<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Encrypted messaging on ARPOKRAT</title>
    <link>https://arpokrat.com/blog/tags/encrypted-messaging/</link>
    <description>Recent content in Encrypted messaging on ARPOKRAT</description>
    <generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Thu, 10 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://arpokrat.com/blog/tags/encrypted-messaging/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Encrypted Messaging Apps Compared 2026: Encryption Is No Longer Enough</title>
      <link>https://arpokrat.com/blog/encrypted-messaging-apps-comparison-2026/</link>
      <pubDate>Thu, 10 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/encrypted-messaging-apps-comparison-2026/</guid>
      <description>&lt;p&gt;Open WhatsApp, Telegram, Signal, Messenger, Google Messages. Every one of these apps now displays the same promise somewhere in its interface: end-to-end encryption. The phrase has become a standard sales argument, on a par with &amp;ldquo;no contract&amp;rdquo; from a mobile operator. It no longer separates anything, precisely because it has become true almost everywhere.&lt;/p&gt;
&lt;p&gt;And yet these apps have nothing in common. One demands your phone number and hands the courts the list of people who have you in their address book. Another literally knows nothing about you, not even that an account exists. Between the two, some fifteen projects make very different trade-offs, and none of them explains those trade-offs clearly on its home page.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;End-to-end encryption&lt;/strong&gt; means that the content of your messages is unreadable to the intermediary carrying them. That is an important achievement, and it would be absurd to play it down. But it says nothing about what that same intermediary learns outside the content: that you wrote, to whom, at what time, from which IP address, how often, in which groups, with which phone number attached to your legal identity.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Encryption protects what you say. It does not protect the fact that you said it, nor to whom, nor when, nor from where.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This article does not draw up a ranking. There is no best messenger in the absolute, because there is no generic adversary. What this piece offers is first a grid of seven criteria that lets you judge any application, including ones that do not exist yet, then an honest profile for each of the fourteen apps selected, and finally recommendations by threat profile. Every profile includes a section devoted to what the app does not protect, without exception, including our own.&lt;/p&gt;
&lt;h2 id=&#34;contents&#34;&gt;Contents&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#criteres&#34;&gt;The seven criteria that replace encryption&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#critere-chiffrement&#34;&gt;End-to-end encryption, a settled matter that no longer separates anyone&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#critere-metadonnees&#34;&gt;Metadata, what the service knows without reading your messages&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#critere-identifiant&#34;&gt;The identifier required, a number, an address or nothing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#critere-audit&#34;&gt;Open source and independent audit, two ideas to stop confusing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#critere-juridiction&#34;&gt;Jurisdiction and the CLOUD Act&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#critere-perennite&#34;&gt;Project sustainability, the criterion nobody looks at&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#critere-pratique&#34;&gt;Practicality, a security criterion in its own right&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#grand-public&#34;&gt;Mainstream messengers&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#whatsapp&#34;&gt;WhatsApp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#telegram&#34;&gt;Telegram&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#standard&#34;&gt;The de facto standard&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#signal&#34;&gt;Signal&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#molly&#34;&gt;Molly&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#sans-numero&#34;&gt;Messengers without a phone number&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#session&#34;&gt;Session&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#threema&#34;&gt;Threema&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#wire&#34;&gt;Wire&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#element-matrix&#34;&gt;Element and the Matrix protocol&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#sans-identifiant&#34;&gt;Messengers with no identifier at all&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#simplex&#34;&gt;SimpleX Chat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#arpokrat&#34;&gt;Arpokrat Messenger&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#briar&#34;&gt;Briar&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#cwtch&#34;&gt;Cwtch&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#convergence&#34;&gt;The convergence of 2026, the messenger becomes a wallet&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;#radar&#34;&gt;Radar&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#zerion&#34;&gt;Zerion&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#tableau&#34;&gt;Summary table&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#profils&#34;&gt;Which messenger for which profile&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#choix-arpokrat&#34;&gt;What we chose at Arpokrat and why&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#conclusion&#34;&gt;Conclusion&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;#sources&#34;&gt;Sources&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;criteres&#34;&gt;The seven criteria that replace encryption&lt;/h2&gt;
&lt;p&gt;This section is the most important one in the article. If you read only one, read this one: it will let you judge any messenger yourself, including those released after this text is published.&lt;/p&gt;
&lt;h3 id=&#34;critere-chiffrement&#34;&gt;End-to-end encryption, a settled matter that no longer separates anyone&lt;/h3&gt;
&lt;p&gt;The Signal protocol, published in 2013 and formally analysed by cryptography researchers ever since, has become the de facto standard. WhatsApp has used it since 2016, Google Messages uses it, Messenger uses it. The cryptographic debate is largely closed for the content of one-to-one conversations.&lt;/p&gt;
&lt;p&gt;The questions that remain useful are no longer about the presence of encryption but about its terms. Is it on by default or do you have to ask for it? Does it cover groups or only two-party exchanges? Does it cover backups, or do those go off to Google and Apple in the clear? Is there &lt;strong&gt;forward secrecy&lt;/strong&gt;, meaning a regular rotation of keys guaranteeing that the compromise of a key today does not give access to yesterday&amp;rsquo;s messages?&lt;/p&gt;
&lt;p&gt;Those questions still separate apps. The presence of the word &amp;ldquo;encrypted&amp;rdquo; on a marketing page does not.&lt;/p&gt;
&lt;h3 id=&#34;critere-metadonnees&#34;&gt;Metadata, what the service knows without reading your messages&lt;/h3&gt;
&lt;p&gt;In May 2014, during a public debate at Johns Hopkins University against the legal scholar David Cole, former NSA and CIA director Michael Hayden uttered a line that has become famous. Cole had just quoted former NSA general counsel Stewart Baker, according to whom &amp;ldquo;metadata absolutely tells you everything about somebody&amp;rsquo;s life, and if you have enough metadata you don&amp;rsquo;t really need content&amp;rdquo;. Hayden replied, approvingly: &amp;ldquo;We kill people based on metadata.&amp;rdquo; He immediately added that this was not what the American domestic collection programmes did, a qualification that has to be restored to be honest. It changes nothing essential: the most senior American intelligence official publicly confirmed that metadata is enough for lethal decisions.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Metadata&lt;/strong&gt;, in a messenger, is everything that is not the content: who writes to whom, at what time, from which IP address, how often, in which groups, with what file size. Reconstructing a link between a journalist and a source does not require reading their exchanges. It is enough to observe that they started writing to each other three days before an investigation was published. The same reasoning applies to a lawyer and a client, a doctor and a patient, an employee and a union, two people who would rather their relationship not be known.&lt;/p&gt;
&lt;p&gt;A service can therefore be beyond reproach on content encryption and perfectly transparent about everything else. That is in fact the most common situation. We have detailed elsewhere how this same reasoning applies to other passive everyday signals, notably in our article on &lt;a href=&#34;https://arpokrat.com/blog/how-your-phone-tracks-your-location/&#34;&gt;permanent phone location tracking&lt;/a&gt; and in our analysis of Leonardo&amp;rsquo;s &lt;a href=&#34;https://arpokrat.com/blog/signaltrace-leonardo-bluetooth-surveillance/&#34;&gt;SignalTrace system&lt;/a&gt;, which reconstructs journeys and relationships from nothing more than Bluetooth identifiers picked up in passing.&lt;/p&gt;
&lt;p&gt;A good question to put to any vendor: what is left on your servers if a judge seizes them tomorrow morning?&lt;/p&gt;
&lt;h3 id=&#34;critere-identifiant&#34;&gt;The identifier required, a number, an address or nothing&lt;/h3&gt;
&lt;p&gt;This is the most concrete and most underestimated criterion. Three models coexist.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The phone number.&lt;/strong&gt; In most countries it is tied to an identity document. It is unique, durable, and already present in hundreds of people&amp;rsquo;s address books. Requiring a number means tying every account to a legal identity and making the discovery of the social graph trivial: you just compare address books. The number is also the well-known weak point of authentication, as we showed in our article on &lt;a href=&#34;https://arpokrat.com/blog/2fa-sms-vs-yubikey-hardware-keys/&#34;&gt;SMS-based 2FA&lt;/a&gt;: a successful SIM swap does not just steal a code, it steals a messaging identity.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The email address or a random identifier.&lt;/strong&gt; Better, because a disposable address costs a few seconds and a random identifier says nothing. It nevertheless remains a durable identifier on the server side, and therefore a hook for correlating sessions over time.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;No identifier.&lt;/strong&gt; This is the most recent and rarest model. There is no account at all, no directory, no permanent address. You exist as a set of cryptographic keys on your device, and people reach you through a single-use invitation link. Nothing to enter, nothing to leak, nothing to correlate.&lt;/p&gt;
&lt;h3 id=&#34;critere-audit&#34;&gt;Open source and independent audit, two ideas to stop confusing&lt;/h3&gt;
&lt;p&gt;These are two different things and it is time to stop presenting them together.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Open source&lt;/strong&gt; means the code is readable. It is a necessary condition for trust, not a proof of security. Nobody reads the code, except by accident. Serious flaws have survived for years in widely watched free software projects.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Independent audit&lt;/strong&gt; means a third party paid to look for flaws has looked, and has published what it found. That is infinitely stronger, and infinitely rarer, because it is expensive.&lt;/p&gt;
&lt;p&gt;You then have to distinguish two kinds of audit. A &lt;strong&gt;cryptographic design review&lt;/strong&gt; examines whether the protocol is well thought out on paper. An &lt;strong&gt;implementation audit&lt;/strong&gt; examines whether the code actually does what the protocol claims. Both are useful, they do not prove the same thing, and a project can have the first without the second.&lt;/p&gt;
&lt;p&gt;The Threema case illustrates the value of the exercise perfectly. In 2022, three researchers from ETH Zurich found seven attacks against its protocol, across three different threat models, and disclosed them to the vendor. Threema responded with a new protocol, Ibex, published in late November 2022. A closed, unaudited application would never have had that episode, which would not have meant it was any safer.&lt;/p&gt;
&lt;h3 id=&#34;critere-juridiction&#34;&gt;Jurisdiction and the CLOUD Act&lt;/h3&gt;
&lt;p&gt;Where a company is established determines which governments can compel it. It is a legal criterion, not a technical one, and it is decisive.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;CLOUD Act&lt;/strong&gt;, passed in the United States in 2018, settles a question raised by the Microsoft Ireland case: can an American company refuse to hand over emails stored on an Irish server? The legislator&amp;rsquo;s answer is no. The text requires providers under American jurisdiction to disclose the data they control, regardless of where it is stored. A server in Frankfurt operated by an American company remains within reach of an American demand. The provider can object if the request conflicts with foreign law, but the objection is a procedure, not a shield.&lt;/p&gt;
&lt;p&gt;The practical consequence is simple: hosting in Europe is not enough if the host, the parent company or the holding company falls under American law. The question to ask is not &amp;ldquo;where are your servers&amp;rdquo; but &amp;ldquo;who can legally compel you, and on what basis&amp;rdquo;.&lt;/p&gt;
&lt;p&gt;Two qualifications have to be added. First, a protective jurisdiction is useless if the service nonetheless holds exploitable data: the best defence remains having nothing to hand over. Second, a hostile jurisdiction does not condemn a service that structurally knows nothing. Signal is American and has never been able to hand over anything but two timestamps.&lt;/p&gt;
&lt;h3 id=&#34;critere-perennite&#34;&gt;Project sustainability, the criterion nobody looks at&lt;/h3&gt;
&lt;p&gt;A very well designed messenger that disappears in eighteen months leaves you with an unusable address book and, often, a lost history. This criterion never appears in comparisons. The year 2026 made it unavoidable.&lt;/p&gt;
&lt;p&gt;In April 2026, the Session Technology Foundation publicly announced that it had raised only about 65,000 dollars in donations, that it needed roughly one million dollars a year to operate, and that its cash would not last beyond July. All staff were let go and development stopped. Session has more than one million monthly active users. In June, the foundation announced that the project had been saved by donations from thousands of users, most of them small amounts, and that it was restarting with a team of three developers led by software architect Jason Rhinelander.&lt;/p&gt;
&lt;p&gt;Three weeks later, on 9 July 2026, the Briar project published a comparable message: after considering shutting down, it is moving to maintenance mode, meaning security and bug fixes only, with no development of new features, for lack of sustainable funding.&lt;/p&gt;
&lt;p&gt;Two emblematic projects, two different economic models, the same year, the same dead end. The question to ask before adopting a messenger has therefore become: who pays, how much, and for how long? A foundation living on donations, a company selling licences, a subsidised university project and a volunteer community piece of software do not have the same life expectancy, and that has nothing to do with the quality of their cryptography.&lt;/p&gt;
&lt;h3 id=&#34;critere-pratique&#34;&gt;Practicality, a security criterion in its own right&lt;/h3&gt;
&lt;p&gt;This last criterion is often treated with contempt by purists. That is a mistake.&lt;/p&gt;
&lt;p&gt;A messenger your contacts refuse to install protects nobody, because the conversation will take place elsewhere, in the clear. A messenger whose notifications do not arrive pushes its users back to WhatsApp for urgent exchanges. A messenger that requires both people to be connected at the same instant is unsuited to ordinary correspondence across two time zones.&lt;/p&gt;
&lt;p&gt;The real security of a system is the security of its real use, not that of its spec sheet. A slightly less pure model that your contacts actually use protects more than a perfect model you are alone in using.&lt;/p&gt;
&lt;h2 id=&#34;grand-public&#34;&gt;Mainstream messengers&lt;/h2&gt;
&lt;h3 id=&#34;whatsapp&#34;&gt;WhatsApp&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://www.whatsapp.com&#34;&gt;WhatsApp&lt;/a&gt; is the most used messenger in the world. It belongs to Meta, it is free, and its business model rests on the group&amp;rsquo;s advertising ecosystem and on business services.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it really protects.&lt;/strong&gt; The content of messages, with the Signal protocol, since 2016. This implementation is serious and that has to be said plainly: the content of your WhatsApp conversations is not readable by Meta. End-to-end encrypted backups exist and are worth turning on, because they are not on by default. The app is extremely reliable, available everywhere, and your contacts already have it.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it does not protect.&lt;/strong&gt; Everything else. On a simple legal demand, Meta discloses subscriber data: account name, creation date, last connection, IP address, email address. On a search warrant, the company provides the address book of the person targeted, and also the list of other WhatsApp users who have that person in their contacts. In other words, the social graph is deliverable in both directions. The metadata retained includes timestamps, sender and recipient identifiers, delivery statuses, group composition and its changes. According to an FBI document made public, WhatsApp is able to produce certain metadata for a targeted user every fifteen minutes as part of real-time surveillance. Finally, the phone number is mandatory, and Meta falls under the CLOUD Act.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who it is for.&lt;/strong&gt; For everyone, as an ordinary communication channel where you accept that the relationship graph is known to Meta and disclosable to a judicial authority.&lt;/p&gt;
&lt;h3 id=&#34;telegram&#34;&gt;Telegram&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://telegram.org&#34;&gt;Telegram&lt;/a&gt; is often filed among the secure messengers. That is a misunderstanding to clear up without aggression, because Telegram is excellent at what it actually does.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it really protects.&lt;/strong&gt; Nothing more than a classic online service, for everyday use. Ordinary conversations, called cloud chats, are encrypted between the client and the server, then stored encrypted on Telegram&amp;rsquo;s side, which holds the means to read them. End-to-end encryption is only available in &lt;strong&gt;secret chats&lt;/strong&gt;, which are not on by default, are limited to one-to-one exchanges, remain tied to the original device and do not sync. What Telegram does excellently, on the other hand, is the massive group, the broadcast channel, large file sharing and multi-device presence. It is a formidable publishing network, and that is how it should be judged.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it does not protect.&lt;/strong&gt; The content of ordinary conversations against the vendor, the phone number, the IP address. The company&amp;rsquo;s position changed in September 2024, after the arrest of Pavel Durov in France: Telegram now discloses the numbers and IP addresses of reported users, in response to valid legal requests, whereas the previous commitment limited such disclosures to terrorism cases. The figures published for 2024 reflect the change in scale: roughly 900 requests fulfilled in the United States for 2,253 users, 14,641 in India for 23,535 users, 142 in the United Kingdom. The group is also registered in the British Virgin Islands and run from Dubai, a structure whose opacity is in itself a data point for analysis.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who it is for.&lt;/strong&gt; For public broadcasting, large communities, monitoring. Not for a conversation that must stay confidential from the vendor.&lt;/p&gt;
&lt;h2 id=&#34;standard&#34;&gt;The de facto standard&lt;/h2&gt;
&lt;h3 id=&#34;signal&#34;&gt;Signal&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://signal.org&#34;&gt;Signal&lt;/a&gt; is the benchmark, and this article treats it as such. It is published by the Signal Foundation, an American non-profit funded by donations and by an initial endowment from Brian Acton.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it really protects.&lt;/strong&gt; The content, with the protocol it invented and which serves as the industry reference. But above all, and this is what sets it apart, the rest: private contact discovery, sealed sender, systematic minimisation of retained data. The proof is not declarative, it is judicial. Signal publishes its responses to legal demands on a dedicated page, and those responses all look alike: the organisation can provide only the account creation timestamp and the last connection date. In a case brought before the District of Columbia court, the authorities requested subscriber information for thirty-seven phone numbers. The answer was the same. It is the only public record of resistance to legal demands of that quality in this entire comparison, and it is worth more than any marketing promise.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it does not protect.&lt;/strong&gt; The phone number remains mandatory at sign-up in 2026. Usernames, introduced in 2024, mean you no longer have to give your number to your contacts, which is real progress, but they do not remove the requirement at account creation. Public work indicates that Signal is studying registration without a number, possibly backed by a one-off payment to limit abuse, but at the time of writing it is not available. Signal also falls under American law, and therefore the CLOUD Act: the protection does not come from the jurisdiction, it comes from the fact that there is nothing to hand over. Finally, the infrastructure is centralised and the ecosystem is closed to third-party clients, a point we return to later.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who it is for.&lt;/strong&gt; For just about everyone. It is the best ratio of protection to real-world adoption on the market, and it is the default recommendation when the phone number is not a problem in your threat model.&lt;/p&gt;
&lt;h3 id=&#34;molly&#34;&gt;Molly&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://molly.im&#34;&gt;Molly&lt;/a&gt; is a hardened fork of Signal for Android. It changes neither the protocol, nor the network, nor the identifier model: it hardens the client.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it really protects.&lt;/strong&gt; What Signal does not protect on the device side. Molly encrypts the local database behind a passphrase, which locks the entire application, and wipes RAM with random data on lock, to resist forensic analysis after seizure. It also lets you route traffic through a SOCKS proxy or Tor. A Molly-FOSS variant removes Google&amp;rsquo;s proprietary components. All things the official client does not do.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it does not protect.&lt;/strong&gt; Everything on the server side. Molly uses Signal&amp;rsquo;s servers, therefore requires a phone number and inherits exactly the same metadata profile and the same jurisdiction. It exists only on Android. And it runs on Signal&amp;rsquo;s network with the foundation&amp;rsquo;s tolerance, not with its formal authorisation, which has been incident-free for years.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who it is for.&lt;/strong&gt; For a Signal user on Android whose threat model includes physical seizure of the phone: a journalist travelling, an activist, a lawyer crossing a border.&lt;/p&gt;
&lt;h2 id=&#34;sans-numero&#34;&gt;Messengers without a phone number&lt;/h2&gt;
&lt;h3 id=&#34;session&#34;&gt;Session&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://getsession.org&#34;&gt;Session&lt;/a&gt; made a radical bet: get rid of the number and the email. At sign-up, the app generates a random account identifier, and nothing else is asked for. The project is run by the Session Technology Foundation, a foundation under Swiss law.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it really protects.&lt;/strong&gt; Identity at sign-up, and the IP address. Messages transit through a decentralised network of onion-routing nodes, so that no server knows both the origin and the destination. The code of the Android, iOS and desktop clients was audited in a report published by the French firm Quarkslab, which raised seven issues on Android, seven on iOS and two on the desktop client, most of them since fixed. The app is available on every platform and looks like an ordinary messenger, which is no small thing in this category.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it does not protect.&lt;/strong&gt; Session removed forward secrecy in 2021, citing stability problems with its decentralised architecture. Concretely, the compromise of a long-term key exposes past messages. In December 2025 the foundation announced a V2 protocol reintroducing forward secrecy and adding a post-quantum key exchange based on ML-KEM, but that protocol was not finalised at the time of writing. And above all, the sustainability criterion weighs heavily here: the project came within a few weeks of shutting down in 2026 and now runs with three developers for more than a million users.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who it is for.&lt;/strong&gt; For anyone who wants to do without a phone number without changing their usage habits, and who accepts the current absence of forward secrecy.&lt;/p&gt;
&lt;h3 id=&#34;threema&#34;&gt;Threema&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://threema.ch&#34;&gt;Threema&lt;/a&gt; is a Swiss company that sells its application. It is the only paid player in this comparison, and that is precisely what makes its model legible.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it really protects.&lt;/strong&gt; Identity and jurisdiction. On installation, the app generates a random Threema ID. The phone number and email address are optional and serve only to let your contacts find you, which nothing forces you to enable. The servers belong to the company and sit in an ISO 27001 certified data centre in Zurich, under Swiss law, outside the CLOUD Act. The source code is published and reproducible builds are available on Android, which makes it possible to verify that the distributed app matches the code. Threema had its mobile apps audited by Cure53 in October 2020, then its desktop app in January 2024. The Ibex protocol, adopted in late 2022, was the subject of a formal security proof published by German researchers in 2023.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it does not protect.&lt;/strong&gt; The price, around six euros as a one-off purchase, is a real obstacle to adoption by the people close to you, and it is the main practical brake. The 2022 ETH Zurich episode is also a reminder that even a serious player can have a vulnerable protocol for years: seven attacks found, a protocol entirely rebuilt. Finally, the Threema ID remains a durable identifier on the server side, which is not the no-identifier-at-all model.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who it is for.&lt;/strong&gt; For a European company, a law firm, a public body, or an individual who would rather pay for a product than depend on donations, and who wants a clear Swiss jurisdiction.&lt;/p&gt;
&lt;h3 id=&#34;wire&#34;&gt;Wire&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://wire.com&#34;&gt;Wire&lt;/a&gt; has changed a great deal in nature. Born as a consumer messenger, it repositioned itself towards organisations, businesses and the public sector.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it really protects.&lt;/strong&gt; The content, with the Proteus protocol and then with MLS, the IETF&amp;rsquo;s group messaging standard of which Wire was one of the first serious implementers. Sign-up is by email, which avoids the phone number. The audits are public: Kudelski Security and X41 D-Sec published a review of the protocol implementation in 2017, then application audits of the iOS, Android and web clients in 2018.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it does not protect.&lt;/strong&gt; Metadata, which Wire keeps in the clear on the server side, a point the vendor has never concealed and which has been regularly criticised. The legal structure is also complex: operations fall under Wire Swiss GmbH in Switzerland, the group&amp;rsquo;s holding company is established in Berlin and the vendor states that more than 90% of the capital is held by European institutional investors, but an American entity was created in Delaware in 2019. This complexity deserves to be understood before selecting Wire for sensitive use.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who it is for.&lt;/strong&gt; For an organisation that needs compliant encrypted collaboration, with commercial support and centralised administration, more than for an individual seeking anonymity.&lt;/p&gt;
&lt;h3 id=&#34;element-matrix&#34;&gt;Element and the Matrix protocol&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://element.io&#34;&gt;Element&lt;/a&gt; is the main client for &lt;strong&gt;Matrix&lt;/strong&gt;, an open, federated protocol. The model differs from every other one in this comparison: anyone can host their own server, and servers talk to each other the way email servers do.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it really protects.&lt;/strong&gt; Autonomy. An organisation can host its server, control its infrastructure, depend on no vendor and remain reachable from the rest of the network. It is the only model in this comparison that offers that combination, and it is the reason several European public administrations selected it. End-to-end encryption of messages is in place.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it does not protect.&lt;/strong&gt; Metadata, and that is structural. Your server&amp;rsquo;s administrator sees who talks to whom, when, and in which rooms. Room metadata, name, topic and other state events, is stored in the clear on the server. Element is working on encrypting these state events, but the feature was still experimental and confined to lab options in September 2025. Federation makes the problem worse: a room&amp;rsquo;s history is replicated to the participating servers, which retain it. The vendor also sells a gateway designed to filter federation in order to limit these leaks, which is a useful admission.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who it is for.&lt;/strong&gt; For an organisation that wants sovereignty over its infrastructure and whose adversary is not its own system administrator. Not for an individual seeking to conceal their relationships.&lt;/p&gt;
&lt;h2 id=&#34;sans-identifiant&#34;&gt;Messengers with no identifier at all&lt;/h2&gt;
&lt;p&gt;This is the most recent category. The principle is not to hide an identifier but not to create one.&lt;/p&gt;
&lt;h3 id=&#34;simplex&#34;&gt;SimpleX Chat&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://simplex.chat&#34;&gt;SimpleX Chat&lt;/a&gt; is the first messaging network with no user identifier, random ones included. It is a genuine conceptual advance and it should be presented as such.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it really protects.&lt;/strong&gt; The social graph, by design. There is no account, no directory, no permanent address. Each conversation rests on one-way queues hosted on different relays: what you send goes through a queue on one relay, replies come back through another queue on another relay, so that no relay sees both ends. The relays are blind, they know neither the sender nor the recipient. The project has published two independent audits carried out by Trail of Bits: a security assessment of the implementation in November 2022, then a review of the cryptographic design of the protocols in October 2024, including a formal verification of the queue negotiation protocol and concluding with three medium-severity issues and one low-severity issue, all difficult to exploit. The protocol adds a post-quantum layer to the double ratchet. The relays are self-hostable, clients exist on Android, iOS and desktop, and the vendor, SimpleX Chat Ltd, is a British company registered since October 2021.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it does not protect.&lt;/strong&gt; Two things deserve to be said. First, the default hosting: the relays operated by the project run at a single provider, Linode, a subsidiary of the American company Akamai, in its European data centres in London, Frankfurt and Stockholm. A user who does not enable Tor and does not change relays therefore depends on infrastructure operated by an American company, which puts the CLOUD Act back in the picture. The topic is publicly documented in the project&amp;rsquo;s repository. Second, the user experience remains demanding: establishing a connection requires exchanging a link or a QR code, notification reliability on iOS was long a weak point and scaling up large groups is still a work in progress. Funding, finally, now rests on an equity crowdfunding round launched in August 2026.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who it is for.&lt;/strong&gt; For anyone who wants the no-identifier model with the best level of external verification available today, and who accepts a more technical learning curve.&lt;/p&gt;
&lt;h3 id=&#34;arpokrat&#34;&gt;Arpokrat Messenger&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://arpokrat.com/messenger&#34;&gt;Arpokrat Messenger&lt;/a&gt; is our product, and this profile follows the same grid as the others. It has to be said bluntly up front: &lt;strong&gt;Arpokrat Messenger is a fork of SimpleX&lt;/strong&gt;. The architecture described above, absence of identifiers, one-way queues, blind relays, is not ours, it is SimpleX&amp;rsquo;s. We do not claim to have improved it cryptographically, we credit it, exactly as &lt;a href=&#34;https://arpokrat.com/protocol/&#34;&gt;our protocol page&lt;/a&gt; does explicitly. It is the same position we hold for ArpokratOS with respect to GrapheneOS.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it really protects.&lt;/strong&gt; What SimpleX protects, plus a series of operational and product choices. The relays we operate are spread across five jurisdictions chosen for their law, Switzerland, Iceland, Panama, Malaysia and Mauritius, none American, and the infrastructure rests on no American hyperscaler, neither Amazon Web Services, nor Google Cloud, nor Microsoft Azure, nor Cloudflare. Pending messages live only in RAM, swap is disabled, a power cut wipes everything, and release manifests are signed on a Qubes OS machine isolated from the network. Tor turns on with a single button, without a third-party app, and stays off by default. Incognito mode assigns a different profile per contact, display name and relay included, which prevents linking a professional life and a private one. The relays are self-hostable by anyone, the software being open. The clients are published under the AGPLv3 licence. The self-custodial wallet handles Bitcoin, Ethereum, Monero, Polygon, Solana and Tron, with keys never leaving the device, and Zcash support is announced without being available to date. The built-in Swap is an aggregator that compares offers from independent providers, rating each from A to D according to the level of identity verification required, from A for no KYC to D for mandatory KYC, with funds moving directly between the user and the chosen provider. To our knowledge, no other messenger offers this rating. The vendor, finally, is an identifiable commercial entity, Arpokrat GmbH, domiciled in Zug, Switzerland, with a public postal address, a PGP-signed warrant canary renewed on a sixty-day validity window, and a commitment to answer support within 24 hours. The app is free, without advertising.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it does not protect.&lt;/strong&gt; And this is where we have to be precise, because it is the only way to be credible about the rest.&lt;/p&gt;
&lt;p&gt;Arpokrat Messenger has to date &lt;strong&gt;no independent cryptographic audit published in its name&lt;/strong&gt;. SimpleX has two. The underlying protocol is therefore audited, our implementation and our operations are not, and that is not the same thing, as explained earlier in this article.&lt;/p&gt;
&lt;p&gt;Arpokrat has &lt;strong&gt;no public record of resistance to legal demands&lt;/strong&gt;. Signal has one, verifiable, spread over years. A warrant canary is a serious commitment, it is not a judicial precedent.&lt;/p&gt;
&lt;p&gt;The app today exists only on &lt;strong&gt;Android&lt;/strong&gt;. The iOS, Linux, macOS and Windows versions are announced, not available. For anyone exchanging with iPhone users, that is an immediate obstacle and there is no workaround.&lt;/p&gt;
&lt;p&gt;The network, finally, is young and small. The number of users does not make security, but it does make your correspondents available, and that is a legitimate criterion we ourselves defended above.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who it is for.&lt;/strong&gt; For anyone who wants a no-identifier architecture without giving up everyday usability, and who prefers an identifiable commercial entity to a community project whose funding can stop. The positioning we defend is not &amp;ldquo;the most private&amp;rdquo;, it is narrower and more honest: the most usable among no-identifier architectures, with an asynchronous model that peer-to-peer architectures do not offer, an ecosystem and commercial support.&lt;/p&gt;
&lt;h3 id=&#34;briar&#34;&gt;Briar&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://briarproject.org&#34;&gt;Briar&lt;/a&gt; is probably the most uncompromising project on this list. There is no server at all: messages pass directly from one device to another through Tor, and failing a connection, by Wi-Fi or Bluetooth between nearby devices.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it really protects.&lt;/strong&gt; Everything that depends on infrastructure, since there is none. Nothing to seize, nothing to subpoena, no operator to compel. Offline mesh mode genuinely works during an internet cut, which makes Briar the reference tool for blackouts and demonstrations. The code was audited by Cure53 in March 2017, with twelve issues raised and fixed. The project is free software and its design is authoritative. Briar Mailbox, a separate app to install on a spare Android device left switched on, makes it possible to receive messages while the main phone is offline, which partly answers the main limitation of the peer-to-peer model.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it does not protect.&lt;/strong&gt; Comfort of use, and now the project&amp;rsquo;s trajectory. Battery consumption is high, background operation on Android is erratic, account backup and attachments are missing, and adding a contact is laborious. There is no iOS version. The desktop version remains in beta, the latest being 0.6.5-beta released on 20 February 2026. And above all, the announcement of 9 July 2026 places the project in maintenance mode: security and bug fixes, without feature development. The project specifies that rumours of a complete shutdown are out of date, but its ambition is clearly suspended.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who it is for.&lt;/strong&gt; For an internet blackout zone, a demonstration, a censorship context, or a small group that accepts the constraint in exchange for the total absence of infrastructure.&lt;/p&gt;
&lt;h3 id=&#34;cwtch&#34;&gt;Cwtch&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://cwtch.im&#34;&gt;Cwtch&lt;/a&gt; is developed by the Open Privacy Research Society, a Canadian non-profit based in Vancouver. The project explicitly targets metadata-resistant group messaging.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it really protects.&lt;/strong&gt; Metadata, including in groups, which is the hard problem. Connections go through Tor v3 onion services, and the servers that relay group conversations are designed to be untrusted on principle: they must learn nothing. Version 1.13, released in September 2023, marked the end of the long alpha and beta phase, and the project has continued through to 1.15.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What it does not protect.&lt;/strong&gt; Sustainability, once again. The organisation lives essentially on individual donations and has said so publicly on several occasions. There is no iOS version. The pace of development is that of a small team, and the user ecosystem is very limited. We have not found a published external audit equivalent to those of SimpleX or Briar.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who it is for.&lt;/strong&gt; For an activist or research group that needs metadata-resistant collective conversations and whose members are technically comfortable.&lt;/p&gt;
&lt;h2 id=&#34;convergence&#34;&gt;The convergence of 2026, the messenger becomes a wallet&lt;/h2&gt;
&lt;p&gt;Here is the most interesting observation of the year, and to our knowledge nobody has yet put it this way.&lt;/p&gt;
&lt;p&gt;In 2026, three forks of three different protocols, developed by three unconnected teams, had the same intuition at the same moment: integrating a self-custodial wallet into an encrypted messenger. Radar is a fork of Signal with Bitcoin over Lightning. Zerion is derived from Briar with Bitcoin and Monero. Arpokrat Messenger is a fork of SimpleX with a multi-chain wallet and a swap aggregator.&lt;/p&gt;
&lt;p&gt;Three opposite technical bases, one and the same conclusion. That is no coincidence, it is the sign that two needs that used to be handled separately are converging. Sending money and sending a message pose the same problem: an intermediary who knows both ends. The answer built for messages, content encryption and metadata minimisation, is exactly what cryptocurrency users are looking for. And messaging is the only place where you already know your recipient.&lt;/p&gt;
&lt;p&gt;The three approaches are nevertheless very different, and the comparison is instructive.&lt;/p&gt;
&lt;h3 id=&#34;radar&#34;&gt;Radar&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://radar.chat&#34;&gt;Radar&lt;/a&gt; was launched on 7 July 2026 by the Cake Wallet team, under a separate entity, Radar Chat, Inc., led by its founder Vikrant Sharma. It is a fork of Signal, free, open source, available on iOS and Android. The wallet is self-custodial, with a twelve-word recovery phrase and encrypted backups. The payment layer deserves a clarification, because the sources do not say the same thing. Radar&amp;rsquo;s site describes a Bitcoin wallet backed by the Lightning network, assigns a Lightning address to each account, and mentions nothing else. Several articles published in July 2026 indicate, on the contrary, that the underlying machinery rests on Spark, a Bitcoin layer 2 network integrated via the Breez SDK, a transfer between two Radar users then settling Spark to Spark in under a second. The two versions are not mutually exclusive, since the Breez documentation describes an SDK that supports Spark and Lightning together, Lightning addresses and bolt11 invoices included. Absent public confirmation from the vendor itself, we go with what is verifiable on its own site: self-custodial Bitcoin payments reachable over the Lightning network.&lt;/p&gt;
&lt;p&gt;The most striking choice lies elsewhere. Radar is not a separate network: you connect to it with your &lt;strong&gt;existing Signal account&lt;/strong&gt;, and contacts, conversations, groups and username follow. That is Radar&amp;rsquo;s competitive advantage, and it is also its main open question.&lt;/p&gt;
&lt;p&gt;This interoperability implies that Radar inherits Signal&amp;rsquo;s model in full: the phone number remains the identifier, the Signal PIN controls account recovery and therefore, by default, access to the wallet keys that Radar encrypts into the Signal account, and the infrastructure called upon is the Signal Foundation&amp;rsquo;s, under American jurisdiction.&lt;/p&gt;
&lt;p&gt;The sustainability of that arrangement then has to be questioned, without stating it as a fact. Signal has historically refused to let third-party clients use its servers: in 2016, the LibreSignal project was abandoned after Moxie Marlinspike made it known that he did not want either Signal&amp;rsquo;s name or its servers used by a fork, and he also ruled out any future federation. The foundation retains the technical ability to block a third-party client by its signature. To date it has not done so, and Molly has used the network for years without incident, a precedent the Radar team explicitly invokes. Radar also pays a monthly contribution to the Signal Foundation and plans to increase it as it grows. Nothing therefore indicates that Radar will be blocked. But a product whose network access depends on the continued tolerance of a third party carries a structural risk that neither SimpleX nor Briar carries, and the user deserves to know it before placing funds there.&lt;/p&gt;
&lt;h3 id=&#34;zerion&#34;&gt;Zerion&lt;/h3&gt;
&lt;p&gt;&lt;a href=&#34;https://zerion.chat&#34;&gt;Zerion&lt;/a&gt; is derived from Briar, built on the Bramble transport protocol, published under GPL v3, and the project states clearly that it is neither affiliated with nor endorsed by the Briar project. It exists only on Android.&lt;/p&gt;
&lt;p&gt;Credit where it is due, because it does several things remarkably well. All traffic goes through Tor, without exception: your device builds a three-hop circuit, your correspondent&amp;rsquo;s builds another, and the two meet at a rendezvous relay, six hops in total and no IP address exposure. Every message is protected by a post-quantum key exchange based on ML-KEM-768. Version 3.0 added a Bluetooth offline mesh that relays individual and group messages through nearby phones, each relay carrying only ciphertext, as well as an optional I2P transport. A hardened mode refuses to start on a compromised device, under a debugger or with hooking frameworks. Since version 3.0.4, an encrypted vault can hold self-custodial Bitcoin and Monero wallets, whose keys are generated on the device, protected by their own password, with reproducible builds from frozen sources and published fingerprints.&lt;/p&gt;
&lt;p&gt;The limitation is structural and the project does not hide it: its documentation states in black and white that a message is only delivered when both devices are online and connected to Tor, and that no server stores it in the meantime for long offline periods. In other words, there is no equivalent of Briar Mailbox. That is the decisive technical point, and it is what separates a peer-to-peer model from a &lt;strong&gt;store and forward&lt;/strong&gt; model in which a blind relay keeps the encrypted message until the recipient comes to collect it. For ordinary correspondence between two people who are not connected at the same time, the difference is not theoretical, it decides usage.&lt;/p&gt;
&lt;p&gt;A second question remains open, and we frame it as a question since we have found no public measurement: what is the real quality of peer-to-peer audio and video calls on a six-hop Tor architecture? The technical choices announced are serious, Opus, H.264, AES-256-GCM encryption and padded frames, and calls are off by default. But Tor is not designed for low latency, and in the absence of published measurements, neither the vendor nor we can claim that the experience is comparable to a classic call.&lt;/p&gt;
&lt;p&gt;Finally, we have found no published independent audit for Zerion.&lt;/p&gt;
&lt;p&gt;Compared, the three approaches sketch three clear trade-offs. Radar chooses immediate adoption at the price of dependence on a third party and of keeping the phone number. Zerion chooses maximum network resistance at the price of deliverability and of availability on iPhone. Arpokrat chooses the asynchronous model and jurisdictional spread at the price of a track record and an audit that do not yet exist. None of these three trade-offs is absurd, and none is free.&lt;/p&gt;
&lt;h2 id=&#34;tableau&#34;&gt;Summary table&lt;/h2&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;Application&lt;/th&gt;
					&lt;th&gt;Identifier required&lt;/th&gt;
					&lt;th&gt;Jurisdiction and hosting&lt;/th&gt;
					&lt;th&gt;Server-side metadata&lt;/th&gt;
					&lt;th&gt;Published external audit&lt;/th&gt;
					&lt;th&gt;Offline delivery&lt;/th&gt;
					&lt;th&gt;Code&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;WhatsApp&lt;/td&gt;
					&lt;td&gt;Phone number&lt;/td&gt;
					&lt;td&gt;United States (Meta), CLOUD Act&lt;/td&gt;
					&lt;td&gt;Extensive, contact graph deliverable on warrant&lt;/td&gt;
					&lt;td&gt;No for the service&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Closed client&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Telegram&lt;/td&gt;
					&lt;td&gt;Phone number&lt;/td&gt;
					&lt;td&gt;British Virgin Islands, management in Dubai&lt;/td&gt;
					&lt;td&gt;Extensive, cloud chats readable by the vendor&lt;/td&gt;
					&lt;td&gt;No&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Open client, closed server&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Signal&lt;/td&gt;
					&lt;td&gt;Phone number&lt;/td&gt;
					&lt;td&gt;United States, CLOUD Act&lt;/td&gt;
					&lt;td&gt;Two timestamps, public judicial record&lt;/td&gt;
					&lt;td&gt;Protocol formally analysed&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Open&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Molly&lt;/td&gt;
					&lt;td&gt;Number (Signal account)&lt;/td&gt;
					&lt;td&gt;Signal servers, United States&lt;/td&gt;
					&lt;td&gt;Identical to Signal&lt;/td&gt;
					&lt;td&gt;Inherited from Signal&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Open&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Session&lt;/td&gt;
					&lt;td&gt;None, random identifier&lt;/td&gt;
					&lt;td&gt;Switzerland, decentralised node network&lt;/td&gt;
					&lt;td&gt;Minimal, no forward secrecy to date&lt;/td&gt;
					&lt;td&gt;Yes, Quarkslab&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Open&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Threema&lt;/td&gt;
					&lt;td&gt;None, Threema ID&lt;/td&gt;
					&lt;td&gt;Switzerland, servers in Zurich&lt;/td&gt;
					&lt;td&gt;Minimal&lt;/td&gt;
					&lt;td&gt;Yes, Cure53 and ETH Zurich&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Open, paid&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Wire&lt;/td&gt;
					&lt;td&gt;Email or number&lt;/td&gt;
					&lt;td&gt;Switzerland and Germany, American entity in Delaware&lt;/td&gt;
					&lt;td&gt;Retained in the clear&lt;/td&gt;
					&lt;td&gt;Yes, Kudelski and X41&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Open&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Element / Matrix&lt;/td&gt;
					&lt;td&gt;Depends on the server, often email&lt;/td&gt;
					&lt;td&gt;Your host&amp;rsquo;s&lt;/td&gt;
					&lt;td&gt;Visible to the server, room state in the clear&lt;/td&gt;
					&lt;td&gt;Audits published on the protocol&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Open&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;SimpleX Chat&lt;/td&gt;
					&lt;td&gt;None, no identifier&lt;/td&gt;
					&lt;td&gt;United Kingdom, default relays at Linode and Akamai&lt;/td&gt;
					&lt;td&gt;No correlation possible by a single relay&lt;/td&gt;
					&lt;td&gt;Yes, two Trail of Bits audits&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Open&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Arpokrat Messenger&lt;/td&gt;
					&lt;td&gt;None, no identifier&lt;/td&gt;
					&lt;td&gt;Switzerland (Zug), relays in five non-American jurisdictions&lt;/td&gt;
					&lt;td&gt;Blind relays, RAM only&lt;/td&gt;
					&lt;td&gt;None to date&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Open, AGPLv3&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Briar&lt;/td&gt;
					&lt;td&gt;None, no identifier&lt;/td&gt;
					&lt;td&gt;None, no server&lt;/td&gt;
					&lt;td&gt;None, nothing to seize&lt;/td&gt;
					&lt;td&gt;Yes, Cure53 in 2017&lt;/td&gt;
					&lt;td&gt;Via Briar Mailbox&lt;/td&gt;
					&lt;td&gt;Open&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Cwtch&lt;/td&gt;
					&lt;td&gt;None, no identifier&lt;/td&gt;
					&lt;td&gt;Canada for the association, servers untrusted by design&lt;/td&gt;
					&lt;td&gt;Group metadata resistance&lt;/td&gt;
					&lt;td&gt;Not identified&lt;/td&gt;
					&lt;td&gt;Partial&lt;/td&gt;
					&lt;td&gt;Open&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Radar&lt;/td&gt;
					&lt;td&gt;Number (Signal account)&lt;/td&gt;
					&lt;td&gt;Signal servers, United States&lt;/td&gt;
					&lt;td&gt;Identical to Signal&lt;/td&gt;
					&lt;td&gt;Not identified&lt;/td&gt;
					&lt;td&gt;Yes&lt;/td&gt;
					&lt;td&gt;Open&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Zerion&lt;/td&gt;
					&lt;td&gt;None, no identifier&lt;/td&gt;
					&lt;td&gt;None, no server&lt;/td&gt;
					&lt;td&gt;None, everything goes through Tor&lt;/td&gt;
					&lt;td&gt;Not identified&lt;/td&gt;
					&lt;td&gt;No, both devices must be online&lt;/td&gt;
					&lt;td&gt;Open, GPL v3&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id=&#34;profils&#34;&gt;Which messenger for which profile&lt;/h2&gt;
&lt;p&gt;There is no winner, there are situations.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For family and close friends.&lt;/strong&gt; Signal, without hesitation. It is the only choice that combines serious protection with a real chance that your contacts will install it. If the phone number bothers you, turn on a username so you do not have to share it. If your family absolutely refuses to move, at least turn on end-to-end encrypted backups on WhatsApp: it is not the same protection, but it is real progress and it is free.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For a journalist with sources.&lt;/strong&gt; The problem is not the content, it is the link. A no-identifier architecture is the only coherent answer here: SimpleX Chat or Arpokrat Messenger, with Tor enabled and a different profile per source. If your source already uses Signal and refuses to install anything else, use Signal rather than nothing, with a dedicated number that does not identify you, and Molly on Android to protect the device itself in case of seizure.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For an executive or legal counsel.&lt;/strong&gt; The dominant criterion is jurisdiction, not anonymity. Threema for a firm or a small structure, with clear invoicing and Swiss servers. Self-hosted Element for an organisation that has a technical team and wants sovereignty over its infrastructure, bearing in mind that the server administrator sees the metadata. Wire for an organisation that wants a commercial collaboration product, after examining its shareholding structure.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For an internet blackout or censorship zone.&lt;/strong&gt; Briar, because Bluetooth and Wi-Fi mesh mode works with no infrastructure at all, and Zerion for the same reasons with a more recent offline mesh. These are the only two real answers when the network itself is the adversary. Plan for Briar Mailbox if your correspondence has to survive extended offline periods.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For anyone handling crypto daily.&lt;/strong&gt; This is the only profile where the convergence of 2026 changes anything. Radar if your usage is Bitcoin and your network is already on Signal, accepting the dependence on Signal&amp;rsquo;s infrastructure and the phone number. Zerion if you want Bitcoin and Monero with maximum network resistance, and your correspondents are on Android and often online. Arpokrat Messenger if you want several chains, asynchronous availability and the ability to compare swap providers by their KYC requirements.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For anyone who wants the maximum with no usability compromise.&lt;/strong&gt; This category does not exist, and that is the honest conclusion of this comparison. The theoretical maximum is Briar or Zerion, and it is paid for in deliverability, in battery and in the absence of iPhone. The most favourable compromise today, if your correspondents are on Android, is a no-identifier architecture in store and forward mode, SimpleX Chat or Arpokrat Messenger, with Tor enabled. If you have to include iPhone users, SimpleX Chat is today the only one in this family to cover both platforms. Arpokrat Messenger, available on Android, is under development for iOS and for desktop platforms, with no availability date announced.&lt;/p&gt;
&lt;h2 id=&#34;choix-arpokrat&#34;&gt;What we chose at Arpokrat and why&lt;/h2&gt;
&lt;p&gt;This section is not a sales pitch, it is an explanation of trade-offs, including the ones we did not make.&lt;/p&gt;
&lt;p&gt;We started from SimpleX rather than writing a protocol. The reason is simple: a secure messaging protocol only has value once it has been inspected, and a new protocol has by definition no inspection behind it. SimpleX has a public specification, public code and two Trail of Bits audits. Inventing our own cryptography would have let us make a better marketing page and a worse messenger.&lt;/p&gt;
&lt;p&gt;We chose the store and forward model rather than peer-to-peer. That is an explicit trade-off against the theoretical maximum. A blind relay that keeps an encrypted message until it is collected is one more piece of infrastructure, and therefore one more surface. In exchange, a message leaves when you write it and arrives when your correspondent connects, which is the condition for normal correspondence. The practicality criterion, defended at the start of this article, is not a stylistic clause: we applied it to ourselves.&lt;/p&gt;
&lt;p&gt;We spread the relays across five jurisdictions outside the United States and excluded American hyperscalers, not out of posturing but because the CLOUD Act works by compelling an American provider over the data it controls. A blind relay that keeps nothing on disk has little to hand over; a blind relay that no American order can reach has even less. The two measures add up, neither replaces the other.&lt;/p&gt;
&lt;p&gt;We integrated a wallet and a swap aggregator because the same person who refuses to let an intermediary know their contacts generally refuses to let an intermediary know their transactions. The A to D rating of swap providers by their identity verification requirements comes from the same logic: we do not decide on the user&amp;rsquo;s behalf what level of privacy they want to pay for, we give them the information to arbitrate.&lt;/p&gt;
&lt;p&gt;What we have not yet done, finally, deserves to be said in the same section. We have no independent audit published in our name. We have no history of published legal demands, only a warrant canary. We are not yet on iOS. These three gaps are real, they are documented in our profile above, and none of them is closed by a press release.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;The right question is not &amp;ldquo;which is the best messenger&amp;rdquo;. It has no answer, because it is badly framed. The right question is: who are you protecting yourself against?&lt;/p&gt;
&lt;p&gt;Against an advertiser who wants to profile your interests, just about every app in this comparison will do. Against a violent partner who has access to your phone, the question is local locking and memory wiping, and Molly answers better than Threema. Against a legal demand in your country, the question is jurisdiction and what the service holds. Against an adversary trying to establish that you spoke to someone, the only answer is an architecture that does not create that information. And against an adversary able to cut the network, the only answer is not to depend on it.&lt;/p&gt;
&lt;p&gt;No app answers all these threats at once, and those that claim to deserve your suspicion first. What 2026 demonstrated is that encryption has become the easy part. What remains hard is metadata, jurisdiction, and a project&amp;rsquo;s ability to still exist in two years. Session came within a few weeks of disappearing, Briar scaled back its ambitions, and those two events say more about the real state of the sector than any comparison of cryptographic primitives.&lt;/p&gt;
&lt;p&gt;So choose according to your adversary, not according to a ranking. And keep in mind that the best tool in the world is worth nothing if the conversation ends up elsewhere because the person you are talking to would not install it.&lt;/p&gt;
&lt;h2 id=&#34;sources&#34;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://signal.org/bigbrother/district-of-columbia/&#34;&gt;Signal, Government Requests, District of Columbia&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.justsecurity.org/10311/michael-hayden-kill-people-based-metadata/&#34;&gt;Just Security, Michael Hayden, We Kill People Based on Metadata&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.congress.gov/crs-product/R45173&#34;&gt;Congressional Research Service, Cross-Border Data Sharing Under the CLOUD Act&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://cyberinsider.com/session-avoids-shutdown-as-community-donations-save-the-project/&#34;&gt;CyberInsider, Session avoids shutdown as community donations save the project&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://briarproject.org/news/2026-maintenance-mode/&#34;&gt;Briar, Briar is in maintenance mode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://simplex.chat/blog/20241014-simplex-network-v6-1-security-review-better-calls-user-experience.html&#34;&gt;SimpleX, Cryptographic design review by Trail of Bits&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://simplex.chat/blog/20221108-simplex-chat-v4.2-security-audit-new-website.html&#34;&gt;SimpleX, Security assessment by Trail of Bits&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://getsession.org/blog/session-code-audit&#34;&gt;Session, Code audit published by Quarkslab&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.privacyguides.org/news/2025/12/03/session-messenger-adds-pfs-pqe-and-other-improvements/&#34;&gt;Privacy Guides, Session messenger adds PFS, PQE and other improvements&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://inf.ethz.ch/news-and-events/spotlights/infk-news-channel/2023/01/threema.html&#34;&gt;ETH Zurich, Vulnerabilities in secure messenger Threema discovered&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.usenix.org/system/files/usenixsecurity23-paterson.pdf&#34;&gt;USENIX Security 2023, Three Lessons From Threema&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://briarproject.org/raw/BRP-01-report.pdf&#34;&gt;Cure53, Pentest Report Briar Project App and Protocol&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://wire.com/en/blog/independent-security-audit-2017/&#34;&gt;Wire, Independent security audit of the protocol implementation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://element.io/blog/hiding-room-metadata-from-servers/&#34;&gt;Element, Hiding room metadata from servers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://therecord.media/telegram-shares-ip-addresses-enforcement&#34;&gt;The Record, Telegram says it will share phone numbers and IP addresses with authorities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://freedom.press/digisec/blog/telegrams-compliance-with-data-requests-skyrockets/&#34;&gt;Freedom of the Press Foundation, Telegram&amp;rsquo;s compliance with data requests skyrockets&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.justsecurity.org/79549/we-now-know-what-information-the-fbi-can-obtain-from-encrypted-messaging-apps/&#34;&gt;Just Security, We Now Know What Information the FBI Can Obtain from Encrypted Messaging Apps&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://cryptobriefing.com/radar-chat-signal-fork-bitcoin-lightning/&#34;&gt;Crypto Briefing, Radar Chat launches as Signal fork with built-in self-custodial Bitcoin Lightning payments&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://sdk-doc-spark.breez.technology/&#34;&gt;Breez, SDK Spark, documentation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://lwn.net/Articles/687294/&#34;&gt;LWN, The perils of federated protocols&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://zerion.chat/faq.html&#34;&gt;Zerion, User Guide and FAQ&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
    </item>
    <item>
      <title>The Time Bomb: Harvest Now, Decrypt Later and the Zero-Knowledge Imperative</title>
      <link>https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/</link>
      <pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/</guid>
      <description>&lt;p&gt;The dependence of European governments on American cloud infrastructure poses more than just an immediate interception problem. The great revelation, the most devastating threat for decades to come, is what intelligence specialists call the &lt;strong&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/Harvest_now,_decrypt_later&#34;&gt;HNDL: &amp;ldquo;Harvest Now, Decrypt Later&amp;rdquo;&lt;/a&gt;&lt;/strong&gt; strategy.&lt;/p&gt;
&lt;p&gt;This is not a frontal intrusion, but a silent theft. Intelligence agencies and state adversaries are intercepting and storing immense amounts of encrypted data today, simply because the cost of storage has become negligible.&lt;/p&gt;
&lt;p&gt;They wait patiently for the moment when technological leaps and the unpredictable evolution of computing power will render current cryptographic keys obsolete. What constitutes a protected state secret in 2026 could become an open book in fifteen or twenty years.&lt;/p&gt;
&lt;h2 id=&#34;retroactive-liability-and-temporal-risk&#34;&gt;Retroactive Liability and Temporal Risk&lt;/h2&gt;
&lt;p&gt;The HNDL model introduces a novel concept: delayed legal harm. Traditionally, a breach of secrecy is a static event. With the massive collection of data for future decryption, confidentiality becomes a time-dependent variable.&lt;/p&gt;
&lt;p&gt;To quantify this risk, the HNDL scientific model defines that confidentiality inevitably fails when the required lifespan of the secret exceeds the adversary&amp;rsquo;s decryption horizon. Sectors of critical exposure are currently in a state of latent vulnerability.&lt;/p&gt;
&lt;p&gt;If a state or an organization does not guarantee the absolute sovereignty of its hardware infrastructure, it is practically signing a waiver of long-term confidentiality for its citizens and institutions.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Today&amp;rsquo;s interception is tomorrow&amp;rsquo;s compromise. Turning cloud dependence into a national security debt is a gamble impossible to repay.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&#34;the-arpokrat-antithesis-legal-impossibility-by-code&#34;&gt;The Arpokrat Antithesis: Legal Impossibility by Code&lt;/h2&gt;
&lt;p&gt;Faced with this vulnerability, the industry is responding by creating &lt;a href=&#34;https://arpokrat.com/&#34;&gt;radical digital sovereignty ecosystems&lt;/a&gt;. The Arpokrat model emerges as the perfect antithesis to centralized messaging: this architecture operates on a decentralized network, protected by the very strict &lt;a href=&#34;https://www.edoeb.admin.ch/en/basic-knowledge&#34;&gt;Federal Act on Data Protection (FADP) in Switzerland&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The core logic is one of absolute &lt;em&gt;Privacy by Design&lt;/em&gt;. By removing the need to provide a phone number, the user becomes a simple cryptographic key, devoid of physical identity.&lt;/p&gt;
&lt;p&gt;Legally, this drastically changes the rules of the game. If the &lt;a href=&#34;https://arpokrat.com/infrastructure&#34;&gt;architecture is fundamentally Zero-Knowledge&lt;/a&gt; and non-custodial, the company faces a technical impossibility to comply with foreign warrants.&lt;/p&gt;
&lt;p&gt;This is not civil disobedience against extraterritorial laws, but an unstoppable mathematical and legal safeguard: &lt;strong&gt;what you do not hold cannot be disclosed.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&#34;beyond-encryption-devaluing-the-target-data&#34;&gt;Beyond Encryption: Devaluing the Target Data&lt;/h2&gt;
&lt;p&gt;The true response, natively integrated into the &lt;a href=&#34;https://arpokrat.com/messenger&#34;&gt;Arpokrat messaging app&lt;/a&gt;, is not to bet on eternal mathematics, but to &lt;strong&gt;devalue the data itself&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Without central metadata, without phone numbers, and without IP logs to link a message to a physical individual, the encrypted content loses its strategic value because it becomes unattributable.&lt;/p&gt;
&lt;p&gt;However, software alone can do nothing if the hardware betrays it upstream.&lt;/p&gt;
&lt;p&gt;Ultimately, security in the 21st century requires the independence of the machine itself. Deploying a &lt;a href=&#34;https://arpokrat.com/os&#34;&gt;sovereign de-Googled OS&lt;/a&gt; has become an absolute survival requirement for anyone handling state secrets.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>The Illusion of Sovereignty: The Olvid Case and the CLOUD Act Trap</title>
      <link>https://arpokrat.com/blog/illusion-of-sovereignty-cloud-act-fisa/</link>
      <pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/illusion-of-sovereignty-cloud-act-fisa/</guid>
      <description>&lt;p&gt;The announcement sounded like a true &amp;ldquo;cry of independence&amp;rdquo; in the corridors of Paris: the Prime Minister ordered the government to abandon WhatsApp and Signal in favor of Olvid, a messaging app presented as &amp;ldquo;native.&amp;rdquo; The stated goal was clear: protect state secrets from the long reach of foreign intelligence agencies.&lt;/p&gt;
&lt;p&gt;However, a bitter irony quickly emerged: Olvid&amp;rsquo;s core — its server infrastructure — beats within Amazon Web Services (AWS), an American giant.&lt;/p&gt;
&lt;p&gt;For the general public, this seems like a simple technical hosting issue. But for &lt;a href=&#34;https://arpokrat.com/infrastructure&#34;&gt;architects of sovereign cybersecurity&lt;/a&gt; and those tracking data geopolitics, it is a primary political vulnerability.&lt;/p&gt;
&lt;h2 id=&#34;extraterritoriality-and-conflict-of-sovereignties&#34;&gt;Extraterritoriality and Conflict of Sovereignties&lt;/h2&gt;
&lt;p&gt;By relying on Amazon&amp;rsquo;s infrastructure, Olvid automatically enters the orbit of the US &lt;a href=&#34;https://wikipedia.org/wiki/CLOUD_Act&#34;&gt;CLOUD Act&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The legal analysis of this case reveals a scenario of jurisdictional insecurity that simply adopting a national &amp;ldquo;app&amp;rdquo; does not resolve. The tipping point lies in the concept of &amp;ldquo;control&amp;rdquo; versus &amp;ldquo;localization.&amp;rdquo;&lt;/p&gt;
&lt;p&gt;The CLOUD Act radically changed the legal paradigm by stipulating that the physical location of the server does not matter. The service provider&amp;rsquo;s (here, AWS) obligation to cooperate stems solely from its jurisdictional tie to the US. Thus, Washington can demand data from companies under its jurisdiction, even when that data is physically stored on European soil.&lt;/p&gt;
&lt;p&gt;Legally, this creates a frontal conflict with the General Data Protection Regulation (GDPR). The Court of Justice of the European Union (through the famous &lt;a href=&#34;https://wikipedia.org/wiki/Max_Schrems&#34;&gt;Schrems I and II rulings&lt;/a&gt;) has already established that US surveillance laws do not offer a level of protection equivalent to Europe&amp;rsquo;s, as they are not limited to what is &amp;ldquo;strictly necessary.&amp;rdquo;&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Digital sovereignty is not an attribute of software, but a property of the integrity of the chain of custody.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&#34;the-spectre-of-fisa-and-the-false-promise-of-encryption&#34;&gt;The Spectre of FISA and the False Promise of Encryption&lt;/h2&gt;
&lt;p&gt;Worse still, this dependence on American infrastructure places this data under the shadow of the &lt;a href=&#34;https://wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act&#34;&gt;Foreign Intelligence Surveillance Act (FISA)&lt;/a&gt;, which authorizes electronic surveillance for &amp;ldquo;foreign intelligence&amp;rdquo; purposes targeting individuals located outside the US.&lt;/p&gt;
&lt;p&gt;Faced with these threats, Olvid asserts that its end-to-end encryption constitutes a sufficient shield. From a privacy engineering perspective, this defense is dangerously partial.&lt;/p&gt;
&lt;p&gt;The recent rejection of backdoors by the French National Assembly shows legislative resistance to vulnerability by design. Yet, even if the content of a message is encrypted, AWS&amp;rsquo;s centralized infrastructure exposes &lt;strong&gt;metadata&lt;/strong&gt;. Knowing &lt;em&gt;who&lt;/em&gt; is talking to &lt;em&gt;whom&lt;/em&gt;, &lt;em&gt;when&lt;/em&gt;, &lt;em&gt;how often&lt;/em&gt;, and &lt;em&gt;from where&lt;/em&gt; is often much more valuable to foreign intelligence than the message content itself.&lt;/p&gt;
&lt;p&gt;Encryption protects the text, but the centralized server betrays the network of contacts.&lt;/p&gt;
&lt;h2 id=&#34;the-real-danger-is-yet-to-come&#34;&gt;The Real Danger Is Yet to Come&lt;/h2&gt;
&lt;p&gt;As long as European infrastructure relies on entities subject to extraterritorial statutes, the legal security of our communications will remain purely temporary and illusory.&lt;/p&gt;
&lt;p&gt;National security in the 21st century requires much more than good legislative intentions or superficial software shields: it demands &lt;a href=&#34;https://arpokrat.com/os&#34;&gt;total infrastructure and hardware independence&lt;/a&gt;. Because while intercepting this metadata and encrypted packets seems harmless today, it actually feeds the most devastating threat of the next decade: the strategy of &lt;em&gt;&amp;ldquo;Harvest now, decrypt later&amp;rdquo;&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;A state secret intercepted today is nothing but a mathematical time bomb.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;(Read the rest of our analysis in Part 2: &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;The Time Bomb and the Zero-Knowledge Imperative&lt;/a&gt;)&lt;/em&gt;&lt;/p&gt;
</description>
    </item>
  </channel>
</rss>