Why is the Signal app not safe?
A few weeks ago we released our new security feature in Signal, Signal App Locking.
It turns on when you open the app and turns off when you close it or go to another app.
It's part of our ongoing effort to make Signal better and safer for your communications. Since releasing it, a lot of people have asked: Why is Signal App Locking not safe? Signal App Locking is not safe is essentially the same as Signal is insecure. The premise is that we're doing things with app locking that aren't safe. We're saying that we're safe because we've built a security system around the notion that apps are inherently untrustworthy.
The key is the first reason why Signal App Locking isn't safe: We're not saying that apps are untrustworthy. When you first install an app to your device, whether it's Signal, WhatsApp, Twitter or anything else, it has access to your private data like your contact list. So while Signal might ask for permission to get access to contacts, it only has permission to access those contacts because it trusts you that you didn't share them with other apps.
This doesn't mean that Signal thinks you're trustworthy. Your contacts don't trust Signal with their information. Because we ask them to do that.
We're asking you to trust us with our information. Because we think you're a trustworthy person. And when we ask you to trust us, we also have to give up some of our control over the user experience.
And there's nothing about app locking that makes it any more or less trustworthy than what happens before you go to lock Signal. This first reason why Signal is not safe doesn't just apply to new installs. It applies to all the data you've been sharing with apps.
We can't know who you were talking to when we got access to your contacts, and we can't know what you're planning to share with other apps.
What is the new app called Signal?
It's called Signal.
What is it for? The goal of Signal is to provide a simple way to send and receive secure text messages, photos and videos without worrying about censorship, monitoring or eavesdropping. Is it a WhatsApp clone? No. Signal was born when WhatsApp added end-to-end encryption to its chat service.
How does Signal work? Signal encrypts text messages using the Signal Protocol (SMP), which we also use in our WebRTC apps at Signal Messenger, Signal Desktop and Signal Android. SMP ensures that only the sender and the recipient can read and write the message contents.
Does it mean that if I'm sending a message, it's end-to-end encrypted? If you choose to send an unencrypted message using Signal, that message will still be sent over the internet, and can be captured and read by anyone. However, any messages that are encrypted using Signal will not be read by anyone else unless you share them.
What about private key security? Yes, we use private keys for encryption. The private key can never leave your device. We make sure that the device is completely offline before sending the keys to the server so that if your device is ever compromised, you can simply wipe it and generate new keys.
How do you know I'm not using Signal to listen in on my conversations? We don't know for sure, but we can't think of any reason why you would use Signal to eavesdrop on your friends' conversations. Are you guys using any particular kind of back end? Yes, we're using the Amazon web service (AWS) to host our infrastructure. When can I get my hands on Signal? We're working on a web version right now. But for now, you can download the app from Google Play here.
Thanks for your time. Thanks for reading and we hope you'll find Signal to be the best way to stay connected.
Related Answers
What data does signal collect?
Most smartphones are equipped with signal data which you get from network service prov...
How do I download an older version of Signal?
How do I install Signal on Android without Google Play S...
Why is Signal asking for donations?
In a recent post of mine I explained that one reason Signal Foundati...