← all articles

Encrypted messaging compared: Signal, WhatsApp and iMessage

encrypted-messaging signal whatsapp imessage metadata

A customer asked me last year which messenger was the safe one. He asked on WhatsApp. I answered on WhatsApp, and the exchange became a line in a record saying those two numbers talked, that evening, for about four minutes. The contents were sealed shut. The fact of the conversation was wide open.

That is the whole comparison in miniature. Verdict first, reasoning after.

App What it protects What it leaks
Signal Message contents, plus almost all of the record of who spoke to whom Very little. Your number, to anyone you have not switched to a username, and the fact an account exists
WhatsApp Message contents, properly, using Signal’s own protocol Your contact graph, who is in which group, when you are online, how often you message, all held by an advertising company
iMessage Message contents between Apple devices, if you have switched on Advanced Data Protection Every word of a plain text message to an Android phone, and your whole history if iCloud backup sits on its default setting

Now the part everyone argues about and should not.

The cryptography is a tie

Signal wrote the protocol. WhatsApp adopted it wholesale in 2016 and still runs it. Apple built something different that arrives in a comparable place and has since added protection against a future quantum attack nobody can currently mount.

No one has broken the message cipher in any of the three. Signal’s has been public and picked over for more than a decade.

Choosing between them on encryption strength means choosing on the one axis where they are level.

What survives after the encryption has worked

A company can be completely unable to read a word you wrote and still hold a map of your life.

My business runs on WhatsApp. Which means Meta holds a decent approximation of my customer list: the numbers I talk to, how often, at what hours, which groups we share, when a new number starts appearing daily. I have never sent them a spreadsheet. They can assemble most of one anyway.

Signal went the other way deliberately. They publish the responses they give to legal demands, and those responses are close to empty, because the underlying data was never collected. Date the account was created. Date it last connected. That is more or less the reply.

Apple sits between the two, and where exactly depends on your settings, which is the next section.

The test worth running is what a company can physically produce on the day it stops arguing with a court. Signal produces two dates. The other two produce a picture of your life with the words taken out, and the picture is often enough.

Your backup is where it actually goes wrong

Your messages get encrypted in transit. Then your phone makes a copy and puts it somewhere else, and that copy is where most real world leaks happen. No cipher gets broken to cause it.

On iPhone, a standard iCloud backup historically carried the key material needed to read your iMessage history, which meant Apple could hand your conversations over even though the app itself is end to end encrypted. Advanced Data Protection closes that hole. It is off until you switch it on, it lives several screens deep, and until you find it your encrypted messenger has an unencrypted twin in someone else’s data centre.

WhatsApp has the same shape of problem. Your chat history goes to Google Drive or iCloud, and it can be locked with a password or a 64 digit key that only you hold. Also opt in. Also easy to skip.

Signal refuses to play at all. There is no cloud backup. You move your history from the old phone to the new one yourself, and if you drop the old phone in the sea first, your history is gone.

People find that infuriating, and they are entitled to. It is the honest price of the guarantee, and the clearest example in consumer software of privacy costing you something you can feel.

So every row in that table assumes you have gone and turned the backup protection on. If you have not, the row you picked barely matters.

The colour of the bubble is a security indicator

iMessage is only iMessage between Apple devices. Send to an Android phone and the conversation falls back to a different transport. For years that meant SMS, readable by both carriers and by anyone who can persuade a carrier to cooperate.

RCS improved the fallback, and encryption across the two ecosystems has arrived in stages over several releases. The honest position today is that a cross platform thread is private only while both apps are actively telling you it is.

Which means the colour of a chat bubble carries security information. Strange thing to be true. It is true.

Every linked device is another complete copy

All three let you attach a desktop or a tablet, and each attachment is a full copy of your conversations on a machine with its own problems. A work laptop somebody else administers. A shared home computer that four people know the password to.

All three have a screen listing what is currently linked. Almost nobody opens it.

I opened mine while writing this and found a desktop still attached that I had not touched since I rearranged the machines at home last year. Nothing bad came of it. It was still a full copy of my messages on a machine I had stopped thinking about, which is the pattern that goes wrong everywhere else in security: access granted once outlives the reason for it.

Unlink the old machine before you wipe it. After the wipe usually means never.

The number is the identity, with one exception

All three tie you to a phone number by default. That is a problem if you want to talk to somebody without handing over a permanent identifier that also receives your bank codes.

Signal added usernames, so you can be reached without revealing your number. You still register with one. You no longer have to show it. That is a genuine difference and the one place Signal pulled clearly ahead.

WhatsApp is your number, visible to every person you message and every group you join. There is no setting for it.

iMessage will accept an email address instead, which helps a bit. Most people are reachable at their number anyway.

Disappearing messages are housekeeping

A timer deletes the message from both devices after the period you set. Useful, and smaller than people think.

It limits what a lost or seized phone gives up. It stops a chat turning into a five year archive nobody decided to keep. Both are good reasons.

What it will not do is stop the other person keeping a copy. A screenshot takes a second, and a second phone photographing the screen defeats every screenshot detector any app could ever build. Anyone selling a timer as a guarantee of deletion is describing software that does not exist.

I run a short timer on most personal chats for the first reason only. If my phone goes missing I would rather it hold a fortnight of conversation than four years of it.

The other person decides how private your chat is

You can run Signal on a locked phone with a timer set, and if the person on the other end keeps a plain unencrypted backup, or forwards a screenshot into a group of forty, your careful configuration protected nothing.

The security of a thread is set by whoever in it is least careful, and you have no way to audit them.

Which makes app choice a per conversation decision. The threads that need protection go somewhere private, everyone in them knows why, and the rest live wherever is convenient. Migrating an entire contact list to one app fails every time, and I have watched people burn months on it.

What none of the three fix

None of them help if the device is compromised. Encryption protects a message in transit. Something reading your screen sees the decrypted text at the same moment you do.

None of them help against a person holding your unlocked phone. Put a passcode on the app where that option exists, and use a real device lock rather than a four digit code you use elsewhere too.

And none of them make you anonymous. The person you are messaging knows exactly who you are. Obvious, and forgotten constantly.

What I use, which is inconsistent

I use all three. There is no principle in that. It is what happens when your work requires reaching people who will not move.

Signal for anything I would mind being read back to me later. WhatsApp for most of my working life, because in this part of the world it is where business happens, and telling a customer to install something else before ordering is a good way to lose the order. iMessage barely, since almost everyone around me is on Android.

The app with the best guarantees is worth nothing for a conversation the other person refuses to have inside it. Pick the private one for the threads that need it and stop trying to relocate everybody. The other tools I have tested the same way are here.

The model I had wrong for years

I treated end to end encryption as a yes or no property and recommended apps on that basis. Tick means safe. No tick means unsafe.

That produced bad advice. I told people WhatsApp was fine, full stop, when the accurate version was that the contents are fine and the surrounding record sits with an advertising company. Those are different claims, and the difference mattered to at least one person I said it to.

The question worth asking is what is left once the encryption has done its job, and who is holding it.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →