Signal, Session, SimpleX, Keet, Cwtch, Briar: Which Private Chat App Fits Your Threat Model?
End-to-end encryption protects message content but leaves metadata such as identities, IP addresses, and contact patterns visible to network observers. This piece compares six chat apps by how much metadata they remove, using the LINDDUN framework of identifiability, linkability, and detectability: Signal's centralized encryption, Session's decentralized onion routing, SimpleX's identifier-free queues, Keet's serverless peer-to-peer connections, Cwtch's Tor-only routing, and Briar's offline mesh. No single app suits everyone. Each one trades privacy guarantees against everyday convenience, so the right pick depends on your threat model.
The spectrum of commitment: six eras of private messaging
We have been conditioned to believe a comforting lie: that end-to-end encryption (E2EE) is synonymous with privacy.
When an app advertises encrypted messages, it is offering a digital padlock. If someone intercepts your data stream, they see only ciphertext, gibberish. But this padlock sits inside a glass box. Nobody can read your letter, but anyone watching can see who sent it, who received it, the minute it went out, the IP address behind it, how often you correspond, and how large each payload is.
This peripheral data is called metadata. In hostile environments, the content of your messages is often the least interesting thing to an adversary. Metadata is what gets people mapped, profiled, fired, or arrested. It exposes associations, habits, and physical locations.
Most people treat Signal as the default secure messenger. Meanwhile a handful of smaller projects are trying to solve the metadata problem, each giving up something different to do it.
It helps to line these tools up by how far they go:
- Signal encrypts your content.
- Session removes your identity.
- SimpleX erases your existence as a user.
- Keet removes the centralized server.
- Cwtch removes the metadata.
- Briar removes the internet itself.
Each step removes more, and each step costs more.
The LINDDUN lens
Marketing words like “unbreakable” do not help. LINDDUN, a threat-modeling framework researchers built for finding privacy flaws in software design, offers three sharper questions:
- Identifiability: Can an observer, or the system itself, connect an account to a real person through a phone number, email, or IP address?
- Linkability: Can an observer tie separate messages or sessions to the same person over time, even under a pseudonym?
- Detectability: Can an outsider such as an ISP or a national firewall tell that communication is happening at all?
Every privacy tool manages these three properties. No app wins on all of them, so the choice comes down to which threats you care about most.
THE SPECTRUM OF COMMITMENT
Signal -------> Session -------> SimpleX -------> Keet -------> Cwtch -------> Briar
[Encrypts [Removes Phone [Erases User [Removes the [Removes the [Removes the
Content] Number/ID] Identifiers] Server] Metadata] Internet]
1. Signal: the gateway drug
The origin and the irony
Signal is the foundation of modern secure messaging, and it comes from an unusual founder. Moxie Marlinspike, a sailor, anarchist, and computer scientist, wrote a cryptographic protocol that became the industry standard.
The irony is that his Signal Protocol now runs inside the products of the surveillance companies he wanted to route around. It secures WhatsApp, Google Messages, Skype, and Facebook Messenger.
┌────────────────────────────────────────────────────────┐
│ The Signal Architecture │
│ │
│ [User A] ───(E2EE Signal Protocol)───► [Signal Cloud] │
│ (Centralized) │
│ │ │
│ [User B] ◄───────────────────────────────────┘ │
└────────────────────────────────────────────────────────┘
Under Meredith Whittaker, a former Google researcher who criticizes AI hype and data monopolies, Signal has taken an openly political stance as a defense against state surveillance and commercial data scraping.
The technical core and the centralization debate
Signal uses a double-ratchet algorithm that provides forward secrecy (a key compromised today does not expose past messages) and break-in recovery (future messages become secure again).
Signal’s defining choice is centralization. Marlinspike has argued that decentralization breeds stagnation. In his essay “The Ecosystem is Moving,” he wrote that networks like email or XMPP move slowly because changes need agreement across a fragmented community.
Central servers let his team ship security updates, protocol improvements, and features like video calling without waiting on a distributed network to catch up.
The weakness: identifiability and the phone number
For all its cryptography, Signal has one conspicuous weak point. Registration required a phone number. Signal recently added usernames so daily contacts never see your number, but the account stays tied to a SIM card in their database.
The infrastructure is centralized on commercial clouds such as Amazon Web Services and Google Cloud, so anyone watching network traffic can tell when you connect to Signal’s servers.
Signal runs on money from the non-profit Signal Technology Foundation, started with a $50 million interest-free loan from WhatsApp co-founder Brian Acton, who left Meta over its data business. It fits journalists, political campaigns, and ordinary people who want a replacement for SMS or WhatsApp. Its limits are the phone-number tie at registration and the metadata about who talks to whom, which stays visible to anyone watching the network endpoints even though the server cannot read message content.
2. Session: the onion-routed ledger
The origin: from blockchain to messaging
Where Signal centralizes, Session distributes. Session came out of the Loki Project in Australia, a Monero-style privacy coin effort. The team realized the infrastructure built for routing payments could route messages instead. They set up the Open Privacy Technology Foundation (OPTF) to run Session on its own, dropping the blockchain requirement for users while keeping the decentralized design.
┌─────────────────────────────────────────────────────────────────┐
│ The Session Architecture │
│ │
│ [User A] ───► [Service Node 1] ───► [Service Node 2] ───┐ │
│ (Layered Onion Encryption) │ │
│ ▼ │
│ [User B] ◄─────────────────────────────────────── [Service Node 3]
└─────────────────────────────────────────────────────────────────┘
The technical core: decoupling identity
Session removes registration credentials entirely. No phone numbers, no emails, nothing tied to a real identity.
When you open Session, your device generates a public-private key pair. Your public key is a 66-character hexadecimal string. That string is your Session ID.
Example Session ID: 05a1b3...[60 characters]...f4e2
To route messages without any central server knowing who you are, Session uses a custom onion-routing network called Lokinet.
When you send a message, it is wrapped in multiple layers of encryption and bounced through three decentralized “service nodes”, servers run by independent operators who stake cryptocurrency to take part. Each node sees only the previous hop and the next hop. No single node learns both the sender’s IP address and the recipient’s identity.
The debate: the node pool and ledger integrity
The trade-off is the node network itself. Tor runs on volunteers. Session’s routers are paid operators with staked crypto behind them.
So the open question is whether onion routing through a small, known set of crypto service nodes protects you as well over time as Tor’s larger volunteer network. An attacker who buys or compromises enough nodes could analyze traffic to connect senders with receivers.
The OPTF runs Session, supported by the Sentinel/OXEN coin ecosystem plus premium features. It suits people who want strong anonymity with ordinary features like group chats and voice messages, including those who left Telegram after its policy shifts in late 2024. The costs are extra latency from onion routing and the risk of Sybil attacks if one actor corners enough staking nodes.
3. SimpleX: the erasure of identity
The radical premise: what if “you” don’t exist?
SimpleX drops user identifiers altogether.
Signal gives you a phone number. Session gives you a 66-character ID. Either way you carry a lasting identity on the network, and anyone who compromises your device can try to map your past contacts from it.
SimpleX creator Evgeny Poberezkin rejected that assumption. His protocol has no user profiles, no global IDs, and no long-term account keys.
┌──────────────────────────────────────────────────────────────────────┐
│ SimpleX Queue Architecture │
│ │
│ [Sender] ───► [Outbox Queue Server] ───► [Inbox Queue Server] ───┐ │
│ (One-way, rotating cryptographic hops) │ │
│ ▼ │
│ [Receiver] ◄─────────────────────────────────────────────────────┘ │
└──────────────────────────────────────────────────────────────────────┘
The technical core: unidirectional communication queues
Instead of giving you an address, SimpleX builds unique, unidirectional channels (queues) for every contact you have.
If you connect with a friend, your app sets up two independent, rotating queues on servers:
- Queue A: For you to send messages to your friend.
- Queue B: For your friend to send messages to you.
The servers holding these queues cannot tell they belong together. The cryptographic keys for reading them rotate constantly.
To an observer, and even to the servers handling the traffic, the sender of a 9:00 AM message cannot be connected to the sender of a 9:05 AM message. A 2024 audit by security firm Trail of Bits confirmed that the SimpleX protocol keeps these connection graphs isolated.
The trade-off: high friction and zero recovery
Linkability drops close to zero. Usability pays for it.
With no central database and no lasting user key, there is no “account recovery.” Lose your phone, drop it in water, or delete the app without a manually exported database backup, and your network is gone for good. You cannot log back in. Your contacts watch your old queues time out, and you start over by swapping out-of-band invitation links, usually QR codes.
SimpleX raised seed money from conventional venture capital, including Bessemer Venture Partners, a strange backer for an ideological open-source project with no revenue plan. It fits whistleblowers, high-risk individuals, and security researchers who need maximum protection against metadata analysis. The costs are backups you manage yourself, no multi-device sync without manual database exports, and total data loss if a device is compromised or lost.
4. Keet: the peer-to-peer runtime
The heritage: the distributed web
Keet skips client-server entirely. It runs on the Hypercore Protocol (once the DAT project), an append-only signed Merkle log system from the decentralized-web world. On top of that, parent company Holepunch built Pears (Pear Runtime), a peer-to-peer app platform. Keet is the flagship app showing what Pears can do.
┌────────────────────────────────────────────────────────┐
│ Keet P2P Architecture │
│ │
│ [User A (IP: 192.x.x.1)] ◄────► [User B (IP: 192.x.x.2)] │
│ ▲ ▲ │
│ │ Direct Connection │ │
│ └───────────(DHT Lookup)────────┘ │
└────────────────────────────────────────────────────────┘
The technical core: serverless swarms
Signal, Session, and SimpleX all land your data on a server at some point, however well encrypted. Keet has no middleman.
When you start a chat, share a file, or launch a video call on Keet, your device uses a Distributed Hash Table (DHT) to find your peer’s device. Once found, the two devices punch through their firewalls and connect directly.
Send a 10-gigabyte video file and it streams straight from your drive to your friend’s drive. No file size limits, no storage fees, no servers holding your data.
The funding reality and the IP exposure trade-off
Tether, the company behind the USDT stablecoin, funds Keet’s development, and CEO Paolo Ardoino promotes it. That money buys serious engineering, but Tether’s centralized structure and regulatory history make privacy advocates uneasy.
Keet also exposes your IP address, which surprises some users.
Because the app connects devices directly, both sides must know each other’s IP addresses. Anyone you chat with, friend or adversary, can log your public IP and work out your approximate location or ISP. The Pear Runtime documentation says it plainly: “If your IP is sensitive, route through a VPN or Tor.”
Tether’s funding pays for fast, polished engineering. Keet fits teams moving huge datasets, media people doing server-free video calls, and decentralized-web supporters. Its limits are IP exposure to every chat partner and call quality that depends on each side’s connection and firewall setup.
5. Cwtch: the consensual sanctuary
The philosophy: built for vulnerable populations
Cwtch is the least known app here, and arguably the most consistent in its principles. The Open Privacy Research Society built it under Sarah Jamie Lewis. The name comes from a Welsh word meaning both a “safe hiding place” and “a hug.”
It was designed with and for marginalized groups: domestic abuse survivors, trans youth, and activists under heavy surveillance.
┌────────────────────────────────────────────────────────┐
│ Cwtch Tor Architecture │
│ │
│ [User A] ───(Tor Onion Service)───► [Tor Network] │
│ │ │
│ [User B] ◄───(Tor Onion Service)──────────┘ │
└────────────────────────────────────────────────────────┘
The technical core: Tor onion services by default
Cwtch makes one uncompromising call. Every byte travels over Tor onion services, with no clearnet fallback.
When you add a contact, you swap Tor onion addresses. The app runs a lightweight Tor node on your device, and your messages never leave the encrypted, multi-hop anonymity network. That largely shuts down both linkability and detectability.
Groups work differently too. Instead of a central server or shared keys, a group is a short-lived “server” running on one member’s own device.
If you host a group and shut your laptop, the group goes offline. If you leave a group, the host’s server loses all cryptographic ability to associate your past presence with your identity. It is built to emulate physical spaces: when you walk out of a room, you leave no footprints behind.
The unpolished reality
Strict privacy costs performance.
Running a Tor onion service on a phone is resource-heavy. It drains the battery, burns processor cycles, and fights standard mobile background limits. Cwtch is often slow, notifications arrive late, and the mobile experience lags well behind the desktop version.
Public donations, research grants, and non-profit sponsors pay for Cwtch. It fits human rights defenders, at-risk individuals, and privacy purists. Its limits are heavy battery use, slow delivery, and an interface less polished than mainstream apps.
6. Briar: the offline resister
The origin: built for the blackout
Briar sits at the far end of the spectrum. Groups like the Open Technology Fund, Access Now, and NLnet fund it. Briar was built for the worst case: a total internet blackout during an uprising, a natural disaster, or a military occupation.
┌────────────────────────────────────────────────────────┐
│ Briar Multi-Transport Mesh │
│ │
│ ┌───────► [Tor (Internet)] ───────┐ │
│ │ ▼ │
│ [User A] ──┼───────► [Local Wi-Fi] ──────────┼──► [B] │
│ │ ▲ │
│ └───────► [Bluetooth (Mesh)] ─────┘ │
└────────────────────────────────────────────────────────┘
The technical core: multi-transport mesh networking
Briar trusts no servers, cell towers, or fiber backbones. It runs three transport layers at once:
- Tor Network: When the internet works, Briar routes over Tor onion services, matching Cwtch’s metadata protection.
- Local Wi-Fi: If the ISP cuts the wider web but the local router still has power, Briar talks across the local intranet.
- Bluetooth Mesh: If towers are down and grids fail, Briar turns your phone into a mesh node that passes messages directly to nearby phones.
In a crowd of protestors during a shutdown, your message can hop from your phone to a stranger’s phone to a third phone over Bluetooth until it physically reaches its recipient, never touching the global internet.
Peer-to-peer networks usually need both sides online at once. Briar’s answer is the Briar Mailbox: a spare low-power Android device at home that stores encrypted messages for your contacts and hands them over when they appear. The mailbox owner cannot read them.
The trade-off: range and power
Offline mode only reaches as far as nearby devices, so range is the main trade-off.
If your contact is in another country and the internet is shut down, Briar cannot reach them. Keeping Bluetooth and Wi-Fi radios constantly polling for peers also drains batteries fast, which makes Briar impractical as an everyday messenger.
Public-interest tech funds and civil liberties foundations support Briar. It fits people in conflict zones, environmental activists, journalists, and anyone preparing for infrastructure failure. Its limits are heavy battery drain, short offline range, and contacts who must come online periodically to sync.
Comparative matrix
| Feature | Signal | Session | SimpleX | Keet | Cwtch | Briar |
|---|---|---|---|---|---|---|
| Primary Focus | Content Encryption | Identity Obfuscation | Metadata Minimization | Serverless P2P | Consent & Sanctuary | Offline Resilience |
| Registration Required | Phone Number | None | None | None | None | None |
| Routing Protocol | Centralized Server | Lokinet (Onion) | Unidirectional Queues | Direct P2P (DHT) | Tor Onion Services | Tor / Bluetooth Mesh |
| Funding Source | Non-Profit / Loans | Crypto Foundation | Venture Capital | Tether (Corporate) | Grants / Donations | Grants |
| LINDDUN Strength | Content Privacy | Low Identifiability | Low Linkability | Serverless | Low Detectability | Offline Intangibility |
| Primary Trade-off | Metadata Visible | Lower Node Pool | No Account Recovery | IP Address Exposed | High Latency / Power | Battery / Geo-limits |
Who should use what?
No single app here is “best.” Match the tool to your threats:
- Standard cybercrime and data brokers: use Signal. It is the easiest to adopt, your contacts will actually install it, and its protocol is the best tested for encrypting content.
- Online life without a phone number attached: Session balances onion-routed anonymity with ordinary features like group chats and voice messages.
- Targeted metadata surveillance or relationship mapping by states or institutions: SimpleX isolates you best, as long as you handle your own manual backups.
- Huge files and real-time collaboration with no servers: Keet moves data peer to peer at full speed, but run it through a VPN to hide your IP.
- Highly vulnerable groups needing a consensual, metadata-resistant space: Cwtch was built for exactly that, if you can tolerate the slowness.
- Civil unrest, censorship, or infrastructure collapse: install and configure Briar before you need it.
The direction is clear. The privacy movement started by securing centralized channels (Signal), then moved to decentralizing routing (Session), erasing persistent identity (SimpleX), and building alternative physical networks (Briar).
No app promises absolute safety. Learn what each tool does and where it stops, accept the trade-offs, and pick the one that matches your situation.
Every profession seems to have its own "thinking" now, design thinking, systems thinking, product thinking, critical thinking. This article traces where that pattern comes from. It turns out that pairing "thinking" with another word does something specific in both directions: the modifier gives thinking a track to run on, and "thinking" transforms the modifier from a noun into a methodology. Underneath the branding, these frameworks all share a common purpose, they are structured tools for forcing the kind of slow, deliberate mental effort the brain actively tries to avoid. The article breaks down why this linguistic trend has taken over professional life, what three contrasting examples reveal about how these frameworks actually work, and offers a five-question tool for decoding any new "X thinking" term you encounter.
Visual aggression is the enemy of thought. Here is why I prioritize text over everything else.