2026.04.14

You Ain't Seein' Shit

Unless you're in the room. And even then, good luck!

A phone face-down on a steel desk under harsh fluorescent light, next to a sheet of paper with a phone number written on it

In 2019, a doctor in Wuhan sent a message to a private group chat. He told his medical school classmates that a SARS-like virus was showing up in patients.
He included a clinical report.
He told them to be careful.

Four days later, police arrived at his door.
Not because someone in the group said anything.
Because the platform did.

His name was Li Wenliang.
He died of the virus he tried to warn people about, two months later.

Count the ends

Every platform listed claims to protect you, or markets itself as the kind of place where protection is assumed.
Some say end-to-end encryption.
Some say messages disappear.
Some say nothing and let you fill in the blank.

SMS is a postcard, the protocol is honest about being a postcard, and the carriers don't pretend otherwise. Anyone who treats SMS as a privacy mechanism is doing something stupid all by themselves. Banks, Google, your bookkeeper sending tax documents, every site that texts you a 2FA code as proof you're you, on a protocol that's been broken since the nineties, on a network owned by carriers with intelligence liaison desks. That's a problem, but it's not a deception. SMS isn't lying to anyone. The institutions using it for identity verification are.

Every platform below is different. They lie.
By claim or by omission.

Let's count those ends, shall we?

The scenario

A modern journalist running from a rogue nation-state

Let's say a journalist pisses off a nation-state. Or a doctor warns the wrong people. Or you, for reasons you don't yet know, become someone a state wants to read.
Not a hypothetical state. A real one with an intelligence service, direct access to telecom infrastructure, and a permanent liaison desk at every major carrier.
No warrants. No courts. No legal process.
Just capability and motivation.

Here is what happens on each platform:

WhatsApp

3.3 billion monthly active users

End-to-end encrypted with the Signal Protocol.
Solid math.

Message history backs up to Google Drive or iCloud. For years, those backups were completely unencrypted. They eventually added encrypted backups. To their credit, the architecture is better than Messenger's. The encryption key is supposedly stored in a hardware security module that supposedly rate-limits password guesses and permanently destroys the key after ten failed attempts.

Here's the thing tho,

The HSM sits in Meta's data centre, running Meta's firmware, on Meta's hardware. Anyone outside Meta decapped the chip? Audited the firmware? Verified the rate-limiting actually destroys the key instead of moving it to a recovery partition?
Nope.
The underlying OPAQUE protocol is peer-reviewed.
Meta's implementation of it is not. The whitepaper is Meta describing Meta's system. And yes, it's literally called OPAQUE.

A motivated adversary that controls the jurisdiction both companies operate in doesn't need to crack the HSM. They compel Meta to push a firmware update that logs keys going forward. Or they compel Meta to modify the WhatsApp client to exfiltrate the key at backup time. The encrypted backup blob sits on Google or Apple servers.
One FISA order covers the blob and the key.
Everything after is plaintext.

And none of that is necessary because the device path exists. Zero-click the phone. Reset the backup password from the compromised device using biometrics. The HSM rate-limiting is irrelevant. The attacker never guesses. They just reset.

Underneath all of it:
Phone number identity.
Same carrier.
Same SIM.
Same shared secret in the same database.

Ends:

5

* No cryptography was harmed in the making of this compromise.

RCS

~2.5 billion monthly active users globally

RCS isn't a messenger. It's a carrier protocol the GSMA designed to replace SMS. The bare protocol uses TLS in transit. Your carrier sits at one end of that TLS. Their carrier sits at the other. The protocol does not pretend to be end-to-end encrypted.

Google bolted the Signal Protocol onto their Messages app in 2020 and called the result end-to-end encrypted. It is, when both parties use Google Messages and have RCS chats turned on. The crypto is real.

That covers about a billion of the 2.5 billion users.

The other 1.5 billion are on Samsung Messages, carrier-provided clients, regional Asian implementations, or Apple's Messages app on iPhone. None of those had E2EE for RCS until March 2025, when GSMA's Universal Profile 3.0 added MLS-based interop encryption to the standard. As of mid-2026, that standard is in limited rollout and testing across Google Messages and Apple Messages. iPhone-to-Android RCS in your pocket today is mostly TLS-only between carriers.

40% of RCS traffic claims encryption.
The rest is just on the desk.

Backup is where it gets interesting. Google Messages RCS conversations sync into Android system backup, encrypted by Google's Cloud Key Vault service, anchored by Titan security chips in Google's data centres. Same architectural pattern as WhatsApp's HSM. Your lock screen PIN unlocks a recovery key. The Titan chip rate-limits restoration attempts.

Forget your PIN, you lose your messages. Forever.
That's the user-facing story.
And it's true.

The state-facing story is different. Google designed the chip. Google manufactures it. Google signs the firmware. The Cohort Private Key that wraps every recovery claim lives only inside the chip. Per Google's own published threat model, that chip resists physical attack, but a sufficiently motivated adversary with physical access to a Titan can perform an invasive attack to extract the private key. With the private key, every recovery claim Google ever processed becomes decryptable. Then it's a 4-6 digit PIN brute force.
Seconds.

Or skip the physical attack entirely. Compel Google. One firmware update later, the chip is logging keys, exfiltrating them, processing attacker-supplied claims with rate-limiting disabled going forward. Google holds the firmware signing key. They can change what the chip does whenever the firmware reloads.
The chip is real silicon. It does what its current firmware says it does.
Nothing more.

Then there's the part nobody mentions. When RCS can't deliver, poor connectivity, recipient offline, carrier issue, the message falls back to SMS. Plaintext. Same SS7 backbone that's been broken since the nineties. The encryption you thought you had is gone, the message is now postcard-grade, and the user interface gives you no indication that the security model just collapsed.

Underneath all of it: phone number identity. Carrier owns the number. SIM swap takes everything.

Ends:

More if it ever fell back to SMS. Fewer if you weren't on Google Messages to begin with.

7

* Some cryptography was harmed. (psst... It was decorative.)

WeChat

1.41 billion monthly active users

WeChat tells you it's encrypted. They use a proprietary protocol called MMTLS, AES-256, the whole vocabulary. The marketing is technically accurate.

It is not end-to-end encrypted, and they don't claim it is. The encryption protects messages between your device and Tencent's servers. Tencent reads them on arrival.

And not in the abstract "could be compelled to" sense. Citizen Lab documented that WeChat monitors foreign user conversations in real time to train the censorship algorithms applied to mainland accounts. Your messages aren't sitting in a database waiting for a subpoena.
They're being read.
Right now.
By a system designed to read them.

"Encrypted" is true.
It is also irrelevant
when there's a guy with a clipboard
at the other end of the wire.

Ends:

4

* The cryptography is fine. It's just pointed the wrong way.

Instagram

~1 billion daily DMs sent

Meta started rolling out end-to-end encryption to Instagram DMs in 2023. By 2026, it's still partial. Some conversations get it. Some don't. The user can't easily tell which is which.

The default for any conversation that doesn't qualify is server-side plaintext. Same architecture as Telegram. Same Meta servers that house the WhatsApp HSM somewhere across the data centre.

Same parent company runs three messengers. WhatsApp gets full Signal Protocol with HSM-backed backups. Messenger gets Signal Protocol with five recovery paths. Instagram gets Signal Protocol on the conversations Meta got around to upgrading.

One company. Three security models. Three different trust-me-bros.

Pick a conversation. Pick a year. Pick a Meta engineer's priority queue. That determines whether your message is private.

Ends:

5 if you got the upgrade. 3 if you didn't. Coin flip.

?

* No cryptography was harmed in the making of this compromise.

Facebook Messenger

1+ billion monthly active users

End-to-end encrypted with the Signal Protocol. Solid math. Real encryption between devices.

Your message history is encrypted with keys and backed up to Facebook's secure storage so you can restore it on a new device. Five ways to get those keys: a six-digit PIN, your Google account, your Apple account, a one-time code from your original device, or a 40-character code.

Five recovery paths. Each one an attack surface.

The six-digit PIN is the fastest kill. One million possible combinations. Deploy a single cluster and it's basically a sledgehammer on a bicycle lock.

Even crazier? You don't even need the PIN! The Google or Apple account path gets the same keys, you do one SIM clone, two SMS password resets, and you're in.

The end-to-end encryption is real. Five recovery mechanisms make it decorative. Facebook built a vault and hid spare keys under every doormat on the porch.
Oh, and in the flower pot.

Ends:

5

* No cryptography was harmed in the making of this compromise.

Telegram

1 billion monthly active users

Regular chats are not encrypted. They never have been. Messages sit on Telegram's servers in a form Telegram can read. "Secret Chats" are end-to-end encrypted, but they're opt-in, most people never enable them, and they weren't available on desktop for years.

A motivated adversary doesn't even need to touch the carrier. Telegram has the messages. In readable form.
On their servers.
Right now.

This one isn't even behind a locked door.
It's on their desk.

Ends:

3

* No cryptography was harmed in the making of this compromise.

iMessage

~950 million estimated

Apple's built different, right? PQ3 is genuinely forward-thinking. Hybrid post-quantum key exchange, automatic rekeying, real cryptographic engineering. Honestly the best crypto in the consumer messenger space I've seen.
Credit where it's due.

Messages sync to iCloud. By default, Apple holds a recovery key for that backup. They can decrypt your messages.
A FISA order gets them.
Done.

There's a setting buried in your iCloud preferences called "Advanced Data Protection" that removes Apple's recovery key so only your devices can decrypt. Most people don't know it exists. It's off by default. And even if you turn it on, the person you're messaging probably hasn't. Your messages are in their iCloud backup too, unprotected. Apple can read your conversation thru the other end.

OK but say you both found it and both turned it on. Now your backup is protected by Apple's Secure Enclave, a proprietary coprocessor running proprietary firmware with a proprietary boot chain that nobody outside Apple has ever audited. The silicon does whatever Apple says it does. Maybe that's exactly what the whitepaper describes. Maybe there's a debug interface. Maybe there's a key escrow path baked into the hardware. We don't know. We're trusting Apple's word.

And even if the hardware is perfect, your iMessage identity is still tied to your Apple ID. Your Apple ID password reset still uses your phone number for SMS 2FA. Clone the SIM, trigger a password reset, receive the 2FA code on the cloned SIM, take over the Apple ID, sign into a new device, iCloud syncs the entire message history all the way down.
Automatically.
Every message.
Right there.

Ends:

5

* No cryptography was harmed in the making of this compromise.

Snapchat

932 million monthly active users

The whole brand is built on disappearance. Messages vanish after being read. Photos self-destruct. The marketing is so successful that people genuinely believe sending something on Snapchat means it can't be retrieved.

Here's what actually happens. You take a photo. Your phone uploads it to Snap's servers. Snap routes it to the recipient. The recipient's phone downloads it, displays it, and the app issues a client-side delete command.

Disappearance is a UX feature.
It is not cryptography.

Snap servers see every message in transit. Every photo. Every video. Every text. Stored long enough to deliver. Sometimes longer. Snap publishes a transparency report. They fulfil law enforcement requests routinely. They store "My Eyes Only" content under their own escrow keys.

The bytes existed on Snap servers. They were readable. They could be subpoenaed. The fact that your phone deletes the local copy after viewing has zero cryptographic meaning.

This is the cleanest piece of security misdirection in consumer messaging. People believe their messages are gone because the UI removed them from view. The servers know better.

Ends:

3

* No cryptography was harmed in the making of this compromise.

Signal

70 to 100 million monthly active users

No message backups on their servers. Messages are deleted after delivery. Sealed sender to obscure who's messaging whom. The encryption is real, the protocol is sound, and Signal has published the subpoenas they've received to prove they have almost nothing to hand over.

Here is what a nation-state does anyway:

Future messages: Cloak the SIM. The journalist's carrier has the Ki, the private cryptographic key for the SIM, sitting in a replicated database. An intelligence agency with a liaison desk at the carrier doesn't file paperwork. They just tell the carrier to mirror the session. The original SIM stays live. The journalist notices nothing.

That's passive interception. For active takeover, they clone the SIM and register a new device. Signal added a registration lock for this. A PIN that Signal says prevents re-registration. The PIN is validated by an Intel SGX enclave on Signal's servers that rate-limits guesses. Two problems. First: the registration lock expires after seven days of inactivity. A nation-state that controls the carrier controls your connectivity. Disrupt the target's connectivity for a week, lock expires, register freely. Second: the SGX enclave is Signal's trust root for the entire PIN system, and Intel SGX has been broken repeatedly by academic researchers with far fewer resources than a nation-state. Break the enclave once and every registration lock PIN on the platform is offline-brutable. Break it and every registration lock on Signal is yours.
Every user. Every account.
One exploit.

But the cleanest kill doesn't touch the registration lock at all. The carrier deactivates your SIM. The attacker's clone is now the only device that owns your number. You can't re-register. You can't recover. You can't even prove the account was yours because the entire identity system is built on a number you no longer control. Your contacts see a safety number change, but from their end, it looks like you got a new phone.

Past messages: They're only on the device. Deploy Pegasus. NSO Group's zero-click exploit. No link to tap. No attachment to open. A silent, invisible compromise that gives full access to the device, including the Signal database decrypted in memory. Every message exfiltrated in the background.

Stored traffic: Signal recently upgraded to PQXDH, adding Kyber alongside X25519. Two locks instead of one. There's also years of traffic that predate the dual lock upgrade, captured and stored at Room 641A at AT&T San Francisco, on fiber optic splitters on undersea cables that I've had colleagues lay off the west coast, at upstream collection points on every major exchange. All of it X25519-only. Break that one algorithm and every message sent before the upgrade unravels. And going forward? Two key exchange algorithms, but X25519 and Ed25519 are the same curve. A Curve25519 break takes out the key exchange and the authentication in one shot. The symmetric encryption underneath is one algorithm. It's basically two same-branded locks.
Still not twelve.

Detection: Signal's safety number mechanism is cryptographically sound. When the attacker registers with your number, every contact sees "safety number changed." The detection is real. It's also post-compromise. The attacker already has your account. And recovery? You re-register, which triggers another safety number change. Your contacts can't tell the difference between you getting your account back and the attacker taking it again. A nation-state could rotate: take over, capture everything, release, let you re-register thinking the app glitched, take over again next week. Each time it looks like a hiccup. No persistent evidence is retained.

Oh, and if you lose your phone? Your messages are gone.
Permanently.
Signal doesn't store them on servers, and there's no way to retrieve them from your contacts. They eliminated the server side attack surface by making message loss permanent.
The trade-off nobody explains until it's too late.

Signal is the strongest of the messengers people typically use. It built a solid house but the carrier owns the land. Which means, the carrier owns Signal's identity model. And whoever owns the carrier owns every account on the platform.

Ends:

Still too many.

4

* Some cryptography was harmed. (psst... It was Intel's.)

Matrix

tens of millions of active accounts

Open protocol. Open source. Federated. You can run your own server. This is a genuine effort and it deserves respect.

Here's what actually happens. You download Element, hit create account, and the default server is matrix.org. Most people don't change it. Your account is now @you:matrix.org, hosted by the Matrix Foundation, a UK nonprofit, under UK jurisdiction, under the Investigatory Powers Act. Your metadata, your room memberships, who you talk to and when, all on their server.

You message someone. If they're on matrix.org too, the message stays on that one server. If they're on a different homeserver, the message federates. Both servers get it. Every conversation in Matrix is a "room," even a private DM. There is no other mode. Every room involves every participant's homeserver as a trusted party in the protocol.

"But I can run my own server." You can. Almost nobody does. And even if you do, the moment you message someone who didn't, their homeserver operator is inside your trust boundary. You can't audit what's running on the other end. Could be stock Synapse. Could be a fork that logs every event. Could be an intelligence service.

In 2022, researchers found exploitable cryptographic vulnerabilities showing that Matrix's encryption provided neither authentication nor confidentiality against a malicious homeserver. The bugs were patched. The researchers concluded the protocol still needs a formal security analysis.
That analysis still doesn't exist.

In 2025, two more high-severity federation vulnerabilities required a coordinated emergency release across every Matrix server implementation.

Same pattern, different clothes. Signal trusts the carrier. WhatsApp trusts Meta's HSM. Matrix trusts every homeserver.

Ends:

The number changes per room.

?

* No cryptography was harmed in the making of this compromise.

The locks

Set aside the identity problem. Set aside the metadata.
Look at the encryption itself.

The entire industry converged on the same architecture:
pick one hard mathematical problem, build your key exchange on it, trust that nobody solves it before your data stops being interesting.

For decades that was elliptic curve cryptography. Then quantum computing became a credible threat and everyone started panicking about Shor's algorithm. NIST ran a competition. Winners were declared.

It took the credible threat of a machine that doesn't exist yet to convince anyone to add a second lock. Signal uses X25519+Kyber. Apple PQ3 uses ECDH+Kyber. Chrome ships hybrid TLS by default. Two locks.

Nobody has shipped three. The obvious next question, why stop at two, appears to not have been asked.

Two padlocks hanging from a steel hasp, one brass, one translucent. Room for more.

What a real audit looks like

Every section above includes a chip nobody outside the company has ever held. Meta's HSM. Apple's Secure Enclave. Signal's SGX. Google's Titan. Each one anchored to a security claim. Each one closed silicon.

Here is what verifying any of those claims would look like:

Random sampling. Pull production chips from random data centres, retail boxes, supply chain points. No advance notice. No vendor selection of which units get inspected.

Physical verification. Decap the package. X-ray the die. Cross-reference the actual silicon against the published mask set. Electron microscope the layers nobody else gets to see. Verify the chip in your hand is the chip the documentation describes.

Firmware reproducibility. Source published. Build pipeline published. Independent parties compile from source and verify the resulting binary matches what's deployed in production.

Number of consumer messengers that meet this bar:

0

The closest any of them gets is Google paying NCC Group to read the design documents once in 2018. That's it. That's the bar.
It is on the floor.

Here is what makes it worse. The Titan chip cannot be purchased. It exists only inside Google data centres. Which means the entire public security research community, the people who broke Intel SGX repeatedly, who broke Apple's Secure Enclave with checkm8, who break TPMs and YubiKeys at academic conferences every year, has never had a Titan to try.

The chip's reputation for resisting attack is not a track record.
It's an absence of attempts.

A chip nobody can buy
is a chip nobody can break.
Or rather:
nobody can publicly break.

You don't get to know whether your messages are safe.
You get to know what Google says.
What Apple says.
What Meta says.
What Signal says.

Every messenger above is asking you to trust silicon you've never seen, audited by no one, attacked by nobody whose findings you'll ever read.

2

Every platform above promises something. End-to-end encryption with five recovery paths. Disappearing messages on stored servers. Federation built on trust you can't audit. A carrier protocol with a vendor in the middle and a chip nobody outside Google has ever held. Every one of them has more than two ends. A backup server. An HSM. An SGX enclave. A carrier. A cloud provider. A federated homeserver you've never seen. Closed silicon you've been told to trust.

End-to-end means two.

That's the whole list.

Not end-to-end-to-cloud.
Not end-to-end-to-HSM.
Not end-to-end-to-carrier.
Not end-to-end-to-centralized-enclave.
Not end-to-end-to-every-homeserver-in-the-federation.
Two ends.
2.

The industry redefined the term to mean "encrypted in transit between your device and their device, but also accessible to us thru a side channel we built for your convenience."

Someone keeps counting higher.

Oh, and I can count.

Photon screenshot

3 users. Maybe more. No way to count.

This is Photon. I built it. It's free. Nobody owns it.

I actually want your shit secure.
Period.

No phone number. No server. No carrier. No SIM. No backup on any third-party infrastructure. No metadata to collect.

Eight independent key exchange primitives across four mathematically unrelated families. Three elliptic curve algorithms from different origins with different constants, different fields, different designers. Two structured lattice algorithms with different ring architectures. One unstructured lattice with no ring to exploit. Two code-based algorithms, including one that has been unbroken since 1978.

All eight run simultaneously.
Their outputs combine into a single seed.

To compromise that seed, an attacker has to break all eight at once. Not the weakest one. All of them. Including the one that has resisted forty-seven years of dedicated cryptanalysis by the entire global mathematical community.

Here's the thing tho, that's still not enough.

The rolling chain that encrypts messages advances with every single message. Each one dependent on all prior state. To decrypt message five hundred, you needed to be there for message one and every in between. Miss any of them and the chain is gone. Permanently.

And even that won't do it!

The handles, the human-readable names you use to find each other, never touch the network. Not obfuscated. Absent. Exchanged out-of-band, in person, over a phone call, however you like. They can be exchanged on separate occasions, months apart, in different cities. An attacker needs both handles. Not one. Both. Which means being physically present for two potentially independent exchanges that may have happened anywhere at any point in the past.

Eight cryptographic primitives.
Two handles exchanged out-of-band.
Two rolling message chains.
Twelve independent problems.

If you can do all of that, you can have my money.

A massive vault door standing open with money spilling out, illustrating what twelve locks of security actually looks like

What's left

Here is the complete list of remaining attacks:

That's it. That's the list.

Pegasus is on that list. Zero-click exploits that own the operating system are on that list. Qualcomm baseband vulnerabilities that compromise the radio processor before the OS even sees the packet are on that list. These are real. Against a sufficiently motivated nation-state with access to NSO Group's toolkit or equivalent capability, your device can be silently compromised.

When the processor itself is the adversary, encryption is pointless. The attacker reads the screen the same way you do. The fix is sovereign hardware: devices built from silicon you control, with baseband processors you audit, running firmware you compiled. That doesn't exist for consumers.
It should.

In the meantime, there's a practical countermeasure. Don't run Photon on the phone. Hotspot it. Use the phone as a dumb pipe and run Photon on a Linux laptop tethered to it. Pegasus compromises the phone and gets encrypted traffic it can't read. Your keys, your messages, your plaintext all live on a device with a completely different attack surface. Both sides do this and Pegasus has nothing to read. It's not perfect, but it moves the target off the platform that NSO has spent a decade learning to exploit.

But everything above the hardware, the network, the identity, the metadata, the key exchange, the message storage, the routing infrastructure, all of it is solved. The attack surface that every other messenger leaves wide open is closed. What remains is the device itself.

"But what if I lose my phone?"

Your messages aren't stored on one device. They're stored on two. Yours and the person you were talking to. And probably your watch. And your laptop. And your TV. And your car. All yours. All on hardware you own. Drop your phone in the ocean, your conversation partner still has every message on their hardware. No cloud. No server. No HSM. No third-party infrastructure. Your devices. Their devices. That's it.

Identity recovers thru your social graph. The same Shamir secret sharing described in the previous post. Your trusted contacts attest your new device. The recovery path is the relationship, not the infrastructure. Nobody remembers a password. Nobody stores a 64-digit key. Nobody trusts an enclave they've never audited. The math handles it.

"But what about the code? How do I know it does what you say?"

You read it. Have your trusted Claude read it. Every line of Photon I made public. Every key exchange primitive, every rolling chain, every bit of handle resolution. Auditable by anybody. The people most motivated to find a flaw can look all they want. Meta asks you to trust their word on an HSM nobody has seen. Signal asks you to trust proprietary silicon in their data center. Photon doesn't ask you to trust anything.

Remote interception isn't made hard. It isn't made expensive. It isn't limited to nation-states with exotic hardware.

I just chose not to make it a defined operation.

The math doesn't have a word for
"read a message you weren't there for."
If nobody else is in the room, or in your hardware, the conversation doesn't exist to anyone else.
Not probably. Not computationally.
You weren't there.

Ends: two.
Problems to solve: twelve.
Trust required:

0