but send the password via Messages.
  • Time- or access-expiring links: Send a link to the information that expires after a short period or after a limited number of views, thereby shrinking the window during which a breach could occur.

Choosing the Right Solution

The best approach for any given communication depends on four factors:

  • Audience: What are your recipients’ technical capabilities? Messages is easy and secure, but only Apple users can access it. Email reaches everyone but offers less protection. A password-protected PDF is probably easier for less-technical users than an encrypted disk image.
  • Content type: Sharing a password differs from sharing a document, which in turn is different from sharing a collection of files.
  • Importance: How problematic would it be if the sensitive information you’re sharing fell into the wrong hands? There’s a world of difference between the password for a club discussion forum and the credentials to your retirement account.
  • Persistence: Does your recipient need to glance at something only once, or do they need to retain a copy permanently?

Eight Secure Sharing Methods

With all that in mind, here are eight secure methods of sharing information that you can employ in different situations:

  1. Use a secure portal when available: Doctors, lawyers, accountants, and other professionals who regularly receive sensitive information often use secure customer portals or services like DocuSign for sending messages, documents, and files. Use whatever system they provide unless you have good reason to doubt their IT competence.
  2. iMessage, Signal, or WhatsApp: For quick sharing of sensitive information, these end-to-end encrypted messaging services work well. They’re particularly useful for sending information that isn’t useful on its own—for instance, send a login URL and username via email but the password separately via Messages.
  3. Self-destructing links: Services like 1ty.me and One-Time Secret generate encrypted links that contain text. Once the recipient views the link, the server deletes the data, and the link self-destructs. If the recipient reports the link was already used, you know it was compromised. Be aware that some email systems automatically scan links, which could trigger premature self-destruction.
  4. Password manager sharing: 1Password, Bitwarden, and some other password managers (but not Apple’s Passwords) offer secure sharing features that make it easy to share credentials with someone who needs to access a particular account. You can create links with expiration dates, limit access to specific email addresses, and cause links to self-destruct after being viewed once.
  5. Password-protected PDF: For documents that could be printed, create a password-protected PDF. From nearly any app, choose File > Print, click the PDF menu at the bottom, and choose Save As PDF. In the Save dialog that appears, click Security Options, select “Require password to open document,” and enter a strong password (online services can remove weak passwords). Share the file however you like, but send the password through a different channel, preferably via an expiring link.
  6. Password-protected disk image: For Mac users sharing files that can’t easily become PDFs, or for sharing collections of files, create a password-protected disk image. In Disk Utility, create a new compressed disk image (File > New Image > Image from Folder), choose an encryption option (256-bit for more sensitive information), and enter a strong password. Again, share the password separately, ideally via an expiring link.
  7. Password-protected Zip archive: A password-protected Zip archive serves the same purpose and may be easier for Windows users to extract. Apps like Keka and BetterZip can create these. For the fastest approach, open Terminal, type zip -er ~/Desktop/filename.zip (with a space at the end), drag in the files you want to compress, press Return, and enter your desired password when prompted.
  8. Time-expiring cloud storage links: Some cloud storage services offer links that expire after a specified time. Dropbox Professional supports this feature, enabling you to share files while ensuring that links become useless in the event of a breach.

There’s no one-size-fits-all solution for securely sharing sensitive information. Match your approach to the sensitivity of the data, your recipient’s capabilities, and how long they need access.

(Featured image by iStock.com/metamorworks)


Social Media: Need to share passwords, financial details, or sensitive documents securely? Email alone isn’t safe enough. Learn eight practical methods—from self-destructing links to encrypted disk images—that protect your data in transit and at rest.

Similar Posts

  • New Features in iOS 26.1

    The first feature update to iOS 26 is now available—go to Settings > General > Software Update to install iOS 26.1. It doesn’t…

  • Watch Out for Modern Tech Support Scams

    Although Apple’s products and services generally live up to Steve Jobs’s phrase “it just works,” problems do occur, opening the door to scams…

  • Droids, Drones, Scooters, Cars and USB C

    I remember only a couple years ago when drones were new and cutting edge technology. Now, there are huge sections of the show devoted to drones of all sorts: fighting drones, mini drones, paper airplane drones and dancing drones. I don’t know if it is the Star Wars influence but droids were everywhere, including “laundroids” for folding your laundry, grill cleaning droids, window washing droids and all kinds of robots.

    3D printers were new and unique and again whole sections of the show were devoted to “replicators” making everything from iPhone cases to clothing to spare body parts. Several companies were there just to show their filaments for these 3D printers.

    Scooters were everywhere. You know, the ones in the news that have the batteries that blow up. Well, literally dozens of companies were showing their versions and the original Segway had a booth, too. Some one-wheel scooters were there as well as shoes with wheels that zipped you around.

    p{text-align: center;}. !http://blog.smalldog.com/images/4638.jpg!

    Self-driving cars and technology for self driving cars dominated the North Hall and some concept cars were shown, too. My favorite was the Faraday electric car that looked like a single seat batmobile.

    USB-C made its debut at the show with hubs, cables and some USB display port displays, too. I think we will see a lot of USB-C stuff coming up!

    Less prevalent this year was the huge variety of iPhone and iPad cases. There were huge sections last time but while there were several companies showing cases it was toned way down. In their place, power banks of all sorts were being shown in every imaginable shape and size. The Apple battery case, aka the hump, was universally panned but several companies had slim battery cases for the iPhone.

    p{text-align: center;}. !http://blog.smalldog.com/images/4641.jpg!

    I did walk through the TV section but it was not as notable as in past years. The 3D fad has sort of expired and 4K displays are common. I still love the OLED displays, though.

    Other areas that were huge were health care and fitness with a lot of wearable fitness devices and health monitors or all sorts from implantable blood glucose devices to blood pressure cuffs, thermometers and scales. The home automation section was larger than previous years and there were some new HomeKit compatible devices. I liked the NoLok offering of bluetooth compatible padlocks and bike locks that work similar to the Kevo system.

    It was a quick trip out to Vegas but it was certainly worthwhile. I will follow up next week with a bit more.