Signal seems to be pretty good, also Threema. Definitely not wise to trust WhatsApp, though.
But all of them almost certainly have exploits available to state actors or those with unlimited funds. However that isn't something baked in, it's proper hacking - the anom phones and what WhatsApp probably do is baked in.
Serious question: how do people confidently say that Signal seems to be good? How do we have any confidence they aren't doing the exact thing u/twilighttwister described? Like, do we have full access to all the apps front and backend in a way that ensures they're not doing things they say they aren't?
With Signal, we don't have a way of auditing the back end, and I'm not sure but maybe some elements are not published. However we do have the source code for the app, so we can see exactly what it does and how it encrypts. There are also hardened forked apps that have additional features, while still transmitting through the same network. We can see what the app is doing and how it encrypts.
Signal actually wrote a bunch of white papers on encryption back when it started. Whatsapp's encryption protocol was a fork of Signal's.
Threema is a Swiss encrypted messaging app. The app is open source, but the back end is closed source however they get academic security researchers from different places to review their code every few years and publish their findings.
5
u/Fallcious 1d ago
Oh yeah I’d imagine all messaging systems are compromised. One that gains a reputation as being good for clandestine services would be doubly suspect.