Start from your threats, not from the app's promises

Published: October 7, 2026 · Updated: October 8, 2026

A threat model is just an honest list: who are you worried about, what can they do, and does your app actually stop them? Signal is superb protection against some adversaries: your internet provider reading your messages, a hacker intercepting traffic, a company mining your chats for ads. It is honest-to-goodness inadequate against others, like someone with physical access to your unlocked phone or a government that can compel you to unlock it. Most privacy advice fails because it starts with the tool ("use Signal!") instead of the threat ("who am I actually worried about?"). This guide flips that: name your adversary first, then check what Signal does and does not cover at each level.

You do not need security training to do this. You need five minutes, a piece of paper or this page, and the willingness to be specific instead of vague. "I want to be private" is not a threat model. "I don't want my employer reading my chats" is. Let us build yours.

A shield with layered rings showing different threat levels from nosy contacts to state actors

Why bother with a threat model

Because security is always a trade-off, and you cannot make a good trade-off without knowing what you are trading for. The person who wants to keep their chats away from an advertiser needs different protection than the person hiding from an abusive partner, who needs different protection than a journalist protecting a source from a state intelligence agency. All three might install Signal. For the first two, that is probably the whole answer. For the third, Signal is one layer in a much bigger plan.

Skipping this step produces two classic mistakes. The first is under-protection: assuming the app's reputation covers threats it was never designed for, like a stolen unlocked phone. The second is over-protection: burning hours on elaborate setups against adversaries that do not exist in your life, while ignoring the real weak point: usually the people you talk to, or your own unlocked screen. A threat model kills both mistakes at once.

Here is the framework security professionals use, stripped of jargon: (1) name the adversary, (2) describe what they can realistically do, (3) ask whether your tools stop that, (4) fill the gaps. The rest of this page walks you through it with Signal as the tool under examination.

The five levels of adversary

Not every "bad guy" is the same kind of bad guy. These five levels cover the realistic range, from the mundane to the extreme. Most readers live at levels 1–3; levels 4–5 are for people with genuinely dangerous adversaries.

Illustration of the five adversary levels as a pyramid
Signal handles the bottom of the pyramid well; the top needs more than an app.
LevelAdversaryWhat they can do
1Nosy people around you: friends, family, coworkersGlance at your screen, pick up your unlocked phone, ask "who was that?"
2Companies and data brokers: advertisers, analytics firmsCollect, profile, and sell behavioral data at scale; cannot read encrypted content
3Your network observers: ISP, employer Wi-Fi admin, café networkSee which domains you connect to and when; on work networks, sometimes much more
4Determined individuals: abusive ex, stalker, targeted hackerSocial engineering, phishing, device theft, spyware, physical access
5State actors: police, intelligence agenciesLegal compulsion, large-scale surveillance, targeted device hacking, network taps

The key insight: each level up changes the game, not just the difficulty. Level 2 is defeated by encryption; level 4 is defeated by device security and human judgment; level 5 is defeated by operational discipline that no app can provide alone. Signal's strength is concentrated at levels 2–3, with real but limited help at 1 and 4, and honest limits at 5.

What Signal handles at each level

Level by level, here is where Signal genuinely earns its reputation:

Where Signal's protection stops

This is the section most "why Signal is great" articles skip. Signal does not protect you against:

Illustration of where Signal protection stops
Encryption is strong; the device and the human are the weak points.

None of these are flaws in Signal. They are the boundaries of what any messenger can do. The app secures the channel; everything at the ends of the channel is yours to secure.

Download the official Signal APK

from Signal's official site — file hosted by Signal, not by us

When Signal is not enough

Concrete cases where "just use Signal" is the wrong answer on its own:

The pattern: whenever the adversary can reach your device or your person, the messenger is downstream of the real problem. Fix the device and the human situation first; the app choice is secondary.

Complements, not replacements

No product endorsements here. Just the categories of protection that sit alongside a messenger in a serious setup:

Build yours in five minutes

Grab this checklist and answer honestly. Your threat model is the set of boxes you tick:

Revisit this once a year or whenever your situation changes. New job, new country, new relationship, new phone. Threats move; your model should move with them.

The one-line rule. Signal defeats interception, profiling, and corporate data-mining completely; it helps against snoopers and stalkers only as far as your device and your judgment hold; and against states or anyone holding your unlocked phone, it is one layer in a plan the app cannot write for you.

Frequently asked questions

What is a threat model?

A clear statement of who you are worried about, what they can realistically do, and whether your tools actually stop them. It is how you avoid both under-protecting and over-protecting yourself.

Does Signal protect against hackers?

Against network interception, yes. Encryption defeats eavesdropping completely. Against hackers targeting your phone itself with spyware or phishing, no messenger can help; the device is the battlefield.

Can the government read my Signal messages?

Signal's encryption has no known backdoor and the protocol is publicly audited, so message contents resist interception. States typically attack the phone, the person, or the metadata instead. Areas where no app alone is sufficient.

Is Signal enough for journalists or activists?

It is usually part of the answer, not the whole answer. High-risk work needs device security, careful practices, and often expert operational-security guidance alongside the app.

What is the weakest link in Signal security?

The endpoints: your unlocked phone, malware on the device, and the people you chat with. Encryption secures the channel; everything at either end is yours to secure.

Keep reading