Seriously secure messaging
The Threema Advantage
Why metadata might reveal more about you than you intend to disclose, and how Threema can help prevent it
Even operators of messenger apps that make a living by selling targeted ads have started to use end-to-end encryption for message contents – something that Threema is known for providing since its launch in 2012. Giving up access to message contents (assuming the end-to-end encryption is implemented properly) will hardly affect the business model of such companies, though. It's merely window dressing since the most interesting kind of data – i.e., metadata – will most certainly still be collected, analyzed, and aggregated.
Metadata refers to all data occurring during communication except for the message content itself. Serious protection of data privacy must include both protection of content and protection of metadata. Thus, the sole protection of content is insufficient because metadata allows uniquely identifying individuals, analyzing their behavior, determining their circles of friends, detecting their frequent locations, and monitoring their communication behavior. Combined with data from other platforms, the picture that can be drawn of a person is much more detailed than one that could ever be drawn from message contents alone.
What's Threema’s advantage over other messengers?
Threema was created with data protection in mind, and it is designed from the ground up to generate as little metadata as technically possible. The less metadata is generated in the first place, the less it can be misused, be it by corporations, advertisers, or governmental surveillance activities.
In contrast to other messengers, Threema doesn't require any personal information, such as your phone number, in order to be used. Instead, a randomly generated character string serves as a unique identifier, meaning that full anonymity can be maintained.
Here's a list of privacy-related features that set Threema and the widely used WhatsApp Messenger apart 2):
Threema |
||
---|---|---|
Vendor |
||
Company ownership | Independent, privately owned | Facebook, Inc. |
Business model | User pays for service by purchasing the app | Unknown |
Server location | Switzerland | USA / others |
Data Privacy Standard and Place of Jurisdiction | Switzerland | USA |
Privacy |
||
No phone number necessary for registration | ||
Can be used without access to/synchronization of address book | ||
Contact lists and groups are managed entirely on users’ devices, no central storage of personal data | ||
No capturing and forwarding of online status | ||
Read receipts can be disabled | Partially (not available for group chats and voice messages) | |
“Is typing” indicator can be turned off | ||
Automatic loading of received locations in chats can be disabled | 1) | |
Full control over sharing of profile pictures, no central storage | ||
Passcode/fingerprint lock | ||
Optionally prevent capturing of screen shots and thumbnails in App Switcher | 1) | |
No permission to read SMS history and device ID required | 1) | |
Received URLs aren’t loaded automatically | ||
Encryption |
||
Strong encryption of chats and media on users’ devices (on Android, with passphrase) | ||
No fallback to unencrypted connection possible | ||
Verification level permanently displayed for each contact | ||
Even control messages (e.g. for changes in group chats) are end-to-end encrypted | ||
Strongly encrypted full backup, no cloud |
1) | |
Entropy for creation of key pair is generated using user input |
||
Purchase |
||
App package can be downloaded directly from vendor bypassing app store (if supported by platform) | ||
Can be purchased anonymously with Bitcoin | 1) | |
Validation |
||
Open-source API for sending and receiving end-to-end encrypted messages | ||
Independent encryption validation possible (https://threema.ch/validation/) | ||
External audit of data security and data privacy | ||
Transparent and concise privacy policy; no rights waived by user; reverse engineering permitted |
If you value data privacy, Threema is still the best choice. No other mobile instant messenger offers a similar metadata restraint without compromising on features and usability. On top of that, Threema provides unique functionality, such as the handy poll feature. It’s available on all major mobile platforms (i.e., Android, iOS, and Windows Phone).
For general information, please consult https://threema.ch.
If you are technically inclined, you might want to have a look at our comprehensive Whitepaper.
1) On Android platform
2) Data is current as of April 13, 2016. The information has been gathered from publicly available sources with utmost care. However, we do not assume any responsibility for the correctness of the information presented here. WhatsApp is a registered trademark of WhatsApp, Inc.