# Which private messaging / communication app is best?

**URL:** https://discuss.privacyguides.net/t/which-private-messaging-communication-app-is-best/23335
**Category:** General
**Tags:** software
**Created:** 2024-12-20T23:55:26Z
**Posts:** 39

## Post 1 by @tabitha — 2024-12-20T23:55:26Z

Signal being based on a phone number (a clear identifier) is a non-starter. Signal is also a centralized model, using Big Tech servers (`https://www.messenger-matrix.de/messenger-matrix-en.html`), with a clearly identifiable contacts graph (`https://youtu.be/LrLsS7-woN0?t=3600`) and Signal’s multi device cloning capability bypasses the protections of the Signal protocol (`https://youtu.be/PIi9jkWdJL0?t=1624`). If the software only hides the content and not your contact network, it is **not private** , PERIOD. Moving on…

Cyph and Threema cost money to use and people expect messenger apps to be free so those apps will probably never get much traction.

I understand that XMPP and Matrix store lots of user metadata on the servers: contacts, IP addresses, accounts directory, time of sent messages, etc. I also understand that Matrix is fairly centralized. So the federation models are not currently interesting options.

Synchronous apps that require both users to be online simultaneously are also a non-starter. So Cwtch, Ricochet Refresh, Briar and Quiet are for very limited use cases and will never likely have much of a user base. Plus, in a crisis with these apps, where you need to get a message out in an emergency and the other party is not available, you may be out of luck. (No, the Briar and Quiet mailbox ideas are not very practical for most people.)

I consider Tox, Status, Retroshare, Berty and many others to be too complicated (Retroshare), too buggy, not mature enough (Status/Berty), not well maintained (Tox), or lacking basic functionality (group chats, audio/video calls, file share–all e2e encrypted).

Jami has been inconsistent in my experience.

Then there’s Telegram and Wire that often end up on privacy app lists but have little to do with privacy.

I looked for easy to use apps for I2P, Freenet, Hyphanet and GNUnet with the idea that Darknet hidden networks might offer greater privacy. I found no app that was ready for prime time. Nothing even close.

Without getting into too much detail about the design flaws of these aforementioned apps (many with poor metadata protection, email requirements when signing up, etc.) the reasons stated are enough to disqualify them from my list.

Up until Simple X Chat (`https://simplex.chat/`) came to my attention, I considered Session (`https://getsession.org/`) the obvious choice. These two apps are the only ones that are worth considering in my opinion.

**Some Comparisons: Session vs. Simple X Chat**

Though Simple X has made some important design improvements over Session I still feel that the user interface is much cleaner and easier with Session. If Session adopted the Simple X method of creating social links via “temporary anonymous pairwise identifiers of message queues, separate for each of your connections” and abandoned the persistent Session ID I would say that Session could still stay in the race. Otherwise I expect that Simple X will over take Session. The no user ID of Simple X is the primary reason for why I am interested in Simple X.

Session uses the onion routing network Lokinet (being re-branded as the Session Network) to hide metadata. Simple X uses a proxied P2P architecture. Session’s solution to the latency and reliability issues of the Tor network was to build a faster onion routing network. [I have heard Rob Braxman state that the Session Network is faster (less latency than Tor) but does anyone have any data on this?]. Simple X’s solution to the latency issue with the Tor network was to use a 2-relay system (as opposed to 3), to cut out a node and improve the speed of data transfer by reducing the number of hops. I prefer the onion routing (Session Network) approach as I prioritize the stronger anonymity and I don’t care about latency for chat messages as long as the transfer time is within 10 seconds or so. Simple X allows me to select my servers but I do not know who these server operators are and there is no tangible difference to me between Simple X/Flux servers, Session Network servers, or Tor network servers–except that I suspect that there are more malicious nodes in the Tor network.

I don’t use voice messages so this feature is of no real importance to me. Voice messages do work on Session. Voice messages are still in the works for Simple X.

File sharing works well in Session. In Simple X they use a less intuitive file management tool.

Both Session and Simple X use the same calling design as far as I can tell. P2P e2e encrypted WebRTC.  
1-on-1 calls in both apps work fine. I prefer that the call in Session takes place within the app as opposed to pulling up my default browser unexpectedly (without my permission), as occurs with Simple X. Session claims to have onion routed calls soon on the way. If they can pull this off without much latency I will be impressed. This would make the calling feature significantly more secure in Session compared to the Simple X model.

Simple X does a much better job than Session with the communities part. Session does not encrypt it’s community channels and requires self hosting (`https://getsession.org/faq`). Is has a directory online: `https://sessioncommunities.online/` but this directory is not accessible within the app. There are 3 official channels available within the app and these are just one way Session announcement channels for Session, Oxen crypto, and Lokinet). Due to not providing any e2e encryption privacy in Session communities and a higher barrier for setting up and finding communities it’s not a surprise that Session groups have lower participation. This failure of Session might be fine for someone who is just using Session as a private messenger for known contacts but not for someone who wishes to connect to a larger population. Session’s communities part is not worth using until they overhaul their system.

I should say that if there is going to be any chance that I will be able to convince some of my friends to ditch Telegram (etc.) for a private messenger app, the app will need to have a good community directory for news, etc.

Simple X communities are easy to find in the app and I understand that all communications are e2e encrypted. (Awesome!) Though there are stricter limitations on content for those who want to be listed in the directory compared to Session. Overall though they have done a good job with the communities part.

Session abandoned Australia for Switzerland because of draconian laws in Australia and increased oppression by the Australian government. Simple X is based in the UK which is a lousy privacy jurisdiction. As Simple X grows in popularity their strategy is to comply with the legal due process but design a system that limits network liability and offers no meaningful data to be available to the police. In the short run this strategy may be fine. I have my doubts that Simple X’s legal strategy will be effective long term because I expect that any truly effective tools that thwart the Technocrat’s agenda will be targeted if these tools gain sufficient enough popularity. I wonder if the Simple X team are willing to relocate, if necessary, in order to protect the privacy of their users? Session has shown their commitment to privacy already. Both projects should prepare for their respective projects to continue to function in a decentralized manner even if the founders are no longer able to continue participating.

For me, in addition to e2e encrypted 1-to-1 chats, group chats, file sharing, and 1-to-1 calling, I am REALLY looking for a secure group video conference call option for up 15-20 people.

I have been looking hard for the most private group video calling solution and the options are not great. With more than 4 people it seems a SFU server is generally required for reliable calling and the P2P options start losing performance/reliability. The best I have found is using a VPN with the Brave browser on a public Jitsi instance with e2e encryption enabled in the Jitsi settings. I am not sure what device/browser metadata is available to a malicious Jitsi server that keeps logs?

Group video calling options are typically either: proprietary, don’t work well consistently, don’t scale well beyond a few people, few offer e2e encryption by default, most are not clear about what privacy protections they provide by design (privacy policies do not carry much weight), very few have a 3rd party security audit, most are not clear about what metadata they collect, most are not clear about which servers are hosting the calls, very few are responsive to questions (if there even is a way to contact the service).

So for me if either Session or Simple X is able to offer group calling for 15 or so people while maintaining the highest standards for privacy available and create a consistent/reliable calling experience, that would be a major win. A highly private open source group calling app would be reason enough to use the app, even if there were no other functions.

I know that Evgeny of Simple X visits the forums of Privacy Guides and has a more extensive critique of Session including:

-security problems with unlimited cloning of Session accounts for device portability  
-the crypto business model for the Session Network  
-how Session abandoned parts of the Signal protocol, sacrificing the double ratchet algorithm (including break-in recovery, perfect forward secrecy and non-repudiation). Maybe he can unpack all of that and explain what it means in terms of privacy compromises?  
-not post-quantum resistant  
-the persistent Session ID making it possible to identify users

Perhaps Evgeny would be willing to write up a comprehensive comparison, critique and analysis of how Simple X and Session stack up to each other from his perspective?

That might help me better understand which app to go with.

---

## Post 2 by @WhinyHamletPayer — 2024-12-21T00:12:54Z

> [@tabitha](#):
>
> Signal being based on a phone number (a clear identifier) is a non-starter.

Use a text verification service (e.g. textverified) where you receive a text with the code in it. Or use jmp.chat to get a voip number and you continue to use the number.

---

## Post 3 by @anon21489307 — 2024-12-21T00:42:35Z

I use Element (Matrix).

**Pros:**

1. It’s able to log in simultaneously on many of my devices.
2. Do not require a phone number or an email address for registration.
3. The account verification and recovery process are the easiest to use among E2EE services. This is very important for my mom, grandmom, etc. who’s not so good with technical staff.
4. The closest to Discord in terms of features.
5. Work great on all platforms, including Linux.
6. Not perfect, but still a very secure option.

**Cons:**

1. Very slow mobile app. Element X is planned to replace the current app. it’s up to [6000x faster](https://element.io/blog/element-x-experience-the-future-of-element/) than any other Matrix client. But the features it provides are not comparable to the current app _yet_.
2. I wouldn’t consider voice and video calling usable. Hopefully, this will be improved with native calling.

I don’t consider Signal at all. While Matrix is not so much of decentralized in reality (since most people and spaces are on [matrix.org](http://matrix.org) server), but Signal is fully centralized. Signal app is also only officially available on Debian based Linux. I believe the app would work inside a container, but it shows that they don’t take Linux seriously. And most important of all, it requires the users’ _phone number_. Sure, all of those issues have workarounds. But I’m not a fan of workarounds, especially when a similar service doesn’t require one.

---

## Post 4 by @Niek-de-Wilde — 2024-12-21T01:01:54Z

For normal folks, just use signal.

---

## Post 5 by @anon36940904 — 2024-12-21T01:19:07Z

I know right? When someone’s makes such a long post debating with themselves about which encrypted messenger to use with such detail while discounting Signal up front - I just turn away from it. If their threat model is really this high, I don’t think posting about it here is going to get them an answer that would satisfy them.

---

## Post 6 by @anon73250778 — 2024-12-21T03:21:24Z

Yeah they hate that we are special snowflakes that needs our own app just to talk with. If we make them use a, god forbid, _complex_ app, we’ll cause them to burst a vessel in their head and completely nope out of our “non-sense”.

Sadly this is the state of the world.

---

## Post 7 by @anon5410820 — 2024-12-21T04:51:03Z

Yeah, Signal just works like the ones people expect. I’ve had no problem getting people on Signal (aside from them not wanting to install another messenging app, but ehhh not really a thing you can fix).

---

## Post 10 by @jerm — 2024-12-21T10:39:38Z

> Which private messaging / communication app is best?

Best in terms of privacy and security:

> **[SimpleX Chat: private and secure messenger without any user IDs (not even...](https://simplex.chat/)**
>
> SimpleX Chat - a private and encrypted messenger without any user IDs (not even random ones)! Make a private connection via link / QR code to send messages and make calls.

> Simple X is based in the UK which is a lousy privacy jurisdiction.

Unlike any other messenger, SimpleX Chat is truly decentralized, anyone can host servers and you can choose what servers you want connect to in the settings.

If you want their opinion about their company jurisdiction see [this](https://xcancel.com/SimpleXChat/search?f=tweets&q=UK&since=&until=&near=).

---

## Post 11 by @anon39279085 — 2024-12-21T11:05:31Z

I’m sorry can we have a TL;DR  
It sounds like you’re hating on signal for almost no reason.  
This thread is a mess my goodness.  
Look being centralized doesn’t always mean bad, it always depends on how someone like signal operates it which they do just fine (However the disadvantage of centralized is that if they shut down, it’s gone basically unless the signal proxy could allow it to be alive but not that we know of) and while the phone number is an understandable frustration there’s already ways you can workaround it like using Non-KYC Sim/e-Sim/VoIP. That’s what I’m doing for my signal personally.

Also if we do keep call out signal to make changes especially for the desktop app, This is how they can listen which isn’t good but if we can hold them accountable then we surely can do it. Which has happened and les the decision to encrypt the keys on your PC now. so it is secure from there.

It feels like a Rant to just god forbid people shouldn’t use something that’s more private than say Whatsapp and easy to use.  
I know this is the internet but the level of hypocrisy here is crazy.

However It can be understandably which is why I have both SimpleX and Signal so. But still

---

## Post 12 by @jerm — 2024-12-21T11:46:10Z

> [@Anon47486929](#):
>
> [Insanely insecure](https://news.ycombinator.com/item?id=8659456)

The comment about Cyph is from 2014, there have been some changes done and got an audit (a lot of security vulnerabilities were found, critical and high). But still not far from great compared to today’s options. Also it is still web based even if they got “[Websign](https://www.cyph.com/websign)” which is interesting tbh and they offer it as a [service](https://www.websign.app/)?, but I didn’t check out yet. You can’t pay with Monero.

Their code is [non-free](https://github.com/cyph/cyph?tab=License-1-ov-file#readme), [Source Code Licenses — Cyph](https://www.cyph.com/blog/source-code-licenses) “this means that third parties can’t fork and modify our code or deploy their own instances of Cyph without our permission.”.

> Tox

You forgot [Tox Handshake Vulnerable to KCI · Issue #426 · TokTok/c-toxcore · GitHub](https://github.com/TokTok/c-toxcore/issues/426), there have been efforts into fixing this issue, but isn’t implemented yet

Idk about Hyphanet (previously Freenet), but there’s a separate project based on its design also called [Freenet](https://freenet.org/faq/#what-is-the-projects-history), they are getting consistent updates and funded by FUTO.

---

## Post 14 by @anon21489307 — 2024-12-21T16:37:44Z

> [@Anon47486929](#):
>
> [[Matrix]insecure by design](https://nebuchadnezzar-megolm.github.io/).

1. All the vulnerabilities in this link _requires_ a malicious _home server_ to perform the attacks. But most people are using [matrix.org](http://matrix.org) server anyway. Nonetheless, with these vulnerabilities, it means that the users need to trust the server that’s supposedly to be trustless which is crucial in decentralized environment.
2. Many of the vulnerabilities [had been fixed since 2022](https://matrix.org/blog/2022/09/28/upgrade-now-to-address-encryption-vulns-in-matrix-sdks-and-clients/).
3. Element X is using a new matrix-rust-sdk that’s not the same SDKs that are reported to be vulnerable in the link. Hopefully, it will be ready for my needs soon.

Basically, the insecurities proof of concept that derived from the _insecure by design_ had been fixed, and had never been affected people who are on [matrix.org](http://matrix.org) server. Sure, the overwhelming usage of the [matrix.org](http://matrix.org) server is contrary to the supposedly decentralized intent. But that’s still better than using a centralized service where hosting your own server is not possible.

---

## Post 16 by @anon21489307 — 2024-12-22T03:26:36Z

It’s not like everyone has to be on [matrix.org](http://matrix.org), it just happens to be the most developed, so people use it the most. The same goes with Element vs the rest of other Matrix clients.

Even then, there are other reasons for me using Element over Signal. The main one is the web client that works great on every desktop OS. Otherwise, I wouldn’t bother moving away from LINE, WhatsApp, Facebook Messenger, etc. that everyone of my friends are using.

I just don’t see the point of moving away from the like of LINE or WhatsApp to Signal. They’re centralized services that regardless of their source availability, no one is able to prove what’s actually running on their servers at the moment. At least, with Matrix, there’s an option to host my server, and those vulnerabilities would never affect me. The moment I host my own server, it has become trustless that none of the centralized options could’ve been.

---

## Post 18 by @asanyan — 2024-12-22T04:03:14Z

IMO the options are limited to SimpleX, Cwtch, Matrix, and XMPP, if anonymity is desired. Session probably shouldn’t be considered as a long-term solution because Lokinet is built around a lie.

SimpleX and Cwtch are probably too new to be seriously considered as of now, which leaves XMPP and Matrix. Personally I believe XMPP to be the better option as it has less issues than matrix.

> [@Anon47486929](#):
>
> Absurdly insecure

A lot of what is stated there is merely opinion based on what the author considers to be good practice, rather than fact. Point 1 is a non-issue, point 2 is subjective and may or may not be a problem, and point 3 is really a non-issue. [The OMEMO author has responded to this blogpost](https://www.moparisthebest.com/tim-henkes-omemo-response.txt).

Also relevant: [moparisthebest.com - Against Silos+Signal](https://www.moparisthebest.com/against-silos-signal/)

EDIT to avoid doublepost:

> [@anon21489307](#):
>
> they don’t take Linux seriously

When I last checked the official Signal app also doesn’t even work natively under Wayland, only Signal Beta does.

---

## Post 19 by @anon21489307 — 2024-12-22T04:31:56Z

> [@Anon47486929](#):
>
> do you host your own server right now? I already know the answer :slight_smile:

Also, do you compile every app you’re using on your desktop and mobile providing if it’s open source/source available? I already know the answer :grin:

Does that mean opening the source has no merit as an option or transparency of the app? Nope. Same goes for the decentralized nature of Matrix.

> [@Anon47486929](#):
>
> Lets be clear, matrix is insecure compared to Signal.

Not necessary. If you host your own server and use it only among your family members. So, it depends.

---

## Post 20 by @phnx — 2024-12-22T04:35:56Z

> [@anon21489307](#):
>
> Not necessary. If you host your own server and use it only among your family members. So, it depends.

That doesn’t solve the metadata or perfect forward secrecy issues with Matrix/Element. Securing the server is also very important given the trust Matrix places in the server.

---

## Post 21 by @anon21489307 — 2024-12-22T04:36:54Z

Metadata is not an issue if you’re running it in your server.

---

## Post 22 by @phnx — 2024-12-22T04:37:56Z

Yes it is, because the server can be compromised.

---

## Post 23 by @anon21489307 — 2024-12-22T04:39:48Z

Yes, including Signal server or any other messengers’ servers. At that point, metadata is not most concerning issue anymore.

---

## Post 24 by @anon5410820 — 2024-12-22T05:51:00Z

Okay, I like Matrix (personally because it’s fun to self-host), but this is precisely why people use Signal, because it’s zero-trust (aka. It already assumes the server is compromise and know as little as possible)

---

## Post 25 by @anon21489307 — 2024-12-22T06:02:22Z

> [@anon5410820](#):
>
> this is precisely why people use Signal, because it’s zero-trust

That’s not zero-trust/trustless. There, the users require trust in a centralized environment. This is true for any centralized services, since they control both ends, not the users.

This article is a very good read:

> **[moparisthebest.com - Against Silos+Signal](https://www.moparisthebest.com/against-silos-signal/)**
>
> The home of runescape cheating

> It doesn’t actually matter how cryptographically secure your end-to-end encryption is when 1 entity controls all ends, and can instantly update them whenever they want.

---

## Post 26 by @PurpleDime — 2024-12-22T11:00:41Z

Isn’t Element / Element X a paid app, though?

---

## Post 27 by @anon48875053 — 2024-12-22T11:10:12Z

No.

---

## Post 28 by @tabitha — 2024-12-22T14:15:24Z

**Wow! What a mess.**

A lot has happened while I was gone.

Well, um, thanks everyone for sharing your thoughts (…_kinda_ :neutral_face:).

Let’s see if we can salvage this conversation.

**My Definition of Privacy**

1. The content of my communications should only be received by my intended audience.
2. Who I am communicating with should only be known to those I am communicating with. No outside party.

Most communication apps fail on the first point.  
Almost none pass the second point.

This is my criteria for privacy regardless of the threat model.

I will add one more criteria. Communication tools need to be usable out-of-the-box for the average user (no self-hosting required, tricky anonymous sign-up procedures, or a complicated user interface).

**Who this post is for**

People who value freedom and understand that privacy from adversaries is necessary to maintain our freedom.

In the context of this forum, it is for:  
\*App developers: particularly the makers of Simple X and Session, should they come along. I am going to tag @epoberezkin while I am thinking about it. This post is principally directed towards him.

\*People looking for a way of communicating that meets the privacy criteria that I just laid out (presumably the rest of you).

**What my initial post was NOT for**

I was not asking for you to share your favorite messaging app.

I explained in the initial post why I rejected various platforms from consideration. I did not list all of my reasons for rejecting each app.

For apps that I expected some push back on (Signal), I gave several reasons and provided citations.

If my characterization of a platform is wrong feel free to offer a counterpoint _with evidence_.

**Getting focused**

As far as I know the only 2 apps that seem to meet my definition of privacy are Session and Simple X Chat.

If you are aware of a shortcoming of either of those apps and can offer an informed comparison beyond what has already been stated, please share.

If I have overlooked an app that meets my privacy criteria, feel free to bring it into the conversation for consideration.

If we can all agree to keep this discussion focused on the merits of Session vs. Simple X, then I think we can have a productive dialogue.

My apologies for not being more clear in my initial post.

Enjoy the holidays all you privacy warriors (…I mean geeks)!

---

## Post 29 by @PurpleDime — 2024-12-22T14:51:19Z

If it’s free, why do I not see a free tier on [their pricing page](https://element.io/pricing)?

---

## Post 30 by @anon48875053 — 2024-12-22T14:53:06Z

Read the page.

---

## Post 31 by @fria — 2024-12-22T14:59:37Z

> [@tabitha](#):
>
> If you are aware of a shortcoming of either of those apps and can offer an informed comparison beyond what has already been stated, please share.

Session doesn’t have forward secrecy and doesn’t have post-quantum cryptography afaik.

---

## Post 32 by @anon48875053 — 2024-12-22T15:00:58Z

And is also buggy as hell.

---

## Post 33 by @fria — 2024-12-22T15:01:26Z

That also applies to SimpleX Chat from my experience.

---

## Post 34 by @anon48875053 — 2024-12-22T15:02:58Z

Could be the iOS version, idk. It’s miles better than Session on Android.

---

## Post 36 by @anon21489307 — 2024-12-22T16:11:48Z

> [@Anon47486929](#):
>
> Not the gotcha you think it.

Yes, it’s a gocha I think it’s.

> [@Anon47486929](#):
>
> the protections of the app are not dependent on everyone building it from source.

Wrong. You need trust to use other’s compiled binary, no way around it. That’s why it’s generally _not_ recommend to install anything from a community maintain repo/source.

> [@Anon47486929](#):
>
> a release is safe if at least one counter checks.

Yes, but only if you’re doing the check yourself in a reproducible build system. Otherwise, it requires trust. Anyone can just modify the source however they want and release the binary, including the official channel where it happens because of supply chain attack or intentionally, etc.

This is not limited to apps, but also your kernel, driver, etc.

> [@Anon47486929](#):
>
> The privacy protection you attach to Matrix is ONLY available when you self host

Totally not true. The only possible realized attack surface and the vulnerabilities of the protocol you’ve shown until now requires a malicious home server, not when the user uses [matrix.org](http://matrix.org) server, or self-hosting. So, the user’s not required to self-host to get a _decent_ security and privacy protections. It also depends on the user’s usage, e.g. among family members and close friends vs friends and public spaces

> [@Anon47486929](#):
>
> In federated systems, security level of weakest setup is the security level of ALL setups.

This could be true, but it’s not working like what you think it’s. In a federal setup, each other setup is transparent (not totally, but more than the centralized one), including their reputation, etc. The user _needs_ to make their _sane judgement_ when choosing their server and client to use, the same way when they pick up any centralized services. The clear difference is that in a centralized service, the user has no choice of the server and the client they can use, hence everything is controlled by 1 entity.

> [@Anon47486929](#):
>
> Why Signal is better here is because everyone uses the same setup.

1. Signal is worse.
2. Not everyone is using the same setup. One might compile their client from source, while most people download the binary, and there’s definitely someone who grab the binary from unrepeatable source that could be malicious. Nonetheless, Signal themself could alter the binary at any time they want, and it would affect 99.99% of people downloading their app from the stores and their website. They control what the client the user can use, let alone the code that’s currently running on their server.

If you’re still thinking Signal doesn’t require trust, I think I just talked to the wrong person.

---

## Post 38 by @PurpleDime — 2024-12-23T09:47:12Z

I’m sorry, what am I missing? That the pricing page is only for businesses? I don’t see a link for regular users where it says it’s free.

---

## Post 39 by @dngray — 2024-12-23T10:37:03Z

Wow this thread is a mess and I’m not going to address every single poin in it suffice to say if you’re selecting a messenger listed on [our page](https://www.privacyguides.org/en/real-time-communication) it’s likely going to be secure enough.

While some messengers like Matrix have more metadata than say Signal due to the fact they’re federated, I would not describe them as “wildly insecure” or anything alike that.

Just note, though there are certain caveats with session and simplex, for example session does not allow for large attachment sizes (that may not be an issue), and Matrix allows for larger rooms with more participants.

---

## Post 40 by @dngray — 2024-12-23T10:37:07Z


