Signal vs Session vs SimpleX — Private Messaging Compared

Signal, Session and SimpleX compared: how each private messenger handles metadata differently, and which one to pick for your privacy needs.

Comparison table of the Signal, Session and SimpleX private messengers

If you’re trying to move away from WhatsApp or Telegram, three names come up again and again: Signal, Session, and SimpleX. They all claim to be private, end-to-end encrypted messaging apps, and they’re all open source.

The content encryption is genuinely good in all three. Where they really differ — and it’s a much more important difference — is metadata: who you talk to, when, and how often. That’s the thing each of them handles completely differently.

I’ve used all three, and here’s my honest take on what each one actually gets you — and what it costs you.

The Quick Overview

  • Signal — The best default for almost everyone. Centralised, run by a US non-profit, requires a phone number to register (usernames hide it from contacts, not from Signal).
  • Session — Decentralised, no phone number at all, routes messages through an onion network of community-run nodes. You get a permanent Session ID instead of a number.
  • SimpleX — The most radical: it has no user identifier at all — not even a random ID. You connect through one-time invitation links instead of a username or number.

Signal — The Practical Default

Signal is the one your contacts are most likely to already use, and for most people that single fact is decisive. An encrypted messenger nobody you know has installed protects nothing — it just sits on your phone looking smug.

It’s run by the Signal Foundation, a non-profit. The protocol is the double-ratchet design that WhatsApp, Google Messages and Facebook Messenger all licensed, and it’s been independently audited.

What Signal does well

  • E2EE by default — Every chat and call is encrypted end to end, no setting to hunt for. Group chats, voice calls, video calls, linked devices.
  • Audited, battle-tested — The Signal Protocol is the industry reference for forward secrecy and break-in recovery.
  • Minimal metadata — Sealed sender hides who sent a message from Signal’s own servers. Signal’s published transparency reports show it retains almost nothing: registration date and last connection time.
  • Easy for non-technical people — Install, verify your number, done. Your mum can use it.

Where Signal falls short

  • Phone number required — You still need one to register. Usernames (added in 2024) hide the number from the people you chat with, but not from Signal itself. Your account is tied to a number, and a number is a strong real-world identifier.
  • Centralised — All traffic flows through Signal’s servers, run by a US non-profit subject to US legal process. They keep little, but they’re a central point of control.

Session — Decentralised, No Phone Number

Session started as a fork of Signal that removed the phone number entirely. Instead of a number, you get a permanent Session ID — a 66-character public key. No phone number, no email, nothing personal required to sign up.

Traffic is onion-routed through the Session Network, a decentralised set of nodes run by a global community. No single node sees both ends of a conversation, and offline messages are buffered until you fetch them.

What Session does well

  • No phone number, no email — You can create an account with zero personal information. This is the one to pick when registering a phone number is impossible or unsafe.
  • Decentralised — Onion routing over many community nodes makes it far harder for any operator to see your social graph or link your IP address to your messages.
  • Familiar feel — It looks and works like a conventional messenger, so the learning curve is gentler than SimpleX.

Where Session falls short

  • No forward secrecy (yet) — Session removed perfect forward secrecy back in 2021. If a device is compromised, past messages under the same Session ID can be decrypted. A V2 protocol that restores PFS and adds post-quantum protection was announced in December 2025, but it’s still being designed.
  • Permanent ID — Your Session ID is stable across every conversation. It’s not linked to your legal identity, but once anything ties that ID to you, it retroactively ties everything it ever touched.
  • Smaller network — Fewer users, fewer contacts already on it, and some reported reliability quirks with group delivery and device sync.

SimpleX — No Identifier At All

SimpleX takes the most aggressive position in private messaging right now: it has no user identifiers whatsoever — not a phone number, not a username, not even a random account ID. It describes itself as “the first network without user IDs”.

Instead of a lookup-by-identifier, you connect to people through one-time invitation links you exchange out of band. Every contact and group lives on your device, not on a server’s database. Messages look like random noise to the relays that briefly hold them.

What SimpleX does well

  • Strongest metadata story — There’s no account to subpoena, no identifier appearing in two places, no social graph accumulating on a server. Whoever you talk to can’t be correlated.
  • Everyone runs the network — No single entity controls it. Anyone can run a SimpleX server, and the protocol passes through relays you choose.
  • Solid encryption — Double-ratchet end-to-end encryption with forward secrecy, plus private message routing on by default since v6.0. The protocol design was independently reviewed by Trail of Bits in 2024.

Where SimpleX falls short

  • Friction — No identifier means nobody can find you by username. Every new connection means exchanging a one-time link through some other channel — which is also the moment you might leak the very association you were protecting.
  • Harder recovery — With no server-side identity to restore from, moving devices and recovering an account is more involved than a phone-number account.
  • Young and smaller — It’s the newest of the three, the ecosystem is younger, and the user base is far smaller. Less battle-tested than Signal.

Which One Should You Pick?

  • Almost everyone: Signal. The network effect is the security property — an encrypted messenger nobody you know uses protects nothing. Turn on a username so you stop handing out your number.
  • Can’t register a phone number: Session. It’s the most usable option that requires nothing personal at signup.
  • Journalists, sources, sensitive contact relationships: SimpleX as a second messenger, alongside Signal for everyday use. Use it specifically when the fact that two people are talking is itself the sensitive part.

Whichever you pick, remember the half of the picture most people ignore: content encryption is only half the story. Your network and your habits are the other half.

Further Reading

Check out the Signal directory listing on The Web Is Free for more details.

Download Session at getsession.org and SimpleX at simplex.chat — both free, no phone number required.

Related Articles

What do you think? Have you made the switch from WhatsApp or Telegram, and which of these did you land on?
Andrea

Root HTC Wildfire (Android 2.2.1), install Cyanogenmod 7 and fix GPS

I have been using my HTC Wildfire for quite some time now. It is not a bad phone but it is somewhat limited, mainly in memory and speed. Plus, I really wanted to experiment and see what a custom ROM could do.

From my research, SuperOneClick is the most popular tool for rooting the Wildfire. You can find it on the XDA Developers forum — it makes the process very straightforward.

Once rooted, install ROM Manager from the Market and flash a custom recovery. Then download CyanogenMod 7, copy it to your SD card, boot into recovery, and install the zip.

1. Root with SuperOneClick
2. Install ROM Manager
3. Flash ClockworkMod recovery
4. Download CyanogenMod 7
5. Copy to SD card
6. Boot into recovery (Volume Down + Power)
7. Install zip from SD card
8. Reboot

After installing CyanogenMod, if your GPS is not working (a known issue), flash the appropriate GPS fix for your region from the XDA forums.

The difference in performance is night and day. The Wildfire becomes a much more usable device. Give it a try!

Wireless Android/pc file transfer with OnAir

I recently bought a new HTC Wildfire and was looking for a way to transfer files between my computer and the phone without needing a USB cable all the time.

OnAir is an Android app that turns your phone into a wireless file server. You install it, start the service, and browse to the IP and port it shows you — from there you can upload, download, and manage files over WiFi.

OnAir Android app screenshot

The setup is really simple:

  1. Install OnAir from the Android Market
  2. Open the app and start the server
  3. Note the IP address and port shown on screen
  4. Open your browser on your PC and go to that address

You will see a simple web interface with your phone’s SD card contents. You can upload files from your PC to the phone, download files from the phone to your PC, or delete files you no longer need. It supports multiple file selection and works with any browser.

It is not as fast as USB for large transfers — WiFi is slower than a cable — but for quickly moving a few files across the room it is very convenient. No cables, no drivers, no hassle. Perfect for when you are on the sofa and just want to transfer a PDF or a photo.

Enjoy! :-)

Android vs iPhone

Let me begin by saying that I don’t own any of those phones, so I’m not going into a technical comparison. But knowing I’m an Open Source fan, you should immediately understand which side I am leaning towards. :-)

You might think: “he hasn’t tried any of them and he wants to tell me which one is better! How is that?!?” Well, as I said, I’m not going to tell you which one is better technically but I can tell you which one is better philosophically.

Here are the key points I think matter:

Open Source — Developers and manufacturers are free to implement and change Android in any way they like, which opens up the platform to tons of new ideas and innovations.

Fully Hackable — You can do whatever you want with it. It’s your phone. Try hacking the iPhone. There is nothing you can do unless Apple wanted you to do it.

Dozens of Phones to Choose From — The iPhone is a beautiful piece of hardware, but what if you want a QWERTY keyboard? Or something bigger? Or smaller? Or cheaper? With the iPhone you’re stuck with just the iPhone. With Android there are dozens of options.

Never will a software be perfect, but we should never renounce to freedom and choice. That’s what open source is about. And Android, being open source, wins on that front.

That is it! :-)