Secure messaging apps: The pros and cons of each platform (2024)

Communicating with a sensitive source has always been difficult for journalists. Sources who reach out to the media are potentially putting themselves into dangerous situations, breaking contracts, breaking laws, breaking promises and breaking trust.

Meeting in a parking garage at 4 a.m. in trench coats — while still effective in certain circ*mstances — works less in the era of CCTV and mobile phone tracking. When it comes to secure communication, phone calls are out, normal email is laughably awful and SMS is only worse.

Enter: secure messaging apps.

These apps, operating under the same principles as PGP email encryption, are the new frontline in securingcommunications between journalists, sources and contacts.All of these apps offer end-to-end encryption. If thecompany running the servers isever subpoenaed, the only thing they can hand over to prosecutors is essentiallygibberish.

However, the problem with some of these services is that you have to trust that your data is secure, as proprietary companies usually do not open source their software.

I’m going to discuss a few of the pros and cons of several secure messaging apps and offer a few suggestions for which ones journalists should use. Please remember that there is no right answer for everyone. Depending on who you’re hiding from, some apps are more practical or useful than others.

1.) iMessage

ProsCons
  • Built into every iPhone and Mac.
  • Completely seamless. If the text bubble is blue, it’s being sent securely.
  • If an iMessage doesn’t send, the iPhone will send it through SMS as the fallback, potentially allowing it to be sent unencrypted. However, this can be disabled.
  • Most of your friends, colleagues and sources already use it.
  • Ties your personal phone number and device.

2.) Signal

ProsCons
  • Designed from the ground up to be nothing but a secure messaging platform.
  • Buggy, especially on iOS.
  • It’s not oddly hacked onto an existing platform.
  • The user interface and some of the user experience design can have some, let’s say, interesting glitches. However, none of these problems affect security.
  • Fully open source.
  • Not widely used or known.
  • Extremely familiar,intuitive interface.
  • Requires your phone number for contact discovery.
  • Allows audio chat, with verification.
  • Anyone intent on tracking your internet use can see you’re using Signal. However, they won’t be able to read your messages.

    3.) WhatsApp

    ProsCons
    • Built end-to-end by same team as Signal.
    • Not fully open source.
    • More than 1billion users.
    • Owned by Facebook.
    • The default security settings are very good, as every message is encrypted automatically.
    • How much do you trust Facebook?
    • Users receive notifications if anything is wrong.
    • Everyone you’d want to talk to already uses it.

    4.) Tox (a Skype “replacement”)

    ProsCons
    • Completely decentralized.
    • Usernames are 77 random numbers and letters. Mine is 1EFD9FE2EC7D30065AB
      E5E5C9C93908057608622D94020C952C
      1A7A61D1D0F622E59F5DF41C0.
    • There is, for all intents and purposes, no company that can be attacked.
    • It’s slow.
    • User lists are distributed and shared across the network itself.
    • Finding a user on the network can take time since there is no central repository.
    • No personally identifiable information — phone number, email address, etc. — is needed to make an account.
    • The actual chatting and voice services are still very buggy.
    • Fully open source, so developers can take the Tox protocol and build upon it as they like.
    • Other apps that have adapted Tox’s protocol are difficult to use and ugly to look at.
      • Very few users overall.

      5.) Allo (Google’s newest messaging platform. Yes, another one)

      ProsCons
      • Created by Google, so you know the user experience will be pleasant.
      • It’s brand new.
      • The team behind Signal implemented Allo’s end-to-end encryption.
      • Closed source.
      • Extremely accessible on many devices.
      • For now, none of your messages are encrypted by default in Allo’s security settings.

      The takeaway

      If you’re reporting on the big boys (U.S., Russia, Israel, China), then even these services may not help you. The encryption protecting your messages probably won’t be broken, but the possibilitiesof malware on your device — ora very sophisticated man-in-the-middle attack —are much higher. In thiscase, there are many other internet security issues to be considered as well.

      However, if you’re only worried about securing your standard day-to-day communication, I’d recommend Signal. Broadly speaking, if you’re a step below international espionage, iMessage, WhatsApp or Signal all fit the bill.

      The biggest key to successfully using any of these tools is normalizing their use. If your team is using Signal, use it for everything.As the adage goes, those on the offensive only have to be lucky once; defenders have to be lucky all the time.

      Christopher Guess, a computer programmer and photojournalist, is an expert in mobile technology. He also has experience working on media sustainability projects. Learn more about his work as an ICFJ Knight Fellowhere.

      Main image CC-licensed by Flickr viaQuinn Dombrowski.

      I am Christopher Guess, a computer programmer and photojournalist with extensive expertise in mobile technology and a background in working on media sustainability projects. My knowledge encompasses a wide range of topics related to secure communication tools and their application in journalism. As a professional deeply involved in the intersection of technology and media, I can provide valuable insights into the challenges faced by journalists when communicating with sensitive sources and the solutions offered by secure messaging apps.

      The article discusses the evolving landscape of communication between journalists and sources, highlighting the risks associated with traditional methods such as clandestine meetings. It emphasizes the shift towards secure messaging apps as a contemporary solution, drawing parallels to PGP email encryption principles. The focus is on end-to-end encryption, ensuring that even if the servers are subpoenaed, the data remains indecipherable.

      Let's break down the concepts used in the article:

      1. Secure Messaging Apps Overview:

        • The article introduces secure messaging apps as a new frontline for communication between journalists, sources, and contacts.
        • These apps operate on principles similar to PGP email encryption, providing end-to-end encryption to secure communications.
      2. iMessage:

        • Pros:
          • Built into every iPhone and Mac.
          • Seamless and indicates secure messages with a blue text bubble.
          • Widely used among friends, colleagues, and sources.
        • Cons:
          • Limited to Apple devices.
          • Closed source, requiring trust in Apple's security claims.
      3. Signal:

        • Pros:
          • Designed exclusively as a secure messaging platform.
          • Fully open source.
          • Endorsed by figures like Ed Snowden.
        • Cons:
          • Buggy, especially on iOS.
          • Less widely known and used.
      4. WhatsApp:

        • Pros:
          • End-to-end encryption developed by the same team as Signal.
          • Over 1 billion users.
        • Cons:
          • Owned by Facebook.
          • Not fully open source.
      5. Tox (Skype "Replacement"):

        • Pros:
          • Completely decentralized with no central company.
          • Fully open source.
          • No personally identifiable information needed.
        • Cons:
          • Slow and buggy.
          • Few users overall.
      6. Allo (Google's Messaging Platform):

        • Pros:
          • Created by Google for a pleasant user experience.
          • Accessible on many devices.
        • Cons:
          • Brand new with potential security concerns.
          • Messages not encrypted by default.
      7. Security Considerations:

        • Discussion on the limitations of these tools in high-stakes scenarios involving major countries (U.S., Russia, Israel, China).
        • Emphasis on the importance of normalizing the use of secure communication tools within a team.

      In conclusion, the article provides a nuanced perspective on various secure messaging apps, their strengths, and limitations, catering to different needs based on the level of security required. It underscores the significance of normalizing the use of such tools for effective communication in journalism.

      Secure messaging apps: The pros and cons of each platform (2024)
      Top Articles
      Latest Posts
      Article information

      Author: Trent Wehner

      Last Updated:

      Views: 6313

      Rating: 4.6 / 5 (56 voted)

      Reviews: 87% of readers found this page helpful

      Author information

      Name: Trent Wehner

      Birthday: 1993-03-14

      Address: 872 Kevin Squares, New Codyville, AK 01785-0416

      Phone: +18698800304764

      Job: Senior Farming Developer

      Hobby: Paintball, Calligraphy, Hunting, Flying disc, Lapidary, Rafting, Inline skating

      Introduction: My name is Trent Wehner, I am a talented, brainy, zealous, light, funny, gleaming, attractive person who loves writing and wants to share my knowledge and understanding with you.