
Signal was a 'risky' choice for sharing classified plans. Which is the most secure messaging app?
ADVERTISEMENT
A mere three days after US Defence Secretary Pete Hegseth boasted on national television that America "no longer looked like fools," it emerged that he was part of a group of high-ranking officials who
inadvertently texted plans
for an attack in Yemen to a journalist.
Hegseth, alongside Vice President JD Vance, Secretary of State Marco Rubio, National Security Advisor Michael Waltz and others, had been using the messaging platform Signal to discuss highly sensitive and classified information.
Democratic lawmakers swiftly condemned this as an "egregious" security breach, and US President Donald Trump said he knew "nothing about it," as his team claimed
a "glitch"
was to blame for the addition of journalist Jeffrey Goldberg to a message chain named "Houthi PC small group".
Related
What is Signal and should US officials have used it to share Yemen air strike plans?
Though encrypted and technically secure, the platform is "full of risks" related to human error and spyware, and was not the appropriate choice for such a conversation, argues Callum Voge, Director of Governmental Affairs and Advocacy at Internet Society.
"Governments have specific protocols for protecting classified information, and those protocols usually state that classified info can only be shared under certain conditions. So when people say Signal isn't appropriate for sharing state secrets, it's not just about Signal - it's about any consumer messaging app. Whether it's WhatsApp, Signal, or Telegram, they all pose risks," Voge told Euronews Next.
A key danger is that
Signal
is available to the general public and used by millions worldwide.
"Anyone in the world can create a Signal account. So, for example, someone without security clearance could be accidentally added to a group chat. That's one way secrets could be leaked - by accident, human error, or on purpose," Voge added.
"Also, Signal is used on personal devices. That introduces the risk of spyware - software that can record what's happening on your device in real-time and send it to a third party. So even if Signal is the most secure app in the world, if your phone has spyware, it's still a leak".
Related
'My concerns are more about people, institutions than the tech': Signal's Meredith Whittaker on AI
Warnings Signal was a target for hackers
In fact, the Pentagon issued a department-wide memo just days after the Signal group chat leak, warning that Russian professional hacking groups were actively targeting the app.
According to the memo, the attackers were exploiting Signal's "linked devices" feature - a legitimate function that allows users to access their account across multiple devices - to spy on encrypted conversations.
If a device is compromised - whether through malware, unauthorised access, or sophisticated spyware like Pegasus - encryption becomes irrelevant.
Gustavo Alito
Cybersecurity expert, Equans BeLux
"Signal's effectiveness depends on the security of the device used. It's like installing the most secure alarm system in a house without doors," Gustavo Alito, a cybersecurity expert at Equans BeLux, noted.
"If a device is compromised - whether through malware, unauthorised access, or sophisticated spyware like Pegasus - encryption becomes irrelevant. Attackers can monitor and capture all device activity in real time, including messages being written," he told Euronews Next.
"A surprising development in this case is that reports indicate Signal was pre-installed on US government devices. While this suggests an institutional push for encrypted communication, it also raises concerns," Alito added.
"The fact that Signal was made widely available may have led officials to assume it was approved for classified discussions, despite warnings from the NSA and the Defence Department against using it for sensitive matters".
Related
What is Pegasus, the Israeli mobile phone spyware used by governments around the world?
Signal, WeChat, WhatsApp, Telegram: Which is the most secure platform?
On the low end of the spectrum, where messages are most vulnerable, are platforms that either lack end-to-end encryption or don't enable it by default.
ADVERTISEMENT
According to Voge, "that means it's encrypted from endpoint to endpoint. So, for example, one endpoint is your phone and the other is mine - and as the conversation or text goes back and forth between us, no third party can decrypt it, not even the provider".
Apps like WeChat, for instance, do not offer end-to-end encryption, meaning messages can potentially be accessed by the service provider or government authorities - a major concern in countries like China.
Similarly, Telegram does not encrypt group chats or even one-on-one chats by default; users must manually enable "secret chats" for end-to-end protection. Because of this, messages on these platforms are more susceptible to interception.
At the high-security end are apps like Signal, WhatsApp, and to a limited extent, iMessage, all of which offer end-to-end encryption by default.
ADVERTISEMENT
Among them, Signal stands out for its open-source protocol, non-profit governance, minimal metadata retention, and default encryption across messages, calls, and group chats.
Related
Whatsapp faces strictest EU platform rules, but not Telegram
WhatsApp, while also encrypted using Signal's protocol, is owned by Meta and retains more metadata, which some view as a potential vulnerability. iMessage is considered technically secure, but it's a closed-source, Apple-only system, which limits transparency and auditing.
So,
Signal
is widely regarded by experts as the gold standard for encrypted messaging, but, as we've just seen, it is not immune to risks stemming from user error, device compromise, or misuse in contexts requiring classified communication protocols.
"Like any company, Signal regularly audits other parts of their app - like how users verify their phone numbers or add new devices. Sometimes issues come up, and they respond with security patches, which they publish on their website with details," said Voge.
ADVERTISEMENT
"You may have heard of a recent vulnerability involving Russia. This was a phishing attack used in Ukraine: attackers sent fake QR codes to trick people into joining Signal groups. When someone scanned the code, it linked a new device to their account - effectively hijacking it," he continued.
"It wasn't a flaw in the encryption protocol, but in how Signal handled device linking. Signal responded with an update - now, if you want to link a new device, you need Face ID or Touch ID".
Related
Report shows how messaging apps are used to spread political propaganda
What's the best way to message securely?
So what should Hegseth, Vance, Waltz and the rest of the Houthi PC small group have done instead?
The US government almost certainly has its own systems for handling classified information.
ADVERTISEMENT
"Government officials are generally expected to use special devices and systems not available to the public. You might imagine a platform that only government officials can download, and maybe even has levels of classification built in - like confidential, secret, and top secret," said Voge.
Indeed, he pictures "a government setting in which officials go to a secure room, leave their personal devices behind, and use a special computer that's not connected to the Internet to access sensitive information".
"Since people travel, there are probably government networks or apps only accessible to officials using government-provided devices. These systems wouldn't be available to the public, and probably have built-in ways of handling classification levels," he added.
Related
Telegram ban: Which countries are clamping down on it and why?
Or, as Alito puts it, "a government-approved, end-to-end encrypted system designed specifically for classified communications. Secure platforms like the NSA's Secure Communications Interoperability Protocol (SCIP) or classified networks such as SIPRNet and JWICS are more aligned with a governmental organisation's security and encryption needs".
ADVERTISEMENT
The system should also allow for records of conversations to be kept, which ties into record-keeping laws.
"Some governments require policymakers to retain a record of their messages or emails. But Signal has features like disappearing messages. So if government officials use it, that record of communication could be lost, which may go against transparency or accountability laws," Voge said.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Euronews
42 minutes ago
- Euronews
At least five killed in Russian air strikes on Pryluky, officials say
At least five people, including a one-year-old child, his mother and grandmother, were killed on Thursday in an overnight drone attack on the northern Ukrainian city of Pryluky, officials said. Six drones hit a residential area in the city shortly before dawn, injuring nine others, according to authorities. The one-year-old killed was the grandchild of the local fire chief, Ukraine's Interior Minister Ihor Klymenko said. The fire chief, identified by local officials as 50-year-old Oleksandr Lebid, "arrived to respond to the aftermath right at his own home," Ukrainian President Volodymyr Zelenskyy said in a post on Telegram. "It turned out that a Shahed drone hit his house." "Today our hearts are scorched by pain," the police force wrote on Telegram. "This is not just a loss — it is three generations of life uprooted." Liudmyla Horbunova, 55, who lives across the street from where the Shahed drone hit, said Shyhyda had moved with her son last weekend to her parents' house from her home in Kyiv because she was scared of potential Russian attacks on the capital. "She ran away from Shaheds in Kyiv, but they found her here, in Pryluky," Horbunova told AP. Pryluky, which had a pre-war population of some 50,000 people, lies about 100 kilometres east of the capital Kyiv. The city is far from the front line and does not host any known military assets. The last time Pryluky was struck was in November last year, when a Russian missile hit an administrative building and injured one person. Zelenskyy said a total of 103 drones and one ballistic missile targeted multiple Ukrainian regions overnight, including Donetsk, Kharkiv, Odesa, Sumy, Chernihiv, Dnipro and Kherson. "This is another massive strike," Zelenskyy said. "It is yet another reason to impose the strongest possible sanctions and apply pressure collectively." Hours later, 19 people were injured in a Russian drone strike on the eastern Ukrainian city of Kharkiv. Those hurt included children, a pregnant woman, and a 93-year-old, regional Governor Oleh Syniehubov wrote on Telegram. At around 1:05 am, Shahed-type drones struck two apartment buildings in the city's Slobidskyi district, causing fires and destroying several private vehicles. "By launching attacks while people sleep in their homes, the enemy once again confirms its tactic of insidious terror," Syniehubov wrote on Telegram. Those attacks came just hours after US President Donald Trump spoke by phone with his Russian counterpart Vladimir Putin. According to Trump, Putin said "very strongly" that Russia will retaliate for Ukraine's stunning drone attacks on military airfields deep inside Russia on Sunday. Diplomatic efforts to stop Russia's more than three-year-long war have so far delivered no significant progress, and Moscow's grinding war of attrition has continued unabated. Zelenskyy, who has accepted a US ceasefire proposal and offered to meet with Putin in an attempt to break the stalemate in negotiations, wants more international sanctions on Russia to force it to accept a settlement. Putin has shown no willingness to meet with Zelenskyy and has indicated no readiness to compromise. Germany's new Chancellor Friedrich Merz is due to meet Trump in Washington on Thursday as he works to keep the US on board with Western diplomatic and military support for Ukraine.


Euronews
an hour ago
- Euronews
North Korea doubles down on support for Russia's war in Ukraine
North Korea's dictator Kim Jong-un has once again affirmed his "unconditional support" for Russia's all-out war against Ukraine during a meeting with a top Russian official. The authoritarian ruler made the comment during talks with Russian Security Council Secretary Sergei Shoigu in Pyongyang on Wednesday, according to the state-run Korean Central News Agency (KCNA). Kim reiterated his 'unconditional support for the stand of Russia and its foreign policies in all the crucial international political issues including the Ukrainian issue", KCNA reported. The two countries' ties have strengthened in recent years, with Pyongyang sending thousands of troops to Russia to participate in its war against Ukraine. The North Korean soldiers have been deployed in Russia's Kursk region, parts of which were seized by the Ukrainian army in a surprise offensive last August. Speculation about North Korea's deployment of troops to Russia first arose at the end of 2024, with Ukrainian President Volodymyr Zelenskyy and South Korean officials accusing Pyongyang of sending soldiers to support Moscow's war efforts. However, it wasn't until April that Moscow and Pyongyang officially confirmed the presence of North Korean troops on the battlefield. A monitoring group comprising South Korea, the US, Japan and eight other countries last week classified Russia and North Korea's military alliance as 'illegal", saying it flagrantly violates UN sanctions. The report said their pact was allowing North Korea to fund its banned ballistic missile programme. The group also expressed concern that Russia might also transfer sophisticated technologies to help North Korea enhance its nuclear weapons programme. In late April, North Korea unveiled the country's first naval destroyer, named the Choe Hyon, which experts say was likely built with Russian assistance, in further proof of growing military cooperation between Pyongyang and Moscow.


France 24
3 hours ago
- France 24
Greenpeace activists charged with theft of Macron waxwork
The pair have now been released, but their lawyer, Marie Dose, said the activists, a man and a woman, spent three nights in a cell in "absolutely appalling conditions". "I found out this morning that I was going to be charged," one of the charged activists, who did not wish to be named, told AFP. "I find it a bit much, all this for exercising my freedom of expression in France." On Monday, several activists stole a 40,000-euro statue of Macron from the Grevin Museum and placed it in front of the Russian embassy. On Tuesday they placed Macron's double outside the headquarters of French electricity giant EDF to protest France's economic ties with Russia. They stood the statue on its feet and put next to it a sign reading "Putin-Macron radioactive allies". The waxwork, estimated to be worth 40,000 euros ($45,500), was handed over to police on Tuesday night. The pair were detained on Monday. On Thursday they were brought before an investigating judge and charged as part of a judicial inquiry into "the theft of a cultural object on display", the Paris prosecutor's office told AFP. Jean-Francois Julliard, head of Greenpeace France, said that the detained pair were people who drove a truck during the protest in front of the Russian embassy, and not those who "borrowed" the statue from the museum. - 'Tool to deter activists' - The activists' lawyer condemned authorities for detaining and later charging them. "I don't understand this decision to open a judicial investigation, as the Grevin Museum clearly stated that there was no damage," said Dose. "Increasingly, the justice system is becoming a tool to deter activists from exercising their freedom of expression and opinion," she added. The Grevin Museum filed a complaint on Monday but subsequently took the matter in good humour. "The figures can only be viewed on site," it said on its Instagram feed. Speaking earlier, Dose denounced the detention as "completely disproportionate", saying they had spent three nights in a cell. The lawyer condemned the "deplorable" conditions in which the two activists were being held, "attached to benches for hours and dragged from police station to police station". One activist spent the night without a blanket and was unable to lie down because her cell was too small, the lawyer said. "The other had to sleep on the floor because there were too many people in the cell," she added. The lawyer argued that "no harm resulted from the non-violent action", insisting that "all offences" ceased to exist once the statue has been returned to the museum. The activists managed to slip out through an emergency exit of the museum by posing as maintenance workers. France has been one of the most vocal supporters of Kyiv since Russia invaded Ukraine in February 2022. Macron has taken the lead in seeking to forge a coordinated European response to defending Ukraine, after US President Donald Trump shocked the world by directly negotiating with Russia. But Greenpeace and other activists say that French companies continue to do business with Moscow despite multiple rounds of sanctions slapped against Russia after the start of the invasion. © 2025 AFP