I have worked with Trail of Bits before and their cryptography teams are of the toppest of notches, I still have deep skepticism of Signal though. There are safer ways to use it, never getting push notifications is one part of it. I think their work is admirable, but the need for them to bootstrap you with SMS is a gotcha... they have usernames now, but even with those you have to have to bootstrap it with a number/identity.
Signal's mission is to provide maximized privacy in a form the non-technical public can use.
A messaging service filled with bots and spammers is not usable, and possibly not affordable to Signal (what proportion of resources would be spent on spam/bots). What is a more private, usable solution for filtering them out than using a phone number?
Lots of security geeks want Signal to adopt practices unusable to the public. They've made clear that unsusable security is not in their mission.
I'm also worried about that these days. They posted an article a while back that Signal costs $50m per year to run, and that they make that money from "things". Together with how low a profile they keep, I'm not convinced they aren't a honeypot.
I love Signal and it's still my preferred messenger, but if it came out that they're backed by some government agency, I wouldn't be extremely surprised.
I and not necessarily many, but at least some people I know donate (and, somewhat irregularly, will continue to do so) small-ish amounts to the foundation. [1]
You’d imagine that ought to be sufficient to cover running costs. However, it might actually not be enough with hardware prices these days? Not sure.
They’ve also recently (edit: “recently-ish”, it’s actually been a year!) introduced paid storage for backups, which I’d imagine comes with some amount of profit margin, too. [2]
A messaging service filled with bots and spammers is not usable, and possibly not affordable to Signal (what proportion of resources would be spent on spam/bots). What is a more private, usable solution for filtering them out than using a phone number?
Lots of security geeks want Signal to adopt practices unusable to the public. They've made clear that unsusable security is not in their mission.
I love Signal and it's still my preferred messenger, but if it came out that they're backed by some government agency, I wouldn't be extremely surprised.
You’d imagine that ought to be sufficient to cover running costs. However, it might actually not be enough with hardware prices these days? Not sure.
They’ve also recently (edit: “recently-ish”, it’s actually been a year!) introduced paid storage for backups, which I’d imagine comes with some amount of profit margin, too. [2]
[1] https://signal.org/donate/
[2] https://signal.org/blog/introducing-secure-backups/
You don't need to be convinced of such things. In fact, it's better if technical people remain skeptical and check.
I did in 2025. https://soatok.blog/2025/02/18/reviewing-the-cryptography-us...