Signal

Official website (opens in a new tab)

The messaging app that made end-to-end encryption mainstream: open and rigorous, but with founding choices — phone number, central directory — that make the operator an all-powerful trusted third party.

At a glance
• End-to-end encryption — ✅ Good
• End-to-end authentication — ❌ Poor
• End-to-end security — ❌ Poor
• No identity substitution — ❌ Poor
• Open source client — ✅ Good
• End-to-end multi-device — ✅ Good
• Minimal personal data — ❌ Poor
• No contact discovery and spam — 🟠 Partial
• Post-quantum encryption — ✅ Good

No messaging app other than Signal has done more to bring end-to-end encryption to the mainstream. Its encryption protocol, open and extensively analyzed by the academic community, has spread far beyond Signal: it is the one WhatsApp adopted in 2016 to encrypt the conversations of its billions of users. Its code is open, its documentation is solid, and the nonprofit organization behind it has shown rare consistency. If end-to-end encryption is the norm today, it is largely thanks to Signal. But that should not stop us from thinking critically, nor from raising concerns. Signal’s founding choices make sense in their context: the application started out as an SMS encryption tool, a setting in which identifying users by their phone number went without saying, and in which a central directory was the simplest way to make encryption accessible to as many people as possible. These choices make the operator a trusted third party. They were defensible then; they are no longer inevitable today. A secure messaging app must protect its users from a malicious network, and, as explained on the dedicated page, end-to-end encryption is not enough: end-to-end authentication is needed too. Yet cryptography has long provided the tools to achieve itarchived without depending on any third party — Serge Vaudenay’s SAS protocolarchived, for instance, lets two users authenticate their key exchange remotely by comparing very short codes. It is nonetheless the trusted-third-party model that, driven by the success of Signal and WhatsApp, has become the industry standard. One can certainly trust the Signal Foundation and believe that its servers are properly operated; but a messaging app whose security requires that trust does not provide the same guarantees as one that does without it.

Notable points

One thread runs through most of the concerns below: Signal’s constant determination never to ask the user anything. Everything has to work on its own: adding a contact (hence the directory), recovering an account (hence the SMS), verifying “safety numbers” (hence its optional status). This philosophy made Signal a success and helped encryption spread to the general public; it also has a structural cost, because every question spared the user is power granted to the server. Profile backup is a striking example. Restoring contacts and settings relies on a PIN, a six-digit numeric code, which amounts to only a million possibilities: against an offline exhaustive search, such a weak secret is broken in an instant, however sophisticated the key derivation. A million possibilities is not encryption. Signal therefore compensates with architecture: the data that would allow this exhaustive search is confined in secure hardware operated on the server side, programmed to limit the number of attempts. The PIN’s mathematical weakness is thus offset by an infrastructure promise: that nobody, not even Signal, will be able to extract this data from the hardware protecting it. As long as that promise holds, all is well. The day it gives way, through a vulnerability in the secure hardware or a compromise of the infrastructure, all that remains is the PIN’s entropy, that is, almost nothing. Once again, security rests not on a mathematical impossibility, but on trust in the operator and its infrastructure.

By deliberately opting for maximum simplicity for the user, Signal ends up forcing those who care about their security to stay vigilant on many fronts. This is very well illustrated by the note published by the defense-industry CERTarchived of the French Ministry of the Armed Forces (in French): improving the security of your Signal account is anything but simple and, as explained in the criteria below, inevitably runs into the limits that come with using the phone number as an identifier.

End-to-end encryption ✅ Good

All communications (messages, attachments, calls), in every type of chat, groups included, are end-to-end encrypted, and encryption cannot be turned off. The protocol also renews keys continuously (a process known as “ratcheting”), which guarantees the forward secrecy described in the end-to-end encryption criterion.

End-to-end authentication ❌ Poor

To add a contact, the application queries the central directory and trusts the key it returns. Signal lets you verify that key after the fact, by comparing “safety numbers” (60 digits) or by scanning each other’s QR code face to face; this verification is optional, burdensome, and exceedingly rare in practice. Moreover, it has to be redone after every key change, which happens whenever the contact changes phones. Signal has also deployed a Key Transparencyarchived mechanism, which makes its directory auditable and lets the application automatically check the consistency of the keys it publishes. This mechanism reduces the risk of a directory presenting different keys to different recipients, but it does not change where trust is anchored: authentication still rests on a third party, namely the directory and the associated transparency service (see the discussion in the No identity substitution criterion).

End-to-end security ❌ Poor

End-to-end encryption is provided, but end-to-end authentication is not: the guarantee is therefore not met.

No identity substitution ❌ Poor

A Signal account is tied to a phone number, and a new key can be registered with nothing more than proof of possession of that number, that is, a code received by SMS. Anyone along the SMS delivery chain can therefore take control of an account, as detailed in the criterion; the 2022 Twilio incidentarchived, in which at least one Signal account was re-registered by an attacker, showed this in practice. The additional protections (PIN, Registration Lock) are optional and limited in scope: after seven days of inactivity, the account becomes recoverable by SMS alone again. This limit is structural: as long as identity is a phone number, a reassigned number must be able to change hands. Finally, note that changing numbers without access to the old device means losing your message historyarchived: the phone-number identity is anchored deep in the system. So deep, in fact, that Signal’s upcoming standalone desktop client, designed to work without a smartphone, is also set, as of September 2026, to require a phone number to create an account — a choice visible in the ongoing work on the Signal Desktop source codearchived.

The “Signal Loginarchived” feature, introduced in beta on Android in September 2026, should make it possible to use Signal without a phone number. The number is replaced by a cryptographic identifier, which becomes necessary to restore a backup or, more generally, to replace the key associated with the Signal account. This is a paid feature, but it does protect against the risk of impersonation through SMS interception (though not against impersonation carried out by the central directory itself).

Open source client ✅ Good

The clients are published under the AGPLv3 license, and Signal offers reproducible builds on Android, documentedarchived since 2016. The server code is also publishedarchived under AGPLv3, which our criterion does not require.

End-to-end multi-device ✅ Good

Each device has its own key, and it is the primary device, the one contacts know, that signs the keys of the linked devices: the server has no authority over the list. That is the right model. Signal’s device-linking procedure, however, turned out to be too “frictionless”: in early 2025, phishing campaigns documentedarchived by Google led users, through fake group-invitation QR codes, to link an attacker’s device to their own account, handing the attacker their future conversations in real time. Signal has since tightened the procedure (warnings, additional confirmation). The episode illustrates what the criterion stresses: adding a device is a critical operation, one that nobody should be able to trigger from the outside or confirm on autopilot.

Minimal personal data ❌ Poor

A phone number is mandatory to create an account: a rigid identifier, reused everywhere, and a pivot for cross-referencing that leads back to the real identity (see the criterion). On Signal, the social graph that every relay server observes is therefore a graph of legal identities rather than pseudonyms. Beyond that, Signal does try to minimize what it sees (contact discovery designed not to hand over the address book in the clear, and “sealed sender,” which hides the sender from the server for most messages).

The “Signal Login” option makes it possible to stop sharing a phone number with Signal, but because the option is paid, and because managing the account identifier adds complexity, most Signal users are likely to keep sharing their number.

No contact discovery and spam 🟠 Partial

By default, anyone who knows your number can find you and reach out to you. Since 2024, however, Signal has made it possible to restrict discovery by phone numberarchived and has introduced usernames: a user who turns on this setting, and does not publish a username, can no longer be found from an identifier. This first barrier therefore exists, but it is off by default. The second barrier, contact-request confirmation, is however missing: the text of a stranger’s first message is delivered and readable before any acceptancearchived (see also how to protect yourself on Signalarchived); acceptance only governs profile sharing, read receipts, calls and whether links are clickable. Spam through message requests is real enough that Signal has responded by blurring strangers’ profile photos and adding a report button.

Post-quantum encryption ✅ Good

Since 2023, every new session between two devices has been established with the hybrid PQXDHarchived key agreement, which combines X25519 and ML-KEM, and since October 2025archived Signal has been rolling out a “triple ratchet” that continuously renews the post-quantum part of the keys. This encryption is active by default, without any action from the user. Group chats benefit from it as well: group keys (“sender keys”) are distributed to members through these same one-to-one sessions.