In Molly there's three options. Google Play Services, WebSocket, and UnifiedPush.
I use the WebSocket and Molly has used >1% of battery since the last full charge so it doesn't seem like play services would improve battery but maybe if I had more apps depending on it..
Google and Apple can't see the notification content but they can see metadata. If you want metadata privacy you should use SimpleX instead anyway.
(I dont bother with encrypted messenging apps. I prefer to assume that anything I do on my phone is doubleplus unprivate. If I want privacy, I head over to my computer.)
Competition is Qubes but that has usability issues and does not have good hardware security.
Google Pixels have no evidence of a hardware backdoor when a desktop is proven to be much less secure against remote and local exploitation.
It has been shown through leaks that Pixels running GrapheneOS are the most secure against Cellebrite in AFU. GrapheneOS was the first to implement a reboot timer feature which brings the device to BFU (much more secure) and then Android and iOS copied it (with longer, non-customizable duration).
You can inspect network traffic to see that GrapheneOS phones only connect to GrapheneOS-run services.
Here's a team member's thoughts: https://discuss.grapheneos.org/d/10150-not-your-average-why-...
I think it's entirely possible that a compromised Titan module (whether such code ships with the device or is updated at a later point) could leak keys via some covert method, and possibly transmit via the baseband or through some other application/method where the OS is not really aware of what's going on.
Google is a dodgy company. Placing any trust in them is foolish.
Other options also rely on closed-source security chips or have none at all, and are demonstrated to be much weaker against AFU attacks or are able to be extracted in BFU and then brute-forced if there's a weak password.
When I'm at home I don't wanna use a virtual keyboard on a 6.3" (or 7.9 unfolded). I just want to use my triple monitor PC setup with a real keyboard and a wealth of display space.
Mobile is cool for on the go but a productivity killer.
however signal has an obscene fondness for TEEs (secure enclaves) so they may actually be doing something stupid here which will require trust beyond the ZKP.
https://confer.to/blog/2026/09/confidential-workers-for-priv...
They probably avoided Monero to not attract the additional scrutiny. They don't even accept donations in Monero.
Signal is not robust for metadata protection. Neither do they advertise anonymity. They take steps to protect metadata but it's nothing compared to SimpleX.
If it's "the feds", then how? There's reproducible builds on all platforms except iOS so we know the source code is what's running on our devices. Can you point to the code where the E2EE is compromised?
They are the largest messenger that has E2EE backups by default.
To be clear, I use signal pretty heavily, but that's because my threat model doesn't really include competent .us.gov actors. I don't think that they'd either prove they're doing this or go through the trouble of parallel construction over anything in my messages or who I'm talking to.
If you can convince as many of your enemies (the american people who politically organize against them) to use the same platform, your job becomes easier than having to ETL from 20 different privacy platforms..
To be honest, I use signal, I have nothing to hide but it is useful in that nobody can spoof me (easily). I even talk to my 60 year old mother on signal. It has it's uses. But the EFF is definitely a federal psyop to get people using tools and techniques they control.
Just look at the people who created TOR, they're all feds. All these projects are funded by feds. These tools are advertised in CIA recruitment campaigns, they are literal weapons to circumvent nation state firewalls and deliver psychological weapons, overthrow governments or allow covert recruitment of foreign traitors.
This is a known strategy of the Kremlin, by the way. They fund opposition groups which protest them, and then leak the fact of that funding so that people who are genuinely upset at the Kremlin get confused about who is captured opposition and who is legitimate.
It can be a signal in some cases, but funding sources are not a reliable way to make a conclusion about a group's motivations.
Signal is for protecting opposition groups that help in regime change operations.
Why would people embrace privacy nihilism? The Signal shills also agitate against gpg/PGP, so we know it is secure and you should use that instead.
SMS registration flow is trivially blocked in places where regimes are controlling telecom infra. And Twilio is unreliable in dozens of places for non-political reasons. Signal is very first-world centric from this point of view.
I understand using play payments initially but hopefully eventually there's a way to buy an account without going through google.
https://github.com/signalapp/Signal-Android/commit/7da3357b5...
For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet.
Just allow monero payments or something. Alongside Google play for the sheep that want to use that.
I've literally registered a Signal account on one of the free SMS sites floating around. Why would spammers choose the payment route over phone numbers? They would just choose the one that's cheaper.
In terms of what they do with big data there's more evil parties like Palantir but data abuse starts with collecting it, and I would object to it even if Google promised to only use it for good. For me my privacy is already violated when my data is collected, not just when it's abused. And I do consider Google's use of that data abusive, just not in the worst ways.
This is the right solution. A one-time payment in crypto, say $5, ought to be enough to prevent spam. That being said, Signal has demonstrated (when presented a warrant) that they do not store phone numbers. If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.
How do they perform address book matching without an phone number? It just being accessible by SGX does not really count as not storing it.
Problem with phone numbers is they are to short to store as a hash, since you can brute force the sha256 of an phone number in a trivial amount of time on a single consumer device
You cannot keep all 3 of "no gatekeeping" - "anyone can message anyone" - "low spam".
I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.
So for the average person, WhatsApp (which is E2E encrypted) is probably quite secure. SMS is not.
All of it.
At one point in the distant past that was actually true! They used to brag about how many times the government came to them requesting information only to be turned away because they never collected any of that in the first place.
In 2020 they introduced a major update where they started keeping user's name, phone number, photo, and (worst of all) a list of their contacts in the cloud. This is exactly the same information governments had been requesting from them. There is no way to opt out of this data being collected. You can opt out of setting a pin, but if you do that a pin is auto-generated for you and the data still gets uploaded even though you won't have any access to it.
In 2025 they added yet another new feature called "Signal Secure Backups". This was an optional feature that let users store actual message content in the cloud as well. They've refused, for years now, to update their privacy to reflect any of that. Their privacy policy is frozen as of May 25, 2018
See: https://web.archive.org/web/20250117232443/https://www.vice....
https://web.archive.org/web/20230519120156/https://community...
Personally, I think their refusal to update their privacy policy is a big fat dead canary warning users that the service has been compromised and shouldn't be trusted. They may be under gag orders from saying so outright, but while the US government can order companies not to tell the public something, they can't force them to say something. For that reason, unless somebody sues them over it, I doubt their privacy policy will ever be updated.
I concede that if you can't trust the device itself you can't trust anything running on it, but why have you resigned yourself to that? And how does that reflect on signal at all?
While I disagree with these critiques of Signal, the surveillance networks can capture metadata - who talks to who and when - without breaking E2E. The metadata is as valuable as the data.
I think Signal has a feature to protect users, but I can't imagine how it works if the attacker can see all parties' Internet connections.
I think they could make that significantly more difficult by adding csprng delays and padding to the messages. That way you can't really effectively correlate timing and sizes without direct access to signals inner workings. I'm not sure what signal's actual throughput is, but if think as a paid feature it could be economical.
Another crazier way would be to send every message to a large number random latched recipients. Good way to 1000x your bandwidth.
> The metadata is as valuable as the data.
This can be true if you are able to get ahold of a user's device and access their signal messages. It's not true in most other cases. I don't particularly care if you know that I am talking to someone specific as much as I care that you don't know what I'm saying.
> Hayden made the remark after saying he agreed with the idea that metadata - the information collected by the NSA about phone calls and other communications that does not include content - can tell the government "everything" about anyone it's targeting for surveillance, often making the actual content of the communication unnecessary.
https://abcnews.com/blogs/headlines/2014/05/ex-nsa-chief-we-...
Isn't it? I think it has a setting, disabled by default, to proxy connections via a Signal server. If you're not doing that ... it must be P2P? Probably with the IP address of the person you're communicating with in the header of every packet?
If this is part of your threat model then I would suggest a different tool such as SimpleX since it uses onion routing and can be configured to always use private routing/relays.
> Private message routing is, effectively, a two-hop onion packet routing.
And actually, it's even better than that:
> Private message routing routes packets (each message is one 16kb packet), not sockets. Unlike Tor and VPN, it does not create circuits between your client and destination servers. The forwarding server creates one shared session between itself and the destination, and forwards all messages from you and other clients to that destination server, mixing messages from many clients into a single TCP session.
> As each message uses its own random encryption key and random (non-sequential) identifier, the destination server cannot link multiple message queue addresses to the same client. At the same time, the forwarding server cannot observe which (and how many) addresses on the destination server your client sends messages to, thanks to e2e encryption between the client and destination server. In that regard, this design is similar to onion routing, but with per-packet anonymity, not per-circuit.
> This design is similar to mixnets (e.g. Nym network), and it is tailored to the needs of message routing, providing better transport anonymity than general-purpose networks, like Tor or VPN. You still can use Tor or VPN to connect to known servers, to protect your IP address from them.
Do you think this changed in over 18 months? I think it changed in under 18 months.
If I’m not fully mistaken, I checked for the combination of iPhone as main device/Android tablet as iPad-like second device sometime in the past six months, at most since the beginning of the year, and it wasn’t possible (unlike phone + iPad as tablet, which seemed quite strange to me).
In any case, it’s a recently released change.
If it were expensive to release it, that would be a reason. But it costs roughly zero dollars to create a public repo on GitHub and a cron job to push to it once a day.
Making the system public potentially increases the likelihood of a hack, which would be bad for Signal users. But relying on this argument to keep the source secret is, I think, a confession that your security is below par. Or to put it the other way round: A secure software system remains secure even if its source code is public, so making your source public is a strong signal that you are confident in your security measures. Security isn't something I expect all non-profits to focus on, but I think it would be telling for Signal to hide behind this reason.
What other reasons are there?
If I were Signal I wouldn’t want either of those.
2. An app like Signal depends completely on network effects, so there's even less motivation for a community-fragmenting fork than in most OSS cases, where you'll notice that forks are already rare. There would have to be something very weird or contentious happening with the original codebase for people to want to fork it -- otherwise it's in no one's interests.
Actually you're mistaken. Under the 501(c)(3) tax code rules, they are required to act in the public good. Nobody has sued them to enforce this though, but I'd at least like them to acknowledge the game they're playing by ghosting us all on this.
“Apple” was a non-intimidating name that would appear early in the phone book. It had nothing to do with Newton, that logo came after the name.
https://en.wikipedia.org/wiki/History_of_Apple_Inc.
> According to Wozniak, Jobs proposed the name “Apple Computer” when he had just come back from Robert Friedland's All-One Farm in Oregon. Jobs told Walter Isaacson that he was "on one of my fruitarian diets," when he conceived of the name and thought "it sounded fun, spirited and not intimidating ... plus, it would get us ahead of Atari in the phone book."
Plus we all know the Beatles had that company name first.
Just because someone calls themselves something doesn't mean it is.
"Open" is a name that George Soros uses for a lot of the things he puts his billions into e.g. the Open Democracy blog.
I'll leave you to decide whether Soros' enterprises are really open.
Nevertheless the point stands - I don’t see what relationship company organizational mission has with their technical responsibilities. Indeed, if the open sourced everything, standing up a clone would be easier which creates funding risk due to a race to the bottom of people who didn’t invest into the R&D investing very little additional to compete.
> OpenAI is a 501c4 not a 501c3
This is incorrect. OpenAI is actually registered as a 501(c)(3) public charity, not a 501(c)(4) social welfare organization. (Source: Bloomberg Law) > Also the structure is much more complicated for OpenAI.
However, this is correct. Their corporate structure is very complex. Here is a screenshot from OpenAI's corporate structure explanation page (now taken down): https://images.axios.com/fbMDxci4KDAoYxM_v61sPi9jSVs=/0x0:19...As far as I can see, you can invote people to a group chat using QR flyers, but your Signal profile is visible to everyone in a chat, so everyone knows what Tina in marketing thinks about it.
Because nobody is going to have a burner phone with a data plan for a separate Signal identitiy.
For most people and use cases, either will probably do, but if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal.
So that the state actor can listen on the edge of the network and infer with whom you are taking and when? Or maximize their chances of finding a 0-day in the client considering that it's the same client that everyone else's using? Or throwing it all away anyways when it's using Apple/Play services for notifications delivery?
I mean, as opposed to using something like XMPP which you can completely use over Tor and never even reveal which server you use/that you use XMPP, from a client running a secure and minimalistic OS and no service-in-the-middle ?
Some would label Signal as a honeypot and it would be difficult to falsify that.
What do you mean by "all"
Apple, at least, maintained a historical database of your phone's notifications, that it did not clean up after they expired. That includes all notifications from Signal telling you that person XXX has sent you a message that starts YYYY <facepalm>
Anyway, I'm not OP, and they have a mad setup (XMPP via Tor) which is a flaky solution most people wouldn't go for. In general, if you're not going to such extreme measures of hiding among the crowd of Tor users to mask your metadata, you're better off directly connecting and hiding among the crowd of Signal users, rather than hosting your own instance.
This is the whole point. Signal actively prevents me from using it outside of the Apple-Google duopoly. Other messaging apps are not like this.
(Note that I don't care about cryptocurrencies except for the cryptography behind it)
There are fully anonymous cryptocurrencies using ZKP where it's not possible to tell if a transaction sent is a transfer of the cryptocurrency itself or a message. It's decentralized and it's also impossible to tell who the transaction is made for (anyone with a copy of the chain can potentially be the recipient of either the money transfer or the encrypted message).
If people were really serious about privacy and secure messaging they'd look into this instead of constantly attacking the concept.
But then of course there are entire armies of shills who have a vested interest in pushing a narrative explaining that services, at best, collecting metadata and, at worst, being backdoored are offering "secure messaging".
I'm only using Telegram and I don't believe for a second it's secure and private (it's got, supposedly, "one on one" E2EE but not for groups). But at least they're not posturing as the most secure and private messenger on earth.
https://docs.getsession.org/contribute-to-the-session-networ...
SimpleX, Delta Chat, Matrix
Related thread: https://news.ycombinator.com/item?id=21936929
In short, yes, building a standard takes some effort, but that serves your users and to future-proof your solution. Moxie's post boils down to "1- I know better than my users and I don't need input to protocol-design, 2- I'm not willing to put in the effort to standardize and document, 3- I reserve the right to change the deal for whatever reason if I ever feel the need" which is not a good look
As for Moxie's post: all three points feel completely valid for a service they're offering for free. Moxie does know better than most users (most users don't know the first thing about software, programming, protocol design, or UX design) and it's a companies choices that drive users to their platform in the first place. Users who don't like it can choose from the dozens of other chat apps instead.
As for the second point, Matrix's ever-moving target of a protocol makes selecting a client or server that covers all of your needs a massive pain. Currently, Matrix's primary server software, Synapse (which is also at the base of the matrix.org server many people default to when joining the network), is violating the Matrix protocol, making it impossible to invite users to chat if they are on compliant Matrix servers. On the XMPP side, there are two different methods of achieving E2EE communication, with seemingly no standard mechanism to support the use case "I want to log in to my chat on my laptop and be able to decrypt the messages in the group chat". I can't blame Signal for not wanting to deal with issues like that. One piece of server software, one set of client versions, with fixes ready to deploy when they're called for: Signal's current design saves a lot of time and effort.
As for the third point, that's part of the reason I use Signal in the first place. I like federated networks as much as the next nerd and I like open standards even more, but the decisiveness behind the company, even when I disagree with their decisions sometimes, is what makes it clear what you can and cannot expect.
On the XMPP defence: yes, I believe what they are saying, XMPP could in theory be a good product, just like Matrix could be, and like Signal is. However, currently, it isn't. XMPP is currently losing in terms of public marketshare to Matrix, which I also wouldn't exactly call a great success.
could you expand on this in detail?
I'm certainly not willing trade a theoretical minor annoyance in exchange for my (literally) vital messaging needs to be subject to enshittification, or abuse by a single actor (which controls whether I can access the network, when, whom I can speak with, what features I am allowed to use, and whether it's time to rope me into buying some cryptoshitcoin).
I didn't say it needed to be federated, I said the infra automation code needs to be opened.
Signal app can update itself at any time
The app is constantly phoning home to Signal servers checking for updates even when it has not been launched and is not being used
That means the client could change at any time, for any reason, unbeknownst to the user
If the advanced user is free to write, edit and compile source code for a Signal client, software developers might call this a "third party client" because there is allegedly some "business transaction" between Signal Corporation and the user where Signal Corporation and the user are first or second parties (although, curiously, the Signal app and service are free)
But it's arguable the more important use of the term "third party" in this context, i.e., "secure" communications, is to indicate a party that is not a first or second party to the communication, a potential eavesdropper
Signal Corporation is a third party to the communication
Because it forces users to use its closed source client software that can be updated at all times for any reasons when it's installed on a user's computer, there exists the potential for remote code execution and, for example, eavesdropping
For example, a US corporation subject to US law could be legally forced to eavesdrop on a particular user. This could be done with an "update"
The point I was making is that this goes against Signal's terms of service, and can get your user account terminated. That's a very oppressive clause in practice, you may want to use a non-signal client for all kinds of legitimate reasons (porting to a non supported platform, to adapt for accessibility needs, for privacy, for compliance, to remove nagging and dark patterns, etc). Signal don't want that, they want to control your user experience, even if this makes it worse for their user.
Separate usernames completely from phone numbers. Period.
There's a reason Signal is still "US based". No, I am not talking about some CIA/NSA/DoD/tom/jerry funding conspiracy, just good old human obstinacy and hubris. They don't give a f about who uses it, it's about who makes and maintains it all.
Faced with mounting statutory damages per violation for wiretapping claims under CIPA and Pennsylvania's wiretap act, Meta forced arbitration
https://ia801900.us.archive.org/6/items/gov.uscourts.cand.46...
"48. After Meta acquired WhatsApp in 2014, WhatsApp partnered with Open Whisper Systems to integrate the Signal Protocol, which is an end-to-end encryption cryptographic protocol, into the WhatsApp platform.26 The integration of the Signal Protocol onto the WhatsApp platform was completed by April 5, 2016.27
58. Recent reporting has confirmed that WhatsApps numerous promises that no one other than intended recipients has access to users communications is false. Indeed, contrary to WhatsApps repeated assurances otherwise, Meta, WhatsApp, their employees, contractors, and/or third-parties personnel have access to users WhatsApp messages.32
59. According to whistleblower accounts reported to federal investigators, employees of Meta and WhatsApp and third-party contractors employed by Accenture are able to access the contents of users messages, contrary to the privacy representations made by the company.33
60. Former Meta contractors reported to special agents with the U.S. Department of Commerces Bureau of Industry and Security that they and some of their colleagues had broad access to the substance of WhatsApp messages that were supposed to be encrypted and inaccessible.34 The two sources confirmed that they had employees within their physical work locations who had unfettered access to WhatsApp, and one stated that she spoke with a Facebook team employee and confirmed that they could go back always into WhatsApp (encrypted) messages.35
61. Moreover, these whistleblowers have outlined much broader access by Meta employees and third-party contractors than the limited access described in WhatsApps Privacy Policy and website.36
32. Jake Bleiberg, US Has Investigated Claims WhatsApp Chats Arent Private, Bloomberg (Jan. 29, 2026, at 16:22 ET), https://www.bloomberg.com/news/articles/2026-01-29/us-has-in....
33 Id.
34 Id.
35 Id.
36 Id."
Unless users control the client software, "end-to-end encryption" is just marketing
Closed source apps and backends by US companies means communications can be monitored if US law requires it
A "backdoor" in the client app can be easily installed remotely by the company through an "automatic update"
https://timesofindia.indiatimes.com/india/ats-probes-use-of-...
https://www.aninews.in/news/national/general-news/accused-da...
https://www.deccanherald.com/india/secure-messaging-apps-lik...
https://india-employmentnews.com/tech-category/delhi-blast-n...
https://timesofindia.indiatimes.com/tech-news/Dangerous-Sign...
And it doesn't matter you use a connected phone or not, they just get data from ISPs.
And yes, using a VPN will get you knocked up as well.
https://www.aljazeera.com/news/2026/1/12/indias-vpn-ban-in-k...
India also bans most satellite phones by the way. I have one so I looked into that as to not get caught out travelling.
Well, damn.
In Britain, and presumably India: "get you knocked up" = "get your door knocked on".
In the US: "get you knocked up" = "get you pregnant".
Source : I'm British
I'm interested on learning ZKPs -- they seem so much like "fairy-tale come true" because I don't know much
Also ZCash.
https://en.wikipedia.org/wiki/Zero-knowledge_proof
Main caveat is that ZKPs are probabilistic. The protocol (number of rounds etc) determines how sure, e.g. 99.9%. But never 100%.
Second caveat: tech- and crypto-bros play fast and loose with the term "ZKP", either because they don't know any better (marketing) or they straight up lie. Whether any application you run actually uses ZKP (or any other cryptography scheme) is unknown unless you have the source code.
One in particular on pratical implementation of ZKPs was popular on HN back in 2024: https://zkintro.com/articles/programming-zkps-from-zero-to-h... (discussion at https://news.ycombinator.com/item?id=41398092)
But if you have a spare phone with your account on, e.g. kids or whatever
You can install Authenticator and get codes, even if the other phones need biometrics.
MacOS, iOS, Windows, Linux, Android are all made in the US and are also virtually universally used. This idea that people avoid American products is super niche.
https://www.zdnet.com/article/europes-plan-to-ditch-us-tech-...
https://github.com/switch-to-eu/switch-to.eu
https://www.europeanswitch.com/why-european-providers/
https://www.techspot.com/news/112362-europe-may-restrict-mic...
https://www.independent.co.uk/news/world/europe/europe-zoom-...
linux us made in the US? An open source OS, with collaborators from all over the world initially started by a finnish student and still actively the main orchestrator of it, linux torvalds. Not to mention the thousand distros derived from it.
https://en.wikipedia.org/wiki/Linux
PS: take this post as an opportunity to educate yourself rather than downvoting it.
see: https://web.archive.org/web/20250117232443/https://www.vice....
https://web.archive.org/web/20230519120156/https://community...
Meanwhile SimpleX and Delta Chat (over chatmail protocol) have it by default for years without any payment requirements, offer relatively better level of data security and are available on F-Droid main repo.
But if the replacement is Google or payment info, then... did we really fix much?
Kinda feels like trading one ID for another.
Some combination with TEE to act as a mixer with a time limited internal secret in the TEE sandbox for verification before converting it to a "paid" flag?