Locking down Signal (2024)

Also available in Spanish.

The encrypted messaging app, Signal, is quickly becoming a newsroom staple for communicating with sources, accepting tips, talking to colleagues, and for regular old voice calls and messages. While it’s a practical tool for anyone concerned with the security and privacy of their conversations, people working in newsrooms are particularly interesting targets, and should benefit from locking down Signal.

(If you’re not yet using it, learn how to get started here.)

Signal makes it easy to have a secure conversation without thinking about it. On its face, it looks and feels identical to your default text messaging app, but security experts so often recommend it because of what it does in the background.

First, Signal offers end-to-end encryption, meaning only conversational participants can read the messages. While regular phone calls or text messages allow your phone company to unscramble your conversations, even the team behind Signal can’t listen to them. You don’t need to take their word for it. Signal is open source, meaning the code is available for anyone to review. This also makes security audits simpler for independent specialists, who have torn apart the code and published findings that everything works as intended. Finally, Signal retains nearly no metadata — information about who spoke to whom, and when. (The developers proved as much in court.)

These are some of the advantages you want in an encrypted messaging app.

Because newsrooms can attract a lot of attention, journalists who already use Signal should consider hardening it against physical access, as well as unwanted remote access and network-based eavesdropping. So let’s talk about how.

Remote access and network eavesdropping

Confirm your connection security with safety numbers

Most messaging apps will not allow you to ensure the security of your connection with your conversational partners. But Signal allows you to verify that your session is encrypted to the right person (and not an eavesdropping third party).

First, open up a conversation with someone you want to talk to. Next, look for their “safety numbers.” These numbers represent the connection between your device and your conversational partner’s device.

iPhone users: Press your partner’s name (at the top of the screen) > View Safety Number
Android users: Press Settings (the “three-dot” menu) > Conversation settings > Verify safety numbers

You’ll see a your safety numbers and a QR code, representing the numbers.

If you and your conversational partner see the same numbers, your session is secure. You should verify your safety numbers over a different channel where you feel confident you’re talking to the right person, such as Twitter, Facebook, or Google Hangouts. If possible, exchange safety numbers in person.

If you and your contact are together in person, one of you can press “Scan code” on the safety number screen. Now, scan the other person’s QR code with your camera.

If you see a mismatch, something is definitely wrong and you shouldn’t talk over this channel. But chances are, your safety numbers will match. If everything looks good, mark your partner as “Verified.”

Locking down Signal (1)

You won’t need to verify safety numbers again until someone resets the session. For example, when you begin using Signal from a new phone, you will get new safety numbers.

You’ll receive a notification if your safety numbers with a partner have changed. If this happens, use another channel to verify that the session is secured before you continue communicating sensitive information.

Using secondary Signal numbers

Signal treats your phone number like a username, and journalists may not want to use and share a personal phone number with sources. The good news: You can register Signal with any phone number you have access to.

There are a few ways to get access to an alternative phone number. Read our guide here.

For those in the United States, the easiest way to set up a secondary number is with Google Voice. (Your Signal messages will still go over Signal servers, not Google servers.)

In most countries you can use a secondary SIM card to create another number. Read this post by Jillian York of the Electronic Frontier Foundation to learn more. You can also use an online service called Twilio to create a number for as little as $1 each month. Learn how here.

If you've already set up Signal with your personal phone number, you can change to a new number through your settings.

iPhone users: Press Settings (profile icon at top left) > Account > Change phone number
Android users: Press Settings (profile icon at top left) > Account > Change phone number

Registration lock with PIN

Use Registration Lock to lock in your Signal number.

iPhone users: Click Settings > Account > Registration Lock > Enabled
Android users: Click Settings > Account > Registration Lock > Enabled

Your account is protected by a PIN. This PIN will prevent your number from being re-registered from a different device, so write it down or keep it somewhere safe. This might be a physically hidden notebook, or password management software.

By default you are offered a short numeric PIN, but you can make it stronger by using a PIN that also enables text beyond the phone number.

iPhone users: Click Settings > Account > Change your PIN > Create alphanumeric PIN
Android users: Click Settings > Account > Change your PIN > Create alphanumeric PIN

Signal will occasionally nudge you with a prompt to re-enter your PIN to ensure you still remember it.

Disable link previews

Signal offers the ability to retrieve previews of web pages linked within a conversation. According to the developers, when this feature is enabled Signal makes direct requests to websites to generate these previews. In other words, link previews leak the websites you share in your conversation to those websites.

Confirm link previews are disabled.

iPhone users: Press Settings > Chats > Generate link previews > Disabled
Android users: Press Settings > Chats > Generate link previews > Disabled

Don't leak keyboard data

Many phones come with multiple keyboards for different languages and functionalities, and allow you to download customized keyboards. This can be useful, but keyboards can share data with third parties. For example, Google’s keyboard is enabled by default on many Android devices, and unless you customize your keyboard settings, you may unknowingly save keyboard data beyond Signal.

Android users should enable the “Incognito” keyboard in Signal.

Android users: Settings > Privacy > Incognito keyboard > Enabled

Beyond Signal, your choice in keyboard can affect your privacy so make sure you know which keyboard(s) you have enabled.

iPhone users: Settings app > Keyboard > Keyboards
Android users (may be slightly different, depending on your version): Settings app> General management > Language and input > On-screen keyboard

iOS users: Keep your Signal history off iCloud

Signal allows you to see your call history from your regular phone app. This might be convenient, but will also allow your iPhone to sync this call history with iCloud, including who spoke to whom, when, and the call length.

If you use iCloud and you don’t want to share call history on Signal, confirm it’s turned off here: Settings > Privacy > Show Calls in Recents > Disabled.

Why you want disappearing messages

While Signal lets you delete individual messages, these messages will only be deleted on your device. Instead, use Signal’s “disappearing messages” feature to remove messages from a conversation automatically, after a time amount of your choosing. This is particularly important for journalists concerned about messages on a source’s phone.

To turn on disappearing messages, first open a conversation.

iPhone users: Press on your partner's name at the top of the screen to open the settings menu for this conversation. Press "Disappearing Messages."

Android users: Press the settings (three-dot) icon in the top right corner. Press "Disappearing Messages."

Set the amount of time you'd like to keep the messages, between 30 seconds to four weeks, or a custom time of your choice. This works both for one-on-one conversations and group chats.

You can also set a default message disappearance time for new conversations.

iPhone users: Settings > Privacy > Default timer for new chats
Android users: Settings > Privacy > Default timer for new chats

Messages you've sent or received before enabling disappearing messages will still be there. If you want those to disappear, you will need to manually delete them.

Device security

The weak points in end-to-end encrypted conversations are the “ends”— the physical devices where the messages arrive in human-readable text.

There are a few things you can do to lock down your devices.

Password protect your device

Encryption won’t help with someone who gets access to your unlocked phone, so you’ll want to password protect your device. Exit Signal and turn on a passcode.

iPhone users: Settings app > Face / Touch ID & Passcode
Android users: Settings app > Security > Screen lock

Consider turning on screen lock

Unlocking your phone also means decrypting your messages. You can require one additional step to re-enter your password before unlocking Signal.

It doesn’t happen every day, but unlocked phones are stolen in plain sight — while walking down the street, or on the train. Likewise, maybe you allow your son or daughter to entertain themselves on your phone, but you don’t want them to see photos from your source.

iPhone users: Press Settings > Privacy > Screen Lock
Android users: Press Settings > Privacy > Screen Lock

Turn on disk encryption

If your phone is ever lost, stolen, or seized, it’s possible to copy and read any data on the device, including your encrypted messages. The good news: You can easily protect your device with disk encryption.

If you use a modern iPhone, congratulations! Your device is already encrypted.

Many modern Android devices are encrypted by default (e.g., Pixel devices, some phones in the Nexus and Samsung Galaxy lines). Check your Android system settings for disk encryption to make sure disk encryption is enabled. If not, setting up disk encryption is easy.

Hide screen in app switcher

Signal gives you the option to prevent a preview from being shown in your app switcher, unless you explicitly open the app.

iPhone users: Press Settings > Privacy > Hide Screen in App Switcher
Android users: Press Settings > Privacy > Screen Security

Notification privacy

Even when your phone is locked with a password, anyone who picks it up can still read the message and sender name from your lock screen.

iPhone users: Settings > Notifications > Show. To receive notifications with no information about the sender or the content of your messages, turn on “No Name or Content.”

Android users: Settings > Notifications > Show. To receive notifications with no information about the sender or content, press “No name or message.”

Updates and defending against malware

Many types of malware are designed to send screenshots of your messages, or recordings of conversations, to a remote hacker. The single best thing you can do is stay on top of software updates, which usually include security patches for your operating system, Signal and any other apps you have. Older devices that no longer receive security updates are at the greatest risk.

Safest choice: Only use your mobile device

Signal offers a desktop application, but it's safer to keep your messages only on your mobile device.

Desktop devices typically allow applications to talk to one another. Android or iOS devices deliberately isolate apps, requiring strict permissions for what data can be accessed, and when. Malware has a significantly more difficult time compromising your data on an updated mobile device.

Know the limits of end-to-end encryption

  • Using Signal only on mobile and locking down your device is a security win, but there are drawbacks if you lose your phone or need to purchase a new one. While the registration lock feature prevents others from taking your Signal number, it would also temporarily prevent you from being able to re-register your number.
  • Signal isn't designed to protect against live metadata surveillance, so it doesn’t protect your identity or the identity of anyone you talk to. It's best to assume you are identifiable to other Signal users.
  • Even if you’re practicing great security hygiene, your conversational partner can put your messages at risk if they are not being careful. Encourage others to lock down Signal as well.

For news organizations looking for more hands-on assistance with encrypted messaging tools and practices, please contact us about our training options. If Signal is a service you value, consider donating to support their work.

As an enthusiast with a deep understanding of secure communication tools, especially Signal, I can confidently explain the concepts and practices highlighted in the article you provided.

Signal has gained attention for its robust encryption, making it a go-to platform for secure conversations. The app's foundation lies in end-to-end encryption, ensuring only the intended participants can decipher messages. This stands in stark contrast to conventional calls and texts susceptible to interception by phone companies.

One standout aspect of Signal is its open-source nature. The app's code is available for review, allowing independent security experts to conduct audits and validate its security claims. These experts have dissected the code and confirmed its integrity, adding credibility to Signal's security protocols.

Regarding metadata, Signal minimizes the retention of such information, exemplified by a court case where the developers demonstrated the app's minimal metadata storage.

Let's break down the practices discussed in the article:

  1. Safety Numbers Verification: Users can confirm the security of their conversations by verifying safety numbers. This ensures encryption between devices and guards against third-party eavesdropping.

  2. Secondary Signal Numbers: Signal allows users to register with alternate phone numbers, crucial for journalists seeking anonymity when communicating with sources.

  3. Registration Lock with PIN: Adding an extra layer of security, the registration lock prevents others from re-registering your Signal number on a different device without a PIN.

  4. Disabling Link Previews: Prevents leaking of shared website information during conversations.

  5. Disappearing Messages: Automatically removes messages after a set duration, enhancing confidentiality, especially for journalists communicating sensitive information.

  6. Device Security Measures: Strategies include password protection, screen lock, disk encryption, hiding app previews, and notification privacy to safeguard messages from physical device breaches.

  7. Updates and Defending against Malware: Regularly updating the Signal app and device software mitigates potential vulnerabilities and protects against malware threats.

  8. Mobile vs. Desktop Usage: Using Signal solely on a mobile device is recommended due to stricter isolation of apps and reduced risk of data compromise.

  9. Limits of End-to-End Encryption: While Signal ensures message security, it doesn’t protect against live metadata surveillance, so maintaining awareness of identity exposure is essential.

  10. Encouraging Secure Practices: Encouraging others to secure their Signal settings also contributes to overall conversation security.

For newsrooms or organizations seeking guidance on encrypted messaging tools, tailored training options are available, and supporting Signal through donations can help maintain and enhance its services.

Understanding and implementing these practices can significantly bolster security for individuals, especially those in sensitive professions like journalism, ensuring secure and private communication channels.

Locking down Signal (2024)

FAQs

How do you lock a Signal? ›

Android users can manually lock Signal without a timeout. Swipe down from the top of your screen to view the notification tray > Lock Signal.

Can Signal messages be intercepted? ›

Signal offers end-to-end encryption, meaning only conversational participants can read the messages. While regular phone calls or text messages allow your phone company to unscramble your conversations, even the team behind Signal can't listen to them. You don't need to take their word for it.

Why is my message paused on Signal? ›

Sending, spinning or paused. What do I do? Signal uses your phone's internet connection for all private communication. The most common reason why you can't send messages is that you are not connected to the internet or have restricted Signal's internet access.

Is Signal app really private? ›

Signal is designed to never collect or store any sensitive information. Signal messages and calls cannot be accessed by us or other third parties because they are always end-to-end encrypted, private, and secure.

Can you lock Signal with a passcode? ›

To lock Signal, open its in-app settings and select "Screen Lock." Signal will use the same security method and passcode that your phone uses.

What does the lock mean on Signal? ›

Once the app is locked, only the rightful owner of the device will have access to the app, helping to ensure private messages remain private. Speaking of privacy features, Signal also offers a 'disappearing messages' option that allows users to apply a deletion timer on all messages and conversations.

Can cops get into Signal? ›

Our Services do not provide access to emergency service providers like the police, fire department, hospitals, or other public safety organizations.

Can Signal texts be recovered? ›

Signal messages, pictures, files, and other contents are stored locally on your device. If you have your old device, select the platform to transfer messages: Android.

Can Signal texts be subpoenaed? ›

Ephemeral usernames instead of phone numbers safeguard privacy — and makes Signal even harder to subpoena. March 4 2024, 5:00 a.m. In October 2021, an assistant U.S. attorney issued a subpoena to Signal demanding that the messaging app hand over information about one of its users.

How do you pause Signal messages? ›

To hide notifications, mute a chat:
  1. Open the chat with your contact.
  2. Tap the contact name or header to view chat settings.
  3. Tap. Mute.
  4. Select how long you want to mute notifications for this chat. 1 hour. ...
  5. You will see a mute icon. by the contact name or header. ...
  6. Optionally, choose to display a badge count for muted chats.

Why is my message sent but not delivered on Signal? ›

What can I do if my Signal message was not delivered? You can wait until your contact has an internet connection and their phone is able to retrieve Signal messages. Ask your contact to troubleshoot notifications for their device and ensure that battery optimization settings are not interfering with message delivery.

Is Signal Russian owned? ›

The Signal Technology Foundation, commonly known as the Signal Foundation, is an American non-profit organization founded in 2018 by Moxie Marlinspike and Brian Acton.

Is Signal a cheaters app? ›

Many people who cheat on their partners use secret messaging apps, like Signal, which allow them to chat with others discreetly. Depending on the cheating your partner is engaging in, whether sexual, emotional, or otherwise, there are different apps they might use to cheat or hide their behavior.

What are the disadvantages of Signal app? ›

Disadvantages Of Using Signal App

The application is decentralized and stores all data on the user's device, so if the information is lost or deleted, it will be impossible to restore it. It is also important to keep in mind that Signal does not support simultaneous use across multiple devices.

How do I block a Signal in my house? ›

You can use a thick wall, such as a concrete wall, or a physical barrier like a metal mesh or Faraday cage, to block the WiFi signal from entering the room. 2. Install a wireless signal blocker. There are devices available that will emit a signal that will block wireless devices from connecting to the WiFi.

How do I make my Signal private? ›

> Privacy > Phone Number > Who can find me by my number. This setting determines whether someone is able to see that they can message you on Signal by searching for your phone number. If everybody can find you by your phone number, you can choose whether everybody or nobody can see your phone number.

How do I block my mobile Signal? ›

Wire Mesh is widely used to protect key equipment from Radio Frequency Interference (RFI) and/or Electromagnetic Interference (EMI). A wire mesh 'Faraday' cage can also be used to screen mobile phone signals from entering a building.

How do you block electronic signals? ›

Materials That Can Block Radio Waves.
  1. Dielectrics.
  2. Conductors.
  3. Utilize the Sleep Canopies Designed for Protection.
  4. Apply a Shielding Paint.
  5. Use EMF/RF Blocking Wallpaper.
  6. Utilize Electric Filters.
  7. Use Window Shielding Films.
  8. Buy Aluminum Mosquito Nets.
Oct 2, 2023

Top Articles
Latest Posts
Article information

Author: Virgilio Hermann JD

Last Updated:

Views: 5736

Rating: 4 / 5 (61 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Virgilio Hermann JD

Birthday: 1997-12-21

Address: 6946 Schoen Cove, Sipesshire, MO 55944

Phone: +3763365785260

Job: Accounting Engineer

Hobby: Web surfing, Rafting, Dowsing, Stand-up comedy, Ghost hunting, Swimming, Amateur radio

Introduction: My name is Virgilio Hermann JD, I am a fine, gifted, beautiful, encouraging, kind, talented, zealous person who loves writing and wants to share my knowledge and understanding with you.