← all articles

Signal vs Session for private messaging

I run proxy and SIM businesses out of Singapore, which means I’m messaging suppliers in Shenzhen, customers who don’t want their name attached to a purchase, and occasionally someone who has a real reason to not want their phone number sitting on a server anywhere. Signal and Session both come up in that world, and they get lumped together constantly because both are “the encrypted messenger for people who care.” They’re not solving the same problem.

Signal is the app cryptographers actually trust with the content of your messages. It’s the protocol WhatsApp and Google Messages license for their own encryption, it’s been picked apart by academic researchers for over a decade, and it’s run by a nonprofit that has publicly shown, subpoena after subpoena, that it genuinely has almost nothing to hand over. Session takes the opposite bet: it assumes the message content problem is basically solved and goes after the metadata problem instead, no phone number, no email, no central server that knows who’s talking to whom. That gets you a different, harder kind of privacy at the cost of a protocol with a much shorter track record.

If you just want WhatsApp without Meta reading the room, Signal wins and it’s not close. If you need an account nobody, not even the app maker, can tie back to a real identity, Session is doing something Signal structurally cannot. Read on for where each one actually holds up.

TL;DR comparison table

Signal Session
Pricing free, donation-funded free, funded via the Session/Oxen node network
Identity required phone number (usernames can hide it from contacts) none, random Session ID generated on install
Network model centralized servers run by Signal Foundation decentralized service nodes, onion-routed
Message content encryption Signal Protocol (Double Ratchet, X3DH) Session Protocol, forked and modified from Signal’s
Disappearing messages yes yes
Voice and video calls yes, both voice only
Platforms iOS, Android, Windows, macOS, Linux iOS, Android, Windows, macOS, Linux
Jurisdiction United States (Signal Foundation, nonprofit) Switzerland (Session Technology Foundation)
Best for most people replacing WhatsApp or Telegram people who need the account itself to be untraceable

Signal at a glance

Signal started as Open Whisper Systems, built by Moxie Marlinspike and Trevor Perrin, and the protocol they wrote is now the closest thing the industry has to a default standard for end-to-end encryption. WhatsApp runs it. Google Messages runs it for RCS chats between Android users. Even Meta’s “secret conversations” in Messenger borrowed from it. That’s not marketing, that’s just where the cryptography ended up because nobody’s found a better-vetted alternative.

In 2018, WhatsApp co-founder Brian Acton put $50 million into standing up the Signal Foundation as a nonprofit, specifically so the app would never need to sell user data or run ads to survive, as Signal announced on its own blog. Meredith Whittaker has been president since 2022. The app itself is simple on the surface: it looks like any other messenger, but every message is end-to-end encrypted by default, there’s no setting to turn that off, and the server is built to hold as little as possible. Signal added usernames in 2024, so you can finally give someone a way to message you without handing over your actual phone number, which used to be Signal’s single biggest usability compromise.

Session at a glance

Session comes out of the Loki/Oxen project, originally an Australian team, now organized as the Session Technology Foundation in Switzerland. The pitch is structural: don’t just encrypt the message, remove the thing that lets anyone link an account to a person in the first place. Installing Session generates a Session ID, a long public key string, and that’s your entire identity. No phone number, no email, no SMS verification step to trip up.

Messages don’t route through a company’s own servers. They bounce through a decentralized network of service nodes using onion routing, similar in spirit to Tor, and get temporarily stored across a “swarm” of nodes so offline recipients can still receive them later. Nobody operating a single node sees the full picture of who’s talking to whom. It’s a genuinely different architecture from Signal, not just a reskin, and it shows in both the strengths and the rough edges.

Head-to-head

Threat model it actually addresses

Signal assumes your biggest risk is someone intercepting message content, whether that’s a criminal on the same wifi, an employer, or a government demanding data from a server. It does that extremely well. What Signal can’t erase is that you signed up with a phone number, and however carefully they minimize what they log, a phone number is still a real-world identifier if someone gets it. I’ve written before about how a phone number tracks you across apps you never meant to link, and Signal doesn’t fully escape that problem, it just fences it off well.

Session assumes the scarier risk is that someone maps your social graph, not that they read one conversation. If you’re a source talking to a journalist, an activist, or just someone who doesn’t want a supplier keeping your number forever, an account that was never tied to your identity in the first place is worth more than slightly better message encryption. Worth reading my piece on building a threat model for normal people before picking either app, because the “right” answer genuinely depends on what you’re defending against.

Encryption and protocol

Signal Protocol combines X3DH for the initial key exchange with the Double Ratchet algorithm for ongoing messages, giving you forward secrecy (an old key compromise doesn’t expose future messages) and post-compromise security (a compromised session heals itself going forward). Signal publishes the full technical specifications, and the protocol has had a decade of academic papers picking at it, which is exactly what you want from cryptography, not obscurity, scrutiny.

Session Protocol started as a fork of Signal’s code and diverged to work without a server-assigned, always-online identity. That’s a real tradeoff: Session has been open, including in its own documentation and in outside reviews it has commissioned (Quarkslab did a protocol assessment), that some of the per-message forward secrecy guarantees Signal offers don’t carry over cleanly to Session’s decentralized model. You’re trading some cryptographic elegance for metadata resistance. That’s a legitimate engineering decision, but it’s not the same guarantee, and anyone telling you the two protocols are equivalent hasn’t read either whitepaper.

Jurisdiction and logging policy

Signal Foundation is a US nonprofit, which means it’s reachable by US subpoenas and national security letters. The redeeming part is that Signal has actually been tested on this, repeatedly, and published the results. On signal.org/bigbrother, you can read real, redacted grand jury subpoenas where Signal’s response was, more or less, “here’s the account creation date and the last time it connected, that’s the entire database.” No message content, no contact list, no history, because sealed sender means Signal genuinely doesn’t have it to give. That’s a stronger proof point than any privacy policy, it’s Signal showing its hand under legal compulsion.

Session’s foundation sits in Switzerland now, which has stronger data protection law than most jurisdictions, and the decentralized node network means there’s no single company to subpoena for a full message archive the way there would be with a centralized server. The project’s roots are in Australia, a country whose 2018 Assistance and Access Act lets authorities compel companies to build in interception capability, and that kind of jurisdictional exposure is exactly the sort of thing worth weighing before you trust a provider with your traffic at all. If that tradeoff interests you, I’ve gone deeper on self-hosting versus trusting a provider, because decentralization is really just distributed trust, not zero trust.

Independent audits

Signal Protocol’s cryptography has been formally analyzed by outside academics multiple times since 2016, and the apps themselves have gone through contracted audits over the years covering everything from the client code to the disappearing messages feature. It’s one of the most independently reviewed pieces of consumer software that exists, mostly because so many other companies now depend on the same protocol working correctly.

Session has had its own reviews, including the Quarkslab protocol assessment mentioned above, but it doesn’t carry anywhere near the same volume of outside academic scrutiny that Signal Protocol has accumulated simply by being older and more widely deployed. Newer isn’t automatically worse, but less-examined is a fair thing to weigh.

Open source status

Both are fully open source, and this is a genuine tie. Signal’s clients and server code are public, Session’s clients and protocol code are public too. Neither one is asking you to trust a closed binary, which rules out a huge chunk of messaging apps that claim to be “encrypted” without ever showing their work.

Platform coverage

Both cover the same footprint: iOS, Android, and desktop apps for Windows, macOS, and Linux. Neither has a browser extension anymore, Signal killed its old Chrome app years ago in favor of standalone desktop clients. If you’re setting up devices for a trip, both apps install cleanly, though I’d point you to getting a phone ready for travel first regardless of which messenger you end up on, since the messenger is one layer and the phone underneath it is the bigger attack surface most people ignore.

Pricing

Both are free with no premium tier and no ads, and neither is likely to start charging given how each is funded. Signal runs on donations plus what’s left of Acton’s original grant. Session’s economics run through its node network, where operators stake the OXEN token to run service nodes and earn from network fees, which is a very different sustainability model but doesn’t cost the end user anything either way.

Usability for non-technical people

Signal wins this one cleanly. Because it uses your phone number, it can auto-discover which of your contacts are already on Signal, the same way WhatsApp does, so onboarding a non-technical relative takes about ninety seconds. Push notifications work reliably, calls connect fast, the interface doesn’t ask you to understand anything about how it works under the hood.

Session asks more of you. Without a phone number to anchor contact discovery, you’re exchanging long Session ID strings or QR codes, which is fine for someone who already cares about privacy and mildly annoying for someone who doesn’t. Message delivery through a decentralized node network has historically been a little less snappy than hitting Signal’s own servers directly. I wouldn’t hand Session to a parent who just wants to text the grandkids. I would hand it to someone who specifically asked me how to talk to a source without either of us leaving a number behind.

Use-case verdicts

Everyday chat with friends, family, and most business contacts: Signal. Auto contact discovery, video calls, and near-universal name recognition make it the obvious default when the other person just wants something that works.

Talking to someone you don’t want holding your phone number, a source, a supplier you’re not fully sure about, a stranger on a forum: Session. The account was never tied to a real identity in the first place, so there’s nothing to leak even if the other end turns out to be careless with it.

Living somewhere that actively blocks or pressures encrypted apps: leans Session, since the decentralized node network is harder to take down or block wholesale than a single company’s server infrastructure, though it’s not a clean win, Signal shipped its own proxy feature during Iran’s 2022 protests specifically to route around censorship, so neither app leaves you completely stuck.

Wanting the most heavily vetted cryptography for the message content itself, with less concern about who knows your account exists: Signal. A decade of academic scrutiny on the same protocol WhatsApp runs is hard to beat, and it’s not something Session claims to match yet.

Who should pick Signal

Pick Signal if you’re replacing WhatsApp, Telegram, or iMessage for daily use and want the best-audited encryption available without giving up ease of use. Pick it if the people you talk to are mostly non-technical, since Signal’s phone-number-based contact discovery removes almost all onboarding friction. And pick it if your actual worry is someone reading your messages, not someone knowing you have an account. That covers most people reading this.

Who should pick Session

Pick Session if the existence of a paper trail between your phone number and your messages is itself the risk, not just the message content. Pick it if you’re a journalist, a source, or someone in a country where an authoritarian government or an abusive partner could subpoena or coerce a phone number’s worth of metadata out of a centralized service. And pick it if you’re willing to trade some of Signal’s protocol maturity for an account structure that was never traceable to begin with. That’s a narrower group, but for that group, Signal genuinely can’t do what Session does.

Verdict overall

Neither app beats the other outright, and that’s the honest answer, not a dodge. Signal has the better-audited cryptography, the easier onboarding, and a public track record of proving under legal pressure that it holds almost nothing. Session has the harder-to-achieve property of an account that was never linked to a real identity, at the cost of a younger protocol and a rougher day-to-day experience. If you’re not sure which camp you’re in, default to Signal, it’s the safer general-purpose choice and it costs you nothing to install. If you already know your risk is “who knows I have this account” rather than “who can read what’s in it,” Session is solving the problem Signal was never built to solve.

None of this replaces thinking through what you’re actually protecting against before you pick a tool, which is the whole point of doing a threat model for normal people instead of just grabbing whichever app a forum told you to install. And if you’re the type who ends up down every privacy rabbit hole, not just messaging but browser fingerprints and device profiles too, that’s a different mess entirely, I’ve covered more of it on the antidetect browser side over on Antidetect Review. For everything else privacy-related, the rest of what I’ve written is on the blog.

Written by Xavier Fok

disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-09-17.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →