InvestigationU

Personal security

Signal, and Why Investigators Use It

Signal turns up in the news attached to the worst possible stories, which gives people the impression it exists for criminals. It’s an encrypted messenger. The reason professionals use it’s dull and practical.

Cost
Free
Run by
A non-profit foundation
Metadata retained
Account creation date, last connection
Needs
A phone number to register

Signal uses end-to-end encryption, which means the message is encrypted on your device and decrypted on the recipient’s, and nothing in between can read it. Not the network, not the carrier, and not Signal itself. Anyone intercepting it gets ciphertext.

Ordinary SMS has none of that. Your carrier can read it, stores it, and hands it over on a subpoena. Most other chat apps encrypt in transit but hold a readable copy on their own servers, which is a different thing entirely, and which is why those companies can produce your messages on request.

Why that matters for investigative work

If you take work from attorneys, you handle material that’s privileged or close to it. If you take work from private clients, you handle names and addresses of people who didn’t ask to be in your case file. Sending that through SMS puts it into a system you don’t control and can’t delete from.

It matters more for the people talking to you than for you. A source deciding whether to tell you something is weighing whether it can come back on them. Being able to say the conversation is encrypted and set to delete is sometimes the difference between getting the information and not.

The features that earn their place

FeatureWhat it is for
Disappearing messagesSet a timer per conversation. Messages delete from both devices when it expires. Reduces what a lost or seized phone gives up
Screen securityBlocks screenshots inside the app and hides content in the app switcher
Relay callsRoutes calls through Signal’s servers so the other party doesn’t learn your IP address
Registration lockA PIN that stops someone re-registering your number on their device after a SIM swap
UsernamesLets someone contact you without you handing over a phone number

Turn on registration lock the day you install it. SIM swapping is the realistic attack against anybody whose work makes them worth targeting, and that PIN is what blocks it.

What it does not do

Encryption protects the message in transit and at rest. It doesn’t protect against the person on the other end screenshotting it, and it doesn’t protect against somebody with your unlocked phone in their hand. Most real compromises are one of those two, not the cryptography.

Signal also still holds a little metadata — when the account was created and when it last connected. That’s all, and it’s all they have ever been able to produce in response to a subpoena, which is a matter of public record because they publish the requests.

And registration requires a phone number, which is a real limitation. Usernames mean you no longer have to reveal it to contacts, but the number still exists behind the account.

The framing problem

Needing privacy isn’t evidence of wrongdoing, and it’s worth saying plainly because the coverage implies otherwise. Attorneys use it. Journalists use it with sources. Domestic abuse advocates recommend it. Ordinary people use it because they would rather their conversations weren’t scanned to sell them things.

The strength of the tool comes partly from ordinary people using it. If only sensitive traffic were encrypted, the encryption itself would be the signal. The more mundane the user base, the less any individual user stands out.

Getting it

It’s free, on Android, iOS and desktop. There’s no paid tier and no advertising — it’s run by a non-profit and funded by donations, which is the reason your messages aren’t the product.

Get the people you actually work with onto it. An encrypted messenger nobody you deal with uses doesn’t accomplish anything.