The Japan Times - What is Signal and is it secure?

EUR -
AED 3.998302
AFN 76.426194
ALL 99.362051
AMD 421.123927
ANG 1.941049
AOA 996.026725
ARS 1153.728687
AUD 1.72704
AWG 1.962117
AZN 1.854862
BAM 1.955447
BBD 2.174607
BDT 130.896355
BGN 1.955447
BHD 0.408126
BIF 3192.223348
BMD 1.088553
BND 1.446139
BOB 7.441656
BRL 6.269201
BSD 1.077005
BTN 92.037374
BWP 14.713342
BYN 3.524563
BYR 21335.645872
BZD 2.163309
CAD 1.565395
CDF 3126.873796
CHF 0.958764
CLF 0.026358
CLP 1011.477284
CNY 7.906494
CNH 7.914197
COP 4493.088357
CRC 538.202778
CUC 1.088553
CUP 28.846664
CVE 110.245085
CZK 25.060719
DJF 191.59539
DKK 7.500573
DOP 67.97772
DZD 144.798843
EGP 54.763107
ERN 16.3283
ETB 141.49494
FJD 2.531
FKP 0.839756
GBP 0.840874
GEL 3.020779
GGP 0.839756
GHS 16.693984
GIP 0.839756
GMD 77.835757
GNF 9311.317979
GTQ 8.308499
GYD 225.319298
HKD 8.473245
HNL 27.551023
HRK 7.572635
HTG 141.144503
HUF 404.648363
IDR 18074.340003
ILS 4.017546
IMP 0.839756
INR 93.114315
IQD 1410.845141
IRR 45828.096874
ISK 143.243157
JEP 0.839756
JMD 169.309415
JOD 0.771827
JPY 163.114321
KES 139.154863
KGS 94.055146
KHR 4311.221209
KMF 496.928739
KPW 979.724085
KRW 1600.612986
KWD 0.335536
KYD 0.897538
KZT 542.771952
LAK 23339.783839
LBP 96508.666417
LKR 319.022371
LRD 215.401089
LSL 19.571864
LTL 3.214215
LVL 0.658455
LYD 5.208059
MAD 10.419018
MDL 19.42849
MGA 5046.088461
MKD 61.523886
MMK 2285.50551
MNT 3795.873688
MOP 8.629641
MRU 42.853259
MUR 49.834385
MVR 16.767792
MWK 1867.66262
MXN 22.185919
MYR 4.83046
MZN 69.562619
NAD 19.571864
NGN 1665.966016
NIO 39.632841
NOK 11.420726
NPR 147.259399
NZD 1.904231
OMR 0.416905
PAB 1.077005
PEN 3.920692
PGK 4.439198
PHP 62.439829
PKR 301.827277
PLN 4.20221
PYG 8627.441516
QAR 3.927091
RON 5.003975
RSD 117.228823
RUB 90.423666
RWF 1551.319765
SAR 4.08195
SBD 9.079475
SCR 15.457408
SDG 653.680295
SEK 10.934617
SGD 1.458775
SHP 0.855432
SLE 24.830306
SLL 22826.420878
SOS 615.488816
SRD 39.786085
STD 22530.856788
SVC 9.423298
SYP 14153.162141
SZL 19.567465
THB 36.936834
TJS 11.728481
TMT 3.809937
TND 3.354494
TOP 2.549505
TRY 41.346309
TTD 7.30768
TWD 36.140629
TZS 2848.985352
UAH 44.67283
UGX 3943.287674
USD 1.088553
UYU 45.371804
UZS 13907.487714
VES 75.03677
VND 27839.752203
VUV 134.17424
WST 3.04287
XAF 655.838528
XAG 0.031916
XAU 0.000353
XCD 2.94187
XDR 0.815653
XOF 655.838528
XPF 119.331742
YER 267.784488
ZAR 19.910036
ZMK 9798.290415
ZMW 30.66746
ZWL 350.513738
  • RBGPF

    68.2200

    68.22

    +100%

  • BCC

    -2.0600

    98.3

    -2.1%

  • JRI

    -0.1300

    12.87

    -1.01%

  • SCS

    -0.2000

    11.1

    -1.8%

  • AZN

    0.9500

    73.79

    +1.29%

  • NGG

    1.6400

    65.57

    +2.5%

  • GSK

    0.2200

    38.74

    +0.57%

  • CMSC

    -0.0300

    22.83

    -0.13%

  • CMSD

    0.0100

    22.71

    +0.04%

  • RIO

    -1.3100

    61.03

    -2.15%

  • RELX

    0.0900

    50.16

    +0.18%

  • VOD

    0.0900

    9.45

    +0.95%

  • BTI

    0.0691

    40.51

    +0.17%

  • RYCEF

    0.0100

    9.92

    +0.1%

  • BP

    -0.5500

    33.86

    -1.62%

  • BCE

    -0.1900

    22.97

    -0.83%

What is Signal and is it secure?
What is Signal and is it secure? / Photo: Lionel BONAVENTURE - AFP

What is Signal and is it secure?

Signal is an end-to-end encrypted messaging app that is considered one of the most secure in the world by security professionals, but was never intended to be the go-to choice for White House officials planning a military operation.

Text size:

What differentiates it from other messaging apps, and why has its use by top Trump officials plotting strikes on Yemen raised concerns?

- What is end-to-end encryption? -

End-to-end encryption means that any sent message travels in a scrambled form and can only be deciphered by the end user.

Nobody in between -- not the company providing the service, not your internet provider, nor hackers intercepting the message -- can read the content because they don't have the keys to unlock it.

Signal is not the only messaging service to provide this service, but unlike WhatsApp and Apple's iMessage, the app is controlled by an independent non-profit -- not a big tech behemoth motivated by revenue -- winning it more trust to those concerned about privacy.

Signal crucially goes further than WhatsApp on data privacy by making metadata such as when the message was delivered and who it was sent to invisible even to the company itself.

WhatsApp, meanwhile, shares information with its parent company Meta and third parties, including your phone number, mobile device information, and IP addresses.

For these reasons, Signal has always been a go-to messaging service for users especially concerned about communications secrecy, notably people working in security professions, journalists, and their sources.

- Who owns Signal? -

Founded in 2012, Signal is owned by the Mountain View, California-based Signal Foundation.

Its history is linked to WhatsApp: the site was founded by cryptographer and entrepreneur Moxie Marlinspike, with an initial $50 million from WhatsApp co-founder Brian Acton.

Both Signal and WhatsApp, which was bought by Mark Zuckerberg in 2014, are based on the same protocol built by Marlinspike.

"We're not tied to any major tech companies, and we can never be acquired by one either," Signal's website reads. Development is mainly supported by grants and donations.

Very outspoken compared to other Silicon Valley bosses, Signal's CEO is Meredith Whittaker, who spent years working for Google before helping to organize a staff walkout in 2018 over working conditions.

Whittaker campaigns for privacy and is a fierce critic of business models built on the extraction of personal data.

- How secure is Signal? -

"Signal is a very solid platform because of the way that it goes about doing its business, the way that it frequently updates the app, the way that it uses end-to-end encryption," said Michael Daniel, former White House cybersecurity coordinator under Barack Obama and current head of the Cyber Threat Alliance.

But "it was never built or intended to be used for discussing military plans," Daniel told AFP.

The real vulnerability, Daniel said, is not so much the app itself, "but everything that goes on around it. It's more that these are on personal devices that may or may not be stored in a secure manner or protected in the right way."

He noted that given their responsibilities, the high-level officials involved in the Huthi conversation would have communications teams with them at all times capable of handling the conversation using the appropriate methods.

Under normal circumstances, "It wouldn't have been that difficult to jump off their phones and do this in the proper protocols," he said, adding that having an outsider on the call would have been impossible if the right technology was used.

Matthew Green, who teaches cryptography at Johns Hopkins University and has collaborated with the development of Signal, said on Bluesky that by asking it to step up to "military grade" communications, Signal was "being asked to do a lot!"

He warned that Signal, which shot up on the list of most downloaded apps after the revelation, could become a victim of its own success.

"As the only encrypted messenger people seem to 'really' trust, Signal is going to end up being a target for too many people," he said.

M.Matsumoto--JT