Secure Messaging
Definition
The practice of protecting one-to-one and group communications against interception, device seizure, metadata exposure, and social-engineering attack.
It operates at three layers: the transport (end-to-end encrypted messaging apps — Signal for one-to-one and small group, Wire and Briar as alternatives, Matrix/Riot for larger federated groups); the device (full-disk encryption, screen lock, OS kept up to date, no sensitive content unlocked in airports); and the practice (no screenshots of sensitive threads, disappearing messages by default, separate identity for high-risk work).
Practitioner guides (EFF Surveillance Self-Defense, Tactical Tech’s Holistic Security, Access Now Digital First Aid Kit) treat the practice layer as the hardest to enforce — even the best transport cannot protect a message that has been screenshotted into a non-secure phone.
Full page: [[secure-messaging]]. [source: secure-messaging] [source: ssd-eff]
FAQ
What is secure messaging?
Secure messaging is the practice of protecting one-to-one and group communications against interception, device seizure, metadata exposure, and social-engineering attack. The full-page version of this definition lives on [[secure-messaging]]. The 2026 operational baseline is end-to-end-encrypted messaging (Signal, Threema, Matrix), a registration-lock PIN, disappearing-message timers, safety-number verification, and lock-screen notification hygiene.
What are the three layers of secure messaging?
It operates at three layers: the transport (end-to-end encrypted messaging apps — Signal for one-to-one and small group, Wire and Briar as alternatives, Matrix/Riot for larger federated groups); the device (full-disk encryption, screen lock, OS kept up to date, no sensitive content unlocked in airports); and the practice (no screenshots of sensitive threads, disappearing messages by default, separate identity for high-risk work).
What does the practice layer cover?
Practitioner guides (EFF Surveillance Self-Defense, Tactical Tech’s Holistic Security, Access Now Digital First Aid Kit) treat the practice layer as the hardest to enforce — even the best transport cannot protect a message that has been screenshotted into a non-secure phone. The practice layer is where most operational failures happen [source: ssd-eff].
Why is the practice layer the hardest to enforce?
The practice layer is the hardest because it depends on consistent human behaviour across the group, not on a single technical control. The transport layer (end-to-end encryption) is enforced by the app; the device layer (full-disk encryption) is enforced by the operating system; the practice layer (no screenshots, disappearing messages by default) is enforced only by the group’s shared expectations.
