From MTL Counter-Info
Anonymous submission to MTL Counter-info
The following are lesser-known problems with Signal that anarchists and other targets of state repression should know about. These issues are known to the Signal developers.
Potentially sensitive information is permanently saved in account databases.
Despite being hidden, the following information is permanently saved.
- All visible phone numbers: Most Signal users still have the phone numbers of all other chat members from before March 2024, when they could first change their phone number visibility to “no one.”
-
Group metadata: Leaving and deleting a Signal group mainly deletes the messages. The group members, the group name, the group description, the joined timestamp, the last message timestamp, the group ID, the group keys, member labels, the admins, removed members, the group link password, the draft message, the message count, the sent message count, the disappearing message time, and more are permanently saved.
Example:
-
"id": "REDACTED", "groupId": "REDACTED", "type": "group", "version": 2, "expireTimerVersion": 1, "unreadCount": 0, "verified": 0, "messageCount": 3, "sentMessageCount": 2, "name": "REDACTED", "revision": 8, "publicParams": "REDACTED", "secretParams": "REDACTED", "accessControl": { "members": 2, "attributes": 2, "addFromInviteLink": 4, "memberLabel": 2 }, "membersV2": [ { "role": 2, "joinedAtVersion": 0, "aci": "REDACTED", "labelString": "REDACTED" }, { "role": 1, "joinedAtVersion": 1, "aci": "REDACTED", "labelString": "REDACTED" } ], "pendingMembersV2": [], "active_at": null, "avatars": [ {REDACTED} ], "groupVersion": 2, "groupVerifiedNameHash": "REDACTED", "masterKey": "REDACTED", "profileSharing": true, "timestamp": null, "needsStorageServiceSync": false, "sealedSender": 0, "color": "A110", "senderKeyInfo": { "createdAtDate": REDACTED, "distributionId": "REDACTED", "memberDevices": [] }, "lastMessage": "", "lastMessageReceivedAt": REDACTED, "lastMessageReceivedAtMs": REDACTED, "lastMessageDeletedForEveryone": false, "expireTimer": 86400, "left": true, "pendingAdminApprovalV2": [], "bannedMembersV2": [ { "serviceId": "REDACTED", "timestamp": REDACTED } ], "markedUnread": false, "unreadMentionsCount": 0, "draft": "REDACTED", "draftBodyRanges": [], "draftChanged": true, "draftIsViewOnce": false, "storageVersion": 27, "storageID": "REDACTED", "description": "REDACTED", "announcementsOnly": false, "terminated": false, "draftTimestamp": null, "draftAttachments": [], "messagesDeleted": true -
Contact metadata: Deleting a chat keeps the contact’s name, their ACI (account identifier), their phone number, their about section, their nickname, the last message timestamp, the contact note, the draft message, the message count, the sent message count, the disappearing message time, profile keys, the profile key credential expiration timestamp, and more. Removing a contact only hides it.
Example:
-
"id": "REDACTED", "serviceId": "REDACTED", "type": "private", "version": 2, "expireTimerVersion": 1, "unreadCount": 0, "verified": 0, "messageCount": 4, "sentMessageCount": 2, "sealedSender": 1, "color": "A110", "profileKeyCredential": "REDACTED", "profileKeyCredentialExpiration": REDACTED, "accessKey": "REDACTED", "profileKey": "REDACTED", "profileName": "REDACTED", "note": "", "messageRequestResponseType": 2, "profileSharing": false, "storageUnknownFields": "", "hideStory": false, "isArchived": false, "markedUnread": false, "storageID": "REDACTED", "storageVersion": 33, "needsStorageServiceSync": true, "muteExpiresAt": 0, "colorFromPrimary": 2, "about": "REDACTED", "aboutEmoji": "", "sharingPhoneNumber": false, "capabilities": { "profiles_v2": false, "attachmentBackfill": true, "spqr": true, "usernameChangeSyncMessage": false }, "lastProfile": { "profileKey": "REDACTED", "profileKeyVersion": "REDACTED" }, "unreadMentionsCount": 0, "lastMessage": "", "lastMessageReceivedAt": REDACTED, "lastMessageReceivedAtMs": REDACTED, "timestamp": null, "lastMessageDeletedForEveryone": false, "expireTimer": 86400, "active_at": null, "draft": "REDACTED", "draftBodyRanges": [], "draftChanged": false, "draftIsViewOnce": false, "draftTimestamp": null, "draftAttachments": [], "messagesDeleted": true
The only reliable way to delete this information is to delete all Signal app data, then re-register without entering the PIN or restoring data. This also deletes all contacts and messages.
Re-registering with the PIN recovers all contact metadata. From left and deleted groups, it appears to only restore group IDs, keys, icon colors, and some other items, but this is still potentially sensitive information.
Successfully registering an existing Signal account’s phone number takes over or disables the account.
Signal uses SMS authentication. If a person’s Signal account has registration lock disabled, an attacker who can observe or intercept their SMS messages can receive a Signal verification code to immediately take over their account. If registration lock is enabled, they can immediately deregister the person’s device, making them unable to use their account. The attacker can then take over the account in 7 days if the person cannot re-register.
Once the attacker takes over, they receive all messages intended for their target, including group messages, and they can send messages from their account. Contacts see that their safety numbers have changed, but most people ignore these messages. After all, they may simply indicate that the person has reinstalled Signal. The account’s name changes unless the attacker knows the previous name or guesses the PIN, but name changes are very common.
Additionally, deleting a Signal account does not delete it on the Signal servers for 30 days. If someone registers the number during this time, they can immediately access the account. Deleting an account leaves all groups, but they can still send and receive messages as the original user.
These design choices weaken the security and reliability of Signal accounts. Anyone can put a person’s SIM card in another phone. Intelligence agencies intercept most or all SMS messages. Cell site simulators, SS7 attacks, and SIM swaps can also be used to intercept SMS messages.
ACIs are associated with phone numbers on the Signal servers, and they are difficult to change.
ACIs are unique 128-bit numbers that identify Signal accounts to other accounts and to the Signal servers. Accounts save the ACIs of all known accounts. ACIs are not shown in the Signal apps, and they are not mentioned on Signal’s website, but they can be collected and tracked over time and between groups. People can also send messages to ACIs without any other information.
Signal’s servers save ACIs with account phone numbers, so they can give account phone numbers to governments. According to an article by Micah Lee, “If Signal receives a government request for information about an account based on an active username, Signal will be able to hand over that account’s phone number along with its creation date and last connection date.” Looking up an active username simply provides the account’s ACI, so it should be assumed that this is possible. It may have already occurred.
To obtain a new ACI, users need to delete their Signal account for 30 days or use a new phone number.
Other issues
Signal is centralized and runs on Amazon, Microsoft, and Google servers. These companies share massive quantities of data with intelligence agencies. They likely send Signal metadata to the US government, even though Signal probably does not. In addition, because Signal is centralized, it is easier to censor. Many governments already block Signal, and the US government could fully shut it down.
Notifications on iOS, Android, MacOS, and Windows give Apple, Google, and Microsoft the timing of messages. This does not happen on Linux and GrapheneOS.
The timing of message receipts from silent messages can be used to gain information about people’s habits and devices. This is difficult to fully prevent, but the Signal developers do not have a plan to mitigate it. However, using Signal through Tor or a VPN likely reduces the accuracy of this attack.
Alternatives
These do not have all of the same features as Signal, and they are not as well-tested. Like Signal, they are not appropriate for all threat models.
Cwtch is a peer-to-peer encrypted messaging app which uses Tor to avoid surveillance and censorship. It does not require phone numbers, it is more metadata resistant than Signal, it has database encryption, it can use multiple accounts, and it functions with or without servers. It has not been independently security audited. The development team is small and could use support.
Briar is similar to Cwtch, but it also has basic blog, forum, and RSS reader features. It has received security audits, but it does not currently work on Tails or similar systems. In order to chat, two accounts require an exchange of links or QR codes.
Delta Chat is decentralized and does not require phone numbers. It is less metadata resistant than Signal, but it is easy to make new accounts. It does not have forward secrecy, so it is possible to decrypt multiple past messages with a leaked key. The developers plan to add forward secrecy and post-quantum cryptography in late 2026. It can be used with Tor, but UDP features such as calls and multi-client syncing cannot currently use Tor. Signal and most other apps face the same issue.
Other similar alternatives are not currently recommended, except for PGP email if it is necessary. Many other options are currently too experimental, not metadata resistant enough, or not trustworthy enough.
Signal suggestions
For those who continue to use Signal, these suggestions should be evaluated for each threat model. If anonymity and reliability are required, Signal is not the best option.
- Do not use Signal to organize or protest.
- Purchase a virtual phone number or a secondary phone plan to use only once for Signal registration. Continue paying for it or change numbers to avoid losing your account. This is not easy to do anonymously, but it is possible.
- Use GrapheneOS on a supported device. GrapheneOS is more resistant to data extraction tools like Cellebrite than other phone operating systems.
- Encrypt devices with long random passwords, and turn them off when they are not in use.
- Use Molly with database encryption.
- Use Tails, Orbot on GrapheneOS, or a trustworthy VPN. Note that VPNs are not anonymous, and using Signal calls with Tor may leak IP addresses.
- Verify safety numbers and identities, and treat safety number changes as possible account compromises.
- Avoid Signal groups with unknown people.
- Change your Signal settings to better options.
- Do not link additional devices.
- Make backup chats in Cwtch, Briar, or Delta Chat.
Further reading
The P.E.T. Guide: New Communication Infrastructure for Anarchists
Comments
Just a detail... how's…
anonymous (not verified) Thu, 07/02/2026 - 19:06
Just a detail... how's relevant to be using GrapheneOS for better security when it's only taking Google Pixel devices, that all have SOC backdoors? I prefer using phones with Chinese or Taiwanese chips with custom ROMs to that they might not be calling home to somewhere in the US.
Could you link to reliable…
anonymous (not verified) Fri, 07/03/2026 - 09:05
In reply to Just a detail... how's… by anonymous (not verified)
Could you link to reliable stores for hardware? It's really hard to find good brokers with reliable prices
Please provide your source…
anonymous (not verified) Wed, 07/08/2026 - 00:24
In reply to Just a detail... how's… by anonymous (not verified)
Please provide your source grapheneos being more susceptible to alleged SOC backdoors than any other available smartphone hardware / software combination. You think chinese and taiwanese hardware is magically somehow not susceptible to exploitation? Where do you think google pixel soc is manufactured? Big Hint...TSMC. please also identify this custom rom you speak of that is more secure than grapheneos..doubtful.
"You think chinese and…
anonymous (not verified) Wed, 07/08/2026 - 11:42
In reply to Please provide your source… by anonymous (not verified)
"You think chinese and taiwanese hardware is magically somehow not susceptible to exploitation? "
Of course not? Chinese devices are often not designed accordingly to NSA standards. So it's more likely these SOCs will be "calling home" to Beijing than the Pentagon. But that's just my assumption.
As for GrapheneOS, the issue's not the OS but the devices they're compatible with (Google Pixels). And Google Pixels SOCs are made in the Taiwanese and South Korean foundries following Qualcomm designs. Foundries only manufacture SOCs accordingly to a chip company's -and ARM's- plans. Basically if anarcho-techies would get to make billions out of (???), they'd be able to order their own chips from these foundries. Or they can try self-manage Qualcomm or something, lol.
There are pretty "safe" custom roms, like LineageOS and crDroid. Perhaps as good as GrapheneOS, tho they'll work on a much broader variety of devices.
Andreu Nin was tortured by…
SPEC OPS: THE LINE (not verified) Wed, 07/08/2026 - 23:59
In reply to "You think chinese and… by anonymous (not verified)
Andreu Nin was tortured by Moscow, wonder what lengths Beijing would go to if necessary. The chip is tantamount to death like all commodities. Put your phone in the bin. On top of your computer.
But you can’t, can you? A slave to the bloops…
This comment appears to have…
anonymous (not verified) Thu, 07/09/2026 - 10:54
In reply to Andreu Nin was tortured by… by SPEC OPS: THE LINE (not verified)
This comment appears to have been written and posted on a computer or smart phone.
And yet wasn’t. Poor things,…
SPEC OPS: THE LINE (not verified) Fri, 07/10/2026 - 02:15
In reply to This comment appears to have… by anonymous (not verified)
And yet wasn’t. Poor things, you think you have imaginations.
Please oh Ascended Master…
anonymous (not verified) Fri, 07/10/2026 - 11:36
In reply to And yet wasn’t. Poor things,… by SPEC OPS: THE LINE (not verified)
Please oh Ascended Master of the Fourth Vibrant Density... teach us from the Temple of Anarchist Consciousness how to transpose words and thoughts to code to be computed by these gross 2nd density machines. We yoga yuppies will send u a montly dole amount tp Patreon. NAMASTE!
Pressing X mentally to close…
SPEC OPS: THE LINE (not verified) Fri, 07/10/2026 - 23:55
In reply to Please oh Ascended Master… by anonymous (not verified)
Pressing X mentally to close this window. No.
Decentralisation
anonymous (not verified) Thu, 07/02/2026 - 23:01
Doesn't decentralisation come with the problem that now the information is stored in multiple places and there's no guarantee things are deleted from all those servers when you delete something?
Seems like a big problem with mastodon etc
Is that any less an issue…
anonymous (not verified) Fri, 07/03/2026 - 08:10
In reply to Decentralisation by anonymous (not verified)
Is that any less an issue with centralized servers? How can you really trust Signal's servers over a gazillion decentralized servers? Even Telegram's centralized servers, hosted in Dubai, can be a security concern.
I suppose you were just not properly educated in federated networks and how they work with encrypted packets. It's "everyone can hold the keys" Vs "some monopoly we're supposed to trust, who holds the keys".
I’m hardly Clausewitz but…
SPEC OPS: THE LINE (not verified) Fri, 07/03/2026 - 02:36
I’m hardly Clausewitz but Millennium Challenge 2002 was won by the asymmetric force by using lo or ancient technology: runners, light signalling, zero comms. Phone addiction is not simpatico with risky activity and it’s bad for the brain anyway.
A better approach, yes. Or…
anonymous (not verified) Fri, 07/03/2026 - 08:18
In reply to I’m hardly Clausewitz but… by SPEC OPS: THE LINE (not verified)
A better approach, yes. Or else you may search through the clusterfuck of privacy-enchanced options on smart phones that were built for surveillance tracking in the first place. The sheer complexity of nano-scale chips and the multilayered software/firmware infrastructures makes these things absurdly inaccessible to reclaim. And yes, to reply to the bad joke... there *are* plenty of low-tech alternatives between an iPhone and smoke signals.
The problem's the appeal of…
anonymous (not verified) Fri, 07/03/2026 - 10:52
In reply to I’m hardly Clausewitz but… by SPEC OPS: THE LINE (not verified)
The problem's the appeal of normativity or how to get "friends" and fuck friends while refusing the non-solutions enforced by big tech, with the help of little benevolent cunts ("friends").
Also there's issues like the few wannabe anticap revolutionaries I came across lately had brain issues, one for not being too smart and the other for being way messed up in his head. How do you get to build a functional insurgency out of such people... *before* you have it crushed with the unintended help of your accomplices? Let's face it; we need a secret society of wise people able to carry this thing for at least a few decades, and to a worthy, victorious ending... and not some "in girum" reactionary hell.
Or my chosen shortcut: individual nihilist anarchy, for myself and a few like-minded people, coz like is short and keeps getting shorter as you age. Another thing that the US DoD won't overcome, as it's not even within their field of interest.
Preaching to the choir, amen…
SPEC OPS: THE LINE (not verified) Fri, 07/03/2026 - 15:39
In reply to The problem's the appeal of… by anonymous (not verified)
Preaching to the choir, amen Padre. Contrary to most anarchos’ sheepishness, a secret society always gets the ball rolling. The protocommunists understood this, Bakunin, Friend of Durruti and a few other groovy people. It’s the moderns that are shit. Did you know the avant-garde/vanguard originally referred to the first troops into battle? I don’t think you can will it into existence but on the other hand, I recall Nikey’s enigmatic advertisement slogan…
PS. US & NATO military doctrine has long been Auftragstaktik, decentralised command. We’d have to do the funniest counter.
Why are people still…
anonymous (not verified) Mon, 07/06/2026 - 12:53
Why are people still referring to the white"dreads" serial CEO who started Signal as an anarchist? He's one of many EX-anarchists.
"as an anarchist"
anonymous (not verified) Tue, 07/07/2026 - 10:56
In reply to Why are people still… by anonymous (not verified)
"anarcho-hipster with shady morals".
FTFY
Gimmie a ride in his…
anonymous (not verified) Thu, 07/09/2026 - 21:39
In reply to Why are people still… by anonymous (not verified)
Gimmie a ride in his helicopter
why are you techtards doing…
anonymous (not verified) Tue, 07/07/2026 - 08:33
why are you techtards doing anything remotely sketchy over a phone???
oh, that's right, addiction, conformity, and lack of creativity
Add new comment