Looking for a better alternative to email for secure communication? This guide highlights the best secure messaging apps and services, frequently asked questions, as well as some messaging apps and practices you should avoid.
Have you ever whispered something in someone’s ear that you didn’t want others to hear?
We all have. These days, many of us spend more time talking to people online than we do face to face. Do you ever say (or type or show) anything that you don’t want others to hear (or read or see)? If so, you had better be using some kind of encrypted messaging app to do it.
In this new and updated guide, we’ll talk about why you need to use a secure messaging service. Then we’ll take a quick look at the latest versions of several secure messaging apps and the services they run on, along with some important characteristics to look for. As you’ll see, each has its own pros and cons, and each takes a different approach to the problem of providing secure messaging capabilities.
Why you need to use secure messaging
When you chat with someone online, you might assume that only yourself and the other person are privy to the conversation. But as we’ve learned over the years, there are lots of groups that are expending considerable effort to spy on your communications. Whether it is corporate surveillance or government agencies snooping up data, your private information is under attack.
- Corporations want to read your messages so they can better target ads to you or sell your personal information to the highest bidder.
- Hackers want to use the information to steal your identity, break into your bank account, sell your company’s new business plans to the competition, or blackmail you with those pictures from that wild night in Vegas.
- Governments want to know everything you think and say and do, and maybe even catch a terrorist or two.
Unless you are using a secure messaging service, any or all of these groups will have an easy time intercepting your messages should they choose to do so.
The situation has gotten even worse with governments forcing people to work from home to protect against that virus. Businesses generally have better internal security than someone sitting on their sofa at home, exposing even your company communications to greater threats than before.
That’s why there has been a boom in new messaging services that claim to be private, secure, anonymous, or any combination of those. But some only protect your messages in transit, while leaving them accessible to the employees of the service. Others are owned by companies with bad reputations for protecting your privacy. Some may even have been hacked by the NSA or other national intelligence agencies, but all hope is not lost.
Here are some secure messaging apps that make the grade…
Best encrypted messaging apps
We’ve tested quite a few messaging services over the years. The ones listed here are the ones we consider to be the best options for secure messaging.
Signal – The most secure messaging app
Signal is one of the two messaging apps that really benefited from WhatsApp’s privacy problems in January 2021. A tweeted recommendation from Elon Musk during the crisis certainly didn’t hurt. And since then, Signal continues to get lots of attention.
Signal is generally considered to be the most secure messaging service available. Originally published by Open Whisper Systems, their encryption protocol (the Signal Protocol) is so good that many other services (including giants like WhatsApp) base their own encryption protocol on it. Signal is end-to-end encrypted, open source, and completely free of charge. It allows you to create disappearing messages (a.k.a. self-destructing messages), has successfully completed third-party audits, and also publishes Transparency Reports.
And if that wasn’t enough, it has recommendations from top privacy advocates including Bruce Schneier and Edward Snowden.
However, Signal does come with a few drawbacks. Perhaps most problematic, it requires a telephone number for registration. This, of course, links what you do on Signal to your identity through your phone number, which could be a dealbreaker for some people. Fortunately, there are some workarounds for the Signal phone number registration issue. And of course, you can also use another one of the secure messaging apps listed below.
+ Pros
- End-to-end (E2E) encryption
- Encryption algorithms: Signal protocol, with Perfect Forward Secrecy (PFS) for text messages, voice messages, and video calls
- Open source
- Disappearing messages (aka self-destructing messages)
- Published transparency reports and security audits
- Logs minimum amount of data
- Does not log IP Addresses
- Can replace your phone’s SMS messaging app
- Focus is totally on individual users
- All Signal products are free of charge
– Cons
- Requires a telephone number to sign up
- Does not support 2FA (Two-Factor Authentication)
https://signal.org
Read our Signal Messenger review for more info.
Wire – Secure messaging and collaboration app
Wire is a well-regarded corporate collaboration suite with secure messaging, group chat capabilities, file-sharing, and the ability to collaborate securely with external clients. For this roundup, we reviewed Wire (free version), a secure messaging app for individuals. According to third-party testing, the Proteus protocol that Wire relies on is secure. Like Signal, Wire is open source and gives you self-destructing messages. Also like Signal, Wire requires some personal information to create an account, either an email address or a phone number. However, you can always use a burner temporary disposable email for this.
Judging on its technology, Wire messenger is a great secure messaging app for individuals. On the downside, there are only approximately 500,000 Wire Free users. Another drawback is that the company has announced they will be focusing more on corporate users, rather than individuals. Take this into account if you are looking for a long-term solution to your encrypted chat app needs.
+ Pros
- End-to-end (E2E) encryption
- Encryption algorithms: Proteus protocol, WebRTC (DTLS, KASE, SRTP) with PFS
- Open source
- Self-destructing messages
- Published transparency reports and security audits
- GDPR compliant
- Wire Personal is free
– Cons
- Registration requires email address or phone number
- Some logging of personal data
- Does not support 2FA
- Small number of Wire Personal users (roughly 500,000)
- Company focus is now on the corporate market, not individual users
https://wire.com
Here’s our full Wire Messenger review.
Threema – Anonymous messaging app with no data collection
Threema is one of the less well-known secure and private messaging apps. With around 5 million users and over 8 years on the market, it is a mature, powerful product that somehow never gained a massive following like Telegram, or widespread fame like Signal. But none of this means that Threema isn’t a good option for certain use cases. Here’s why…
First, you can use Threema totally anonymously. Unless you choose to link the app to an email address or phone number, the only way to identify a user is through a randomly generated ID that has no connection to any user-identifiable data. Likewise, each user’s private key is stored on their device, meaning only the user of the relevant device can read messages sent to it.
Note: You have the option to securely back up your Threema ID, contacts, groups, and other data in a Threema Safe which can reside on the company’s servers or on your choice of other location.
Threema offers a business/education version of the product, along with add-ons for broadcasting messages to Threema groups, and an API to use the Threema message network with your own software.
Even Threema’s relative obscurity can be an advantage in some circumstances. Anyone trying to spy on, hack, or otherwise tamper with a messaging service is much more likely to target the services with larger user bases or greater notoriety. There can be advantages to being overlooked.
While there is currently no free version of Threema, you can still purchase this app through the Threema store for direct download, or the Google Play and Apple stores.
+ Pros
- End-to-end (E2E) encryption
- NaCl open source encryption
- Anonymous messaging; no telephone number or email address needed
- Text and voice messages, voice and video calls, file sharing, polls, groups and distribution lists
- Mobile apps plus browser-based, secure desktop chat
- Transition to Open Source is complete
- No IP Addresses or metadata logging
- They own all their own servers for better security and privacy
- Regular security audits and transparency reports
- GDPR compliant
– Cons
- Small user base
- No 2FA
- No free version
https://threema.ch/en
See our Threema review here.
Telegram – Secure messaging app with 500+ million users
Telegram was the biggest beneficiary of the WhatsApp privacy issues at the start of 2021. How big a beneficiary? Telegram gained tens of millions of new users in just the first few weeks of 2021.
It doesn’t matter how secure and private a messaging app is if you can’t talk to anyone with it. When a messaging service has over a billion users like WhatsApp or Facebook Messenger, the odds are high that the people you want to chat with already have an account. When a service has less than a million users (Wire, for example) the odds that the people you want to talk to already have an account are pretty small.
Telegram occupies the middle ground. With over 500 million active monthly users, the odds that the people you need to talk to already have an account are pretty darn good. And the service is free, too. So let’s talk about the other characteristics of a secure messenger service.
While we love the widespread acceptance of Telegram, and the ever-expanding feature set, we do have some concerns about the service. Communications in Telegram are not end-to-end encrypted by default. Only voice calls and Secret Chats are E2E encrypted. Unless you use one of these two modes, your communications within Telegram are not really secure. Even if you do use the E2E encrypted parts of the service, MTProto, the encryption protocol used by Telegram, is questionable at best, insecure at worst – all depending on who you ask. Besides, Telegram logs more user information than the other services listed here.
Whether Telegram is an option for you depends heavily on your threat model and use cases. You may well find that access to the rich feature set and huge user base of Telegram outweighs the questions about exactly how secure and private Telegram really is. If you do decide to give Telegram a try, make sure to use a good VPN service as well. Hiding your IP address and physical location using a VPN goes far toward overcoming the privacy concerns of all that user data logging.
+ Pros
- End-to-end (E2E) encryption
- Encryption algorithms: MTProto, a custom protocol
- Open source apps and Telegram Database Library
- Self-destructing messages
- Users can be logged in on multiple devices simultaneously
- Supports Two-Step Verification
- GDPR compliant
– Cons
- Registration requires a phone number
- E2E encryption only for voice calls and Secret Chats
- Servers are not open source
- Lacks published formal third-party audits
- Logs IP Address and other metadata
https://telegram.org
See our Telegram review here.
Messaging apps and practices to avoid
So now that we’ve covered the best secure messaging apps above, let’s touch on another topic: messaging apps to avoid.
1. WhatsApp (owned by Facebook)
Sure, WhatsApp may be encrypting your messages – but that doesn’t make it a safe and secure solution. It is owned by Facebook and operates under US law. Here are a few reasons to avoid WhatsApp:
- WhatsApp collects metadata about every user, which can be exploited by Facebook and/or handed over to government agencies. This data includes your name, IP address, mobile number, location history, cell network, contacts, and device type.
- Facebook and WhatsApp will be forced to share users’ encrypted messages with British police under a new treaty.
- Reports suggest governments can easily access encrypted WhatsApp data through “WhatsApp Web”.
- In early 2021, news broke about major privacy policy changes at WhatsApp, which puts more data in the hands of Facebook.
Check out our guide on the best alternatives to WhatsApp.
2. Keybase (now owned by Zoom)
Keybase, which has grown in popularity over the years, sold out to Zoom back in 2020. We covered the story more in our Keybase review.
We know that Zoom is not a business that respects the privacy or security of its users. In fact, there have been numerous scandals with Zoom over the past few years. It’s also worth noting that Zoom has questionable ties to China. In fact, it was even busted routing user data through China.
With Zoom now owning Keybase, we can no longer recommend it.
3. Regular (unencrypted) SMS text messages
While this does not fall under the category of encrypted messaging apps, it’s still worth repeating. If you expect any privacy or security, don’t use standard (unencrypted) text messages.
These text messages can easily be seen by your mobile carriers and the entities they share data with. Additionally, regular text messages are susceptible to man-in-the-middle attacks and also eavesdropping by Stingray devices.
It is important to realize that this applies to SMS messages sent by Signal too. If you configure Signal to manage your SMS messages, it can send and receive SMS. But there is no way to encrypt SMS messages, so even if Signal is managing them, SMS messages go out unencrypted.
Characteristics to look for when selecting an encrypted messaging app
What characteristics should you look for when selecting an encrypted messaging app or service? Even if you have some very specialized requirements, these are characteristics you should definitely look out for:
- End-to-end (E2E) encryption
- Third-party testing / reviews
- Open source code
- Self-destruction
- Limited user data collection
- The specific features you need
- Anonymous signup options
End-to-end (E2E) encryption
End-to-end (E2E) encryption is the #1 characteristic to look for in a secure messaging service. When a messaging service uses end-to-end encryption, only the people who are communicating can read the messages. No one else, not even the company providing the service, can read the messages. Whether you decide to go further down the E2E rabbit hole or not, the key thing to remember is this: If a service doesn’t offer end-to-end encryption, it is not secure.
However, there are two additional conditions that an end-to-end encrypted service must fulfill to ensure it is secure. First, it must use proven encryption algorithms. Second, the end-to-end encryption must be applied to your messages. So let’s look at those two conditions a bit more.
Trusted encryption algorithms
The security of E2E encryption assumes that no one can break the encryption. Or more realistically, it would take a vast amount of time to break the encryption being used. Vast as in millions or billions of years. This normally isn’t a problem. That’s because messaging services typically use trusted encryption algorithms. Algorithms like Signal‘s Signal protocol have been analyzed by cryptographers and shown to be secure against any reasonable attacks. If a service doesn’t use trusted encryption algorithms, it doesn’t mean that the service isn’t secure, but it is something to consider.
End-to-end encryption is turned on
E2E encryption is only useful if it is turned on. Most secure messaging services have E2E encryption turned on by default. Telegram, on the other hand, does not. You need to be sure that you are using Telegram’s Secret Chat system or communicating by voice messages if you want E2E encryption to be turned on in Telegram.
Third-party testing / reviews
One of the big concerns when dealing with any kind of secure messaging service is being able to validate their claims. There are a few different questions you need to answer for yourself:
- What is the service’s definition of “secure?” One service might take a zero-knowledge approach, encrypting/decrypting all messages in the client with the servers having no access to your passwords and encryption keys. Another might use TLS to secure data in transit, and encrypt it at rest on their servers, using their own encryption keys. Both can claim their service is secure, but they would both be using different definitions of the word “secure.”
- What is your threat model? You need to understand what threats you are trying to protect against. If all you want security against third parties spying on your messages while they are zooming back and forth across the Internet, that’s one type of security. If you want your messages to be secure against someone (the NSA perhaps) getting into the messaging service’s servers and decrypting your messages using their copy of your encryption keys, that is an entirely different level of security. Which one you need to search for depends on your threat model.
Once you have the answers to the first two questions, you need to decide if the service you are considering is fit for your particular situation. But how?
Is it practical for you to validate their claims yourself? Knowing that a secure messaging service you are interested in has open source code is great. But can you analyze their code to see if it really delivers on their claims? I certainly can’t. Nor can I do penetration testing or any of the other tests that would be necessary to see whether a service really delivers what it promises.
This is where third-party testing, audits, and reviews come in. Many companies now hire third-parties to come in and validate the service. The exact testing that they get done varies, as does the amount of test results they publish. But this kind of testing can at least give us some sense whether or not a product delivers on their marketing promises.
Open source code
Open source code can also make us more confident that a service will deliver on its promises. Why? Not because you or I are likely to review their source code looking for back doors or flaws in their algorithms. But because it is possible for someone to do exactly that. There are people out there who can, and do, dig into open source code looking for problems.
The more popular a messaging service is, the more likely that people are looking at the code, ready to call out problems. The simple fact that there are people willing and able to go through open source code like this means that errors are likely to get fixed sooner, and anyone trying to do something sneaky in the code will get called out publicly.
Self-destruct messages
The idea of providing security through self-destructing messages has been around for a long time. Today’s secure messaging apps have revived the idea of self-destructing messages, although they aren’t quite as dramatic about it as the old Mission Impossible team was.
Some services allow you to set specific messages to self-destruct a certain amount of time after they are read. Depending on your use case for a secure messaging service, this could be a crucial feature.
Limited user data collection
Just because all your messages are securely E2E encrypted, it doesn’t mean that the service has no information about you. Most services collect a certain amount of user data. This could be your email address, your phone number, the IP address you connect to the service from, what time you connect, who you connect to, and so on. While collecting this kind of information might not compromise the security of your messages, it does reduce your privacy.
Depending on your threat model, the amount of user data a secure messenger service collects may not be important. If it is, you can easily reduce the impact of this data collection by using a VPN while using the messenger service. A VPN will hide your IP address and your location, even from the apps on your devices. Some of our top-recommended VPNs include:
- NordVPN – Based in Panama, zero logs, fast speeds, apps for all devices (see our NordVPN review)
- Surfshark – Based in the British Virgin Islands, zero logs, very low prices (see our Surfshark review)
Note: A VPN is not a silver bullet that hides all your metadata. It is just one of many privacy tools you should be using for basic digital self-defense. However, a VPN will securely encrypt traffic between your device and a VPN server, while also concealing your true location and IP address. See these best VPN services for more options and info.
The specific features you need
The security and privacy of a messaging app or service means little if it doesn’t have the features you need. Happily, most of the top secure messaging services continue to add features, reducing the risk that the one you want will be missing something you need. For example, the ability to run on multiple platforms is virtually a necessity, whereas the ability to send video messages or voice memos may or may not be, depending on your use case.
One “feature” to look for in particular is compatibility. Specifically, compatibility with the secure messaging services used by the people you need to exchange messages with. Telegram’s user base is growing rapidly and has over 400 million users. The rest of the top services have a small fraction of that user base. Depending on circumstances, you may need to compromise on the security and privacy front to be able to communicate with the people you need to reach.
Secure and Encrypted Message App FAQs
In this article, our goal was to give you several options to choose from when looking for a secure and private messaging app. But some people out there want us to pick a single winner. By far, the most frequently asked question we’ve heard when researching this topic is:
What is the most secure and private messaging app?
We get it that you want us to tell you that one particular messaging app is the most secure and private. But we’re not going to do it. While we have our own opinions on the subject, we prefer to defer to the 82nd Airborne. They recommended Signal.
Conclusion on secure messaging apps
Secure messaging apps remain a great alternative to standard email communications. We’ve said this for years, and even Edward Snowden agrees.
Here are the encrypted messaging apps we have reviewed on RestorePrivacy:
The secure messaging apps and services listed here each takes a slightly different approach to the problem of keeping bad guys out of your business. We’ve given you a quick overview of each of them here. We urge you to think hard about your circumstances, then decide which of these quality products looks best to you.
This guide on the best secure messaging apps was last updated on April 27, 2024.
Saul
Telegram has no place here. Please remove it. It’s also worth mentioning criminals don’t use these apps. They use burner phones bought at 7-Eleven or the grocery store and pay by cash.
My pet peeve here is needing a valid phone number (not VOIP) to register an account to use secure messaging.Then again, with people will use these kinds of apps. I suppose they may use them just for fun. In another blog, it was mentioned to use a disposable email address and VPN? Which messaging apps actually allow signups with just an email address and not also a non-VOIP number?
Every secure messaging app I’ve used mandates a valid (non-VOIP) phone number for registration. “Rental SMS” numbers don’t work. This requirement contradicts the idea of anonymity—you’re essentially giving up personal information that these companies can use to identify you. They have the potential to access your data, including the content of your supposedly secure messages. Notice the contradiction?
It seems to me these apps are primarily marketed as secure and private, yet having them on your phone raises red flags. Should your device be searched, or if your IP address or MAC address is linked to your communications, it compromises the very privacy these apps claim to offer.
Rus
If we do talk about privacy and features balance, SimpleX is the best so far from my testing.
Simplex is very feature reach and extremely secure and private.
Not sure why it wasn’t mentioned. it’s really the best out of the bunch
Bill
yea i agree and i have no idea why telegram is even in article since its garbage
Anonymous
Most Secure Messangers to use on a Google Pixel 9 Pro XL running GrapheneOS, nitrokey and Mullvad VPN or Tor.
Cwtch
Briar and Briar Mailbox
SimpleX
Signal
Jami
TAILS or QubesOS Nitrokey 2 Desktop PC Qubes-Whonix running aforementioned apps and or grapheneos emulator and
TinFoilChat
Sources:
AnarSec
https://anarsec.guide/posts/e2ee
http://uwb25d43nnzerbozmtviwn7unn7ku226tpsjyhy5n4st5cf3d4mtflqd.onion/posts/e2ee/
https://anarsec.guide/series
http://uwb25d43nnzerbozmtviwn7unn7ku226tpsjyhy5n4st5cf3d4mtflqd.onion/series/
SerpentSec
https://web.archive.org/web/20210201234049/http://serpentsec.1337.cx/secure-messaging-choosing-a-chat-app
Wire IP leaks and Metadata leaks
Same with Threema
Suomynona
Lol. Like the majority of people use the Pixel? What’ next, one for Huawei, OnePlus, and NonName?
Why team Alex approved of your post remains a mystery. Even this site is now becoming unhinged.
Rus
Everyone around me uses Pixels
Not sure where you are from, but it looks like you are very far behind on what’s happening in the phone industry.
Bill
tor is not safe and has had more security issues then anything i can think of
Anonymous
Another level of security and privacy messaging!
To all folks check this out
Kraden.com
This is another level and you can sleep calm with its complete secret private and encrypted messaging app that only works with privacy respecting OS
grapheneOS.org
Regarding signal or threema or many others they have vulnerabilities they are downloaded via appstore or playsore and they must comply with terms of these two giants.
initial encryption keys exchange is not safe but I wont go to deep in to that. I just letting you know the rest of the research is on your own shoulders
Jack Sparrow
What about TeleGuard? That’s the privacy app developed by the private search engine company Swiss Cows that’s meant to address some of the shortcomings that Signal has such as being tied directly to your phone number. It even has additional features such as the ability to call and receive regular phone calls using a spoofed number. If you guys were serious about recommending Swiss Cows as a search engine, then I highly recommend you check out TeleGuard as an app. I would like to see a review about it on this website.
Robert
I agree, i really would like to see a teleguard review too. I think the app is underrated
Christopher
closed source
dnz
Your forgot arguably the best one with no identifiers, simplexchat. For me its only con is there is no desktop mobile app sync yet.
Mike
One other secure messaging app worth noting is Simple X.
https://simplex.chat/
It is a decentralized instant messenger that doesn’t rely on phone numbers or user names. Users can either scan a QR code or accept an invitation via link to engage in group conversations. Simple X has many of Signal’s features (like message editing), is E2EE, and can be imported on to another device resulting from a lack of central servers.
Mike
Signal might implement sharing usernames for people to identify one anther in place of phone numbers as early as next year.
https://techcrunch.com/2023/11/09/signal-usernames-test/
anon
About time too!
David
Lol. Someone didn’t read Mike’s comment. Nor read the page he cited. Don’t hold your breath “anon”.
Annonymous
I would love if you looked into Session and SimpleX chat. The former from my own research seems to be the current best for privacy and security. Though, I’d like your opinion.
Sven Taylor
Session review
Nikola
Until you clearly state what models of computer, smartphone, smart TV and other “smart” things (i.e. with what exact hardware) and what operating systems people should use and what should not use, every other advice is not much useful.
No application, as far as I know, can protect the user against its device hardware and against its operating system (and against clever malware).
So, it should be stated like this: “If you use Signal, you must use it on such and such hardware and operating systems and not on others. Also you must not have such and such device so and so meters around if you make voice conversations”.
This would be holistic aproach to privacy.
Yoo
Que hay de cierto que SimpleX la financia un grupo de renombre de elite donde esta Bill Gates? ahoa mismo no recuerdo el grupo de empresas , pero he buscado mucha informaciòn y eso es lo que me desanimo, Session lo he probado es muy rapido y bonito a la vista, lo que me tiene con indesición es que el codigo no es totalmente abierto y que su sede esta en Australia, pero igual Signal tiene sede en USA y supuestamente es de las mas segura, me da desconfianza que muchos solo recomiendan las mismas aplicaciones y no mencionan otras muy buenas como Jami, mas esta deben estar ambas personas en linea.
Mike
This is excellent! Now Signal’s encryption can resist efforts that involve using supercomputers to break the app’s encryption. If you don’t use Signal, please consider doing so.
https://arstechnica.com/security/2023/09/signal-preps-its-encryption-engine-for-the-quantum-doomsday-inevitability/
Visitor
I don’t use iMessage or even WhatsApp. Now, why would I want to use Signal? Are you affiliated with them in some way?
Psychonaut
Needs an update with messengers using the matrix protocol example: Element.
CyberVeille
Not only Element
It would be nice to add to this list BRIAR and my 2 favorites : OLVID and SKRED.
OLVID may be the most secured (free) app on the market
Vasuki
hi
I am using olvid
pls contact to try
veilid
in my opinion, all the messengers described here are the horror of privacy. not having a critical threat model i.e. as an ordinary person, I use xmpp with great pleasure. conversations on Android and Gajim on Windows and other xmpp apps on other OSes. xmpp server or home or calyxinstitute and or with similar settings as calyx, i.e. the maximum number of server settings in the disabled mode. [https://veilid.com/] is coming soon, if it’s really something good, maybe I’ll drop xmpp. I am also aware of all the other good messengers that exist at the moment, but they do not suit me because of their more complex use and unstable work.
Paul
Check out Keet.io – interesting P2P E2EE messaging.
Keet
1) very strange disturbing “Terms of Service”. 2) it is impossible to refuse to use the camera, without this permission the application does not work. 3) there are no links to the application from more trusted sources for mobile devices, you can download it only from the app store and google play. I think the disadvantages outweigh the advantages.
anon
How does RCS (Rich Communication Services) rank?
ayanna
What do you think about Simplex Chat?
Super Sven
Sven Sir I ditched WhatsApp and moved to Signal. I only communicate with my Parents via Signal. WhatsApp is very unsafe,
Nikola
If one uses these recommended applications on Android, iOS, Windows, Ubuntu and others, then companies which produce these operating systems will most probably get the conversation (textual, audio, video…) made with these recommended private and secure applications. Am I right?
Then, the question is: Why the developers of these supposedly private applications would ever allow installation of their applications on those operating systems?
Thanks.
Super Sven
Sven Sir please do something, UK is going to pass its online safely bill:
The Verge-
“WhatsApp, Signal, and other encrypted messaging apps urge UK to rethink ‘flawed’ legislation / ‘There cannot be a “British internet,” or a version of end-to-end encryption that is specific to the UK.’”
https://www.theguardian.com/technology/2023/apr/18/whatsapp-signal-unite-against-online-safety-bill-privacy-messaging-apps-safety-security-uk
Ron Green
Thank for your work. Could you provide a good suggestion for SMS as signal is discontinuing it’s sms support. I know it is not ideal but it is sometimes the only option.
Henry
I second this comment.
ChrisN
Your text messages were not secure or private in any way on Signal, that’s why they ditched support. Use anything you like, SMS will never offer security, privacy, or anonymity.
John
SimpleX is way more secure and private vs all mentioned (decentralized, no ID’s , always p2p encryption and open source).
Robert
Well
Those were all usual suspects and all of them use severs somehow.
When a server is used then even in a decentralized configuration data is stored and connections can be traced.
As far as I know there’s now one real p2p messenger that’s fully serverless and that is Briar Messenger.
https://briarproject.org/
Winterfell
but only for Android
Small Portion
Quiet (TryQuiet).
https://tryquiet.org/
David
I was excited to give Signal a try. I recently purchased a Pixel 7 and am in the process of privatizing it as much as is practical. The issue I ran into with Signal is it would not, will not, import any of my contacts. I’ve been all over forums, support, and youtube but it just refuses to import. I’m sure Signal is fantastic but sadly I will never know firsthand. Perhaps Telegram will work, though it is not my first choice.
Frankie
Sven, I’m not liking what I’m seeing. I used to enjoy reading the comments on your site, but not anymore. The vibe is very different now.
Could you please do something about the trolling going on in the comments section, especially when the trolls are using emojis and other methods to provoke commenters?
At this rate, I fear Restore Privacy will end up like Facebook and Reddit, should the bad “apples” troll the comments section.
Johnnie
Frankie, I do like the comments on the site although I do not always agree with some of them or the vibe. I think freedom of expression is more important than freedom of preventing what others want to say because you do not like what you are seeing. If things get really bad here, you always have the option of not coming here.
Wallabee
Any messaging apps that insist on me providing an actual mobile number (they won’t accept a virtual — VOIP) I avoid. I remain doubtful or skeptical they’re not selling my information including legitimate non-VOIP mobile number.
I believe it’s foolish and naive to assume this isn’t the case. Too many simpletons (many who read and post on RP too) believe it’s not a big deal until they get spammed with robocalls or SMS, or worse.
And even though I use an iPhone, I disable iMessage. I never gave implicit permission for anyone to contact me through iMessage. If anyone wants to reach me, they can call or send me an SMS.
While some businesses only communicate with WhatsApp, I have a virtual phone number for WhatsApp and that purpose only.
I don’t allow WhatsApp to access my contacts on my phone, neither should you. I didn’t give permission to a third party application on YOUR phone to add me to their database and server.
It’s unfortunate how not even RP will write a blog on the shortcomings of using Messenger type apps. Perhaps that will change in 2023?
Hmm
Why would Snowden recommend Signal when it requires a valid mobile number? Was he paid for that endorsement??
mmH
😂😂
For common people Signal is alright as it would help them communicate safely without giving any headaches.
Wallabee
For common (intelligent) people, they’d use SMS, iMessage or WhatsApp (for privacy only), or call!
Canucks
Bottom line: if you want secure instant messaging, use an iPhone and iMessage.
The majority of developed (first world) countries use iPhone. Android isn’t as secure. If privacy is important (although not 100% private), spend the extra money for an iPhone. There’s no such thing as 100% private.
Having said that, I have no bloody idea why Canada’s ‘fabled’ and dysfunctional RCMP equip their employees and police officers with Android devices. Obviously because they’re cheaper. Eventually, there’ll be a breach. It’s a disaster waiting to happen.
skcunaC
😂😂
Common man Pegasus is more effective on iPhone as on Android it needs to trick user to get accessibility access which is not easy. iMessage is very unsecure, and was one of the means to infect users with Pegasus. Apple tracks a lot on iPhone, just prevents others from tracking you so that only it can track.
Wallabee
😂😂
Source??
SMH
😂😂
Using a reverse name generator in the form of the person you’re replying to?? You must think that’s ingenious, right?
Anyhow, I feel your comments are always irrelevant, misleading, and disingenuous.
The Pegasus zero-click iMessage exploit was one of the most technically sophisticated exploits ever. And now, as an Android fanboy you say iMessage is very unsecure? Nice try. Did you read that on Facebook, perhaps watch a YouTube or TIk Tok video claiming this?
At least Apple doesn’t sell your information. But that’s ok as long as a third party messenger developer claims their app is secure because your motives are likely malicious? Is that about right, skcunac?
Wallabee
I totally agree, especially now with the latest iOS version.
John Doe
iPhone is hell for privacy and security
Anonymous
Greetings Sven,
Could you please review these messangers and the reference source material? I’d really like you to do this in the future. Thank you.
List of Messengers:
1. TinFoilChat
2. Briar
3. Jami
Summary:
TinFoilChat is considered, by SerpentSec and other security researchers, to be the most secure messaging application in the world. TinFoilChat is FOSS and tested by security researchers who have verified that its cryptographically secure. TinFoilChat is available on GitHub for desktop linux distros only. I would reccomend installing it on Qubes-Whonix, QubesOS, Whonix, TAILS, ParrotOS, Arch or any simillar security/anomymity OS/distro.
Briar is considered, by SerpentSec, to be the most secure messanger on android. Briar is FOSS and uses TOR. Briar has useful features lile private groups, forums, and blogs. Briar is available on the Google Playstore, F-Droid, Aurora Store, AuroraDroid, and possibly also GitHub (GitHub unverified). Not available on iOS. Not sure if Briar can be ported to Linux desktop distros via github.
Jami is like Briar except it uses P2P instead of TOR.
Review the reference source material below for more detailed information analysis on each app and secure messangers overall. Thank You.
Reference:
SerpentSec:
Secure Messaging: Choosing A Chat App
https://web.archive.org/web/20210201234049/http://serpentsec.1337.cx/secure-messaging-choosing-a-chat-app