Open Whisper Systems, makers of Signal, are testing a way to scan contacts and then provably delete the data from its servers, rolling out in coming months
THE ENCRYPTED-COMMUNICATION APP Signal has a sterling reputation within the security and crypto community, but its critics point to a nagging flaw …
Context & Ripple Effects
Signal has built its reputation on minimizing what touches its servers — self-destructing messages, safety numbers, and QR-code verification all pushed verification onto devices rather than trusting the network. But critics have long pointed at one nagging exception: contact discovery, which requires uploading address-book data to Signal's servers even if briefly.
The fix now being tested — scan contacts, then provably delete the data — matters because it converts a promise into proof, and it comes from a five-person team whose protocol already powers encryption at Facebook and others. It is also an early chapter in a recurring tension for Signal between convenience and server-side data, one that resurfaces years later when storing recovery data on its servers prompts some security experts to threaten abandoning the app.
First-order effects
- Users who adopt the rollout get contact discovery without leaving persistent address-book data behind, closing the gap critics cite in Signal's otherwise minimal-metadata design.
- Open Whisper Systems gains a demonstrable answer to the 'you still upload my contacts' objection, strengthening the app's standing with exactly the security community it depends on for credibility.
Second-order effects
- Rivals building on Signal's protocol — Facebook among them per the related profile — face pressure to match provable deletion rather than relying on policy promises about how long uploaded contacts are retained.
- Provable deletion risks becoming a competitive benchmark in encrypted messaging, forcing other apps to either publish similar proofs or explain why they cannot.
Third-order effects
- If the pattern holds, encrypted messaging shifts from trust-based privacy claims ('we delete it') toward verifiable ones ('we can prove we deleted it'), raising the bar for what counts as a privacy guarantee industry-wide.
- It also previews the structural trade-off Signal keeps negotiating: every convenience feature that touches servers — contacts today, recovery backups later — tests whether its user base will accept any server-side data at all.
The trend: Secure messaging is moving from trust-me privacy policies toward cryptographically provable guarantees, with Signal setting the reference implementation others must match.