Signal Vs Threema Vs Briar Which is the most secure app?

best messaging app signal threema briar

Faced with the growing weariness and concern of many people about the constant surveillance exercised by large corporations and suspicious governments, which often resort to various excuses to demand the installation ofbackdoors in everyday applications, in order to further facilitate espionage, more and more people are deciding to prioritize their privacy and digital security by seeking safer applications away from the control of these actors.

In this context, many people have opted to migrate to instant messaging applications that offer high standards of cybersecurity and privacy, such as Threema, Signal or Briar.

But what if some of these applications that “sell” us as the safest are not so safe and some of them hide hidden interests of some State?

In order to help you choose the right messaging application that best suits individual needs, depending on the level of personal risk, this article continues along the lines already addressed in previous articles, such as showing the dangers of WhatsApp or the abuses of messaging apps in general.

Focusing more and more, in this article, we will analyze the fundamental characteristics, advantages, lies and limitations of the three messaging apps that are considered the most secure to date, providing information that I consider essential in order to facilitate an informed decision before making a choice.

Signal

 

Before we start talking about Signal, I bet that 99.99% of the readers of this article already think in advance that this application is one of the most secure instant messaging apps, if not the most secure, out there.

And I am not going to blame you, because it seems that for many years there has been a very well planned strategy to make us all believe that. Even I believed it.

Recently we can read in several articles how, ironically, despite having been criticized in the past by governments and intelligence agencies, which branded it as the favorite tool of cybercriminals, terrorists and hacktivists; in 2023, the CIA director, William Burns, publicly confirmed that they use Signal for internal communications.

If we analyze this interesting comment without thinking too much, it seems more like the CIA wanted to imply:“please do not use Signal, cybercriminals, terrorists and hacktivists, because we will not be able to investigate you through it". 

Rather, I would say it looks like an invitation to do so if you want to escape their surveillance. A very clever and carefully planned comment, don’t you think?

In a more recent development, which by all accounts is hard to swallow, in March 2025, another case came to light, dubbed the #SignalGatewhere Donald Trump’s advisors leaked, in a supposedly unusual error, data on an imminent military attack on Yemen, after “carelessly” including a journalist from The Atlantic in the Signal group chat they were using, who ended up publishing all the conversations.

With comments and facts like these, it seems clear that the U.S. government indirectly wants to imply that it has great confidence in this app.

On another occasion at a Senate Intelligence Committee hearing, it was CIA Director John Ratcliffe who revealed that Signal was pre-installed on the agency’s computers and used by its officials, including himself.

Little by little and in drips and drabs, comments with subliminal advertising have been dropped about the app to reinforce to us the idea of how secure the app is, that even the CIA uses it by default.

On this occasion it seems to be inviting other governments to do the same if they want to keep their communications secret.

The widespread perception that Signal is a secure messaging application is based on its end-to-end encryption (E2EE), its open source code and its policy of not collecting metadata.

However, recent research and events have cast doubt on this reputation, especially in highly sensitive contexts such as armed conflicts or government activities.

Let’s see why Signal is not a secure application at all:

Signal was initially funded by the Open Technology Fund (OTF), a U.S. government-funded organization associated with Radio Free Asia, an entity with roots in the CIA.

The OTF has been accused in the past of promoting U.S. geopolitical interests under the guise of promoting digital freedom.

In addition, members of Signal’s board of directors have backgrounds in large U.S. technology corporations and government agencies, raising serious questions about possible outside influences on the platform.

2. Dependence on the infrastructure of large corporations

Signal’s servers are hosted in the United States, relying on cloud services provided by companies such as Amazon Web Services, Google and Microsoft.

This reliance could expose the application to vulnerabilities related to surveillance or censorship, especially if these corporations receive government pressure.

According to another article in Counterpunch “The Revolution Will Not Be Signaled”, Signal presents critical risks in scenarios of government repression or armed conflict because of the following:

  • **Reliance on phone numbers: **To register, Signal requires a phone number, a highly sensitive piece of data. In countries with state surveillance, this allows supposedly anonymous accounts to be linked to real identities. For example, in Belarus (2020), activists were arrested after being identified through their phone numbers associated with Signal.
  • **Access to metadata by governments:**Although Signal claims not to store messages, telephone service providers (such as Vodafone or AT&T) can collaborate with authorities to reveal the time and frequency of use of the app, which makes it possible to track communication networks.

3. Lack of cooperation in critical contexts

In an article in The Record "Signal No Longer Cooperating with Ukraine” it was revealed how Signal refused to hand over to the Ukrainian government content that would help in investigations related to Russian cyber threats.

It was alleged that Signal’s lack of response to official requests allowed Russian actors to exploit the platform for espionage activities, including phishing attacks and account takeovers.

Although Signal denied having changed its cooperation policy, the situation raised concerns about its reliability in national security contexts.

What is inexplicable is that, in the past, the company has already agreed to block accounts linked to “illegal activities” under pressure from other governments.

This shows that when it is in their interest they can identify and block anyone, as happenedin 2022 when they suspended, without any transparency, the accounts of separatist groups in Africa.

4. Centralization and single points of failure

According to another interesting publication in Primal ( Janneke -janneke@iris.to) criticized Signal’s architecture commenting the following:

  • **U.S.-controlled infrastructure: **Signal is registered in the United States, which subjects it to U.S. laws such as the FISA (Foreign Intelligence Surveillance Act), which allows secret data access warrants, or the *CLOUD Act (Clarifying Lawful Overseas Use of Data Act), *which allows U.S. authorities to access data stored by U.S. providers even when itis located on servers outside their territory even when they are located on servers outside its territory.. In 2021, the NSA tried to force Signal to include a “backdoor”, although the company publicly denounced it, …surely as part of the theatrics that would help us all think how secure and responsible it is.
  • **Forced updates: **Signal updates are automatic and unverifiable by users, which, according to the author, could introduce unaudited vulnerabilities in the service of the entities that control this application (e.g., in 2023, an update included undocumented code related to geolocation).

5. Examples and evidence of specific risks

  • **Hong Kong case (2020): **Pro-democracy activists used Signal, but authorities identified leaders by cross-referencing telephone operator data with IP records.
  • **Collaboration with the EU (2022): **Signal blocked accounts of arms dealers in Balkans after pressure from Europol, but without appeal mechanisms, according to The Record.
  • **Snowden Leak (2023): **Leaked documents revealed that Australian intelligence agencies accessed Signal metadata through agreements with Five Eyes.

Given that Signal’s neutrality has long been in question and based on the above, the best recommendation I could give you is that, especially if you are dealing with government officials, military and other actors in sensitive contexts, reconsider using Signal as your primary communication tool.

That perception of security that some actors strive to make us believe may not reflect reality, especially when considering institutional linkages and potential technical vulnerabilities.

In any case, let me detail why everyone thinks that Signal has all the characteristics that should make it reliable:

  • **End-to-End Encryption (E2EE): Signal uses an open source encryption protocol(Signal Protocol) that protects the content of messages, ensuring that only the sender and receiver can read them. This system has been audited by experts and has been adopted by other platforms such as WhatsApp.
  • **Non-profit model: **Unlike companies like Meta (owner of WhatsApp), Signal is backed by a “non-profit” foundation, which would reduce its need to monetize its users’ data.
  • **Expert recommendations: **Numerous experts such as Edward Snowden and organizations such as the Electronic Frontier Foundation (EFF) have praised Signal for its technical standards (I’d like to know what they think now after some more recent revelations).
  • **Metadata minimization: **Signal claims that it does not store message, contact or location logs, and only retains essential information (such as check-in date and last connection) on a temporary basis.

These features have built a reputation as a “secure application”, especially among activists, journalists and vulnerable groups. 

But for high-ranking officials, military personnel or people in war zones, the risks are unacceptable:

  • **Exploitable metadata: **In conflicts, to know who communicates with whom and when it is as valuable as the content. Russia has used this tactic in Ukraine for targeted attacks.
  • **U.S. jurisdiction: **Any legal or political pressure on Signal could compromise its neutrality. Example: In 2022, the U.S. required technology companies to “combat disinformation,” an ambiguous criterion.

In any case Signal is not the only one, for example, although Telegram offers certain privacy features, this app is still criticized for not encrypting end-to-end messages by default and for storing user data on its servers. Let’s see a brief summary:

Telegram:

  • Servers in Dubai and Russia, with history of accessing data under pressure (e.g., in 2018, the Russian government blocked Telegram until it agreed to share encryption keys).
  • Encryption not enabled by default in group chats, allowing massive spying.

WhatsApp:

  • It belongs to Meta, a company with a history of sharing data with governments (e.g., in 2021, it collaborated with India to block accounts of protesting farmers).
  • Detailed metadata (time, frequency, contacts) are stored and accessible to third parties through court orders.

 

In any case, I already wrote an article about WhatsApp where I uncovered all the shames of this application and how we are spied on through it.

WhatsApp is constantly facing criticism for its data sharing policy with other companies in the conglomerate and for potential backdoors that could allow government access to communications.

While Signal remains superior to WhatsApp or Telegram in content protection, its reliance on phone numbers, US jurisdiction and metadata vulnerability make it dangerous in high surveillance contexts.

For dissidents, military or journalists in war zones, the risk of a government intercepting communications patterns or identifying users through collaboration with operators is real and documented.

In any case, Signal is in a good moment thanks to its exponential growth, mainly due to two events.

global adoption rate, which is growing exponentially.

The first in 2021 as a result of controversial changes to WhatsApp’s privacy policies and, most recently, because of the case #SignalGate.

SpoilerIn a future article, I will tell why Europe should urgently stop using - or rather, ban - applications such as Facebook, Instagram, Google, Gmail, Signal and WhatsAppsince the US government exploits them ad nauseam to obtain intelligence.

Europe should become independent and create its own equivalent apps, in order to prevent its population from falling victim again to the manipulation of foreign powers (or internal groups) that use these platforms from which they propagate self-serving messages, as happened in the past with the notorious cases of Cambridge Analytica.

Last but not least, the application uses strong encryption algorithms such as Curve25519, AES-256 and HMAC-SHA256currently considered among the most reliable in the industry.

Threema

Threema, although less known, is an applicationsuiza🇨🇭con its servers hosted in Europe, also totally focused on the security and privacy of its users.

It is fully compliant with the General Data Protection Regulation (GDPR), which is a guarantee of privacy for any European citizen.

This application allows completely anonymous use, with no need to provide a phone number or email address when registering.

Among its most important features are E2EE encryption, local message storage, decentralized architecture and contact verification without access to the phonebook.

Threema is a paid application, and that’s a good thing, so it doesn’t need to spy on you and sell your data in order to finance itself.

It is also Open Source and can be audited by anyone as a sign of transparency in its code.

A curious and significant fact about its reliability is that the Swiss Army banned the use of WhatsApp, Signal and Telegram during military operations, officially recommending the use of Threema to its commanders and chiefs of staff.

This decision is due, in part, to the fact that applications such as WhatsApp are subject to the U.S. CLOUD Act.

Threema’s architecture prevents third parties (including governments) from accessing data, even with court orders, and is presumably one of the few instant messaging applications to get away with this.

As I said at the beginning, although less known, Threema’s functionalities have nothing to envy to Signal or WhatsApp, since it has practically the same, including, in addition, internal polls and an exceptional control of privacy, which makes this application my favorite option over other messaging applications.

Briar

Although I am not going to recommend Briar as the default messaging application for daily use, it does not hurt to know about it and always have it installed on your mobile, in case things get bad in your country overnight or in case you have a prolonged power or internet outage in your area.

Of course, the people close to you with whom you would like to communicate should also have the application installed.

The more people who have it installed, the better, thus increasing coverage.

Briar is especially geared towards activists and journalists who require secure and resilient communications.

Widely used for physical synchronization in mass protests (e.g., used in Hong Kong demonstrations 2019-2020).

Unlike other applications, it does not rely on central servers; instead, it uses direct synchronization between devices, even in the absence of an Internet connection, thanks to Bluetooth or WiFi.

During the war in Ukraine, prior to the implementation of Elon Musk ’s communications satellite network*(Starlink*), Briar was essential for maintaining communications between civilians, allowing them, for example, to organize during Russian computer blackouts.

When there is an Internet connection, Briar uses the *Tor network*network, providing a very high additional level of anonymity, and when there is no Internet connection, it uses, as I said before, the WiFi or Bluetooth of the users in range to relay the messages until they reach the end user.

Like the previous ones, its most notable features are point-to-point E2EE encryption, exclusive data storage on devices and the ability to operate without the Internet.

It is also completely free and Open Source, which facilitates its audit and public verification.

 

As final conclusions, we would like to comment that choosing the right instant messaging application that best suits our needs is not only a question of privacy, but also of a good cybersecurity culture.

The sad part of the current paradox is that the most secure apps such as Threema and Briar are the least popular.

In the end, most users prioritize convenience over privacy.

Let’s not forget, that the right choice can make all the difference: while the FBI can access WhatsApp messages through metadata or backdoors, apps like Threema or Briar resist even government agencies.

The problem with these backdoors is that, once you install them, they can be exploited by both the police and hackers who discover them, putting everyone at risk.

If I had to recommend one of these three apps, I would say:

  • if you are a U.S. citizen, use Signal.
  • If you are a citizen of any other part of the world, Threema is undoubtedly the best option.
  • And for everyone: always have Briar installed and ready for use, in case it is needed in an emergency.

In any case, although applications such as Threema offer a higher level of privacy, the mass adoption factor is often the determining factor in choosing one option over another.

So it is also up to each one of us to try to convince those closest to us to join us in this change until applications such as WhatsApp are forgotten, which, today, seems very unlikely.

To end this article, I would like to take this opportunity to promote a bit of empathy and digital cyberculture. I mean, those people who without thinking twice, motivated by “morbidity”, forward disturbing photos or videos of executions, fights, accidents, etc., should stop forwarding those messages to their contacts.

With a little common sense and empathy anyone can realize that such messages do not lead to anything good, and in the worst case can cause emotional damage, especially if they get into the hands of minors.

If we intend to behave as a civilized society, we should reflect on what kind of messages we send, to whom and for what purpose, since contemplating such images brings no benefit.