PRIVACY REPORT:

Why We Do Not Recommend the Signal “Privacy” App

I want to be clear up front: this decision to remove Signal from our list of recommended privacy apps is not based on some over‑zealous, purist view of privacy.

The concerns I’ve uncovered are serious enough that my conclusion is simple:

Do not use Signal for anything that genuinely requires privacy.

Context: OS Upgrades, Broken Apps, and Spyware

I recently upgraded my Mac from Catalina to Ventura because most of my apps had simply stopped working. I delayed that upgrade as long as possible for two reasons:

  1. Stability and breakage
    There was a time when everything on a Mac “just worked”. We’re well past that. These days every major OS update seems to break more things, kill more apps, and risk data loss.
  2. Privacy erosion at the OS level
    macOS has gone from being relatively good on personal privacy to racing Microsoft for the title of “worst spyware OS”. With each release, the amount of telemetry, lock‑in and baked‑in surveillance gets worse.

(For the record: I’m moving to Linux. I already have a Linux system next to me that will replace my old Mac desktop as soon as it’s ready to fully take over.)

I recently had to re-install Signal on my Desktop and was forced to verify it on a mobile device which was already annoying. I shocked to see this message popup when installing Signal on my de-googled phone.

My Research Into Signal

I started looking into Signal with four major concerns that, in my view, immediately disqualified it as a true Digital Freedom technology.

At that point, I still thought Signal might qualify as a Level 2 – “Privacy‑focused on legacy platforms” in our Trust Ranking framework.

But those 4 concerns turned into 5 groups of 13 specific concerns once I dug deeper.

  • The phone‑number requirement was always the biggest red flag.
  • A recent experience with Signal breaking around an OS update exposed more issues.
  • That prompted a deeper investigation into its trust model, infrastructure, dependencies, and governance.

The result:

We have moved Signal from Level 2 down to Level 4 in our Trust Ranking Scoreboard and removed it entirely from our list of recommended privacy apps.

Score Range Level Color Label Summary
81–99 L1 🟦 Blue Digital Freedom Technology Requires P1–P4. Sovereign stack with no Big Tech or centralized control.
61–80 L2 🟩 Green Privacy-Focused on Legacy Platforms Privacy-strong, FOSS-based, but hosted within or distributed through centralized platforms.
41–60 L3 🟨 Yellow Neutral / Unknown Lacks strong evidence either for or against digital freedom. Often semi-proprietary, privacy-ambiguous, or under-documented.
21–40 L4 🟧 Orange Part of Big Tech Ecosystems Relies on closed, centralised systems or cloud infrastructure. Standard commercial behavior.
0–20 L5 🟥 Red Hostile to Digital Freedom Built for surveillance, profiling, lock-in. Should be avoided entirely in privacy-respecting environments.

In plain language:
Signal is now on our “do not use for real privacy” list,
only marginally more trustworthy than WhatsApp.

PRIVACY CONCERNS:

Concerns Regarding Signal Messenger

1. Identity, Metadata, and Centralization

  • Phone‑number identity and telco / state correlation
    The mandatory phone number links accounts to real‑world identities, allowing telcos and states to map networks. Usernames hide numbers from other users but not from Signal or telcos, and legal orders can compel Signal to confirm user status.
    Sources: Proton, Mozilla 2025
  • What this means in practice: Your Signal account is tied to your real-world identity via your phone number. This makes you vulnerable to SIM-swapping attacks, government requests to telcos for your call/SMS metadata, and potential deanonymization if your phone number is compromised or linked to other public data. Even with usernames, Signal itself still knows your number, and legal processes can compel them to confirm if a number is a Signal user.
  • Centralization + AWS + Intel SGX: a powerful leverage point
    Signal’s reliance on a single US non‑profit, AWS infrastructure, and Intel SGX for private contact discovery creates centralized points of failure and legal/technical leverage. SGX has known weaknesses, and there is no federation or alternative infrastructure if Signal is blocked or compromised.
  • What this means in practice: If Signal’s central servers (hosted on AWS) are compromised, or if the US government issues a legal order, there’s a single point of control. Intel SGX, used for contact discovery, has had vulnerabilities, meaning the “private contact discovery” isn’t foolproof. If Signal is blocked in a region, there’s no alternative server to connect to, unlike federated systems.
  • “Sealed Sender” and relationship metadata are not as private as advertised
    Sealed Sender hides some metadata but not all; initial key lookups and other flows can still permit social‑graph reconstruction. Academic and practitioner critiques suggest attacks on Sealed Sender and contact observability that have not been fully or publicly addressed.
    Source: SimpleXChat critique
  • What this means in practice: While your message content is encrypted, sophisticated adversaries might still be able to infer who you communicate with, when, and how often, by analyzing traffic patterns or other metadata not fully obscured by Sealed Sender. Your social graph (who you know and talk to) might not be as private as you assume.
  • Push notifications & third‑party services leaking metadata
    Apple/Google push services can see when devices receive Signal notifications, and some embedded services (e.g. mapping APIs) may leak additional metadata or context.
    Source: Mozilla review
  • What this means in practice: Even if Signal’s servers don’t know who you’re talking to, Apple and Google (via their push notification services) know that you received a Signal message and when. This can be correlated with other data they collect. Additionally, if you use features that integrate third-party services (like location sharing), those services might also collect data.
  • Security ≠ privacy: “Signal = safe” threat‑model mismatch
    Signal’s strong encryption leads many users to assume it delivers total privacy and safety. In reality, design choices (phone‑number identity, centralization, dependence on telcos/cloud) mean content is protected, but metadata and relationship information can still be exposed, creating a dangerous gap for high‑risk users.
  • What this means in practice: Users, especially those in high-risk situations, might overestimate Signal’s protection against all forms of surveillance. They might behave as if they are completely anonymous or untraceable, when in fact their identity, contacts, and communication patterns could still be vulnerable to determined adversaries due due to the design choices mentioned in other points.

2. Governance, Institutions, and Culture

  • Closed culture and weak governance transparency
    In many privacy/security circles there is a noticeable reluctance to criticize Signal’s design choices. This “don’t criticise Signal” culture discourages open scrutiny and honest discussion of limitations. Combined with a highly centralized, non‑federated governance model, this lack of open, transparent debate makes it harder for users to see trade‑offs and hold the project accountable.
  • What this means in practice: It can be difficult for users and the wider community to get clear answers or influence decisions about Signal’s design and future direction. Important discussions about potential vulnerabilities or privacy trade-offs might be suppressed or not happen publicly, leading to less informed users and a less robust ecosystem of critique.
  • WEF affiliation / institutional alignment
    Meredith Whittaker, President of the Signal Foundation, actively participates in World Economic Forum events and is featured as an expert there. Even without a formal governance role, this public association raises questions for users who distrust WEF‑aligned agendas and want to understand which institutional ecosystems Signal’s leadership is embedded in.
    Sources: WEF, CNBC – WEF 2024
  • What this means in practice: For users concerned about globalist agendas or the influence of powerful institutions, the public alignment of Signal’s leadership with organizations like the WEF can raise questions about the project’s long-term independence and priorities. It might suggest a potential for future policy shifts that align with institutional interests rather than solely with the most extreme privacy and freedom principles.

3. Platform Dependence and Device Model

  • Mobile‑centric, phone‑anchored design
    Signal requires a smartphone and phone number as the primary identity; desktop clients are secondary “linked” devices. If the phone/SIM is lost, seized, or disabled, users can be locked out or lose links/history, which is especially dangerous for activists and people in hostile environments. This marginalizes desktop‑reliant users and weakens resilience on non‑mobile platforms.
    Sources: Signal support, GitHub issue, r/signal example
  • What this means in practice: Your ability to use Signal is fundamentally tied to your mobile phone. If your phone is lost, stolen, or its SIM card is compromised, you could lose access to your account and message history, even on desktop. This creates a single point of failure and makes it difficult for users who prefer or rely on desktop-only access, or who operate in environments where mobile devices are frequently confiscated.
  • Practical dependency on Google Play Services for Android
    On de‑Googled Android (GrapheneOS, custom ROMs), Signal strongly recommends Google Play Services and often shows warnings or degraded behaviour (especially around registration and notifications). This creates a two‑tier reality: smooth for fully Google‑integrated users, fragile and frustrating for those trying to avoid Google. For a “privacy‑first” tool, this soft dependency on a major surveillance platform is a serious alignment concern.
    Sources: GrapheneOS forum 1, GitHub #9279, GitHub #10368, GrapheneOS forum 2, GitHub #13624
  • What this means in practice: If you use an Android phone without Google Play Services (e.g., a de-Googled phone), you’ll likely experience a degraded Signal experience, including unreliable notifications and difficulties with initial setup. This forces users who prioritize avoiding Google’s ecosystem into a less functional or more frustrating experience, undermining Signal’s “privacy-first” claim for a significant segment of its user base.
  • Tight coupling to vendor OS lifecycles (forced upgrades)
    Signal tracks vendor OS lifecycles and drops older versions (e.g. macOS Catalina) rather than offering a legacy or “use‑at‑your‑own‑risk” mode. Officially this is framed as security, but it is also clearly driven by cost and convenience, effectively forcing OS upgrades or hardware churn. Other ecosystems (e.g. some Matrix clients via web) show this is not strictly unavoidable; for a “privacy‑first” tool, such close alignment with Big Tech’s forced‑upgrade model is a structural concern.
  • What this means in practice: You might suddenly lose access to Signal if your operating system becomes “too old” and you can’t or don’t want to upgrade it. This can force you to buy new hardware or upgrade your OS, even if your current setup is otherwise functional and secure for your needs. This policy prioritizes developer convenience and alignment with platform vendors over user autonomy and long-term access for those who cannot or choose not to constantly update.

4. App Integrity, Distribution, and Updates

  • App‑store chokepoints & binary trust
    Users must trust Apple/Google/Microsoft app stores (and their policies) for binaries. There is no practical way for normal users to verify that the distributed binaries match the open‑source code. This app‑store dependence introduces censorship and targeting risks: in theory, malicious or geo‑specific builds could be pushed under legal or political pressure.
  • What this means in practice: You are reliant on Apple and Google to deliver the “correct” and untampered version of Signal to your device. These app stores can be pressured by governments to remove apps, delay updates, or even push modified versions. For high-risk users, this means a potential vulnerability to targeted attacks or censorship via the app store distribution mechanism.
  • Backup / migration and expanding server responsibilities
    New backup/migration and sync features, while encrypted, increase what the server is responsible for and expand the overall attack surface. More complex state and more paths for data to move often mean more that can go wrong, especially under sophisticated adversaries.
    Source: Mozilla
  • What this means in practice: While features like encrypted backups and multi-device sync are convenient, they add complexity to Signal’s server-side operations. This increased complexity can introduce new, subtle vulnerabilities that could be exploited by sophisticated attackers, even if the data remains encrypted. It means more potential points of failure or attack beyond just message transmission.

5. Protocol and Trust Model

  • Trust model: Signal’s servers can technically man‑in‑the‑middle
    Signal’s design has the server mediate key exchanges. If the server or its build infrastructure were compromised, targeted man‑in‑the‑middle attacks are technically possible unless users rigorously verify Safety Numbers. This is one reason some projects (like SimpleX) argue Signal is not suitable for the highest‑risk, mission‑critical communications.
    Source: SimpleXChat author
  • What this means in practice: If Signal’s central servers were compromised, an attacker could potentially intercept and read your messages by impersonating your contacts during key exchange, unless you manually verify your Safety Numbers with every contact. This means that for true security against a state-level adversary, manual verification is critical, and relying solely on the app’s default trust model is insufficient.

ALTERNATIVES:

So What To Use Instead?

Nothing is perfect. There is no such thing as 100% guaranteed privacy. But the following projects, with all their own flaws, come significantly closer than Signal to our Digital Freedom criteria:

  • Matrix – Federated, open protocol; you can run your own server and are not locked into a single central provider.
  • Session – Signal‑style crypto without phone numbers, built on a decentralised service‑node network.
  • Briar – Android‑only, peer‑to‑peer over Bluetooth/Wi‑Fi/Tor, designed for high‑risk activists and offline/mesh situations.
  • SimpleX – No phone numbers, no global user IDs, no server‑stored social graph; designed to minimise metadata and central visibility.

We’ll explore each of these in future reports, including where they still fall short and how they can be safely combined in a broader digital‑freedom toolkit.