# Why is Simplex considered the best messenger app?

**URL:** https://discuss.privacyguides.net/t/why-is-simplex-considered-the-best-messenger-app/26151
**Category:** Questions
**Created:** 2025-03-26T02:25:09Z
**Posts:** 62

## Post 1 by @gribs — 2025-03-26T02:25:09Z

I’ve seen several people claim Simplex is the best messenger app in terms of privacy and security, but does that still stand after reading the threat model page? Personally I was surprised by what can be done.  
Click show origional.

 ![Capture+_2025-03-26-02-15-45](//forum-uploads.privacyguidesusercontent.com/original/2X/6/60177cc02e4270d8ec793bdfaf4d3c72d1ea164a.png)

> <https://github.com/simplex-chat/simplexmq/blob/0c3b25706ac138af78f2dfb86d770b632d39f13a/protocol/overview-tjr.md#threat-model>

---

## Post 2 by @anon36940904 — 2025-03-26T02:30:28Z

What would you like it to rather not do from the list you shared?

---

## Post 3 by @gribs — 2025-03-26T02:44:50Z

Well, everything. Its supposed to be anonymous yet a server can see and watch everything from everybody and link it back to real IP, so much for anonymous. I don’t think people would speak as highly of Simplex if they read that page.

---

## Post 4 by @anon36940904 — 2025-03-26T03:02:08Z

> [@gribs](#):
>
> Well, everything

Absolutely not true and objectively false.

I don’t think you understand how this app and service works. The app can’t see everything as you claim or think it does.

It is indeed anonymous, you can self host or use a VPN to mask your IP for good measure or have the app use the Onion network instead.

You should read the page you linked again and this too: [SimpleX Chat: private and secure messenger without any user IDs (not even random)](https://simplex.chat/#how-simplex-works)

You should also read what it cannot do, and the entire page again.

I don’t know if you’re new to privacy or not and how much you know about how to assess privacy app info even from a technical POV, but I think you’re misguided and misunderstanding SimpleX Chat. Please read up more on it and ask specific questions if you have any. Rest assured, SimpleX is indeed fully private and as secure as it can be for what it is for now and may as well be one of the paragons of an encrypted messenger app.

> [@gribs](#):
>
> I don’t think people would speak as highly of Simplex if they read that page.

People have read that page. It still stands true for all that it claims.

---

## Post 5 by @gribs — 2025-03-26T03:04:53Z

Would you trust it with critical actions like whistleblowing against a government agency?

---

## Post 6 by @anon36940904 — 2025-03-26T03:06:57Z

Using the app for that is one thing, but your device and other opsec must also be ideal for you to be safe if you or anyone wants to do that.

But since you asked, all other things ensured, yes I would. But if state actors are actively and particularly targeting you, then know that no app or system is 100% perfect so you’ll have to choose the best “bad” option. In this particular case, I would then use OnionShare instead. But you can certainly use SimpleX too. It would not matter a lot or won’t be too big a difference.

---

## Post 7 by @yipii — 2025-03-26T03:08:14Z

The main difference here is that simplex chat does offer you a thread model page, with clear things written of what is possible and what is not. Of course it’s more frightening than having … Absolutely no list and and see none of those threats if you look at whatsapp or facebook messenger. Dont be affraid of having more info and a better communication that other app. Aso don’t imagine perfect security and privacy exists. Simplex help you by giving you am accurate picture and keeping you grounded.

---

## Post 8 by @gribs — 2025-03-26T03:08:43Z

You also run the risk of loading Simplex by mistake before starting tor or VPN and then you get leaked to the app designed to keep you secure.

---

## Post 9 by @anon36940904 — 2025-03-26T03:11:57Z

And that’s what I mean by opsec. It is upto the user to be cautious of these other factors first. And that’s why its best to do this in a public space and not in a residential area if forgetting to turn on VPN is a likelihood.

But again, this is a simple thing you must remember if you’re really going to partake in critical actions like whistleblowing.

---

## Post 10 by @anon36940904 — 2025-03-26T03:14:41Z

Hell, you can also use Signal in a pinch for this type of work. Metadata collection is minimal if any, Signal doesn’t and cannot know anything about anything except just to register you with any phone number on which you can get 1 SMS and the last time you were online on Signal.

All other data, as far as I know and understand is private, secure, and encrypted.

---

## Post 11 by @anon36940904 — 2025-03-26T03:18:06Z

> [@gribs](#):
>
> then you get leaked to the app designed to keep you secure.

It is indeed designed to keep you secure. But a user must also use it properly for it to work for you and not against you. It’s like driving a car, you only do it if you know how to. And if you know how to, it will work exactly how its supposed to. If you don’t, you are not safe.

---

## Post 12 by @gribs — 2025-03-26T03:20:05Z

Would it work to use a VPN router so its not possible to forget? Signal needs phone number which nobody would want tied to them just in case it turns out Signl is lying.

---

## Post 13 by @anon36940904 — 2025-03-26T03:22:24Z

> [@gribs](#):
>
> Signal needs phone number which nobody would want tied to them just in case it turns out Signl is lying.

Signal is not lying. I assure you. If you want, you can get a number from ([https://www.smspool.net/](https://www.smspool.net/)) very cheap and register. It doesn’t use your phone number as your identifier or a PII.

> [@gribs](#):
>
> Would it work to use a VPN router so its not possible to forget?

Sure, you can do this. But it’s best to have the VPN set up on device for easy control and management of your connections. Plus, I would use an Android phone with GrapheneOS if you’re on mobile for even better protections all around - again, if this is the type of critical work you’re trying to do. If you’re on mobile, you can choose when you want to be on a VPN and when you want to be on the Onion network.

---

## Post 14 by @anon36940904 — 2025-03-26T03:29:08Z

You should also know that while all I am saying here is as true as I know it to be - I am not an authority on whistleblowing or a technical expert in esoteric and highly critical matters like this.

What I am suggesting and sharing are indeed the best ways to go about it but I am not guaranteeing 100% safety for you with all I am sharing here now. There may be others on the forum with better suggestions and more information. I don’t think anyone can give you 100% safety but I’m still saying.

While you can keep asking follow up questions and I can keep responding, I also suggest waiting a few days while other community members respond with their thoughts before you decide anything for yourself - if this is really what you’re planning on doing.

–

That’s my disclaimer in all honesty and in good faith.

---

## Post 15 by @gribs — 2025-03-26T03:38:46Z

I’m not actually planning on critical whistleblowing, that was just an example.

---

## Post 16 by @anon36940904 — 2025-03-26T03:39:31Z

I see

So much for all that typing. But now you know, nonetheless.

---

## Post 17 by @anon36940904 — 2025-03-26T03:41:58Z

But I believe I have answered your titular and follow up questions as best as I can for now.

---

## Post 18 by @maqp — 2025-03-26T04:25:37Z

It’s not. [https://discuss.privacyguides.net/t/simplex-vs-cwtch-who-is-right](https://discuss.privacyguides.net/t/simplex-vs-cwtch-who-is-right)

---

## Post 19 by @anon63378630 — 2025-03-26T09:46:39Z

> [@anon36940904](#):
>
> Signal is not lying. I assure you.

Signal very well _could_ be lying or be co-opted.

---

## Post 20 by @anon36940904 — 2025-03-26T13:42:43Z

Sure, anything could be the case. Nothing is impossible. Anything can happen. By this logic, don’t trust anything or anyone for any reason.

But that’s not what all evidence we have thus far points to now does it. And we have to trust something at some point and accept whatever implausible risks to at come with it.

Boy, if that’s the thinking one operates their life with, one ought to not use technology at all and we should only trust what we can make and build ourselves that has no dependencies whatsoever. Such an impractical mindset.

I refuse to believe you’re not smart enough to realize that trust has to begin somewhere. And if Signal is not what you trust, then either you have and significantly higher threat model with legitimate concerns that a nation state is actively looking to attack you at all times or that you simply wanted to point out that anything could happen even though it is highly implausible and unlikely just for the sake of it.

I’m sorry, but this type of comment that could have a basis for being true but does not from all we know thus far is irksome and counter productive to any discussion.

---

## Post 21 by @anon63378630 — 2025-03-26T13:47:46Z

> [@anon36940904](#):
>
> By this logic

That isn’t what I’m saying.

> [@anon36940904](#):
>
> all evidence we have thus far

If it was the baby of the USG, why would they let their own courts expose it?

And to be clear, I’m not against Signal, I just don’t think it is appropriate to proclaim _without a doubt_ that they aren’t lying when you (and I) are not in the position to do so.

---

## Post 22 by @anon36940904 — 2025-03-26T13:48:50Z

I’m not proclaiming anything. You have my disclaimer above.

---

## Post 23 by @florahammock — 2025-03-26T14:52:24Z

In the order of your list:

1. Yes, the server knows when a computer connects to it.
2. Yes, the server knows how many messages pass through it. Unless you want clients to send a random number of spam dummy messages? Easily resolved with more users sending encrypted comms.
3. people should be notified about messages they receive. Perhaps this can be updated once the app becomes popular, but you’re not signing up anybody who has to login/decrypt to see if they got a new message.
4. this one is just a problem because the service isn’t i2p. server needs to know how to deliver messages even if it doesn’t know who sent the message.
5. again, server needs to know the destination of a message. again, retreive your message through tor.
6. this one is just “server can be bad, roll your own if you’re paranoid”
7. same as point 6. if you don’t trust the server then roll your own.

---

## Post 24 by @gribs — 2025-03-26T19:16:59Z

The whole thing just feels like a giant honeypot or an accident waiting to happen.  
They talk so much about their anonymous features and lack of ability for any one party to know anything about anybody when you view the front page od their website, its only when you dig through the threat level page that you see the true weaknesses. As stated in the Cwtch thread, that feels misleading to say the least.  
Another big concern is how this software is focused mostly towards spyware laiden smartphones with the desktop option hidden at the bottom of their page. They also suggest tor as a fix to their inbuilt IP leaks, but even their own [guide](https://simplex.chat/blog/20220808-simplex-chat-v3.1-chat-groups.html) only tells you how to go about it on smartphones. I saw this app being talked about on the Dread tor forum with lots of people backing it, I also saw an [article](https://www.pressreader.com/usa/the-guardian-usa/20241005/281608130862081) about how terrorists are moving over to Simplex.  
Could it be that Simplex _looks and sounds_ safe but is actually designed to lure criminals and legitimate targets into a trap?  
A place where there is encryption, tor, mixed servers and all that yet still vulnerable? Ricochet chat used all those things but still got breached. So far I haven’t seen anything which makes me trust any of it.

---

## Post 25 by @beantaco — 2025-03-26T23:13:39Z

> **SimpleX Messaging Protocol server**
> 
> _can_:
> 
> - learn a recipient’s IP address, track them through other IP addresses they use to access the same queue, and infer information (e.g. employer) based on the IP addresses, as long as Tor is not used.

If a SimpleX server can do this, doesn’t it render the 2-hop message delivery system useless?

My concern about SimpleX is they [don’t sign their releases](https://github.com/simplex-chat/simplex-chat/issues/3158), and they rely on build systems outside of SimpleX’s control to build releases (making release signing useless). Until the team resolves this in a satisfactory manner, I would avoid using SimpleX.

---

## Post 26 by @dogeyes — 2025-03-26T23:43:30Z

> [@gribs](#):
>
> Would you trust it with critical actions like whistleblowing against a government agency?

I’ve seen messages like that before, and I’ll just say this: would you trust a tank (yes, a tank, a war tank) to protect your physical safety? The answer to that question is probably a dozen questions instead of a clear and concise answer. I hope you understand the comparison.

---

## Post 27 by @jonah — 2025-03-27T01:26:28Z

> [@beantaco](#):
>
> doesn’t it render the 2-hop message delivery system useless?

~~What 2-hop system?~~ This entire forum topic just has me convinced that nobody understands how SimpleX works :flushed_face:

---

## Post 28 by @gribs — 2025-03-27T01:37:57Z

> Private message routing is a major milestone for SimpleX network evolution. It is a new message routing protocol that protects both users’ IP addresses and transport sessions from the messaging relays chosen by their contacts. Private message routing is, effectively, a 2-hop onion routing protocol inspired by Tor design  
> [SimpleX blog: SimpleX network: private message routing, v5.8 released with IP address protection and chat themes](https://simplex.chat/blog/20240604-simplex-chat-v5.8-private-message-routing-chat-themes.html#private-message-routing)

> Nobody understands how SimpleX works

How about you tell us then?

---

## Post 29 by @jonah — 2025-03-27T02:08:15Z

I did actually forget they added private message routing. However, it was never intended to protect you _from your own relay servers_, which is probably why it wasn’t particularly memorable to me.

Prior to SimpleX 5.8 what was possible was that the recipient of your messages could read your IP directly, because your device would send the message directly to the relay server they controlled.

The 2-hop system in 5.8 just means that instead of your device directly connecting to a server the recipient controls, it now directly connects to a server you control before that.

In most cases the server you’re trusting here and the server the recipient is trusting is the same server operated by SimpleX themselves, so no information is hidden from them. They’ve never claimed to provide anonymity from the SimpleX network’s perspective, and the 2-hop system doesn’t change that.

---

## Post 30 by @fria — 2025-03-27T02:15:32Z

They actually partnered with [Flux](https://simplex.chat/blog/20241210-simplex-network-v6-2-servers-by-flux-business-chats.html) so now you can have a two party relay system going. You do have to accept Flux’s terms of service before it’s enabled however.

---

## Post 31 by @jonah — 2025-03-27T02:17:57Z

Yes but my _point_ is that it does not and was never intended to protect you from the server you choose to use, like Tor would.

It is not a feature which provides you with anonymity, it is a feature which hides your IP from the recipient of your message, which is information that SimpleX’s original design would have leaked.

---

## Post 32 by @fria — 2025-03-27T02:21:47Z

> When both SimpleX Chat and Flux servers are enabled, the app will use servers of both operators in each connection to receive messages and for [private message routing](https://simplex.chat/blog/20240604-simplex-chat-v5.8-private-message-routing-chat-themes.html), increasing metadata privacy for all users.

I’d say it’s clearly intended to protect either party from knowing both your IP address and the IP address of the recipient.

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/9/9a7619be68bf6b4616f757b64220a3453f0311bf.png)  
You can see there’s two hops for both sending and receiving, both using servers from simplex and flux.

---

## Post 33 by @gribs — 2025-03-27T02:33:07Z

> They actually partnered with [Flux](https://simplex.chat/blog/20241210-simplex-network-v6-2-servers-by-flux-business-chats.html) so now you can have a two party relay

And their ToS probably means they’ll screw you over straight away if compelled.  
When talking to a stranger on Simplex you have to be anonymous or fully encrypted to all of these at the same time otherwise there is zero anonymity and that means zero safety: ISP, Simplex, Simplex server owner, Flux server owner and whoever you are talking to. Tor is lots of people and companies spread all over the globe, Simplex is in the UK (terrible country for security and privacy online), plus Simplex and Flux is 2 companies who’s servers are owned by ??? different users across ??? different countries. The lack of secure digital signature is an accident waiting to happen too.

---

## Post 34 by @jonah — 2025-03-27T02:37:01Z

> [@fria](#):
>
> You can see there’s two hops for both sending and receiving

Where is that shown in this screenshot…?  
Also check Matrix I sent you my SimpleX contact lol

> By default, if both Flux and SimpleX servers are enabled in this version, you will be using SimpleX Chat servers to receive messages, Flux servers to forward messages to SimpleX Chat servers, and the servers of both to forward messages to unknown servers. We will enable Flux to receive messages by default a bit later, or you can change it now via settings.

I guess this is true what you are saying, but it is non-default behavior.

> **[Servers operated by Flux - true privacy and decentralization for all users](https://simplex.chat/blog/20241125-servers-operated-by-flux-true-privacy-and-decentralization-for-all-users.html)**

* * *

I still **definitely** would not rely on this over Tor for anonymity. I am slightly concerned that people seem to think this can replace onion routing.

---

## Post 35 by @gribs — 2025-03-27T02:39:27Z

> [@jonah](#):
>
> I am slightly concerned that people seem to think this can replace onion routing.

Maybe they shouldn’t have called it onion routing which confuses people. I’m still yet to be convinced as to why Simplex is the most secure, private and anonymous messenger out there right now. It could perhaps be improved by added tor into the software rather than depending upon orbot for mobile or some unknown bodge for desktop.

---

## Post 36 by @jonah — 2025-03-27T02:58:17Z

Personally I wouldn’t say/claim that it is all of those things. I am not really sure _SimpleX_ would claim all of those things either. They don’t mention anonymity on their homepage, except that your _identifier_ is anonymous, which is _true_… but is not the same as _being_ anonymous.

I guess clearly I need to brush up on what SimpleX has been up to lately though.

When we added SimpleX to the website, it had a very straightforward design, and had a clear threat model. It was very usable in virtually all scenarios where an app like Signal might be usable, but it had the advantage of not requiring sensitive information like phone numbers.

Since then SimpleX has evidently added additional features, which may improve privacy, but they’re still optional and have clear drawbacks compared to actual anonymity networks like Tor.

Anyways, all I feel comfortable saying is that **at minimum SimpleX is just as good as Signal in most scenarios.** I can say that because it was true when we listed SimpleX, so it should still remain true after they’ve added these new features.

I wouldn’t rely on it in scenarios where you wouldn’t also trust Signal though, like for total anonymity. That being said, paired with Tor it should be better than Signal simply because you can use SimpleX over Tor without providing any identifiers like a phone number, which is a huge advantage.

…Does that answer your original question? Or are you not even convinced SimpleX is at Signal’s level?

---

## Post 37 by @yipii — 2025-03-27T04:38:54Z

Its quite sad that most of the time simplex is mentioned, it’s to bash about it not supporting a perfect something. Id argue that most people are not using it for life and death situation. Yet they ways come back on technical points, based on a theorical life and death issue. Then the requestor will let us know that its’ just for argument sake, cause there are not in that life of death argument.

I’m in for good faith argument with concrete details, and useful argumentation, but this thread is mostly question asked with a superior bragging position (just look at the title). I do like SimpleX, it a good software, and if you take the time to look at the announcement and explanation, its very interesting the new technologies they are developing. However I’m starting to think that community around the software is very bad, perhaps even with an agenda aganst simplex creator.

Opinion piece yes, hope to not get banned here.

---

## Post 38 by @yipii — 2025-03-27T04:44:21Z

For those interested,  
Documentation for private routing

> **[SimpleX network: private message routing, v5.8 released with IP address...](https://simplex.chat/blog/20240604-simplex-chat-v5.8-private-message-routing-chat-themes.html)**

Section 2-hop

> <https://github.com/simplex-chat/simplexmq/blob/0c3b25706ac138af78f2dfb86d770b632d39f13a/protocol/overview-tjr.md#threat-model>

Also, I wasn’t really on with flux crypto bro joining simplex recently, but one of the thing they said in the phone interview that interested me was : by using decentralized infrastructure for server hosting, (right now not many server, but thousands in the future), it become much more difficult to censor and detect the network, than to censor a centralized system. At the end, you cant block amazon, gcp and aws ips, and decentralized network is any small operator offering service all around the world.

---

## Post 39 by @securitybrahh — 2025-03-27T07:28:53Z

idk if these are covered here but some practical problems with app:

1. Client side ram usage
2. UX parity not as good as telegram
3. Just slow (probably because of how the client interacts with the servers?)
4. The biz model is not in sight yet, server load is minimum, ig then ppl can provide them on good will? I thought they were implement “stamps” for server donations.

---

## Post 40 by @ignoramous — 2025-03-27T08:36:24Z

> [@jonah](#):
>
> Anyways, all I feel comfortable saying is that **at minimum SimpleX is just as good as Signal in most scenarios.** I can say that because it was true when we listed SimpleX, so it should still remain true after they’ve added these new features

Nah, don’t think one can assume that. In fact, it is the reverse.

More features means more attack surface and attack vectors.[[1]](#footnote-86947-1)

Signal folks are (were?) very deliberate in design & impl when adding new features, or at least they were until moxie was at helm (though, jlund is no slouch either)! That isn’t to say Signal is infallible, but more code + more features is … more pwnage, not less, unless there’s concerted and deliberate effort to avoid it.

* * *

1. See also IPsec v OpenVPN v WireGuard [↩︎](#footnote-ref-86947-1)

---

## Post 41 by @yipii — 2025-04-01T17:16:05Z

Agree, more possibility by using more code usually comes with more risks.

I think the vision is different and this has a big impact in everything. I searched but could not find the reference, but I read on simplex chat blog that they are trying to reach a mass adoption of the software broadly in order to improve the privacy of everyone on the planet.  
In order to reach this goal, they needs to offer a very good ui and all of the features that are commonly offered by non private messengers.

The quote was something like: adding sticker support to our application seems like a loss of time, but if the missing support of sticker is what prevent everybody to join simplex, then in order to improve privacy globally, we need to add sticker support. Sorry that I could not find a reference to the quote.

So yeah… If you need to configure tor or if you can only send message when both people are online, its not usable by the vast majority of the population thus its not going to won or improve the market. Its fine to develop a tool for the few person with a higher thread model, but with all the difficulty of uses, it will probably not go worldwide.

In another thread about simplex, maqp mapq ? Write a nice message about simplex not advertising their capability accurately. I tend to agree. However he was also requiring a metadata resistant messenger, which might be more on the higher thread level with specific person in mind, and not a software that aims to reach global usage for common folks.

---

## Post 42 by @ignoramous — 2025-04-01T17:34:30Z

> [@yipii](#):
>
> However he was also requiring a metadata resistant messenger, which might be more on the higher thread level with specific person in mind

Think you might be misremembering. It isn’t maqp who is holding SimpleX to any unreasonably high standard, it is SimpleX’s marketing that is (at least according to maqp).

> [@SimpleX vs. Cwtch, who is right?](https://discuss.privacyguides.net/t/simplex-vs-cwtch-who-is-right/19256/112):
>
> Because SimpleX is trying to market itself as more private than Cwtch, it sets itself on nothing short of the ~highest pedestal in the category of metadata resistant messaging.

---

## Post 43 by @maqp — 2025-04-01T20:51:45Z

Yeah, like I said in the thread, an app that sends a copy of every message to the NSA, that openly tells it sends a copy of every message to the NSA, is a secure app.

It’s the what’s advertised not meeting what’s offered, that’s the problem. I’m not against SimpleX if it accurately conveys its threat model. I’m against anything that doesn’t, and the app is only one of half-a-dozen I’ve criticized.

I also have zero problem changing my opinion. I complained about iMessage for years, then it upgraded from RSA-1280 into the post-quantum thingy with safety numbers and all. Now I think it beats WhatsApp. But since it’s proprietary, it doesn’t go higher than Signal, even if the protocol is apparently slightly better on paper. I used to complain about Matrix and its crappy E2EE across clients, and now I have no trouble recommending it for large institutions who need E2EE.

I have no trouble recommending SimpleX once its walk matches its talk.

> [@yipii](#):
>
> perhaps even with an agenda aganst simplex creator.

I’m not **against** SimpleX out of principle, I’m **for** the users out of principle.

---

## Post 44 by @yipii — 2025-04-01T21:16:29Z

Yes i’ve not clearly communicated. Obviously they needs to be accurate in their marketting.

---

## Post 45 by @thinker — 2026-03-30T21:41:22Z

I think Simplex is the most secure APP now on the market, if somebody knows a better one share it with proof.

---

## Post 46 by @Cyber-Typhoon — 2026-03-30T22:22:18Z

Briar? What do you mean by proof?

SimpleX is cool but did they add the feature to send things like stickers? I dropped it long ago because of that. My friends and family only accepts Signal because it has those friendly things.

---

## Post 47 by @thinker — 2026-03-30T22:27:53Z

SimpleX is one of the strongest options for privacy, Briar also, but I chose Simplex. By proof I mean if somebody has a better app for privacy and to prove why.

---

## Post 48 by @anonymous590 — 2026-03-31T00:56:18Z

> [@thinker](#):
>
> Simplex is the most secure APP now on the market

> [@Cyber-Typhoon](#):
>
> SimpleX is cool but did they add the feature to send things like stickers?

Off topic, but I found this hilarious.

---

## Post 49 by @Cyber-Typhoon — 2026-03-31T01:18:25Z

> [@anonymous590](#):
>
> Off topic, but I found this hilarious.

It is, but sad at same time. It is hard to find people born after the 2000’s that accepts things like chat communication without those “conveniences”. Anyways, the most secure is probably not the case where my family fits. If I was an activist or journalist I’d be looking at SimpleX and Briar.

---

## Post 50 by @maqp — 2026-03-31T01:36:54Z

> [@thinker](#):
>
> By proof I mean if somebody has a better app for privacy and to prove why.

Read this thread

> [@SimpleX vs. Cwtch, who is right?](https://discuss.privacyguides.net/t/simplex-vs-cwtch-who-is-right/19256):
>
> Two years ago, Sarah, one of the main people behind Cwtch, made this statement: Then the founder of SimpleX replied to her, and this is where it ended. This year, Sarah posted multiple posts about SimpleX on Mastadon: So clearly one of these people is lying to us, but I don’t have the technical knowledge and capabilities to tell who is right and who is wrong. It would be great if someone knowledgeable about this topic could step in to clarify these things for us. It would also be intere…

---

## Post 52 by @anonymous590 — 2026-03-31T02:23:09Z

> [@Cyber-Typhoon](#):
>
> It is hard to find people born after the 2000’s that accepts things like chat communication without those “conveniences”.

> [@Cyber-Typhoon](#):
>
> Anyways, the most secure is probably not the case where my family fits. If I was an activist or journalist I’d be looking at SimpleX and Briar.

Completely agree :sweat_smile: SimpleX isn’t going to be used by me or my friends any time soon, no matter how much I care about my privacy. That’s the unfortunate reality we live in :frowning: It’s just so funny to imagine that someone won’t use X tool/service because of Y feature (or lack thereof) despite Y being the least of your worries.

 ![average privacy advocate POV](https://forum-uploads.privacyguidesusercontent.com/original/3X/8/a/8a1a829b94082418fd57a71175f1183fb60b47b6.png)

> [@ctf](#):
>
> It is a valid complaint tbh

> [@ctf](#):
>
> Security tools are only good if they are used right

It’s a valid complaint when you take into account social dynamics. Is it a valid _security_ complaint? Definitely not. Good and bad depends on the context. Is it bad security? no. Is it bad for advancing privacy to the masses? yes.

---

## Post 54 by @YellowBook — 2026-03-31T14:19:11Z

You could use EweSticker (FOSS android app) and paste stickers from there.

It works as an alternative keyboard, once you are done pasting the sticker you can switch to the normal keyboard.

Hope this helps :grinning_cat_with_smiling_eyes:

---

## Post 55 by @anonymous590 — 2026-03-31T15:30:47Z

> [@ctf](#):
>
> The thread has some valid security complaints I agree with.

I wasn’t talking about that. I was talking about your comment on this

> [@Cyber-Typhoon](#):
>
> but did they add the feature to send things like stickers

> [@ctf](#):
>
> It is a valid complaint tbh

---

## Post 56 by @Skysurfer — 2026-04-26T13:35:45Z

I’m surprised nobody has mentioned the fact that Jack Dorsey is the majority funder of SimpleX. That means he has majority control over it. He co-founded Twitter which started off with a ‘pure’ platform but morphed into working with government banning, censoring and surveilling it’s subscribers to fit a desired narrative/agenda. To me that alone is a major reason to consider SimpleX a major risk.

---

## Post 57 by @maqp — 2026-04-26T15:39:26Z

> [@Skysurfer](#):
>
> To me that alone is a major reason to consider SimpleX a major risk.

Nah. No tech company deserves your trust. It doesn’t matter who’s running the show, because (nation state) hackers are going to breach the vendor side at some point anyway, so you assume the worst from the vendor, always. SimpleX, like every app out there, is exactly as secure as the the client let’s it be:

**Content privacy**

- Is SimpleX E2EE by default for all chats? Yes.

- Is the client open source so you can check? Yes.

- Can you build the binary reproducibly? At least [GitHub points to yes](https://github.com/simplex-chat/simplex-chat/blob/b7876614b8a597decdfdb33de7415910a249248d/scripts/simplex-chat-reproduce-builds.sh).

**Metadata privacy**

- Is it peer-to-peer so there’s no server with access to metadata? No

- Does it anonymize connections to server with Tor by default so server can’t tell who the users are by their IP? No, so it can infer who’s talking to who.

- Does it feature traffic ~~masking~~ flow confidentiality to hide when, how much and what type of communication takes place? No.

- Do we have court evidence to show they have nothing collected about their users? AFAIK no.

So SimpleX is content-private by design, and not metadata-private at all.

Use it under that threat model and it’s fine. Need metadata protection? Look into more secure alternatives like Cwtch, Briar, and Quiet.

---

## Post 58 by @jerm — 2026-04-26T16:14:02Z

> [@maqp](#):
>
> Is it peer-to-peer so there’s no server with access to metadata? No

How would that work? Something like Briar? See [Add support for bluetooth/local wifi messaging · simplex-chat/simplex-chat · Discussion #1501 · GitHub](https://github.com/simplex-chat/simplex-chat/discussions/1501)

> [@maqp](#):
>
> Does it feature traffic masking to hide when, how much and what type of communication takes place? No.

Doesn’t padding count as traffic masking which SimpleX already does?

---

## Post 59 by @maqp — 2026-04-26T16:45:45Z

> [@jerm](#):
>
> How would that work? Something like Briar?

Yeah more or less. You can use say Tox over Tor, or you can use messaging tools that operate via p2p model using Onion Services and web clients.

> Doesn’t padding count as traffic masking which SimpleX already does?

That’s just basically rounding to nearest block size with say PKCS#7. It has nothing to do with traffic flow confidentiality (should’ve used that term above, I’ll fix it) where you have continuous stream of noise data being transmitted, and into which you inject packets you send.

---

## Post 60 by @ignoramous — 2026-04-27T22:04:38Z

> [@maqp](#):
>
> Does it anonymize connections to server with Tor by default so server can’t tell who the users are by their IP? No, so it can infer who’s talking to who.

With Signal’s _[sealed sender](https://signal.org/blog/sealed-sender/)_, does Signal meet this criteria if exclusively used over proxies (not onion/mixnet) built into their clients?

---

## Post 61 by @maqp — 2026-04-28T15:04:52Z

Sealed sender means the server just strips the sender information when they write it to cache. If the server is not compromised in that malware or malicious developer puts the feature back it makes the cached ciphertexts much less useful to attacker as they can at most infer who is popular. So it’s not nothing in practice; we can see in court documents Signal does indeed not have that data to hand out. But as per the criteria of “is it metadata protection by client”, nope.

As for the proxy, I’m unsure what you refer to, the [TLS proxies](https://signal.org/blog/proxy-please/)? If it’s those, then in principle the server would get the proxy’s IP-address, but Signal knows its users’ phone numbers in principle. They do anonymize it again if someone comes asking with a warrant but it’s again not something the client can mask for the user, unless the user takes separate steps of non-KYC SIM and Tor.

The threat model with Signal’s sever-side hardening gets murky if you want to build it around what they promise and try to deploy there. It’s not entirely clear to me which parts of the server’s functionality can the remote attestation check. So IMO it’s just easier to assume Signal is metadata private by policy, i.e., they could collect metadata if they wanted, but as per court docs, they don’t, and content private by design (client has excellent E2EE).

---

## Post 62 by @anon16634871 — 2026-05-01T18:53:14Z

What do you think of the Android apps that “freeze” other apps from running in the background? Some OEM’s provide this where you could select an app that you don’t want running, enable your VPN/tor first and then unfreeze it?
