In late 2024, the FBI and CISA put out a Salt Typhoon advisory recommending that Americans use encrypted messengers like Signal. At the time, the case was straightforward. SMS between iOS and Android was unencrypted, and the Chinese state-sponsored hack of US telecoms made that very tangible. Eighteen months later, the picture has changed: RCS now offers end-to-end encryption between iOS 18+ and Android (Apple shipped it in 2025), and the “iMessage-only between iPhone users” world is gone.
So why still pick Signal? A few real reasons that don’t depend on the FBI for justification.
What Signal still does better than RCS or iMessage
| Feature | Signal | iMessage / RCS |
|---|---|---|
| End-to-end encryption | Yes | Yes (iMessage + RCS as of iOS 18) |
| Metadata minimization | Yes. sealed sender, minimal server-side records | Apple/Google still see who’s talking to whom and when |
| Username-based contacts (no phone number shared) | Yes. Added in 2024 | No. Phone number is the identifier |
| Disappearing messages | Yes, per-chat with default windows | Partial (iMessage), inconsistent (RCS) |
| Open-source clients + server | Yes. Auditable | No |
| Cross-platform desktop apps | Yes. MacOS, Windows, Linux | iMessage on macOS only; RCS desktop story is messy |
| Single corporate entity controls it | Signal Foundation (nonprofit) | Apple + Google |
The metadata point is the underrated one
End-to-end encryption protects the content of your messages. Nobody but the sender and recipient can read them. But Apple and Google still know who sent a message to whom, when, and from where. That’s metadata, and metadata is what intelligence agencies and lawsuits actually subpoena.
Signal’s sealed-sender feature means the server doesn’t know who sent a given message. Only who it’s going to. Signal’s public transparency reports show repeatedly that when subpoenaed, they have nothing to hand over besides “account exists, last connected at this date.” Apple and Google have a great deal more to hand over.
Usernames are a real win
Signal added phone-number-free usernames in early 2024. That means you can hand out a Signal username to a stranger (a journalist, an interview source, someone at a conference) without revealing your phone number. IMessage and RCS both still use your phone number as the identifier.
Getting started
- Download Signal from signal.org/download. IOS, Android, macOS, Windows, Linux.
- Sign up. You can use a phone number for the initial verification.
- Go to Settings → Profile and set a username + handle. Once that’s set, you can share the handle with people instead of your phone number.
- Set a default disappearing-message timer if you want one (Settings → Privacy → Disappearing messages).
Who should still use it
- Anyone whose work involves source confidentiality. Journalists, lawyers, doctors, social workers, anyone where the message graph itself is sensitive.
- People who want their messenger to not be a single-vendor product. Signal isn’t controlled by Apple or Google.
- People who care about disappearing-messages working consistently across contacts. RCS support is uneven here.
Who might not need it
If your threat model is “I don’t want randos reading my texts,” and you’re running iOS 18+ talking to Android 13+ contacts on RCS, you’re already encrypted. There’s nothing wrong with sticking with what’s built into your phone for casual messaging. Signal’s case in 2026 is metadata, usernames, and trust model. Not encryption per se.
Sources: The Verge on Salt Typhoon · Apple iMessage security guide