Video summary

What is the most private messenger? I ranked every messaging app!

Main summary

Key takeaways

Technology

Tech-focused Summary (Privacy Ranking of Messengers)

The speaker claims to identify the “most private messenger” by threat modeling every major messaging app using the LINDDUN privacy threat model, then producing a scoring table to rank apps by how well they mitigate privacy threats.


Method / Scoring Approach

LINDDUN threat categories used

The model evaluates these privacy threats:

  • Linkability
  • Identifiability
  • Non-repudiation
  • Detectability
  • Data disclosure
  • Unawareness
  • Non-compliance

Vectors evaluated (3 dimensions)

Each threat is assessed across three “vectors”:

  1. Account (e.g., login/auth details)
  2. Usage (e.g., app-exposed metadata/usage data)
  3. Service (e.g., what the provider keeps and how it tracks/targets users)

Scoring logic (as described)

  • +3 maximum if a messenger mitigates all vectors for a threat
  • -3 minimum if it introduces exposure for all vectors for a threat
  • The final result is a total score ranking, intended to show which apps are most or least private overall.

Key Findings by LINDDUN Category

1) Linkability (tracking behavior / behavioral profiles)

The speaker criticizes big tech / advertising-based apps for enabling tracking and ad targeting/data sharing, calling out:

  • Negative examples: WhatsApp/Facebook/iMessage (and big platforms more broadly)

“Private apps” are described as aiming to purge data and avoid running ads, with business models such as donations or paid plans:

  • Examples mentioned: Signal, Threema, SimpleXChat
  • Briar and Cwtch are described as “no compromise / most extreme,” routing traffic through Tor and resisting metadata surveillance.

Claimed relative scoring notes (Linkability):

  • Signal: limited points due to phone-number availability for linking; anonymous phone numbers may be allowed
  • Threema: described as a “mixed bag,” anonymous only under specific conditions (Android + paid/cash + no phone-number signup)
  • SimpleXChat & Session: more decentralized → higher than Signal/Threema
  • Briar & Cwtch: highest via Tor routing

2) Identifiability (account revealing who you are)

Identifiability risk is defined as collecting/using personal or uniquely identifying data such as:

  • name, phone number, email, address
  • IP, payment info
  • advertiser ID, unique user ID
  • any personal data enabling linkability

Criticized major offenders (negative points):

  • iMessage, Facebook, WhatsApp, Discord, Viber
  • The video claims these push users toward providing more identity proof (including mentioning possible gov ID/face scan scenarios).

Positive examples / partial improvements:

  • Signal: supports nicknames
  • Wire: only needs email → partial points
  • Session, Threema, SimpleXChat: described as anonymous-account capable → higher points
  • Briar & Cwtch: described as anonymous with no exposed user-identifying data (claimed to operate like “dark web”/device-only approaches)

3) Non-repudiation (plausible denial of secure messenger use)

The speaker frames this as needing to hide:

  • the fact that you use a secure messenger, not just the message contents

Criticism of big platforms:

  • The video claims they can comply with government requests and “rat you out,” because account data is accessible to providers.

Claim about Signal (negative in this category):

  • The video claims Signal fails Non-repudiation because it cryptographically ties the phone number to the account, meaning knowing/compromising the number can enable account attacks.

Apps improving the category (per the video):

  • Wire, Threema, Session, SimpleXChat, Briar, Cwtch

Extra credit for Briar & Cwtch:

  • Claimed because their designs leave less traceable metadata.

4) Detectability (others can tell you use the app)

Core idea: centralized apps may enable account discovery/connection through registries.

Claimed result for centralized systems:

  • Big centralized apps are described as worst due to account discoverability and downstream data sharing (advertisers → brokers → other adversaries).

Notable claim: Signal “double strike”

  • Phone-number requirement
  • “Intentional discoverability,” where knowing your number may reveal whether you have a Signal account

SimpleXChat / Threema / Session

  • Get strikes because traffic typically goes over the regular internet, exposing metadata such as when/where/how and with whom.

Briar & Cwtch

  • “Perfect score” because only a Tor connection is visible, not deeper usage details.

Footnote claims (as described):

  • Session and SimpleX try to obfuscate metadata paths via decentralized networks
  • But they are described as less mature/audited than Tor, leaving correlation attacks feasible.

5) Data Disclosure (default E2EE and protections)

The speaker emphasizes: privacy requires security, treating always-on default E2EE as essential.

Negative examples (strikes):

  • SMS: not encrypted by default
  • iMessage: requires enabling “Advanced Data Protection” and getting others to enable it → strike
  • Telegram: claimed to lack default E2EE for 1:1 chats and not provide it for group chats → “double strike”
  • Discord: voice/video encrypted but chat not fully E2EE → strike

Partial/positive examples (some credit for default E2EE):

  • RCS, WhatsApp, Facebook, Viber, Wire, Matrix

Strong positives (secure-messaging E2EE):

  • Signal, Session, Threema, SimpleXChat, Briar, Cwtch

The video also mentions differences among secure apps (e.g., quantum-safe cryptography, perfect forward secrecy), but says they are all “solid” overall.


6) Unawareness & Non-compliance (policies, law, marketing claims)

These are treated as “soft” threats linked to:

  • privacy policies
  • marketing claims
  • lawsuits
  • malpractice records

Criticized strongly:

  • Apple (claims like “whatever happens stays on your iPhone” are described as false; class action mention)
  • Meta and Google are described as fined for privacy-law violations across countries.

For the “private contenders,” the video claims similar results because they:

  • minimize retained data
  • resist authoritarian surveillance laws

Briar & Cwtch score better

  • Claimed because they lack data even if developers were coerced.

Final Recommendations / Ranking Conclusions (as Stated)

Bottom / near-bottom portrayal

  • Bottom rank: SMS texts (least secure/private “in every category”)
  • Near-bottom: iMessage (marginally better than SMS, but defaults are called a “privacy disaster”)
  • Telegram and RCS portrayed as only slightly better than SMS:
    • RCS is said to be most improved only for default E2EE, but still fails other LINDDUN threats
  • General big-tech social messengers (example: Viber → WhatsApp/Facebook) are described as primarily tracking for ads, even if some E2EE exists.

Additional notes from the video

  • Wire: “pretty good,” but described as enterprise-oriented
  • Matrix: good for communities, not best for private one-to-one chats

“Top 6 Most Secure and Private Messengers” (by the Video)

  1. Briar
  2. Cwtch
  3. SimpleX
  4. Threema
  5. Signal (tied with Session in the video)
  6. Session (tie)

The video describes the relative ordering among the lower two as “shared by Signal and Session.”


Why the Top-Tier Apps Win (per the Video)

  • Signal vs Session

    • Both are strong, but
    • Signal’s phone-number tie harms Non-repudiation/Detectability
    • Session avoids phone-number association, improving those areas
  • Threema

    • Strong privacy but more dependent on signup conditions for true anonymity (paid-only model noted)
  • SimpleX

    • Claimed “no compromises” category:
      • anonymous accounts unless the user makes them identifiable
      • strong protection against many threats
      • “except” for Detectability-like leakage (generally still high overall)
  • Briar & Cwtch

    • Described as the most clandestine:
      • anonymous accounts by default
      • use Tor for routing
      • “no central servers” → no centralized data to hack/collect
      • reportedly can operate via Bluetooth/WiFi if Internet is down (as claimed)

Speaker / Sources

  • Main speaker/source: The video appears to be by “thehatedone”
    • The speaker mentions Patreon/support and describes their own scoring table and podcast-related material.

Original video