Sponsors: El Capo, Dark Forum
Get uncensored cypherpunk news: Session, SimpleX

home / messaging

Signal

slave tech 2
PFScommunity appse2eeunique usernamescentralizedpermissionedphone numberaccount-basedno self-custodycompliant teamhostile jurisdictionweak metadata protectionno token2014

Signal is a centralized platform with a legacy account-based permissioned architecture controlled by a compliant company based in a hostile jurisdiction that leaks metadata, requires a phone number, doesn't provide self-custody of digital identities, and is capable of censoring its users.

In other words, Signal is the most notorious hoax in the privacy community, functioning as a technical IQ test that all average doxxed gatekeepers consistently fail.

No censorship-resistance

Since Signal is a centralized permissioned system without self-custody of digital identities, any user can be deplatformed at any time. That's the core reason it is slave tech.

Leaks metadata

Signal lacks robust metadata protection. Its "sealed sender" is falsely marketed as complete metadata protection, yet it does nothing to hide network-level identifiers like IP addresses and ping or prevent timestamp-based metadata analysis. Additionally, Signal enforces delivery receipts that cannot be disabled (don't confuse with read receipts). This allows trivial sender clustering and identification through a simple analysis, which Tor cannot prevent. Besides, most modern messengers also encrypt the sender, so the "sealed sender" is the basic expectation similar to e2e encryption.

Centralized spyware

All traffic funnels through servers controlled by one company, enabling invasive metadata surveillance that extends far beyond message tracking, exposing your online patterns, sleep, work habits, and physical location through device connection. In other words, Signal is similar to regular corporate spyware, even when accessed via alternative FOSS clients like Molly. Using VPN and Tor doesn't help much either because it can only hide your exact location.

Phone number

Signal requires a phone number to create an account, which immediately compromises privacy of regular non-savvy users who use their KYCed SIMs. Furthermore, virtually no modern device permits IMEI changes and tampering with IMEI is illegal in many police states. Thus, using a non-KYC burner SIM on a primary phone will not mitigate this issue since a burner SIM will be associated with a primary KYCed SIM through IMEI.

Trust on first use (TOFU)

Unlike Session, Status, or PGP where users directly exchange public keys (the ID is the key), Signal relies on centralized servers to map phone numbers and usernames to encryption keys, creating a Man-in-the-Middle vulnerability where various adversaries and the server itself could swap keys and decrypt all messages without detection. This risk is only mitigated by manually verifying the pubkey fingerprint (Safety Number), but most users never do that.

Contacts

By default, Signal tries to access all contacts on your phone.

Nonprofit myth

"Nonprofit" is a buzzword that hides Signal's flawed architecture, which enables censorship, data collection, and discrimination based on a country code. Ultimately, a nonprofit is still a compliant entity that can be coerced to cooperate with adversaries, and it has to generate enough money to pay the bills.

Get started:

Forum:

Fundraising:

The privacy community is controlled by compliant doxxed gatekeepers pushing spyware like Signal and Proton. Our high priority is to get people off slave tech, so consider a donation or sponsorship to help us defend cypherpunk values. We want to create a detailed video explaining why Signal is slave tech and spyware, which will probably take a few weeks to make, but it's really hard to find funding for such videos.