{"id":25742,"date":"2025-03-26T14:44:54","date_gmt":"2025-03-26T14:44:54","guid":{"rendered":"https:\/\/news.godj.com\/news\/what-is-messaging-app-signal-and-how-secure-is-it\/"},"modified":"2025-03-26T14:44:54","modified_gmt":"2025-03-26T14:44:54","slug":"what-is-messaging-app-signal-and-how-secure-is-it","status":"publish","type":"post","link":"https:\/\/news.godj.com\/news\/what-is-messaging-app-signal-and-how-secure-is-it\/","title":{"rendered":"What is messaging app Signal and how secure is it?"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div xmlns:default=\"http:\/\/www.w3.org\/2000\/svg\" id=\"\">\n<div xmlns:default=\"http:\/\/www.w3.org\/2000\/svg\" data-component=\"byline-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<div data-testid=\"byline-new\" class=\"sc-b42e7a8f-0 haItSe\">\n<div data-testid=\"byline-new-contributors\" class=\"sc-b42e7a8f-12 fcCDwR\">\n<div class=\"sc-b42e7a8f-5 evAEAB\">\n<div><span class=\"sc-b42e7a8f-7 kItaYD\">Tom Gerken<\/span><\/p>\n<p><span>Technology reporter<!-- --><\/span><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<figure>\n<div data-component=\"image-block\" class=\"sc-18fde0d6-0 EXUng\">\n<div data-testid=\"hero-image\" class=\"sc-a34861b-1 jxzoZC\"><img decoding=\"async\" sizes=\"(min-width: 1280px) 50vw, (min-width: 1008px) 66vw, 96vw\" srcset=\"https:\/\/ichef.bbci.co.uk\/news\/240\/cpsprodpb\/1231\/live\/9fbe3bf0-097a-11f0-8c19-810852503a69.jpg.webp 240w,https:\/\/ichef.bbci.co.uk\/news\/320\/cpsprodpb\/1231\/live\/9fbe3bf0-097a-11f0-8c19-810852503a69.jpg.webp 320w,https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/1231\/live\/9fbe3bf0-097a-11f0-8c19-810852503a69.jpg.webp 480w,https:\/\/ichef.bbci.co.uk\/news\/640\/cpsprodpb\/1231\/live\/9fbe3bf0-097a-11f0-8c19-810852503a69.jpg.webp 640w,https:\/\/ichef.bbci.co.uk\/news\/800\/cpsprodpb\/1231\/live\/9fbe3bf0-097a-11f0-8c19-810852503a69.jpg.webp 800w,https:\/\/ichef.bbci.co.uk\/news\/1024\/cpsprodpb\/1231\/live\/9fbe3bf0-097a-11f0-8c19-810852503a69.jpg.webp 1024w,https:\/\/ichef.bbci.co.uk\/news\/1536\/cpsprodpb\/1231\/live\/9fbe3bf0-097a-11f0-8c19-810852503a69.jpg.webp 1536w\" src=\"https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/1231\/live\/9fbe3bf0-097a-11f0-8c19-810852503a69.jpg.webp\" loading=\"eager\" alt=\"Getty Images The download screen for the Signal app on iPhone. Its logo is a white speech bubble on a light blue background. In the app's description it reads: &quot;say hello to privacy&quot;.\" class=\"sc-a34861b-0 efFcac\"\/><span class=\"sc-a34861b-2 hesJxn\">Getty Images<\/span><\/div>\n<\/div>\n<\/figure>\n<div data-component=\"text-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">The messaging app Signal has made headlines after the White House confirmed it was used for a secret group chat between senior US officials.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">The editor-in-chief of the Atlantic, Jeffrey Goldberg, was inadvertently added to the group where plans for a strike against the Houthi group in Yemen were discussed.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Signal&#8217;s creator Matthew Rosenfeld &#8211; who is better known by the pseudonym Moxie Marlinspike &#8211;<!-- --><a target=\"_blank\" href=\"https:\/\/x.com\/moxie\/status\/1904271189427802543\" class=\"sc-c9299ecf-0 beIoQm\"> joked<!-- --><\/a> the &#8220;great reasons&#8221; to join the platform now included &#8220;the opportunity for the vice president of the United States of America to randomly add you to a group chat for coordination of sensitive military operations&#8221;.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">But others are not seeing the funny side, with Democrat Senate leader Chuck Schumer calling it &#8220;one of the most stunning&#8221; military intelligence leaks in history and calling for an investigation.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">But what actually is Signal &#8211; and how secure or otherwise were the senior politicians&#8217; communications on it?<!-- --><\/p>\n<\/div>\n<p><h2 class=\"sc-518485e5-0 DkKTF\">The security app<!-- --><\/h2>\n<\/p>\n<div data-component=\"text-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Signal has estimated 40-70 million monthly users &#8211; making it pretty tiny compared to the biggest messaging services, WhatsApp and Messenger, which count their customers in the billions.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Where it does lead the way though is in security.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">At the core of that is end-to-end encryption (E2EE).<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Simply put, it means only the sender and the receiver can read messages &#8211; even Signal itself cannot access them.<!-- --><\/p>\n<\/div>\n<p><figcaption class=\"sc-8353772e-0 iUqqeb\">Cyber correspondent Joe Tidy explains how end to end encryption works<!-- --><\/figcaption><\/p>\n<div data-component=\"text-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">A number of other platforms also have E2EE &#8211;  including WhatsApp &#8211; but Signal&#8217;s security features go beyond this.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">For example, the code that makes the app work is open source &#8211; meaning anybody can check it to make sure there are no vulnerabilities that hackers could exploit.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Its owners say it collects far less information from its users, and in particular does not store records of usernames, profile pictures, or the groups people are part of.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">There is also no need to dilute these features to make more money: Signal is owned by the Signal Foundation, a US-based non-profit, which relies on donations rather than ad revenue.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">&#8220;Signal is the gold standard in private comms,&#8221; said its boss Meredith Whittaker <!-- --><a target=\"_blank\" href=\"https:\/\/x.com\/mer__edith\/status\/1904492855206596882\" class=\"sc-c9299ecf-0 beIoQm\">in a post on X<!-- --><\/a> after the US national security story became public.<!-- --><\/p>\n<\/div>\n<p><h2 class=\"sc-518485e5-0 DkKTF\">&#8216;Very, very unusual&#8217;<!-- --><\/h2>\n<\/p>\n<div data-component=\"text-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">That &#8220;gold standard claim&#8221; is what makes Signal appealing to cybersecurity experts and journalists, who often use the app. <!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">But even that level of security is considered insufficient for very high level conversations about extremely sensitive national security matters.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">That is because there is a largely unavoidable risk to communicating via a mobile phone: it is only as secure as the person that uses it.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">If someone gains access to your phone with Signal open &#8211; or if they learn your password &#8211; they&#8217;ll be able to see your messages.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">And no app can prevent someone peeking over your shoulder if you are using your phone in a public space.<!-- --><\/p>\n<\/div>\n<div data-component=\"text-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Data expert Caro Robson, who has worked with the US administration, said it was &#8220;very, very unusual&#8221; for high ranking security officials to communicate on a messaging platform like Signal.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">&#8220;Usually you would use a very secure government system that is operated and owned by the government using very high levels of encryption,&#8221; she said.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">She said this would typically mean devices kept in &#8220;very secure government controlled locations&#8221;.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">The US government has historically used a sensitive compartmented information facility (Scif &#8211; pronounced &#8220;skiff&#8221;) to discuss matters of national security.<!-- --><\/p>\n<\/div>\n<figure>\n<div data-component=\"image-block\" class=\"sc-18fde0d6-0 jFCfG\">\n<div data-testid=\"image\" class=\"sc-a34861b-1 jxzoZC\"><img decoding=\"async\" src=\"https:\/\/www.bbc.com\/bbcx\/grey-placeholder.png\" class=\"sc-a34861b-0 cOpVbP hide-when-no-script\"\/><img decoding=\"async\" sizes=\"(min-width: 1280px) 50vw, (min-width: 1008px) 66vw, 96vw\" srcset=\"https:\/\/ichef.bbci.co.uk\/news\/240\/cpsprodpb\/edb9\/live\/e3600920-0979-11f0-9832-9b801737499b.jpg.webp 240w,https:\/\/ichef.bbci.co.uk\/news\/320\/cpsprodpb\/edb9\/live\/e3600920-0979-11f0-9832-9b801737499b.jpg.webp 320w,https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/edb9\/live\/e3600920-0979-11f0-9832-9b801737499b.jpg.webp 480w,https:\/\/ichef.bbci.co.uk\/news\/640\/cpsprodpb\/edb9\/live\/e3600920-0979-11f0-9832-9b801737499b.jpg.webp 640w,https:\/\/ichef.bbci.co.uk\/news\/800\/cpsprodpb\/edb9\/live\/e3600920-0979-11f0-9832-9b801737499b.jpg.webp 800w,https:\/\/ichef.bbci.co.uk\/news\/1024\/cpsprodpb\/edb9\/live\/e3600920-0979-11f0-9832-9b801737499b.jpg.webp 1024w,https:\/\/ichef.bbci.co.uk\/news\/1536\/cpsprodpb\/edb9\/live\/e3600920-0979-11f0-9832-9b801737499b.jpg.webp 1536w\" src=\"https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/edb9\/live\/e3600920-0979-11f0-9832-9b801737499b.jpg.webp\" loading=\"lazy\" alt=\"White House A group of men and women sit looking at a screen off-camera. They are in a small room. Some wear smart shirts and ties. One wears a military uniform with many medals. Barack Obama watches intently. Hilary Clinton has her hand over her mouth in shock. Many computers are on the desks.\" class=\"sc-a34861b-0 efFcac\"\/><span class=\"sc-a34861b-2 hesJxn\">White House<\/span><\/div>\n<\/div>\n<p><figcaption class=\"sc-8353772e-0 iUqqeb\">This famous photo taken inside perhaps the most famous Scif &#8211; the White House Situation Room &#8211; in 2011 shows then-President Barack Obama and his team reacting to an update during the US raid to kill Osama Bin Laden<!-- --><\/figcaption><\/p>\n<\/figure>\n<div data-component=\"text-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">A Scif is an ultra-secure enclosed area in which personal electronic devices are not allowed.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">&#8220;To even access this kind of classified information, you have to be in a particular room or building repeatedly swept for bugs or any listening devices,&#8221; said Ms Robson.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Scifs can be found in places ranging from military bases to the homes of officials.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">&#8220;The whole system is massively encrypted and secured using the government&#8217;s own highest standards of cryptography,&#8221; she said.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">&#8220;Especially when defence is involved.&#8221;<!-- --><\/p>\n<\/div>\n<p><h2 class=\"sc-518485e5-0 DkKTF\">Encryption and records<!-- --><\/h2>\n<\/p>\n<div data-component=\"text-block\" class=\"sc-18fde0d6-0 dlWCEZ\">\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">There&#8217;s another issue tied to Signal that has raised concerns &#8211; disappearing messages.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Signal, like many other messaging apps, allows its users to set messages to disappear after a set period of time. <!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">The Atlantic&#8217;s Jeffrey Goldberg said some of the messages in the Signal group he was added to disappeared after a week.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">This may violate laws around record-keeping &#8211; unless those using the app forwarded on their messages to an official government account.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">This is also far from the first row involving E2EE<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Various administrations have wanted to create a so-called backdoor into messaging services that use it so they can read messages they think might pose a national security threat.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Apps including Signal and WhatsApp have previously fought attempts to create such a backdoor, saying it would eventually be used by bad actors.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Signal <!-- --><a target=\"_self\" href=\"https:\/\/www.bbc.co.uk\/news\/technology-64584001\" class=\"sc-c9299ecf-0 beIoQm\">threatened to pull the app from the UK in 2023<!-- --><\/a> if it was undermined by lawmakers.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">This year, the UK government became embroiled in a significant row with Apple, which also uses E2EE to protect certain files in cloud storage.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Apple ended up pulling the feature in the UK altogether after the government demanded access to data protected in this way by the tech giant.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">The legal case is ongoing.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">But, as this controversy shows, no level of security or legal protection matters if you simply share your confidential data with the wrong person.<!-- --><\/p>\n<p class=\"sc-eb7bd5f6-0 fezwLZ\">Or as <!-- --><a target=\"_blank\" href=\"https:\/\/x.com\/matthew_d_green\/status\/1904469904406786092\" class=\"sc-c9299ecf-0 beIoQm\">one critic more bluntly put it:<!-- --><\/a> &#8220;Encryption can&#8217;t protect you from stupid.&#8221;<!-- --><\/p>\n<\/div>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.bbc.com\/news\/articles\/c1kjd091019o\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Tom Gerken Technology reporter Getty Images The messaging app Signal has made headlines after the White House confirmed it was used for a secret group chat between senior US officials. The editor-in-chief of the Atlantic, Jeffrey Goldberg, was inadvertently added to the group where plans for a strike against the Houthi group in Yemen were [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":25743,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[62],"tags":[1596,9260,5869,7437],"class_list":["post-25742","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech","tag-app","tag-messaging","tag-secure","tag-signal"],"_links":{"self":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts\/25742","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/comments?post=25742"}],"version-history":[{"count":1,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts\/25742\/revisions"}],"predecessor-version":[{"id":25744,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/posts\/25742\/revisions\/25744"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/media\/25743"}],"wp:attachment":[{"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/media?parent=25742"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/categories?post=25742"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news.godj.com\/news\/wp-json\/wp\/v2\/tags?post=25742"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}