Submitted by twovests in YouCould

Signal is a good end-to-end encrypted messaging app.

(Note: I will refer to "end-to-end encryption" as "E2EE" or "encrypted" and anything else as not-encrypted. "Transport encryption" is the default and it's not good enough. )

Historically, E2EE encryption has been finnicky and fucky to set up. Signal was a big effort to have uncompromising end-to-end encryption with a usable interface, and it's very successful to both ends. It encrypts your messages, but also your profile info and who you're talking to.

Most messaging apps store your messages centrally on a server, which lets cops, hackers, creeps, and the service read your details. Not good!

On top of this, Signal maintains the Signal cryptographic protocol, which is the gold-standard in E2EE. When someone wants to put an encrypted messaging into their app, they use the Signal protocol.

Signal has been endorsed by the EFF, Snowden, and myriad independent cryptographers and cybersecurity professionals (including me!)

This is in contrast to Telegram, which (1) is not encrypted by default, (2) is never encrypted for group chats, and (3) rolls their own flawed cryptographic protocol (not good). Telegram has been endorsed by Musk and the far-right.


Signal saw a big uptick in 2015 (as TextSecure with the BLM protests), and then again in 2020 (with the BLM protests), and then again in 2025 and 2026 (with the anti-ICE protests).

Every message you send on a surveilled platform is in benefit to ICE et al. Even mundane messages like "does aneyone want potato fries tonite?" The reasons are complicated, but data feeds the AI machine, and it constantly needs fresh data. (Even for those of you not in the US, assuming you're using a US platform somewhere in the loop, it feeds the ICE machine).

Almost everyone I talk to now is exclusively on Signal. That's dozens of contacts, having had spent the past several years evangelizing Signal and getting people on it.

It's very good and you should get on Signal


If there's a TLDR, here's what you need to know:

  1. Download Signal for iOS or Android. You can only install Signal on one phone, but you can install it on iPads and desktops afterwards.

  2. Signal asks for a phone number to sign up, but you can add people by username or QR code without sharing your number.

  3. Your contacts will see your chosen name and profile picture. So, if you use Signal in multiple different circles, consider what single face you'd want to share with those circles. (Friends, family, professional, kink, organizing, art commissioning, etc.)

  4. Signal only protects you from end-to-end. Signal can't protect you if someone steals your phone or takes it over, or if someone adds an untrustworthy individual to a group chat, or if someone takes screenshots of your messages.

  5. Verify safety numbers for cryptographic security, if you want: There is one hole that exists in public-key cryptography. This is a mathematical necessity that Signal can't fix. When setting up the impenetrable end-to-end encrypted tunnel, a hacker can sneak in during the set up. This is called "man in the middle" (MITM). (More specifically, during key exchange, a third party acts like a proxy between you and who you're messaging. This is very difficult to pull off, and I've never heard of it happening with Signal, but it is not impossible to pull off.) To ensure there's no sneaky hacker you can meet with another Signal user face to face to "Verify Safety Number". It is important you only do this in person, face-to-face, and not digitally. (If someone has the capacity to MITM your Signal, they might also alter whatever digital communications you do to verify safety number.)

  6. Verify safety numbers for web-of-trust: Another benefit of verifying safety numbers is that you're marking someone as trusted. This is a social, web-of-trust thing. If you're in a group chat with a dozen people you don't know, organizing against ICE, any one of them could be a bad actor, taking screenshots, etc. This is a social problem Signal can't solve.

3

Comments

You must log in or register to comment.

devtesla wrote

Another benefit of Signal is that it's extremely pleasant to use, while every other app is increasingly a pain in the ass. That counts for a lot.

But yeah...

I'm a bit more suspect of the Signal and E2EE in general. The initial funding for Signal, like Tor, came from the Open Technology Fund. At the time communication that couldn't be intercepted by other governments aligned with American foreign policy interests. I think it's also true that when something is E2EE people will say things that they wouldn't on other lines, which means it can be intercepted in all the other ways that E2EE can break down. This gave advantage to America, which has the capability to hack devices and a history of spooks.

That doesn't mean I don't use Signal, it's super useful. But like, you still probably shouldn't talk about crimes you're gonna do on it because of all those other things that could go wrong. It's a bit of security theater in the end.

2

twovests OP wrote

Yep, this is always true and always possible.

I completely agree with this:

you still probably shouldn't talk about crimes you're gonna do on it because of all those other things that could go wrong


But I do want to contend with this statement:

It's a bit of security theater in the end.

I just disagree with this entirely.

Even if the NSA is sitting on a compromise of the Signal protocol, it probably won't be a complete break of the protocol, and it probably won't be something that can be applied widely.

Cryptographic protocols usually have ridiculous guarantees like "it would take all the computers a trillion years to crack this". I'd have to get into the current iteration of Signal's protocol to talk with concrete numbers here, but we usually start moving away from something when it gets weakened to "it would take all the computers a million years to crack one message".

The key assumption is the data is gathered now, and all the messages are gathered to be cracked with a future weakness. So, maybe in a decade, it would only take one supercomputer one decade to crack every message.

If I were to estimate a total guess of a distribution of scenarios, maybe the 99th percentile worst scenario is "in 10 years, any persons Signal chatlogs will be able to be cracked by the NSA, but they can only crack one persons logs per day with their computational power." And if we still have to worry about todays fascist regime in 10 years, then we're just so fucked.

And even in the 99.999th percentile worst case scenario (the NSA today can read every Signal message at will, even without compromising key exchange), they would still need to (1) be collecting them during the short period they're stored (encrypted) on the servers and (2) they would only be able to burn this kind of thing once, ever. We're all paranoid freaks who are looking for whiffs of this shit all the time.

And I want to stress that this is a wild scenario I'm imagining. (And, as described, there are way easier ways to get your messages). I think it's implausible to get a compromise that breaks Signal in two decades, even if we dedicated every tax dollar to getting people onto a pipeline to become cryptography PhDs. (I sincerely think we're way more likely for the AI bros to create the AI singularity god they keep talking about.)

What this means is, even in the worst case scenario, Signal is still protecting you from everyone who isn't the NSA. The LAPD requesting your chatlogs from Instagram, hackers reading all your SMS messages, or some guy who works at Telegram getting details from a gay furry porn group chat.

tldr: it's not security theater! even in the worst case scenario, e2ee messaging is good, and signal is still the best one.


To repeat, if the US government indeed has a compromise in Signal's E2EE, it's

  • Something so subtle that independent cryptographers have not yet found in the protocol, and

  • It's something they can burn only once ever.

Generally speaking, the ways to get access to the chats (and the way we see it happening) are to:

  • Physically take the device,

  • Compel the vendor (Apple, Google, etc) to sign a compromised version of the app (or compromised software update) for specific individuals,

    • (Note: Except for those who download the APK from Signal directly, Signal can't be compelled to do this, because of how the app store works.)
  • Remotely hack the target device itself,

  • Get into a group chat, or get an informant in with the target. (This is what's happening right now with right wing influencers on X and the FBI),

  • Compromise key exchange. (AFAIK we've not seen this happen, but it's plausible. This is something impossible to solve for, short of either having quantum computers in our phones, or requiring every Signal user to meet in person first), or

  • Learn scary new facts about the laws of physics

2

devtesla wrote (edited )

I want to clarify that I don't think the government has a way to read signal messages. What I mean is, for all the reasons you state, mass adopted E2EE is the start of security and not the end. It can honestly be a little dangerous because it creates a false sense of security, because all the ways to get around E2EE are more common than interception.

2

twovests OP wrote

Oh yeah, I agree with this entirely.

I guess it's kind of like a seatbelt. Very important to driving safely, but then also all the other parts of driving are there, like steering and brakes

2