Signal is a good end-to-end encrypted messaging app.
(Note: I will refer to "end-to-end encryption" as "E2EE" or "encrypted" and anything else as not-encrypted. "Transport encryption" is the default and it's not good enough. )
Historically, E2EE encryption has been finnicky and fucky to set up. Signal was a big effort to have uncompromising end-to-end encryption with a usable interface, and it's very successful to both ends. It encrypts your messages, but also your profile info and who you're talking to.
Most messaging apps store your messages centrally on a server, which lets cops, hackers, creeps, and the service read your details. Not good!
On top of this, Signal maintains the Signal cryptographic protocol, which is the gold-standard in E2EE. When someone wants to put an encrypted messaging into their app, they use the Signal protocol.
Signal has been endorsed by the EFF, Snowden, and myriad independent cryptographers and cybersecurity professionals (including me!)
This is in contrast to Telegram, which (1) is not encrypted by default, (2) is never encrypted for group chats, and (3) rolls their own flawed cryptographic protocol (not good). Telegram has been endorsed by Musk and the far-right.
Signal saw a big uptick in 2015 (as TextSecure with the BLM protests), and then again in 2020 (with the BLM protests), and then again in 2025 and 2026 (with the anti-ICE protests).
Every message you send on a surveilled platform is in benefit to ICE et al. Even mundane messages like "does aneyone want potato fries tonite?" The reasons are complicated, but data feeds the AI machine, and it constantly needs fresh data. (Even for those of you not in the US, assuming you're using a US platform somewhere in the loop, it feeds the ICE machine).
Almost everyone I talk to now is exclusively on Signal. That's dozens of contacts, having had spent the past several years evangelizing Signal and getting people on it.
It's very good and you should get on Signal
If there's a TLDR, here's what you need to know:
-
Download Signal for iOS or Android. You can only install Signal on one phone, but you can install it on iPads and desktops afterwards.
-
Signal asks for a phone number to sign up, but you can add people by username or QR code without sharing your number.
-
Your contacts will see your chosen name and profile picture. So, if you use Signal in multiple different circles, consider what single face you'd want to share with those circles. (Friends, family, professional, kink, organizing, art commissioning, etc.)
-
Signal only protects you from end-to-end. Signal can't protect you if someone steals your phone or takes it over, or if someone adds an untrustworthy individual to a group chat, or if someone takes screenshots of your messages.
-
Verify safety numbers for cryptographic security, if you want: There is one hole that exists in public-key cryptography. This is a mathematical necessity that Signal can't fix. When setting up the impenetrable end-to-end encrypted tunnel, a hacker can sneak in during the set up. This is called "man in the middle" (MITM). (More specifically, during key exchange, a third party acts like a proxy between you and who you're messaging. This is very difficult to pull off, and I've never heard of it happening with Signal, but it is not impossible to pull off.) To ensure there's no sneaky hacker you can meet with another Signal user face to face to "Verify Safety Number". It is important you only do this in person, face-to-face, and not digitally. (If someone has the capacity to MITM your Signal, they might also alter whatever digital communications you do to verify safety number.)
-
Verify safety numbers for web-of-trust: Another benefit of verifying safety numbers is that you're marking someone as trusted. This is a social, web-of-trust thing. If you're in a group chat with a dozen people you don't know, organizing against ICE, any one of them could be a bad actor, taking screenshots, etc. This is a social problem Signal can't solve.
devtesla wrote
Another benefit of Signal is that it's extremely pleasant to use, while every other app is increasingly a pain in the ass. That counts for a lot.
But yeah...
I'm a bit more suspect of the Signal and E2EE in general. The initial funding for Signal, like Tor, came from the Open Technology Fund. At the time communication that couldn't be intercepted by other governments aligned with American foreign policy interests. I think it's also true that when something is E2EE people will say things that they wouldn't on other lines, which means it can be intercepted in all the other ways that E2EE can break down. This gave advantage to America, which has the capability to hack devices and a history of spooks.
That doesn't mean I don't use Signal, it's super useful. But like, you still probably shouldn't talk about crimes you're gonna do on it because of all those other things that could go wrong. It's a bit of security theater in the end.