
Work Here?
Work Here?
Work Here?
Signal is a privacy-focused messaging platform that provides secure, encrypted communication for individuals and groups. It uses state-of-the-art end-to-end encryption so messages and calls can only be read or heard by the intended recipients. The platform supports voice and video calls, group chats, and encrypted stickers, all without long-distance charges. Signal operates as an independent nonprofit and does not rely on ads, data selling, or user tracking; it is funded through grants and donations. This makes privacy an integral part of its operations rather than a feature. Signal aims to give people a reliable, private way to communicate without surveillance or data collection.
Industries
Consumer Software
Social Impact
Cybersecurity
Company Size
51-200
Company Stage
N/A
Total Funding
$50M
Headquarters
Indianapolis, Indiana
Founded
2013
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Total Funding
$50M
Above
Industry Average
Funded Over
1 Rounds
Remote work flexibility
Healthcare, vision, and dental
401(k)
"It is fucked up what is happening": Signal's Whittaker on AI in the operating system. Meredith Whittaker, president of the messaging app Signal, delivered an unusually blunt assessment of the relationship between privacy and artificial intelligence at the TechBBQ conference in Copenhagen. Her argument: today's AI boom is the product of the advertising and surveillance business model that has carried the tech industry since the 1990s. And the next stage of that model, AI assistants embedded deep inside operating systems, could pull the ground out from under Signal as it exists today. Roughly a billion people currently use ChatGPT, and about as many use Google's Gemini, which is also deeply integrated into Android. Billions more will soon have access to Siri AI in the next version of iOS. Anthropic, meanwhile, is heading toward an IPO that could make the maker of Claude the seventh most valuable company in the world. From data collection to inference. Twice a week for free - never miss a story! Whittaker begins by describing a shift in what privacy even means. For a long time, the guiding question was which data a company could collect about a person. Today the question is what models can infer from it. "I think the surface area for data creation and collection and the kind of inferences and modeling of who we are and our behavior has expanded dramatically," she said. That expansion, she argues, is a product of AI, and AI in turn is a product of a specific business model: "a very particular business model that was built around collecting huge amounts of data about users, scaling platforms, scaling tech products (...) in order to create models of types of people that they could sell advertisers access to." She traces its origins to the 1990s, when the regulatory framework for the internet industry took shape in the United States: an advertising-funded tech sector that underwrote the privatization of the internet and remains the economic engine of the industry. Old algorithms, new volumes of data. From there Whittaker derives her explanation for the rise of the AI companies. The deep learning methods themselves are old, she notes. Backpropagation dates back to the 1970s and 1980s and was long regarded as experimental and largely ineffective, "largely because they weren't matched with huge amounts of data and huge amounts of compute." She locates the turning point in the early 2010s, when Google, Facebook and others had both: enormous training corpora such as YouTube videos and user data, plus the server capacity they had already built to collect and process that data. "Suddenly they were reanimated with the huge amounts of data (...) These algorithms, these AI approaches were really, really good at things like calibrating an engagement-driven social media feed." Her conclusion: "This revival of AI actually rests on the basis of this mass data collection, this business model that itself was a contingency of 1990s regulatory and policy decisions, not the inevitable shape of tech today." By now the mechanism runs in both directions, she says, with AI intensifying the hunger for data. Behind product promises such as voice assistants and AI glasses, Whittaker sees first and foremost an apparatus for data capture: "We're talking about a data collection apparatus that they're hoping marketing will lull us into without thinking about the collateral consequences." Her call to users and companies is to ask concrete questions: where the data sits, where it is processed, who owns it, and which other data it gets joined with. Why Signal is a nonprofit. Asked whether a company like Google or Meta could ever be fully privacy-respecting, Whittaker points to economics: "Given the current business model they cannot be." Technically the question is settled, she says, with Signal as the reference point: "The ideas are not scarce. What we're talking about are political economic realities." Signal costs around 50 million dollars a year in bandwidth, servers and staff, according to her, and is funded by donations. She puts the reason plainly: "I cannot have a board member coming back from Davos being like, carve out a little bit of your privacy promises so that you can actually beat those revenue goals." In the AI era, the pressure has grown: "There is an atmosphere of almost psychedelic hype around AI that makes it harder and harder to just defend these fundamentals on technical grounds." On the regulatory front, Signal continues to face attempts to weaken encryption. Whittaker speaks of "zombie bills, like chat controls," meaning efforts such as the EU proposal that justifies blanket scanning of communications as a way to protect children. Signal's announcement that it would leave the EU and the UK if such an obligation passed is meant seriously: "If we puncture the network at one point, we have poisoned it for everyone (...) we'll go home." "It is fucked up what is happening" The danger Whittaker considers most underestimated is the integration of AI assistants and agents into operating systems. Here she gets explicit: "Allow me this morning to be a little bit spicy, but it is fucked up what is happening." Her example is the summarization feature in Siri under iOS 27. Ask the assistant to summarize what is on screen, and it takes a screenshot of the app in the foreground. "It is taking a screenshot if the Signal is there and you haven't blocked it as a user. And it is then sending a screenshot of your Signal message off-site potentially to be processed by an LLM so Siri can say your message says dinner is at 7." Whether the processing happens on the device or on a server is not clearly documented, she says. She sees comparable capabilities in Gemini and in the integration of ChatGPT with iMessage. The point of attack thus moves away from encryption itself, which in Signal's case has been openly documented for more than a decade and scrutinized by the security community. "That is a battleship if you want to get through that. Suddenly, there is a hole in the battleship that is typing that information into an insecure database, off-site, into the hands of a third party, because the operating system is the ocean we and every other application developers swim in." App makers would have control over this only if Apple, Google or Microsoft built in toggles to opt out. Without such options, Whittaker sees Signal's foundation at risk: "I'm not being dramatic here: if this trajectory holds in a year or two Signal will not be able to operate with integrity. We will not be able to make privacy promises that we as developers who are independent can keep, because the water we swim in will have been poisoned." How Signal itself uses AI. Signal has been conspicuously restrained about adding AI features. Whittaker's reasoning, delivered to the room: "Raise your hand if you want an annoying chatbot in your messenger." No hands go up. And further: "We don't have data. So we're not going to turn over data for an inference for a chatbot, and we don't have data to train it on." Then there is the context of use: "You're in Ukraine, you need to quickly talk. You don't need like, let me summarize your dinner plan." Signal has "a duty of care to serious people," she says. There is one AI feature at Signal: a face detection model that runs locally on the device and recognizes whether a photo contains a face. It powers the automatic blurring in the media editor. "If I posted that on social media, I would not be exposing your biometrics to a big tech company. That is a mission-aligned use of AI, but it is very precise." The proliferation of AI features in other products she attributes to internal pressure: "A lot of what you're seeing (...) is like a desperation by teams who've been told from higher up that you have a KPI this quarter to ship AI. Figure it out. Before lunch, they get in a conference room, like Chad, Brad, and Mike are like, I don't know, I guess we put a chatbot in this." The promise is a magic assistant, she says, while the result is often a flawed summary that books the wrong flight. Privacy as a business model for European startups. Asked from the audience what she would recommend to European founders, Whittaker offers a market-gap logic: "Look at what the big tech model can't do well (...) What is the scale at all costs, AI is everything model not able to do? And one thing is privacy." She sees demand in banking, in government and around European defense concerns: "There is still a huge market need for privacy (...) And particularly with the sovereignty concerns, we will have customers here." She backs this with a security argument: "LLMs themselves are not secure architectures. The data extraction attacks, data poisoning, there's a lot of problems with just that form in terms of security and privacy." She is even more critical of the systems built around them, which are designed for sweeping access to user data and broad authority to act: "That looks a lot like malware if you're looking at it from a sort of software architecture perspective." Her appeal to the industry is to make security and privacy the "apex functions" of design. What makes Whittaker optimistic is the widening gap between marketing and reality: "We're in a place where the hype seems almost divorced from reality (...) Every private conversation I have with someone kind of off the record, people are like, yeah, this is weird." Her hope: "People will find the muscle memory, find the strength to sort of stand up and confront a grim map with a strategy that is worthy of it." Aus Datenschutz-Gründen ist dieser Inhalt ausgeblendet. Die Einbettung von externen Inhalten kann in den Datenschutz-Einstellungen aktiviert werden:
Signal to offer phone-number-free registration via one-time payment for enhanced privacy. Signal is reportedly developing a feature for optional registration without a phone number, potentially involving a one-time payment to enhance user privacy and anonymity. Signal, a widely recognized encrypted messaging application, is reportedly developing a new feature that would allow users to register without providing a phone number. This potential enhancement, which is rumored to involve a one-time payment, aims to significantly bolster user privacy and anonymity. Current registration and privacy concerns. Presently, Signal mandates that users register with a valid phone number. This requirement has been a point of concern for privacy advocates, who argue that it creates a potential link between a user's identity and their messaging activities, even though the message content itself is end-to-end encrypted. The new optional registration feature. The forthcoming feature, still in its developmental stages, is said to offer an alternative registration method through a one-time payment. While the specifics of the cost and the exact process are not yet public, this approach could provide a valuable option for users who prioritize anonymity in their digital communications. This development aligns with Signal's core mission of user privacy and its commitment to transparent data handling policies. Implications for user privacy. The ability to use Signal without linking it to a phone number represents a substantial step towards greater user control over personal information. In an era of increasing data collection and scrutiny, such a feature could attract users seeking more private communication channels. This move could further solidify Signal's reputation as a leading platform for secure and private messaging, differentiating it from other Messaging App services. Potential impact and future outlook. While the introduction of a one-time payment might present a barrier for some, the overall potential for enhanced privacy is likely to be well-received. This development underscores the growing demand for secure communication tools, including those that offer alternatives to traditional registration methods, such as those found in Secure Email platforms. The full impact of this feature will depend on its final implementation and accessibility.
Signal adds an extra layer of security to make sure you're actually chatting with the right person. Published Tue 11 Aug 2026 // 21:45 UTC Signal has introduced a new layer of security to help make sure no one has secretly interfered with your encrypted chats. The chat app is favored by diplomats, activists, and journalists for its security. It uses end-to-end message encryption and "safety numbers" - cryptographic fingerprints associated with the keys securing a conversation - which users can compare to verify they have the expected encrypted connection with a contact. But in theory, someone could still intercept messages by corrupting the centralized directory of accounts and posing as somebody else - a classic "man in the middle" attack. Everything would still be encrypted, just going to the wrong place. To fight this possibility, Signal announced a new feature called Automatic Key Verification (AKV) on Tuesday. From a user perspective, AKV is easy: Tap on a Signal contact's profile, navigate to the "View Safety Number" screen, and tap on the "Verify automatically" button. It will then show a green checkmark to verify that the contact's public encryption key matches what Signal's key transparency system expects. Behind the scenes, however, Signal has developed a new architecture for detecting whether someone has tampered with the public keys associated with an account to intercept messages, as that would require a change to the public encryption key and, in turn, the safety number that a user might not recognize. Ledgers and trees and third parties, oh my! Signal described the new system as serving as a ledger of public keys in which every change a user makes to their information (e.g., linked phone number) leads to a new iteration of the ledger. Accompanying that ledger is an index, allowing Signal users to verify the information in the ledger about themselves or their contacts to make sure it hasn't been altered by a malicious third party seeking to intercept messages. This ledger lives on an "open-source key transparency server" Signal created for the AKV process, the company said. "When Signal users register, change their phone number or username, or re-create their account, Signal records the changes in a log tree ('the ledger') and facilitates searching through the log tree with prefix trees ('the index books')," Signal said in the announcement. Digging through an index is hardly automatic, however, so Signal combs the index on the user's behalf to verify the information they're retrieving about a contact is the most up-to-date. Up-to-date doesn't mean it's accurate, however, which is where third-party auditors come in. Cloudflare and security firm Trail of Bits serve as Signal's AKV third-party auditors, according to the announcement. Their role in the whole thing is to verify that Signal's own key transparency server isn't compromised. Per the announcement, third-party auditors check the index to ensure entries don't appear to have been altered. If those checks come out clear, the auditor signs the response to indicate that the keys being provided are the same for both users, thus eliminating the possibility of a man-in-the-middle attack. Yet again we have a security shortcoming, as auditors can guarantee the index and key transparency server hasn't been tampered with, but can't verify the accuracy of the data they contain, which is where the final part of the puzzle comes in: Monitoring. "There are two ways for customers to interact with the ledger: looking up someone else's address, and looking up their own," Signal explained. "Monitoring requires Alice and Bob [your usual cryptographic placeholders] to do both of these things on a regular basis, each detecting a different kind of tampering." Alice and Bob are each able to monitor their own ledger entries via the Signal app, which periodically checks it automatically, and they can verify their connection's data is correct through the View Safety Number "Verify Automatically" button we mentioned earlier. More context. "These two kinds of monitoring, combined with third-party auditing, form a complete detection system: auditing guarantees that Alice and Bob are looking at the same data, and monitoring guarantees that both of them are regularly checking that data for accuracy," Signal explained. Security is never simple. AKV still ultimately leaves Signal users on the hook for their security: If you want to be truly sure your contact is who they say they are, you'll need to hit that verify button every time you want to chat. It's also worth pointing out that this won't always work for all Signal users. "Your Signal app automatically verifies your own phone number and username data in the log," the announcement said. "But to verify this for someone else, you need to have their phone number." In other words, if you don't have your contact's phone number through Signal or a matching entry in your phone's address book, you can't use AKV to verify the encryption key associated with that contact. AKV can also be disabled for users who don't want a third party involved in verifying their identity, in which case Signal recommends relying on good old fashioned safety number or QR code verification. Nothing in the cryptographic verification space is ever easy, is it?(R)
Signal introduces Automatic Key Verification to streamline messaging security. Signal has officially rolled out Automatic Key Verification, a new security feature designed to confirm encryption keys automatically between contacts without requiring manual intervention. While all communications on the platform have always been end-to-end encrypted by default, the updated verification mechanism simplifies how users ensure their encrypted sessions remain secure against potential interceptors. Estimated reading time: 4 minutes Table of contents. PLEASE CONSIDER SHARING, THANKS! The role of Key Verification in end-to-end encryption. End-to-end encryption relies on cryptographic key pairs unique to each user's device. When two users initiate a conversation, their devices exchange public keys to encrypt and decrypt messages. Historically, verifying that no third party modified or intercepted those public keys required users to manually compare "safety numbers" or scan an in-person QR code. While manual verification remains the gold standard for high-security environments, many casual users rarely complete the process. Automatic Key Verification automates this validation step in the background, offering an immediate cryptographic check without adding friction to daily messaging. How Signal implements key transparency. The underlying technology behind Automatic Key Verification is built on key transparency. Key transparency maintains an auditable, tamper-evident cryptographic log that allows client devices to verify that the encryption keys served by central infrastructure match what other devices expect. When the feature is active and verification succeeds, users opening a contact's profile will see a green checkmark accompanied by an "Encryption verified" badge. Key operational parameters for the feature include: * Phone Number Dependency: Automatic verification is available when Signal has access to a contact's phone number, such as when a contact is saved in a user's address book or set to discoverable by phone number. * Username Conversations: If a chat is initiated strictly via a username without an associated discoverable phone number, the system defaults back to standard manual safety numbers. * Device Version Requirements: The automated check requires updated client applications across mobile and desktop platforms, including Android version 8.21.6, iOS version 8.22.0, and Desktop version 8.21.0 or newer. "Automatic key verification provides an additional, streamlined way to confirm that there's no unexpected party between you and the other 'end' of an end-to-end encrypted session. It is an additional check alongside Signal's safety num bers." What Automatic Key Verification does not do. To maintain realistic expectations regarding personal privacy, developers emphasize what automated checks do and do not cover. Automatic key verification confirms that encryption keys between devices match correctly, but it does not verify real-world personal identity. If a malicious actor gains access to a physical device or tricks a user into communicating with a fraudulent account, automated key validation will still succeed because the underlying cryptographic keys are valid. Furthermore, if automatic verification is unavailable due to outdated app builds, network timing discrepancies, or unlisted phone numbers, messages remain fully end-to-end encrypted. In those scenarios, users seeking absolute verification can continue scanning QR codes or comparing safety numbers directly through trusted secondary channels. By integrating automated key transparency directly into client applications, Signal makes sophisticated cryptographic verification accessible to everyday users without compromising underlying message privacy. What do you think of AKV and Signal implementing it? Find me on any of the social media platforms below, follow, and comment. Follow Us On Any of These Social Platforms! In some of its articles and especially in its reviews, you will find Amazon or other affiliate links. As Amazon Associates, Techaeris earn from qualifying purchases. Any other purchases you make through these links often result in a small amount being earned for the site and/or its writers. Techaeris often covers brand press releases. Doing this does not constitute an endorsement of any product or service by Techaeris. Techaeris provide the press release information for its audience to be informed and make their own decision on a purchase or not. Only its reviews are an endorsement or lack thereof. For more information, you can read its full disclaimer.
Signal Android v8.20 and iOS v8.22 updates add support for linking additional smartphones and Android tablets. Signal has started rolling out new updates for its Android and iOS applications, allowing users to link another Android phone, Android tablet, or iPhone to their existing Signal account and keep their messages synchronised across the connected devices. Signal Android v8.20 and Signal iOS v8.22 - linked-device support. The Signal Android v8.20 update will allow users to link another Android smartphone or Android tablet to their existing Signal account. Meanwhile, Signal iOS v8.22 adds support for linking an iPhone, alongside the already available support for iPads. Once linked, messages will remain synchronised across the connected smartphones, tablets, computers, and other supported devices. Speaking more, Signal has updated the Android application's interface with newer navigation and user-interface libraries to better support tablets, foldable smartphones, and devices with larger or unconventional displays. While linking a new smartphone or Android tablet, users can optionally transfer their complete message history along with the last 45 days of saved media. The transfer process remains end-to-end encrypted and uses the same Link and Sync system that Signal previously introduced for its Desktop and iPad applications. In addition to this, the latest update enables Signal to be used on Chromebooks, but the interface optimisation for Chromebooks will be introduced in the future. Certain features such as the Settings interface, in-app camera, and complete support for keyboard shortcuts are still under development for the Android Tablet. Stay tuned for more updates! Listen to audio version of this article Ready to play
Find jobs on Simplify and start your career today
Industries
Consumer Software
Social Impact
Cybersecurity
Company Size
51-200
Company Stage
N/A
Total Funding
$50M
Headquarters
Indianapolis, Indiana
Founded
2013
Find jobs on Simplify and start your career today