Signal proves that zero-knowledge proofs can satisfy legal requirements without sacrificing a single bit of user privacy. This is a masterclass in using advanced cryptography to solve the tension between regulatory compliance and total anonymity.
Deep Dive
Prerequisite Knowledge
- No data available.
Where to go next
- No data available.
Deep Dive
Signal CTO Answers YOUR Questions!
Added:Ryan Grant, digital contract design question is about um decentralized identifiers. Have you considered them?
Uh their main feature is um ways to rotate your keys that are are decentralized obviously. So tell tell us about your thoughts there.
>> Uh yeah so um I assume your question is in regards to sort of like phone number signup that exists on signal today. Uh that is something we are looking at hopefully for later on this year adding a way to sign up without phone numbers.
Uh the main uh downside at the moment and the reason we don't have that yet today is u removing accounts who are are spamming people or otherwise engaging in abuse of the service is sort of our our primary way of protecting people from from spam and other sort of issues like that that would affect the operational stability of the service. Uh so we got to figure out some way to sort of induce a cost for signing up without uh a phone number. The phone numbers effectively add a little bit of cost to the signup process today. Uh and that helps prevent bad actors from just creating accounts on NAS. But it is something we're looking at for later this year.
>> You do a follow-up if really if it's quick. Uh the quick followup here is decentralized identifiers are the specification for identifiers from the W3C and are you considering those? Are you aware of them?
>> I haven't looked at that spec in particular. So um I I'll check it out later on but uh no I haven't looked at that one in particular.
>> Hey Aaron. Um uh my affiliation I guess is FO uh helping out with the press here. Um so a major privacy issue at the moment is the rise of age verification laws around the world and in US states which effectively forces users to submit their personal identification to uh to websites and even to operating systems uh according to some laws being being drafted right now. So I was wondering um obviously Signal doesn't do age verification but what are your thoughts on the issues for privacy there the issues of deanonymization when everyone has to submit their IDs either to operating systems or websites and uh what policy makers are getting wrong here what they're getting right and is there a way to do verification without threatening people's anonymity online >> uh yeah that's a good question um it's it's kind of a highrisisk risk area asking people to upload their IDs in order to use a website or browse the internet. Um, and I think the lawmakers and people who are passing this are really overestimating the efficacy of doing that. Uh, it's going to be uh sort of of questionable actual effect. Uh, but I think the biggest thing that they're missing at the moment and and you see this with some of the uh ID leaks that have already occurred is they're not actually uh requiring that people separate identification from the the verification step. So like I could uh check someone's uh ID and then provide a way to uh blind that from the uh the verifier the person who's checking the ID and the actual service provider who's validating that your age is over whatever age threshold you need.
Um, for example, in in Signal today, uh, we have a donation system and unfortunately when you do payments, you you generally have to do sort of a KYC, know your customer flow, where if you're going to pay money to someone, uh, you've got to identify yourself to do so. Uh, but when we were building this in Signal, if you want to donate to us, we did not want to have identity linked to the Signal account. And allowing someone to just donate uh, and and have it directly linked would be something that like we didn't want that information. So we built an anonymous receipt system where you actually create a payment account that you donate from and then it is sort of separately uh like you can then get a receipt that the mobile app will then uh blind that receipt and when you come back on the signal account side and actually redeem it. We have these little badges in app that show that you uh donated. We can't tell which of the payment accounts you actually were. All it is is a receipt that proves you are one of the set of people who paid but no idea which one.
Uh so this sort of relies on like a Shamian ecash type of system. Uh there were some papers written by David Sha back in the 1980s I believe that are sort of the foundation of this system.
And I think something very similar uh should be really if you're going to do sort of an identity verification system ought to be part of what is required for that system as well so that the people who are doing the ID verification can't link the ID subsequently to the actual like activity of that user. You you can verify that someone has proven their ID is say over 18 over 21 or whatever threshold you need uh without actually directly linking it to the ID.
quick followup.
>> Um, just one quick followup. Uh, so the the current laws demand verification, but they don't demand any sort of technical standard that protects people's privacy or anonymity, which is interesting because there are also privacy laws that do put privacy requirements on companies. So do you think those two things should come together that there should be in the policym process a technical standard that requires some sort of zero knowledge proof system that protects identity?
>> Uh yeah it it seems like that would be a good thing to have if you're going to build this system in the first place which again I'm sort of like the efficacy of it is is sort of like questionable but if you're going to require the system to exist you ought to at least require as well that it be private for people. Uh because otherwise you're just sort of like requiring half of it without the other half. It's like why would you require a system and then not also require that it is uh sort of as privacy preserving as it can be because it is it's not that hard to build. You can build a zero knowledge proof system and they're relatively straightforward. It just requires reading a bit of of papers and they've been around for 40 years at this point.
>> My my question really was like what's next for WhatsApp or sorry for Signal [laughter] >> like you all have done a really good job. Yeah.
>> How dare you? Sorry Aaron.
Well, for WhatsApp, I hope they're going to adopt our postquantum crypto systems at some point here.
>> But like you've done a like the the tech world has kind of adopted it wholeheartedly, right? Like on my phone, it's like I know you can tell who I'm texting by what app I'm using. Like if I'm on Signal, it's somebody in the tech industry and then, you know, I have WhatsApp for like volleyball friends or stuff and then like SMSs are coming across from like family and friends.
like does Signal want to break out and like help me delete those other apps off my phone and how do we as users like attract more people onto Signal like kind of what's what's next in the the iteration? It seems like tech industry is kind of all on board and government officials I guess.
>> Uh yeah, that's a great question. Um it's we are looking to actually get uh those other uh people and other use cases on board and uh this is actually like the reason why some of the features we launched that like some of our early adopters especially were like why are you doing this like we added um status the status updates tab to signal a couple years ago and a number of our early adopters were like why have you done this we hate this feature we don't want this why is this here and it's uh because that feature is considered critical for users in certain countries especially Brazil and India uh who are we can't convince our friends and family to switch without this. Uh we have to have this feature. It's like without it none of our friends and family are going to switch. So we are indeed looking at how do we make it a sort of mass market appeal product uh for for everyone to switch to. And so that's like an example of one of the things that we've built that early adopters were like why? And the answer is because it gets more people on in the door.
>> Caleb Peterson just a friend. Um, have you guys considered adding some kind of meshtastic like things so that people can communicate directly peer-to-peer in case internet is denied?
Messages from peer-to-peer networks can be fed to the internet if someone gets access like through a Starlink thing.
Iran is a perfect example of people that might benefit from this.
>> Uh, yeah, this is actually something we've been looking looking at and talking about for a long time. In fact, even back to my time at at WhatsApp, we've been looking and sort of talking about this. Uh the big challenge for this is sort of the modality it introduces to an application. Uh so people expect their messaging application to essentially instantly deliver a message to someone who's halfway around the world. Uh when you start adding in this like mesh operating mode, uh there's several things that have to happen for it to work. uh one of which you have to have a bunch of intermediate storage on nodes that are sort of acting as the intermediate hops so that it can try to find a route to the person you're talking to. Uh and on mobile phones this tends to be kind of a non-starter. People get very protective of the space on their device um and uh will actually uninstall things that are consuming mass amounts of space. So it's it's difficult to get people to agree to sort of act as relay nodes for other people uh which you need in a sort of mesh uh model. Now, in certain uh events or scenarios where you're like, you know, 20,000 people out in the street at the same time uh attending this event, you can get people to sort of temporarily do that. But as a a way of like normal day-to-day operations, uh they don't generally like to do this. Uh and it has been a source of problem like people start uninstalling apps when they're their spa their phone runs out of space. And we'd even seen this at various points in time like after after Meta bought uh WhatsApp uh one of the big concerns that the blue app team which is the Facebook app they call themselves the blue app had was that uh WhatsApp was storing all the media on device and that was resulting in people uninstalling the Facebook application because they wanted more space for their WhatsApp media. [laughter] So at one point in time they had been considering like deleting the media off the phone and we're like no if you do that they won't have the media because it's not retained. Uh so it in general sort of is a problem where you kind of want two different completely separate modes of operation and the best way to do that in the way that people are most used to on a phone is you have two separate applications.
>> Um I guess you know you are obviously very biased as a CTO of signal. uh but I you know what are the pros and cons of uh the different messaging like for example for WhatsApp uh um if I want to communicate with an Indian um I have to use WhatsApp I think you know I don't think that they know what signal is uh you know so that's like for me that's a pro and you know I have to like oh okay like use WhatsApp but you know like what like how do you guys differentiate yourselves across these different apps like what do you see like what's your take which is obviously biased as a CTO of signal but I just want to know >> uh yeah so I mean the biggest advantage for signal is um on top of the message protection. So WhatsApp has licensed our software to protect their message content. So they're using basically the same uh encryption software we're using uh for the message content itself. But the messaging metadata is uh much more protect uh protected on signal. So the vast majority of messages that flow through signal, we don't even know who the sender is. It's effectively like going to a post office box and dropping in an envelope with just a destination and no return address. So most of the messages that flow through signal, we don't know who sent them. Um for WhatsApp, that's not the case.
Everything is sort of flowing with uh public uh like who sent this and who's it going to sort of information. Also, groups on Signal are much more uh private. We can't tell who's in a group whereas on uh WhatsApp uh the group's information about who's in a group, the group title, the group avatar are visible to the service operator to WhatsApp itself. Um, so we're effectively much more protective of the metadata, but the underlying message content is using the same software. Um, yeah.
>> Hi, I'm Thomas. I'm just a guest. Uh, couple questions about the app. I think you you you addressed some kind of roadmap stuff earlier and like priority of different features. Uh the two features that I've looked for in the last year that I'm I'm curious whether it's kind of a we don't have the prioritization for this right now or there's actually some like institutional barriers to doing so. Uh one was uh iOS to Android transfer. Um I switched from iOS to Android earlier this year and I was unable to port everything over. I had to kind of start from scratch. Uh the second thing is video call quality.
WhatsApp suffers from the same issue.
So, I think maybe it's a protocol thing, but at the same time, uh there are other endto-end encrypted video calling services that don't have that issue. So, I'm I'm curious if there's like a background to that.
>> Uh so, on the first one, uh that should be in place now. Uh we built an online uh backup system that shipped I think in February. Um so, that actually should be addressed. So, I I I like that answer.
It's the easiest one to give. Uh the uh the second one on video call quality. Uh yeah, generally both us and WhatsApp tend to uh try to dial that down towards like more bandwidth efficient because on cellular networks people tend to be pretty sensitive to uh the bandwidth usage. I believe there are some settings in the app that you could go to and adjust to like try to change the the quality uh defaults on that. Um but uh don't hold me to that cuz I'm not quite sure they're there. I know there's one for the quality of sending and receiving media. Uh so if you have unlimited bandwidth plans, one of the things I tell everyone is uh there is a default to sending media in low quality. You should go into the app settings and change it to high quality. Um I have certainly done that and uh I I would recommend that you do that as well. If you uh if you don't mind using a little bit more bandwidth, your photos and videos will come out the other end much higher quality at least for attachments.
I'm not sure if there's one for video calls, but I think there there might be in there as well.
>> Thank you.
Hello. Whoa. Um, Christian unaffiliated.
One of the things I love about Signal is actually it's a really good product. So, I've gotten like multiple members of my family to switch all their chats there.
>> Wait, is your affiliation really Signal?
No, just >> No, no. I said unaffiliated.
>> I know. I'm just wondering. [laughter] >> We got a fanboy here.
>> No, no, no. Unaffiliated. Anyways, uh, yeah. So, I really like I really like the product. It's great. A lot of other privacy or like privacy preservation products are terrible. They have clunky UI. Nobody wants to use them. They're like unattractive to normal people.
Anyways, have you thought about branching into like other products like not just doing a messenger? There's like a bunch of other tech products that suck that could use like uh great UI that could attract normal individuals and not just be clunky.
>> Uh yeah, that's a great question and it is an area where uh one of the things in particular, my favorite point to harp on with our our product manager is uh we need better contacts management. Right now, signal sort of relies upon your system address book and the phone numbers in the system address book as the primary way to manage your contacts.
Uh but in a world where say where you're building registration without phone numbers or already today this problem comes up a lot if people exchange usernames on signal or meet each other in signal groups. Uh there isn't really an identifier for like how to connect to your signal contacts. And so this is sort of a known problem that uh I think we do have to address. Um, and then beyond contacts, uh, the other one that I talk about a fair bit with our our uh, CEO is um, for so signal a 501c3 nonprofit and uh, like in the interest of sustainability, one of the products we could make that I think we could do something rather unique in the space. I I touched on earlier in response to Allen's Alam's question, uh, we have this sort of uh, payment system that separates payments from the actual redemption of the receipt. Um, I think we could build a VPN product where uh you could prove that you paid for the VPN without us actually knowing who you are. Uh, so that would be um I think a pretty great product as well and also help with sort of the sustainability story for Signal.
>> Cool. Hi. Have you ever thought about building >> could you introduce with the name and affiliation if you have one?
>> Uh, hi. I'm Ramos. uh don't have any particular affiliation but uh have you guys ever thought about building something equivalent to a telegram API so that someone can build a custom front end for a signal?
>> Uh we haven't really focused on that at the moment. We're primarily focused on the consumer front. Uh right now uh the API story gets a little bit difficult because a lot of times what people are sort of using uh APIs for looks a lot to our our system like spam. Uh so we just haven't focused on on that particular aspect of uh yet. That said, there are some thirdparty things that are out there like I I don't know how many of you might have looked up like signal CLI. Some people think that's associated with us. It's not. It's just a third party uh thing that someone has built and uh there's a there's a fair bit of people who've used that to like script access to Signal, but it's not something we officially support.
>> Q.
>> All right, Jacob. no affiliation. I'm an Apple Vision Pro user and uh to use Signal on the Vision Pro, you have to take a screenshot, send the screenshot to your laptop and then scan that with your laptop. So, can you integrate Vision Pro into Signal natively?
>> Uh, interesting. I guess you're you're linking operating as a link device. Is that what's going on?
>> Yes.
>> Okay. Um, that's a good question. I haven't really looked into that one. So, um I'll I'll look into like what we could do on that front, but uh it's not it's actually the first time I've heard this request to link the vision pro. So, >> yeah, at the FO don't be evil conference, you can actually uh you know have some input of the product roadmap, it sounds like. So, all right, Naomi, >> good morning. Hi, Erin. Hey, Rosie. Good to see you guys. I'm Paul Stack, a friend of FO.
>> Big Paul.
>> Yeah, big Paul. I just wanted to ask quickly to Aaron um and I can understand why you might want to just say a few words about this, but was there anything interesting about the revelation that there were prominent people in the federal government that were uh favoring using Signal instead of skiffs? And did that high-profile like accelerate adoption for you guys? Anything interesting to report on the inside from that?
>> Well, as they say, there's, you know, supposedly no such thing as bad press, right? So there's a lot of people who heard about signal who hadn't heard about it before. Uh and so sort of getting the name recognition out there uh is a good thing. Um coming in the form of uh becoming another something you know something something gate was kind of unexpected but uh [laughter] you know I guess people know the name more than they did before. Uh that said it's not really a surprise that there's lots of uh you know politicians and various people using it. uh in general around the world there are quite a few uh people run in various government positions and uh high policy makers who are on signal and we generally think that's a good thing because it it sort of aligns their interest with making sure that like messaging and stays private and secure uh and so we like for signal to be used by everybody.
>> All right. Who is this gentleman?
>> Uh I'm Aaron from FO. I was uh can you talk a little bit about how you know as it's challenging as a developer as a programmer what's it like with Apple kind of Apple and Google and the Telos making it easier for maybe their own apps or making it easier for Facebook because they have a billion users or even making it easier for Signal which has 100 million users versus somebody who's in college just for the first time launching an app with no users. Uh the biggest one we run into in this particular space is actually uh with the Android ecosystem, believe it or not. Um because the OEMs in the Android ecosystem uh compete on battery life and a lot of the way that they compete on battery life is to view the applications running on the device as the enemy. Um and if you're a very highprofile, highly used application uh like say WhatsApp, they will ship their uh their operating system with exceptions for your application like you will you will get your notifications on time. You won't get squelched, you'll be able to connect to the internet when the notifications wake up your app. Uh however, if you're a newer app, low usage, not a lot of people know about you yet, uh they are very happy to squaltch your notifications, put you off into a bucket where maybe you can run once an hour and to go fetch your messages. And this comes in the form of user complaints about why do my notifications not show up which for something like a messaging app is kind of a critical failure. Uh so it's it's actually kind of difficult uh in the Android OEM world to ensure that uh you're actually getting your notifications on time just because the OS is sort of treating applications the users install as as an enemy sometimes.
Um and then on uh the the other front you're you're talking about there uh yeah getting getting access to sort of like what's coming next in the Android and Apple ecosystems uh is like helpful to to know uh like when those updates are coming, what's going to be in them and that sort of thing uh that you tend to only get once you're like a larger developer and have some sort of like devril contact at those organizations.
Um, so yeah, there there are there are um like hurdles you have to overcome when you're a new application developer that are sort of smoothed over once you have a lot more users or a lot more people caring about the application.
>> We got Caleb again. Caleb >> Caleb again. Yes. So at the risk of sounding a little paranoid, which no one ever thinks that no one No one's ever thought that.
>> No, no, no. [clears throat] Uh what's the status of historic concerns around WhatsApp specifically? Number one, they were infamously hacked by the Israeli government. It became a vector for Israel to see other things on your phone, not just your WhatsApp messages.
And then two, I think more recently, WhatsApp had the ability to silently insert a mod into any conversation they wanted and then they could see subsequent messages that were exchanged in said conversation. Has that been dealt with? Are you aware of those issues? And then I guess simply because it's not free and open source, who knows what the prospect for doing that kind of thing again is.
>> Uh so on the first point, um the uh that particular issue, uh that one was very public and I have heard about that.
That's uh I believe it was the NSO group uh if I remember correctly uh had famously sent out some sort of um uh worm or something like that into WhatsApp that exploited some pathway in the code to gain access to the phone.
They did it to like a targeted set of individuals. I forget the size, but it was like a thousand people or so or something in that ballpark. And I believe if I remember correctly, I think WhatsApp sued them very publicly about this. Uh and uh like won a case against them saying, you know, you're not allowed to do that again. I don't I don't know how effective that ruling will be. Uh but uh that one was very very public and WhatsApp fought against it. Uh the second one, I'm actually not familiar with that story. So I have not heard about the uh WhatsApp silently inserting members into groups. uh that shouldn't be allowed like the application should notify you about any new members being added to a group. Uh but if that's not the case, that's certainly bad. Uh so yes I I um I think any group membership changes need to be u notified about and uh I was I do know that WhatsApp shipped a feature where someone could silently leave a group uh which is a commonly requested feature where people are like most commonly the the request is I don't want to be part of my family group anymore but I can't leave because they will get upset um and uh so people want to silently leave those groups and sort of uh have long been against that as like no you should tell the people that you're talking to that you don't want to talk to them rather than blame the technology because that tends to be what what happens.
People don't want to have a difficult conversation with their family members about I don't want to hear stories like this or links anymore. So I just want to like silently bow out.
>> No comment. [laughter] >> Uh may maybe Rezie uh you have some story there.
[laughter] >> No, just just continue.
>> Those who laugh loudest know. [laughter] >> Yes. So one more question about governments. There's obviously been this decadesl long back and forth between tech companies and governments over encryption and that's ongoing with EU chat control and various demands of the EU of the UK. Do you think that's driven primarily by technological technical ignorance on the part of policy makers or is it that the case that they're simply determined to break encryption somehow and what are the trend how how is it going at the moment? What the trends is getting worse? Is it getting better? Are policy makers learning? uh maybe like what you said more politicians using signal and seeing the value of secure communications is changing things for the better.
>> Yeah, I certainly think the more people who use it and the more people who depend on and expect the privacy guarantees, the the sort of more uh protection and more defense we have in those scenarios. That said, I think the primary reason why they're doing this is because they're hearing from uh their various like law enforcement agencies and things like that who've gotten used to over the years being able to just wiretap everything uh without having to go do like actual like physically get the device or that sort of thing. Uh they've gotten used to this this process and when the process stops working they complain. Um, so I I've seen this uh I've been to like the Supreme Court of Brazil once before part as part of WhatsApp where there was an entire panel in front of the Supreme Court consisting of university professors, cryptographers, uh us as WhatsApp and then at the very end the federal police and then everyone's sitting there telling the the Brazilian Supreme Court it's a bad idea to block encryption except for the federal police who are like we don't know how to do our job.
Um, so effectively it's just like it's a problem that they're running into where they're they're facing like uh their their policing forces don't know how to like alter their procedures to deal with it. And so it's just a matter of like okay, you've got to go actually like uh arrest the criminal, get their uh their devices, their their their uh you know basically you have to go after the end points. You can't go after the middle anymore. You can't silently tap everything. And that's kind of the the purpose of in encryption is that it protects against mass surveillance.
All right. Uh, we got another question here.
>> My name is Darren. Um, speaking >> any affiliation, Darren? No. Okay.
>> Um, speaking of law enforcement, are there any does Signal have any uh mitigations against devices like Cellbrite and things that pull everything off your phone for forensic an analysis?
>> Uh, we're not really an endpoint protection system. We are we protect everything in between. So, we're providing all the end toend encryption.
uh the device itself, you know, we're hoping the the operating system and the manufacturer have produced uh good hardware security uh like a good TPM that's actually encrypting the device uh storage and that sort of thing. Uh but we do not ourselves provide like endpoint security system that we rely upon the phone.
>> All right, we got Naomi again.
>> Great. I promise there's a question.
>> Okay, just a follow-up question for that. You guys had a great blog post a few years ago where you actually did talk about potential protections and you talked about uh embedding malicious content in a storage vault that if Celebrate were to come and ingest that into a computer it would wipe or destroy their entire system. Did you go through with that? If not, why not?
Uh yeah, so uh Moxy kind of went a little bit rogue on that particular one and he did get a hold of one of those devices and found out that it was sort of a glued together collection of random software uh some of which had uh buffer overflow exploits in it. And so he did actually find uh a a particular file that if you put on the device it would um allow you to execute something in the uh machine that was uh imaging the phone. And I believe we have a video on our blog of him actually accomplishing that uh feat. Uh so that one was a fun one. Um I won't say whether or not that actually shipped or not, but [laughter] all right, I think uh you know we have a little extra time here, so I think I'll just end it there. Thank you. I give it give it out for uh Eric Krat. Thank you.
Related Videos

Multi Vendor Multisig w/ Seed Signer, Hodl Dee & QnA
BitcoinMagazine
985 views•2024-09-05

Oasis Week in Review: Latest blog articles, workshops and more
OasisFoundation
135 views•2024-10-18

Kaspa: How ZK Turn Blockchains Into Settlement Layers (Part II)
cxc
1K views•2025-12-19

以言會友 EP13|當比特幣屢破紀錄 區塊鏈技術能帶來什麼?
dotdotnews
293K views•2021-01-05

Soroban Development: Ecosystem Growth, and the Rise of 70+ Smart Contract Projects
SorobanOfficial
1K views•2023-07-19

Balaji Srinivasan I The Fiat Crisis | Pragma Tokyo 2023
ETHGlobal
37K views•2023-05-06

$22 million NFT scammers arrested (insider evidence)
coffeezillaextras
806K views•2025-02-03

SYMMETRICAL TRIANGLE HOLDS THE KEY TO NEXT MOVE" DON'T IGNORE
xrpfuturemillionaire
800 views•2026-03-15
Trending

Playstation NO DISC/NO BUY Fight Is Over...
DavidJaffeGames
4K views•2026-07-23

Steam and Xbox Just Dropped The Hammer On PlayStation
OhNoItsAlexx
9K views•2026-07-23

Americans Confused in Australia for 17 Minutes Straight
IWrocker
17K views•2026-07-23

SuperBike Factory Has Gone... What's Next for the Motorcycle Industry?
thatbikersimon
11K views•2026-07-22