What this protects, and what it doesn't
Protects
- Against an interception attempt slipping by unnoticed: verifying keys in person, and treating a safety-number change as hostile until you have confirmed it out of band, catches a machine-in-the-middle.
- Against a lost or seized phone handing over your history: short disappearing timers, little retained history and no stray cloud backup leave little to recover.
- Against account takeover by SIM swap: Registration Lock, a carrier account PIN and phishing-resistant keys on the accounts linked to your phone.
- Against a forced fingerprint or face unlock at a border, a protest or an arrest: a memorised passphrase, with biometrics switched off or the phone powered down first.
- Against your least careful contact sinking the whole conversation: rules that both sides actually keep.
Does not protect
- It hides the content, not the fact. End-to-end encryption does not hide that you communicated, with whom, or when, to the same degree; that pattern alone can be revealing, and a well-resourced adversary collects it.
- It does not survive an unlocked or compromised device. Whoever holds your unlocked phone, or has planted malware on it, reads what you read. Verifying keys and setting timers change nothing about that.
- It does not bind the other person. They can screenshot, photograph the screen, forward your messages or be compelled to show them. Disappearing messages do not stop any of this.
- It is not anonymity, and not a guarantee. These steps shrink what a targeted adversary gets; they do not make you untraceable, and no setting here reliably defeats a nation-state implant on the endpoint itself.
Prerequisites
- You have already done <a href="/en/privacy-guides/signal-hardening">Signal: settings worth changing</a>: a strong Signal PIN, Registration Lock, disappearing messages, a hidden phone number and a screen lock are in place. This guide assumes all of that and goes further.
- A written threat model that puts you at the High level — a hostile, well-resourced adversary. See <a href="/en/privacy-guides/threat-model">Threat modeling: start here</a>.
- A password manager already holding your Signal PIN, your backup recovery key and your account passwords.
- A way to meet the people you message, or an existing trusted channel to reach them, so you can verify keys and agree rules without doing it over a channel that may already be watched.
Step by step
-
Agree the rules of the conversation before you need them
At this level your security is the security of the least careful person in the thread. An app's protections are worthless if the other side has them switched off, so settle the ground rules together, in person or over a channel you already trust:
- Which app you both use, and that you have both verified each other (next step). Verification is per side; one side doing it is not enough.
- A short disappearing-message timer that both of you set, so neither device keeps a long record.
- No cloud backups of the sensitive thread, and no screenshots, unless you have agreed otherwise.
- A pre-agreed way to reach each other off the app — a second channel — for the one message that matters: "my key changed", "I lost my phone", "stop talking here".
- What each of you does if a device is lost, seized or acting strangely.
Write none of this down where the adversary can read it. The EFF puts it plainly: an app with great security features is worthless if the people you talk to do not use it in the same way.
-
Verify keys in person and treat any change as hostile
The Signal hardening guide already had you verify safety numbers. At the High level you go further in two ways:
- Verify in person. Meet, compare the safety number or scan each other's QR code face to face, and mark the contact as verified on both phones. A number read out over a channel the adversary may control is a number the adversary may have substituted.
- Treat a change as an attack until proven otherwise. If a verified contact's safety number later changes, Signal warns you. The ordinary cause is a reinstall or a new phone — but at this level you assume the worst first: stop, send nothing sensitive, and confirm through your pre-agreed second channel that the change was really them before you continue.
This is the one control that catches a machine-in-the-middle: someone who sits between you and your contact and swaps in their own keys. Verifying the key is what turns "the app says it is encrypted" into "encrypted to the person I mean".
-
Accept the limits: content is hidden, the pattern is not
End-to-end encryption, the EFF notes, protects only the content of your communication; it does not protect the metadata — "information like who you are communicating with and when" — which "can provide extremely revealing information about you even when the content of your communication remains secret".
CISA's guidance for highly targeted individuals goes further: assume that all communications between mobile devices and internet services are at risk of interception or manipulation, and, when choosing an encrypted messenger, "evaluate the extent to which the app and associated services collect and store metadata."
In practice, for a High-level target:
- The existence and timing of contact can itself be the sensitive fact. Encryption does not hide that you and a particular person talk.
- Do not rely on an encrypted app to conceal a relationship an adversary is trying to prove. Think about when and from where you connect, and whether the mere pattern gives you away.
- Prefer apps whose own documentation says they keep little about who talks to whom. See Messaging apps compared for what each vendor states.
-
Starve the device of history
Anything still on the phone can be read from the phone if it is unlocked or extracted. The goal at this level is for there to be as little as possible to find:
- Short timers, shorter for the sensitive threads. Set a short default disappearing-message timer, and an even shorter one in the chats that matter most. Both sides must do it; a message only disappears from the device whose timer fired.
- Delete threads you no longer need. History you have deleted cannot be recovered from a seized device.
- Think hard about backups. Every backup is another copy of your history that someone with the key, or the backup account, could read. At this level, the safest backup is often none for the sensitive conversation. If you keep one, keep it end-to-end encrypted and store the recovery key offline.
- Keep linked devices to a minimum. Every linked desktop or tablet receives your new messages and is one more thing that can be stolen or compromised. Remove any you do not actively need.
-
Prepare for the phone being taken
If your phone may be seized — at a border, a protest, or an arrest — plan for it before you are in that situation. The EFF's guidance on these situations is direct:
- Lock with a memorised passphrase, not just biometrics. Enabling fingerprint or face unlock "means an officer could physically force you to unlock your device with your fingerprint or face," and "there is currently less protection against compelled face and fingerprint unlocking," while "using a memorized passcode generally provides a stronger legal footing." Use a long, unique passcode; a complex, strong password "is still the best practice."
- Turn biometrics off, or power the phone down, before the risky moment. The EFF suggests turning fingerprint and face unlock off before a protest. A phone that has been powered off and not yet unlocked is in a harder state for forensic tools to break; a "forensic" extraction tool such as Cellebrite "is more likely to be successful if your phone is older or unencrypted."
- Carry the bare minimum. The EFF advises carrying "the bare minimum of data with you," and considering a secondary phone "that doesn't have much personal data on it." Back up what matters beforehand and leave it somewhere safe, not on the device you carry into risk.
- On iPhone, enable Lockdown Mode. CISA recommends it for highly targeted individuals: it "strictly limits certain apps, websites, and features" to reduce the attack surface.
-
Harden the endpoints and the account the phone sits on
End-to-end encryption protects the message between two endpoints. It does nothing if an endpoint is compromised — so a targeted adversary attacks the phone or the account instead of the encryption. From CISA's guidance for highly targeted individuals:
- Patch weekly and auto-update the operating system and apps, and prefer the latest hardware version, which carries security features older hardware cannot support.
- Stop using SMS for two-factor authentication. SMS "messages are not encrypted," so anyone with access to the carrier network can read the codes. Move to phishing-resistant FIDO authentication, with hardware security keys preferred, on the accounts linked to your phone (email, Apple, Google, social).
- Set a carrier account PIN. Most providers let you add a PIN required before porting your number — "a critical step in countering" SIM-swapping. Combine it with your Signal Registration Lock, which blocks a re-registration of your number even after a successful swap.
- Restrict app permissions and avoid granting location, camera or microphone access that an app does not genuinely need.
- Do not treat a personal VPN as a fix. CISA notes a personal VPN "simply shift[s] residual risks from your internet service provider to the VPN provider, often increasing the attack surface."
-
Plan for the moment something goes wrong
Assume that one day a device will be lost, seized or compromised, and decide now what happens then:
- Have a signal for "stop". Agree a plain message you can send through your second channel that means "I may be compromised, do not trust this thread." Keep it simple enough to send under pressure.
- Re-verify after any new device. When you or your contact reinstall or move phones, the safety number changes; verify again, in person where you can, before resuming anything sensitive.
- Remember the other person is not bound by your settings. They can be coerced, their phone can be taken, and they can screenshot or photograph what you send. Disappearing messages and verified keys protect the channel, not the human at the far end.
- Know the limits. These steps make a targeted adversary work much harder and get much less. They are not a guarantee against a determined, well-funded one, and anyone selling you that certainty is wrong.
Your ticks are saved in this browser only (see or delete local data).
Common mistakes
- Verifying only your own side, or reading a safety number out over a channel the adversary might already control.
- Shrugging off a safety-number change as "probably a new phone" without confirming it out of band first.
- Relying on encryption to hide a relationship, when it is the fact and timing of contact — the metadata — that the adversary is after.
- Locking the phone with biometrics alone, so it can be unlocked by force, or leaving biometrics on when walking into a border crossing, protest or arrest.
- Leaving SMS two-factor and no carrier PIN in place, so the account behind your number can be taken by a SIM swap.
- Keeping a cloud backup of the sensitive thread, which quietly stores a readable copy of history you meant to let disappear.
Going further
If your threat model is this severe, treat messaging as one part of a wider posture: harden the phone and its full-disk encryption, reduce what the device carries, and get the people you talk to onto the same discipline — your weakest contact is your real exposure. Review Messaging apps compared for how much metadata each app's own documentation admits it keeps, and consider a professional threat-modeling session with a press-freedom or digital-rights organisation if you are being targeted because of your work. Re-read the primary sources before you rely on any specific setting: vendors and guidance change.