A compact Echo radio rests on a desk beside a closed laptop in morning light.

What an Encrypted Walkie Talkie Actually Protects, and What It Does Not

Encryption scrambles the audio with a key before it leaves the radio. Whether that is permitted depends on the radio service, and whether it protects you depends on what else the system keeps.

A compact Echo radio rests on a desk beside a closed laptop in morning light.

An encrypted walkie talkie is a handheld that applies a key to your voice and sends only the scrambled result, so plain audio never goes over the air. Only radios holding the same key can turn it back into speech. Anyone else on the channel hears noise, or nothing at all.

Two conditions decide whether that matters to you. Whether encryption is even permitted depends on the type of radio: some services allow it, and some do not provide for it. Whether it protects you depends on what else the system keeps. A scrambled call that is stored on a server is private on the way there and not private afterward.

Key Takeaways

  • Licensed business radio (Part 90) and push-to-talk over cellular permit or provide for encrypted voice: the Part 90 rules contain no prohibition on it, and AES is standard on licensed DMR.
  • FRS and GMRS rules do not provide for encryption, and amateur radio rules prohibit obscuring the meaning of a message. None of the three is a route to private voice.
  • Encryption protects the audio while it travels between radios. It does nothing about a member who repeats what was said, a lost handset that holds the key, or a recording at the receiving end.
  • Whether a recording exists anywhere is a separate question from encryption. A system that keeps nothing has no history to leak, and no history to retrieve later either.
  • No radio system is unbreakable. AES-256 is the current standard, the older DMR Basic Privacy scheme deters casual listening only, and any radio needs a signal before encryption matters at all.

Where encryption does not help

A venue security lead pauses at a service door between the loading yard and the hall.

Encryption covers one path: the audio between the radios. Four common situations sit outside that path.

A group member repeats what was said. The people at each end are not encrypted. If someone on the group passes a call along, by mouth or by text, the encryption did its job and the information still left. Who is in the group matters more than the cipher.

A lost or borrowed handset still holds the key. The key lives in the radio, so whoever holds the radio can listen as a member of the group. That stays true until the device is removed from the group or the key is changed. On business systems this is the leak to plan for, and the fix only happens if someone owns the job.

A radio with no signal does not talk, encrypted or not. A frequency-based handheld is limited by distance, terrain and buildings. A push-to-talk radio that runs over cellular data needs a cellular signal from some carrier. Underground, inside heavy shielding, or in areas with no service at all, it does not work, and the encryption setting is beside the point.

A recording made at the other end. Encryption in transit ends when the receiving radio plays the audio out loud. From there it can be recorded on any phone. If the system stores calls on a server, a copy exists no matter how well the call was protected on the way.

Yes on some radio services, and not provided for or prohibited on others. The answer depends on which set of FCC rules the radio operates under.

FRS handhelds. FRS is licensed by rule, so no individual license is needed (47 CFR 95.305, retrieved 2026-09-18). The FRS rules do not mention encryption by name. Instead, they limit what an FRS transmitter may emit: "Each FRS transmitter type must be designed such that it can transmit only the following emission types: F3E, G3E, F2D, and G2D." Those are plain voice and short data bursts. Scrambled voice is not on the list, so the rules do not provide for it (47 CFR 95.571, retrieved 2026-09-18).

GMRS handhelds. A valid individual license is required to operate a GMRS station (47 CFR 95.1705, retrieved 2026-09-18), and the license does not open the door to scrambling. The rules prohibit "Coded messages or messages with hidden meanings ('10 codes' are permissible)" (47 CFR 95.1733, retrieved 2026-09-18). The "privacy codes" on FRS/GMRS handhelds are tone squelch: they filter what your own radio plays and hide nothing from anyone else on the channel.

Amateur radio. Ham radio requires a station license before transmitting (47 CFR 97.5, retrieved 2026-09-18), and it is built on open communication. Amateur stations may not transmit "messages encoded for the purpose of obscuring their meaning, except as otherwise provided herein" (47 CFR 97.113, retrieved 2026-09-18). A ham handheld with an encryption menu is not a lawful way to hold a private conversation.

Licensed business radio (Part 90). This is where a civilian organization can lawfully run encrypted voice. The Part 90 Industrial/Business Pool rules contain no prohibition on encrypting voice. The one explicit encryption rule in Part 90, 47 CFR 90.553, applies to the 700 MHz public safety channels and permits encryption on all but the two nationwide interoperability calling channels (47 CFR 90.553, retrieved 2026-09-18); the FCC confirmed in 2016 that the restriction applies only to those calling channels (FCC 16-113, retrieved 2026-09-18). For a business licensee, encryption is a feature the radios ship with, and the business holds the license, an FCC authorization that eligible businesses obtain under the Industrial/Business Pool rules (47 CFR 90.35, retrieved 2026-09-18).

Push-to-talk over cellular. These radios do not transmit on a shared radio service at all. The voice goes out as data on a carrier's mobile network, the same way a phone app sends it, and encrypting that data is the normal condition rather than an exception. No radio license is involved: under 47 CFR 1.903(c), authority for subscribers to operate mobile stations in the Wireless Radio Services is included in the authorization held by the licensee providing service to them (47 CFR 1.903, retrieved 2026-09-18).

Radio type Who can listen Encryption permitted or provided for? Recording exists anywhere by default? License needed
FRS/GMRS handhelds Anyone on the same channel within range Not provided for (FRS); coded messages prohibited (GMRS) No, unless someone records off the air None; licensed by rule (47 CFR 95.305) for FRS; individual GMRS license (47 CFR 95.1705) for GMRS
Amateur radio Anyone on the frequency Prohibited: messages may not be encoded to obscure their meaning No by default; public transmissions can be recorded by anyone Amateur station license (47 CFR 97.5)
Licensed DMR business radio Only radios holding the key when AES is enabled Not prohibited; a standard feature of licensed DMR Not by default; some dispatch setups add recording Part 90 business license (47 CFR 90.35)
Push-to-talk over cellular Group members; whether the provider's server can decrypt depends on the design Provided for; the voice is data on a mobile network Depends on the provider's server design; ask before buying None for the user (47 CFR 1.903(c))

Two routes to encrypted voice for civilians

A civilian in the US has two practical routes: a licensed DMR business radio running AES encryption, or a push-to-talk radio that carries voice as data over a cellular network.

Licensed DMR business radios. The DMR standard defines several traffic-encryption options, and the DMR Association lists AES256 among them, noting that it covers both voice and data traffic (DMR Association, retrieved 2026-09-18). The catch is the overhead. The business needs a Part 90 license, every radio has to be programmed with the same key, and someone has to manage those keys when a radio is lost or a person leaves. It suits a fixed site with a radio shop on call.

Push-to-talk over cellular. The radio sends voice as data. The LTE standard encrypts user data between the device and the base station at the PDCP layer, the layer of the LTE stack that packages user data; 3GPP TS 33.401, clause 5.1.3, describes user plane confidentiality as an operator option that "is recommended to be used" (3GPP TS 33.401, retrieved 2026-09-18). App-level encryption, such as AES-256 applied to the voice data itself, sits on top of that and does not depend on the carrier's setting. No radio license is needed, and the buyer never touches a key. The radio does need a cellular signal, which rules it out underground and anywhere no carrier reaches.

Can walkie-talkies be private? Three different things people mean

They can be, but "private" covers three separate questions, and a radio can pass one and fail the next. Pages that call a radio "private" almost always mean the first and stay quiet about the other two.

In transit: can someone listen? This is what encryption answers. An analog FRS or GMRS handheld is open to anyone on the channel. A licensed DMR radio with AES, or a push-to-talk radio with AES applied to its data, is not. Group calls over a network are relayed through the provider's server, so whether the provider itself could decrypt audio depends on how the service is built, and that is a question to ask any vendor.

Storage: does a recording exist anywhere? Encryption says nothing about this. A system with a server can keep call audio, or logs of who talked to whom and when, and that copy outlives the call. A radio-to-radio system keeps nothing unless someone records. Ask any vendor the direct question: what do you store, and for how long?

Identity: can a call be tied to a person? Usually, yes. A GMRS or business license is issued to a named licensee (47 CFR 95.1705; 47 CFR 90.35), and on most push-to-talk services a subscriber account is tied to a buyer. The Echo radio narrows this: its product page states the SIM is not registered in your name and there is no account to open. Nobody on the network has a name to attach to your radio. The purchase still has your name on it, though, so no radio system on this page makes a person anonymous. Encryption protects what is said, not who is speaking.

Echo Radios' position on the first two, as stated on its product page: AES-256 encryption in transit; no transmission logs, nothing stored, no backup. Once a transmission is over it is gone. The trade-off is real: nothing stored means there is no call history to retrieve later, for you or for anyone else. That is a privacy feature, and a limitation for anyone who wants records.

What hackable means for each radio type

Some radios are. An analog FRS or GMRS handheld needs no hacking because nothing is hidden; DMR Basic Privacy has been decoded; AES-256 has not. Anyone who tunes to the same analog channel hears the call. "Hackable" only becomes a meaningful question once a radio claims to hide something.

DMR Basic Privacy deters casual listening only. The scheme applies a fixed keystream to the voice, and the md380tools key table holds 256 entries, one per possible key. Open-source tools have recovered it; the md380tools project by Travis Goodspeed carries the key table in its source (md380tools, applet/src/aes.c, retrieved 2026-09-18). It keeps a scanner hobbyist from following along in real time. It does not keep out anyone who wants in.

The DMR Association also defines an Enhanced Privacy option using 40-bit ARC4, alongside AES-128 and AES-256 options (DMR Association, retrieved 2026-09-18). Only the AES options are NIST-approved algorithms (FIPS 197).

Bar chart comparing the number of possible keys: DMR Basic Privacy has 256, AES-256 has about 1.2 times 10 to the 77th power, shown on a logarithmic scale
Sources: Goodspeed, md380tools (Basic Privacy key table); NIST FIPS 197 (AES key length).

AES-256 is the standard. The algorithm is defined by NIST in FIPS 197, first published in 2001 and updated in 2023 (NIST FIPS 197, retrieved 2026-09-18). A 256-bit key allows about 1.2 x 10^77 possible keys, which is why trying them all is not a practical attack. It is the algorithm the DMR Association lists for full traffic encryption, and it is where CISA's SAFECOM guidance points agencies moving away from DES and non-standard algorithms (CISA SAFECOM, Encryption, retrieved 2026-09-18).

No system is unbreakable, and this post does not claim one is. AES-256 protects the audio on the path. The weak points in practice are keys sitting in lost handsets, keys that never get changed, servers that keep copies, and people who repeat what they heard. A radio that scores well on the algorithm and badly on those is not private.

Choosing an encrypted radio for a team

An Echo radio clipped to the chest strap of a security vest inside a venue foyer.

Start with where the team works and who will manage the keys. Those two facts pick the radio for you.

A fixed site with a business license and a radio shop on call can run licensed DMR with AES. Every handset is programmed with the same key, and someone owns the job of changing it when a radio goes missing. It does not depend on a carrier, which matters underground or on a remote site, and it stops at the edge of the repeater's reach (a repeater is a fixed relay that extends a radio's reach).

A team spread across a city or across states, or one with nobody to manage keys, is better served by push-to-talk over cellular. The encryption is already applied, the group is managed from an admin panel, and adding a person means adding a device rather than reprogramming a fleet.

If your team works where there is cellular coverage, the Echo Radios Walkie-Talkie is the one I would recommend. Its product page lists AES-256 on the voice data, no transmission logs and nothing stored, an IoT SIM already inside that is not registered in your name, no FCC license needed, no contract, and groups of up to 250 people as standard, extendable to 5,000 on request. At the time of writing a two-pack is $199.99, and the larger packs cost less per radio. Where no carrier reaches, it does not work, and a licensed DMR system is the better fit.

Alan C., whose review carries the verified-purchase badge in the reviews on the Echo Radios product page, wrote:

"Bought a 6-pack, received last week, and I want you to know that the handsets are beautiful, tough, lightweight, easy, and fun. Next, the communication? 1000% amazing crystal clear, everywhere I've tested them, in elevators, underground garage, beach, places where my cellphone has NO signal, this has full bars and works."

His garage and elevator results are his own; coverage inside a structure depends on the building and on which carriers serve it. Where his phone had no signal and the radio had bars, the multi-carrier fallback the product page describes, together with an antenna larger than a phone's, is the likely reason; it still needs a signal from some carrier.

If that matches your team, the Echo Radios Walkie-Talkie product page lists the pack sizes and what ships in the box.

Frequently asked questions

Can civilians get encrypted radios?

Yes, by two routes. A licensed DMR business radio can run AES because the Part 90 Industrial/Business Pool rules contain no prohibition on encrypting voice, and a push-to-talk radio that sends voice as encrypted data over a cellular network needs no radio license at all (47 CFR 1.903(c)). FRS, GMRS and amateur radios are not a route to encrypted voice.

Are encrypted radios legal?

On some services, yes. The Part 90 Industrial/Business Pool rules do not prohibit encrypting voice, and the one explicit Part 90 encryption rule, 47 CFR 90.553 for the 700 MHz public safety channels, permits it on all but two interoperability calling channels (47 CFR 90.553, retrieved 2026-09-18). FRS does not provide for scrambled voice (47 CFR 95.571), GMRS prohibits coded messages (47 CFR 95.1733), and amateur radio prohibits messages encoded to obscure their meaning (47 CFR 97.113), so none of those three is a lawful route.

Can walkie-talkies be private?

Some can. Analog FRS and GMRS handhelds cannot be, because anyone on the channel hears them and the "privacy codes" only filter what your own radio plays, while a licensed DMR radio with AES, or a push-to-talk radio with AES applied to its data, keeps outsiders from listening in transit. Whether a recording exists on a server is a separate question to put to the vendor before you buy.

Are walkie-talkies hackable?

Some are. An analog handheld needs no hacking because nothing is hidden, DMR Basic Privacy has been decoded with open-source tools (md380tools, retrieved 2026-09-18), and AES-256 as defined in NIST FIPS 197 has not (NIST FIPS 197, retrieved 2026-09-18). The practical weak points are lost handsets holding keys, keys never changed, and stored copies, not the algorithm.

Two questions settle it. Which radio service can your team lawfully use where it works, and do you want a record of your calls or none at all? Answer those, and the radio picks itself.

Checked September 2026.

Back to blogs