overview of all secured-orless messaging apps....

21 min read Original article ↗
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an alternative browser.

overview of all secured-orless messaging apps....

I see sometimes newspaper from general way or even IT-specialised journalists comparing few secure messenging apps, without bringing advanced or expert eyes on that. So Im wondering, about firstly a long list of tools about secured messenging and voice/video conferencing... It's initially made from france, where those types of comparison are generally limited up to ten big ones (as firstly listed here), doesnt help to makes others independents, more recents or just alternative software being known for worldwide internet users. Also, to explain better, to non-IT specialised journalists, to see it with a better glance.

If you have some remarks, suggestions, ideas, or any others good or less good feedbacks.. thanks to it!

original posts (in fr):
(links removed, ask in PM)

NTOP=NotTestedbyOriginalPoster (especially for 2020 and newer apps)

Updated : 2024 apr

my recommendations/ranking:
[*] for mobile phone number uses : 1. quicksy 2. signal 3. telegram 4. threema 5. the others..
[*]for email/URI registration (not necessary email!) : 1. xmpp (conversations), SIP (linphone, voip.ms, callcentric, etc..)
[*] for very secrecy and underground communications : 1. tox. 2. briar 3. session 4. signal 5. telegram
[*] for india : prav (paid fork of free quicksy)
[*] if yu just want to save money in exchange of less privacy : the biggers (marketing) one (whapp, RCS, iMess'..)

the most populars/known/simples :

[*]whatsapp :
2009, usa. Bought by meta (facebook, insta..), the first messenging apps on smartphone : ultra-simple and easy. Enjoys zero-rates in some latino or africa countries -means free cell data usage (illegal in europe)-, and makes it the most used app in the world. Requires android/iphone. Over 2B users (+200M/mo) claimed [https://www.reuters.com/technology/whatsapp-explores-ads-chat-app-ft-2023-09-15/]

en.wikipedia.org
encryption: protocole signal ["WhatsApp messages are encrypted with the Signal Protocol.[217] WhatsApp calls are encrypted with SRTP, and all client-server communications are "layered within a separate encrypted channel"" ]

[*]signal (usa, 2014, Signal protocol) , 40M users claimed
encryption : signal protocol
recommended by lot of geeks/nerds

[*]telegram (dubai, 2013), made by russian gov opponents/protestors ; 900M users claimed.

telegram.org
en.wikipedia.org
encryption : mix of several techniques, under name of "MTProto"
[Telegram uses a custom build symmetric encryption scheme called MTProto. The protocol was developed by Nikolai Durov and other developers at Telegram and is based on 256-bit symmetric AES encryption, 2048-bit RSA encryption and Diffie–Hellman key exchange.]
900M users claimed [https://www.reuters.com/technology/...ln-users-within-year-founder-says-2024-04-17/]

[*]viber (israel, 2010) ; created by formers israel intelligence experts, bought by rakuten (900MdUSD), based in cyprus. 1Bd users in 2018
viber.com
encryption : similar to signal

from big manufacturers :

[*]iMessage, (Apple, 2011), usa, made by and for mac/ios users... only for apple products users

en.wikipedia.org

[*]RCS, (google, 2022, from jibe acquisition, 2015), millions of users du to the rcs default enabled by lot of android-based brands, in the default messaging's android app, starting 2022 (or before)

Turn on RCS chats in Google Messages - Google Messages

With Rich Communication Services or RCS, a modern industry standard for messaging, you can have a more dynamic and secure conversation with someone than SMS or MMS. Learn about Rich Communication Serv
support.google.com support.google.com

NB: google and apple are in thermonuclear war on their respective mobile/cell market, until to avoid compatibility between their own messenging system (imessage vs rcs). with a certain late (about ten years), google tried to compete with apple's imessage in a way by the acquisition of jibe in a first time, then to cooperate with major cell services providers, but they almost all denied in a first time. Then they started to store themself the data of rcs, before having more agreements with differents cell services providers.
NB2: i could had feu BBerry messenger, RIP to it..

the less known/differents/independents/minor apps :

[*]skype, microsoft : most used service in the 2000s, still working.. for individuals (use teams for pro/business)

low security, in a way it's not end-to-end encrypted. Notice skype for business/pro is just a rebranded microsoft lync software. All communications are stored and processed in clear on msft servers

[*]teams, microsoft, usa, 2017 : mainly used for business talks and education communication. about 280M users monthly ; mainly used for videoconferencing.

Vidéoconférence, réunions, appels | Microsoft Teams

Il est plus facile de travailler ensemble avec Microsoft Teams. Les outils et les fichiers étant toujours disponibles en un seul endroit, vous pouvez vous connecter naturellement, rester organisé et concrétiser vos idées.*
en.wikipedia.org

[*] BBMe (BlackBerryMessenger-Enterprise) ; successor of died blackberry messenger ; focused to public-sector, governments, corporates, and individuals.
windows, macosx, android, iphoneOS, free the first year only.
uses both FIPS 140-2 certified cryptographic and TLS.
en.wikipedia.org

[*]Rocketchat, 2016, USA, a bit like teams/slack


[*]slack, usa, 2013, a bit like teams/slack
fr.wikipedia.org

[*]discord, usa, 2015, ~150Millions active users in 2020
very popular regarding young (means 2000born-users) users, mainly videogamers.
en.wikipedia.org

[*]threema (switzerland, 2012, 1€ to open the account -maybe a subscription) ; 10M users.

en.wikipedia.org
encryption: Naci (ECC based)
the encryption process used by Threema is based on the open-source library NaCl library. Threema uses asymmetric ECC-based encryption, with 256-bit strength.

[*]citadel/tchap : thalès/ercom, french, with voice/video on subscription; citadel for individuals and businesses, tchap for fr public service workers. Based on Elements
no wiki..

[*]olvid, 2018, france : made by two crypto pHD/scientists, voice/video on subscription.
Suddenly required by french government, with strong criticals about its adoption.


[*]skred : france, from skyrock, merged with twinme

[*]wire : switzerland, 2014

Wire – Collaborate without Compromise

Collaborate without compromise with Wire, the trusted platform for millions worldwide. Stay in control with end-to-end encryption that's invisible, flexible collaboration, and intuitive user interface. Join now for free and boost your productivity.
wire.com wire.com
encryption : proteus (https://www.x41-dsec.de/reports/Kudelski-X41-Wire-Report-phase1-20170208.pdf)

[*]element : israel, 2016, very popular to opensource communities, uses the matrix protocol, interoperable with jabber/xmpp, to communicate. Matrix foundation is in uk. Can operate with matrix/jabber/xmpp users

en.wikipedia.org
matrix protocol :
en.wikipedia.org
(advantages, disadvantages :ask me PM to translate feedbacks)
very slow/demanding web-interface
2 diff credentials : 1 for the session/account, 1 for the communication history
sometimes the recent messages are encrypted and can't be decrypted
powered with millions by their foundation.

[*]conversations (germany, 2014, used with xmpp/jabber, free, interoperable with jabber/xmpp/matrix/elements, optimised for android ; apps snikket/siskin for ios) ; requires account creation, from the app or jabber server, free. made by Daniel Gultsch. [my favourite with quicksy]
en.wikipedia.org
encryption: OpenPGP, or OMEMO (by défaut)

[*]quicksy : same as last conversations (same developper) but uses the cell phone number instead of login/pass. by Daniel Gultsch. I recommend :)

Quicksy

A spin-off of the popular Jabber/XMPP client Conversations with automatic contact discovery. Sign up with your phone number and Quicksy will automatically—based on the phone numbers in your address book—suggest possible contacts to you.
en.wikipedia.org
quicksy is free (via fdroid), for india, paid alternative is called prav. havent tested it.

[*]cheogram : used for xmpp calls, from canadian project (soprani). Could be used with xmpp/jabber calls worlwide with sipbroker gateways


[*] delta chat : opensource, could send text messages to an email recipient.
delta.chat

Delta Chat: FAQ

Qu’est-ce que Delta Chat ? Delta Chat is a reliable, decentralized and secure instant messaging app, available for mobile and desktop platforms. Instant creation of private chat profiles with secur...
encryption : autocrypt, since 2024, Securejoint is supported

[*]keet (NTOP) : peer to peer app, featuring : video, file sharing, USD+BTC payments, made by holepunch (p2p apps)

[*]DekuSMS, Android (NTOP):
says : Android SMS app ~ Featuring E2EE, Cloud Forwarding, RMQ integrations

[*]Jami
2016, only app being totally federated/uncentralised (means no server) encrypted and opensource. Uses SIP.
Instant secure messaging, and voice/videoconference.

en.wikipedia.org

[*]linphone (SIP, good for voice/video)
first app for free internet voice/video in the 2000's running on win/nux/mac ; about 700k users
en.wikipedia.org
encryption zrtip, srtp

[*]ippi (sip, does same as linphone, but add worldwide phone calls on subscription)
encryption zrtip, srtp


[*]Tribu (2022)
only for groups, for friends/family, for better daily organisation

[*]IRC, ICQ : still used after twenty/thirty years of availability ; lot of adepts of such technology, that protocol is mainly used by geeks/nerds ; works well for "shared conversation channels". Just try it! ;)

fr.wikipedia.org

Specialised in country/area/region:
[*] Weixin/Wechat/QQ: between 1-3Bd users ; hugely used in china.

called weixin there: "here they dont even think that you dont have it. Nobody in china doesnt have it".
you see the little old man drawing portraits within the street near tourists ; at the payment time, he shows you a little pancarte with his qr code printed on it, to let you pay him through wechat, cause everyone doesnt have cash in its pockets.
used for.. almost everything in china.
/!\ dont be confused : wechat, the indispensable app in china ; and weechat, the irc client software

[*]Line, japon, 2011: very used in asia, and not only : japan, korea, china (with censorship), thaïland, also chili, spain..hundred of thousand users

en.wikipedia.org

secret/underground/clandestine/invisibles (no others words ;) )

[*]session : encryption using the blockchain, without server, for strong anonymous purposes : less tracking if voice/video are disabled, by default

en.wikipedia.org
encryption : based on blockchain, with uncentralised nodes (like tor)

[*]ricochet, 2014, uses different tor nodes to do instant messaging.

Ricochet Refresh

A Blueprint For Free speech initiative to update and improve Ricochet
www.ricochetrefresh.net www.ricochetrefresh.net
en.wikipedia.org

[*]tox : encrypted messenging, without server, with different client apps, on ios/android/fdroid, see:
en.wikipedia.org
https://f-droid.org/en/packages/com.zoffcc.applications.trifa/ (nice one for tox, with qrcode with long touch on the ID)
encryption : NaCl (https://en.wikipedia.org/wiki/NaCl_(software))
(advantages, disadvantages :ask me PM to translate feedbacks)

[*]Briar : Herited from Ensichat. Very confidential or underground app : either through tor if using internet, or only wifi without internet, or bluetooth, even through sdcards.. Recommended by edward snowden, and uses the bramble protocol. More paranoïac than tox: voice/videocalls not permited.

f-droid.org
chiffrement : compliqué, voir:
https://briarproject.org/how-it-works/

[*] SimpleX : 2020, claims that: Other apps have user IDs: Signal, Matrix, Session, Briar, Jami, Cwtch, etc.
SimpleX does not, not even random numbers.
(no wiki page yet)

NB: for that least category, some of them are deliberately without, or by default disabled, of voice/videoconference, to help better privacy respect of even clandestinely communication. Session shows a warning message in that case (you can enable it manually) at the difference of briar, whom looks like to totally disable it.

NB2: some observers or comments generally reports that signal, telegram, whapp &co uses either jabber/xmpp or sip protocol ; it's probably true, but on ten years of development it might be probably incompatible with the original opensource one. In other hand, at a specific time, around 2010, when eg google talk was released, it was compatible with others messenging app through xmpp protocol. Google even tried to recruit all over the world engineers skilled with that type of software/communication developpement, including that (fr) one :

various apps may use similar or propers protocols, rarely (or never) compatible with others apps.

less known, most voice/videoconference than messenging:
[*]jitsi, opensource, simple

[*]facetime for apple users

[*]skype, teams, lync(skypeforbusiness/enterprise) (see skype part previously)

[*]galene, little videoconference opensouce software, used in some universities and schools in paris/france https://galene.org/

[*] bigbluebutton, canada, 2007, mainly for school/universities, also adopted in different government teams (france)

en.wikipedia.org

also, sip(voice/video) services or software providers (generally both):

[*]linphone et ippi, both from france, first one detailled before, second one allows calls all over the world on subscription. Could both be reached from sipbrokers.

[*]after xmpp+(openedSIP), whom is the best protocol imho ;)
after imessage,
after RCS,
after gafam's messaging-war,
IETF creates a NEW one :D


another reason to not use facebook:
Samsung even abandoned their own TizenOS for Smartphones because the reality is: most of the people don’t care about the OS, they care about features and apps. And if another OS don’t brings advantages and/or more features than Android (and no, more privacy is not an advantage because most people don’t care about privacy), people will see no need to switch to another OS, unless as I said something happens to Android.

NB: for alternative mobile systems, means no iOS, no android/lineageos-likes, eg postmarketos, mobian, sailfish (xperia/jolla), manjaro, pinephone or purism/pureos...
there are existing jabber/xmpp clients, also SIP apps, working (almost) well, with success to discuss with ios/android-likes contacts though jabber/xmpp.

where even whatsapp most popular is absent, signal and telegram have specific client-messaging apps:

there was a traditionnal phone gateway to SIP explained, but I dont know if it worth the translation, where it's used only by hundred or thousand persons/users all over the world, even if that type of communication, beloved to avoid big apps/companies, or just because everybody doesnt have a smartphone :)D), is still appreciated, eg in Australia, in Canada..(eg with voip.ms provider, app available on fdroid). Where a common phone can be in communication (for free through gateways) with a sip user all over the world -regarding latency.

sip/gw : there is a sipbroker little network/website, whom permits to reach a sip user from all around the world, using a simple landline, or a common cellphone (a pots/pstn, aka common phone network), normally for free. See sip gateways (or ask here or in PM) for more information. You can reach SIP users, and some xmpp/jabber users too. Long post/explaination about that hasnt been translated yet.

others comparators:
EN: https://www.messenger-matrix.de/messenger-matrix-en.html
FR: https://wiki.jabberfr.org/Jabber_en_5_minutes#Comparatif_des_messageries_instantanées
FR: https://www.freie-messenger.de/dateien/system/Messenger_FR.PDF
EN: https://www.freie-messenger.de/dateien/system/Messenger_EN.PDF
DE: https://www.freie-messenger.de/dateien/system/Messenger.PDF
EN: https://www.freie-messenger.de/en/
DE: https://www.freie-messenger.de/
EN: https://en.wikipedia.org/wiki/Comparison_of_instant_messaging_clients
EN: https://en.wikipedia.org/wiki/Messaging_apps
EN: https://en.wikipedia.org/wiki/Comparison_of_user_features_of_messaging_platforms

others interesting things :
https://dontkillmyapp.com/ <= for those who have problems of backgroud refresh app or lack of notifications
let's achieve that damn list work in one draw:

standards.png
messaging_systems.png
chat_systems.png

a reason to have doubts about reliability of google's playstore services:

and what's your favourite?
differents specificities, observations, advices or others warnings or recommendations you'd like to add or share?

(some comments already translated and integrated in eng...)

[translated]the remaining question... "why?", it's complicated regarding a population totally resigned about privacy concerns and closed-source apps ("but they already know everything about us etc etc" as a common answer). Only ones trying to move somewhere else [than popular apps] are the users ones with their ggle/msft/meta account disabled or definitively banned without any type of possible rescourse

will be edited/updateed on long term..
Last edited:
Here's a in my opinion really good and comprehensive matrix:
I would check out SimpleX as well: link. I first learned about it from @Privacydroid here.

Here's a in my opinion really good and comprehensive matrix:
updated :)
Hey all,

Here's a public, cited, copyleft, and machine readable messenger chart that me and a community have built and contributed to and are really proud of. It compares most popular messengers and is always open to contributions!
https://bkil.gitlab.io/secuchart/

Hey all,

Here's a public, cited, copyleft, and machine readable messenger chart that me and a community have built and contributed to and are really proud of. It compares most popular messengers and is always open to contributions!
https://bkil.gitlab.io/secuchart/

added, thanks, even if i just can't deal with matrix
Why are you listing Telegram in your top 5 "extreme privacy" recommendations when it doesn't even use encryption by default, doesn't allow encryption of group chats, doesn't hide its traffic, requires a phone number which is personally identifiable, AND says it will reveal your phone number and contacts to the authorities if they request it for "anti-terrorist" investigations? (They can say whatever they want, depending on the country.)

Judging by the protocol properties I would say SimpleX Chat deserves to be on that list much more than Telegram, hell it might be better than most of them (for example I thought Briar might be the best, but people are complaining about huge battery drain, so much so that it seems like a dealbreaker).

Hello,
Why are you listing Telegram in your top 5 "extreme privacy" recommendations when it doesn't even use encryption by default, doesn't allow encryption of group chats, doesn't hide its traffic, requires a phone number which is personally identifiable, AND says it will reveal your phone number and contacts to the authorities if they request it for "anti-terrorist" investigations? (They can say whatever they want, depending on the country.)

Probably because, until pavel's arrest :
-i didnt knew at all it wasnt secured, and still journalists today claims it is ("encrypted messaging app"), as journalist cannot think there are still without encryption messaging apps
-i just dont use it (used it in past)
-is still a huge used, as telegram, even if encryption would be default-enabled, is kind of copy/paste of whapp/signal, doing almost same basic things
-what is your record?
Judging by the protocol properties I would say SimpleX Chat deserves to be on that list much more than Telegram, hell it might be better than most of them (for example I thought Briar might be the best, but people are complaining about huge battery drain, so much so that it seems like a dealbreaker).
yes, totally true, by best protocol properties.
Here we are not on hacking-protocol-over-the-edge side, but the most privacy-compliant easy and ergonomic tool, not as i would say clandestine/secret/underground tools, as the first purpose of the topic is to provide an answer "not to nerds/geeks/engineer that can look far deeply that subject", but to people whom doesnt know much more to this subject to give them first elements of comparison as a response to avoid (or accept) the usage of big companies tools. For me, it's important to precise that very secrecy (and complicated) applications/protocols exists, but not to promote them as they will immediately lost the random person profile, not looking for technical details, just a comparative things over here.
Probably because, until pavel's arrest :
-i didnt knew at all it wasnt secured
What a joke, that was known for years, all you had to do was Google it. You didn't even do basic research before making these lists.
yes, totally true, by best protocol properties.
Here we are not on hacking-protocol-over-the-edge side, but the most privacy-compliant easy and ergonomic tool
No, that makes no sense. You proposed multiple lists, and for the special one I picked to comment about you said it's "for very secrecy and underground communications", so that's the list where user-friendly UI aka. "ergonomics" is not the priority. All the other lists are about user-friendliness, not this one. And mind you SimpleX doesn't even have that weird of a UI, you just have to get used to the notion that nobody has a public username, all profile names are "invented" by each user and exist only from their local perspective. The rest is pretty straightforward, you have 1-on-1 chats and group chats with owner, admins and members, like in most user-friendly apps out there.
What a joke, that was known for years, all you had to do was Google it. You didn't even do basic research before making these lists.

No, i dont google anything because in my personal usuals : i boycott gafam, google first. So for search it's both wikipedia+official site, any maybe some others comparative sites. But in the idea, i just dont have to think about "this app doesnt do E2E by default" because none is supposed to.
as telegram never says "we dont encrypt everything from end to end", i consider, like lot of people, that they do.
Another example?

skype ; as some people told me, they are forbidden by us laws to do sort of E2E, exchanges must been readable from US authorities.. different from whapp/signal, us companies too?
well, skype will never tell you they dont do E2E, but they will never tell you they do, neither. I knew it because a guy like you told me, as if not, i would never think there are still messaging tools that doesnt provide default E2E on their service. Not my job to point out few things on big apps, the goal was to seek for alternative. Telegram is not that different of whapp/signal/skype in terms of number of users and easiness to use, far far away of simplex, briar or others underground that only family's hackers knows the existence of.

No, that makes no sense. You proposed multiple lists, and for the special one I picked to comment about you said it's "for very secrecy and underground communications", so that's the list where user-friendly UI aka. "ergonomics" is not the priority. All the other lists are about user-friendliness, not this one. And mind you SimpleX doesn't even have that weird of a UI, you just have to get used to the notion that nobody has a public username, all profile names are "invented" by each user and exist only from their local perspective. The rest is pretty straightforward, you have 1-on-1 chats and group chats with owner, admins and members, like in most user-friendly apps out there.

i think the best is now to close this topic.
just people dont give a f about privacy, today they want more followers, $$ and ego-rent social networks. Privacy is an old privilege that have been replaced by virtual ego today. On my own, in addition of not following this topic, i just stopped using ios or android devices today. Hopefully, i do everything on my computer, and xda is not 100% android, wphone and others sailfishos, postmarketos are still running well around here. Daily user of that last one (i dont use any google product nor service today)

:)

No, i dont google anything because in my personal usuals : i boycott gafam, google first. So for search it's both wikipedia+official site, any maybe some others comparative sites. But in the idea, i just dont have to think about "this app doesnt do E2E by default" because none is supposed to.
as telegram never says "we dont encrypt everything from end to end", i consider, like lot of people, that they do.
Another example?

skype ; as some people told me, they are forbidden by us laws to do sort of E2E, exchanges must been readable from US authorities.. different from whapp/signal, us companies too?
well, skype will never tell you they dont do E2E, but they will never tell you they do, neither. I knew it because a guy like you told me, as if not, i would never think there are still messaging tools that doesnt provide default E2E on their service. Not my job to point out few things on big apps, the goal was to seek for alternative. Telegram is not that different of whapp/signal/skype in terms of number of users and easiness to use, far far away of simplex, briar or others underground that only family's hackers knows the existence of.

i think the best is now to close this topic.
just people dont give a f about privacy, today they want more followers, $$ and ego-rent social networks. Privacy is an old privilege that have been replaced by virtual ego today. On my own, in addition of not following this topic, i just stopped using ios or android devices today. Hopefully, i do everything on my computer, and xda is not 100% android, wphone and others sailfishos, postmarketos are still running well around here. Daily user of that last one (i dont use any google product nor service today)

:)

I daily drive a PPP running pmOS edge.
What phone are you running it on?
I daily drive a PPP running pmOS edge.
What phone are you running it on?

grand prime lte
samsung-a3

espressowifi

im not a huge android fan anymore.. and running pmos without damn commercial apps is my new heaven. Hate apps.

sailfishos, postmarketos are still running well around here. Daily user of that last one
OK, interesting, I'll have to look into that PostmarketOS some more, never heard of it. Last I saw something about a new Linux for phones it was droidian.org trying to port Debian to phones (still working on it and it seems they keep adding supported devices).

P.S.: I said "google it" just because it's a well known expression, I haven't used Google for web search in a very long time, except through privacy-preserving intermediaries like DDG and StartPage.

In a slightly different category for text message encryption (E2EE SMS), RavenSMS could be a new and secure option. Some believe it is more secure than online messengers. what do you think?

Similar threads