
Encrypted messengers under harsh scrutiny: what E2EE actually protects in Australia
Encrypted messengers under harsh scrutiny: what E2EE actually protects in Australia
Most "best encrypted messenger" lists read like ads. This one doesn't. We scored nine messengers on two axes: true anonymity (can anyone — app vendor, ISP, or government — work out who you are and who you talk to?) and safety (can content be compromised by bugs, design flaws, or legal compulsion?). The honest answer is that none score full marks on both, and several popular choices score far worse than their marketing implies.
This is not legal advice.
Threat model first: anonymity from whom?
Before choosing an app, answer who you're defending against:
- The app vendor — almost all messengers can read some metadata; a few can read content (Telegram default chats).
- Your ISP / telco — sees you're using Signal or SimpleX via SNI/IP, not with whom. Australia's data-retention regime (Telecommunications (Interception and Access) Amendment (Data Retention) Act 2015) forces telcos to keep two years of metadata — but that metadata covers your internet and phone service, not message content or app-internal contact graphs.
- The government — Australia's TOLA framework (Assistance and Access Act 2018) creates Technical Capability Notices that can compel providers to assist decryption. The framework's amendment bill was reviewed by the Parliamentary Joint Committee on Intelligence and Security in 2025. Whether a provider has complied is largely invisible to the public.
- A local attacker — someone with your unlocked phone. No app helps here; device-level hardening matters more.
The nine, under scrutiny
Signal — E2EE by default, sealed sender hides who's messaging whom from Signal's own servers (sealed sender explained). Harsh truths: your identity is your phone number, so anyone who has your number can find you on Signal — discoverability by design. On stock Android, push goes through Google's FCM, tying your account to Google's infrastructure; on GrapheneOS you can avoid that. On the legal front, Signal publicly threatened to leave Australia in 2025 rather than weaken encryption — a strong signal (sorry) about the pressure such apps face here. Anonymity: moderate. Safety: high.
SimpleX Chat — no user IDs at all; connections route through relays you can choose or self-host, and it doesn't use Google push (SimpleX privacy model). This is the strongest anonymity architecture of the nine. Harsh truths: the UX is clunkier, the user base is small, and your relays are a trust decision you now own. Pairing SimpleX with a GrapheneOS device — like our Pixel 9a · GrapheneOS build (A$849.00) (affiliate link — we sell this) — is the strongest anonymity pairing most people can realistically run. Anonymity: high. Safety: high, smaller audit surface.
Session — no phone or email required, routes messages through an onion-like network of Service Nodes. Harsh truths: the 2021 QuarksLab audit (full report) found real issues; Session's own write-up is admirably candid about them. Anonymity: high. Safety: moderate — the network is younger and the audit is older than Signal's track record.
Threema — paid, no phone number required, Swiss jurisdiction. Harsh truths: a 2023 academic analysis by ETH researchers, Three Lessons From Threema (USENIX Security 2023), found protocol weaknesses Threema has since addressed (see Threema's statement). It survived that scrutiny, but it shows even polished apps get caught. Anonymity: moderate-high. Safety: moderate-high.
Wire — E2EE, GDPR-first, business-oriented. Fine for enterprises that want a defensible procurement story; not an anonymity tool — accounts are tied to email/phone. Anonymity: low. Safety: high.
Element / Matrix — self-hostable and federated, which is a genuine strength. Harsh truth: Matrix leaks a lot of metadata across federation — room membership, membership events, and historical room state propagate between homeservers by design (Matrix.org privacy docs). Your content may be E2EE; your social graph mostly isn't. Anonymity: low-moderate. Safety: high for content.
Briar — peer-to-peer over Tor, no servers at all (how it works). The gold standard for "no infrastructure to subpoena". Harsh truths: no desktop-mobile sync, contacts need to be reachable, Tor on a phone costs battery, and P2P means someone still sees your IP when you connect. Anonymity: high. Safety: high, usability: worst.
WhatsApp — yes, E2EE by default (Signal Protocol). Privacy people exclude it anyway, and they're right: the client isn't independently auditable in practice, metadata flows to Meta, and — the classic footgun — chat backups were plaintext by default for years; the EFF's breakdown of messenger backup handling covers how defaults differ wildly between apps. Meta is also a TOLA-reachable entity if it has an Australian presence. Anonymity: very low. Safety: moderate.
Telegram — the classic bait. E2EE exists only in Secret Chats, are not default, are not available for group chats, and regular cloud chats are stored readable by Telegram Inc. If you use Telegram the way most people use Telegram, you are not using an encrypted messenger — you are using a cloud message store with an encryption checkbox hidden in a menu. Anonymity: low (phone number). Safety: low-to-moderate depending entirely on which chat mode you're in.
Comparison at a glance
| App | E2EE default | True anonymity | Metadata exposure | Biggest weakness |
|---|---|---|---|---|
| Signal | Yes | Moderate | Phone-number identity, FCM push | Discoverability by number |
| SimpleX | Yes | High | Minimal (relay choice) | Usability, small ecosystem |
| Session | Yes | High | Low | Younger network, older audit |
| Threema | Yes | Moderate-high | Low | Cost; past protocol flaw |
| Wire | Yes | Low | Standard account links | Business-oriented, not anonymous |
| Element/Matrix | Optional | Low-moderate | High via federation | Metadata-rich federation |
| Briar | Yes | High | Minimal | Sync, battery, reachability |
| Yes | Very low | Heavy (Meta) | Backups, closed client | |
| Telegram | No (secret chats only) | Low | Heavy | Default cloud chats readable |
Australian legal notes
- TOLA / Assistance and Access Act 2018: Technical Capability Notices can compel designated providers. Signal's 2025 public stance is the clearest example of an E2EE provider refusing in an Australian context (ACS Information Age coverage). What non-public providers have done is not visible.
- Metadata retention applies to carriage services — your telco/ISP, not the messenger itself. But the messenger's own servers hold their own records, governed by their jurisdiction (Signal: US; Threema: Switzerland; SimpleX: wherever you point your relays).
- The Anom precedent: Australian law enforcement ran an encrypted app as an informant, showing the operational reality — sometimes the threat isn't breaking the crypto, it's owning the platform.
- For official framing, the OAIC's privacy guidance and the Attorney-General's eSafety framework sit over all of this; nothing here changes either.
Verdict: winners by threat model
- Maximum anonymity from everyone, including the vendor: SimpleX on GrapheneOS (or Briar if you can tolerate it).
- Best balance for everyday privacy-conscious Australians: Signal — accept the phone-number identity, minimise everything else.
- Corporate/compliance needs: Wire.
- Self-hosting sovereignty: Element/Matrix — know the federation metadata trade-off.
- Not recommended for privacy purposes: Telegram (default chats), WhatsApp (Meta), despite both being "encrypted".
E2EE protects message content. Almost nothing protects your existence in a contact graph except architecture choices like SimpleX or Briar. Choose by threat model, not by logo.
Disclosure: links to /product/ pages are our own store and may earn us a commission. Sources were live-verified at publication.*