Rate this post

🔒 Signal is one of the most secure messaging platforms on the planet but let’s be clear: encryption has limits.

Meredith Whittaker, president of the Signal Foundation, and her team have done extraordinary work building and maintaining the Signal Protocol securing trillions of messages across Signal, WhatsApp, and beyond. As she said in a recent interview:

“Signal is the nervous system of secure government, corporate, military, human rights, and journalistic communications.”

But here’s what needs to be said more often: true privacy doesn’t begin at encryption it begins at the device level.

Even with Signal’s unmatched encryption, sophisticated adversaries state actors, hackers, or corporate spyware vendors can and do exploit devices before encryption ever kicks in. This includes:

• Keyboard input interception

• OS or firmware vulnerabilities

• Zero-click spyware (e.g. Pegasus)

• Baseband and hardware level exploits

The takeaway? If the phone is compromised, encryption is irrelevant. The message is captured at the endpoint before it’s ever protected.

Signal is a critical tool, but it’s not magic. For high-risk individuals, journalists, or activists, app security must be paired with hardened devices (like GrapheneOS), strict opsec, and an awareness of threat modeling.

Whittaker also nails the deeper issue:

“We’ve created an economic engine that rewards surveillance and doesn’t value the kind of privacy Signal offers.”

Until the economic model shifts and until endpoint vulnerabilities are taken as seriously as app-level onesprivacy remains conditional.

#Signal #Encryption #Privacy #CyberSecurity #MeredithWhittaker #SecureMessaging #GrapheneOS #ThreatModeling #OpSec #Pegasus #InfoSec #EndpointSecurity #LinkedInThoughts #bugged #bugged.com #stealthphone #michaelperos

View profile for Marc Hijink

Author of FOCUS – The ASML Way; technology columnist NRC Amsterdam

 

In a world dominated by tech bros, Meredith Whittaker has the academic muscle and the wit to question their power. As president of the Signal Technology Foundation, she leads a team of 50 people responsible for the #Signal app and the encryption protocol securing trillions of messages in WhatsApp, Facebook and Google Messenger.

“Signal is the nervous system of secure government, corporate, military, human rights, and journalistic communications—whenever there is anything sensitive to share. So you can’t just fuck off and go to the beach if there’s work to be done. If you don’t want to carry that responsibility, go optimize ads for AirBnB.”

Some of my favourite quotes from this week’s interview with Meredith Whittaker in NRC.

1 – Signal’s >14% market share in the #Netherlands

“The Netherlands said: fuck #Meta, and everyone downloaded Signal. We love you.”

2 #Signalgate at the Pentagon

“We made sure this big soap opera story wasn’t narrated sloppily as a Signal problem. It wasn’t really about us, like a car crash isn’t really about the road.”

3. Google #Search & AI

“This search engine has busted itself by trying to wedge so many ads and weird AI summaries in there, that it’s hard to get good information. That transformation has happened so rapidly, it’s shocking.”

“What I do not see is a vision, a North Star that is leading. What I see is a series of anodyne compromises made by people who are probably watching their own back more than they are watching out for the future of Google.”

4. #AI in government and #military

“Large AI models are being pushed into government and military contracts, because the consumer market fit has not been sufficient to date to generate the kind of revenue you need to actually make money.”

“What I’m saying here is not an indictment of the military, but historically, where do you go to sell technology that doesn’t work that well? You sell it through large government contracts with a vendor lock-in – like the Star Wars system during the Reagan era.”

5. #Hype and emperor’s clothes

“Technology is an apex of power and there’s a willingness to believe the hype, a willingness to fake it, and an unwillingness to ask basic questions that could dismantle hype narratives.”

6. Privacy vs #profits

“We’ve created an economic engine of tech that rewards surveillance and data collection and does not have a business model for the type of privacy that Signal provides. All the norms are built around the current economic model. That needs to shift.”

7. #Europe missing out

“People in Europe regret that they missed out on having hyperscaler surveillance monopolies. But you don’t beat a monopoly by replicating it. It is more empowering to first think about what kind of future you want, for example regarding climate and democracy in Europe, and then consider what role technology can play in that.”

 

Meredith Whittaker. Photo: Florian Hetz