Signal vs Session: Metadata, Phone Numbers and Trust

Messengers 7 min read Sep 12, 2026 EN 6 views

Explore the architectural differences between Signal and Session, comparing phone registration, metadata protection, decentralized routing, and trust mo...

Architectural Foundations: Centralized Servers vs. Decentralized Nodes

Modern private messaging rests on two distinct engineering philosophies. When evaluating Signal and Session, the fundamental difference lies not just in user interfaces or sticker packs, but in how data travels between devices and who controls the underlying infrastructure.

Signal relies on a centralized client-server architecture operated by the non-profit Signal Technology Foundation. Every message, attachment, and call signal routes through centralized cloud servers hosted on infrastructure providers like Amazon Web Services and Microsoft Azure. Centralization gives Signal absolute control over performance, enabling instant delivery, low-latency voice calls, and rapid deployment of cryptographic updates.

Session takes an oppositional architectural approach by rejecting centralized servers altogether. Originally developed by the Oxen Privacy Tech Foundation, Session operates across a decentralized network of independent servers called the Oxen Service Node Network. Instead of a single entity routing traffic, Session relies on thousands of distributed nodes incentivized through a proof-of-stake cryptocurrency system. No single entity owns the network, and no single computer handles every transaction.

Identity and Registration: Phone Numbers vs. Session IDs

The primary barrier to anonymity in mainstream secure messaging has historically been account registration. The choice of identifier dictates how easily an account can be tied to a physical human being.

Signal mandates a valid telephone number to create an account. While Signal recently introduced public usernames—allowing individuals to share a handle rather than a phone number with new contacts—the underlying account remains permanently anchored to a telecom identifier. This requirement introduces specific trade-offs:

  • SIM Swapping Vulnerabilities: If an attacker hijacks your phone number via carrier fraud, they can attempt to re-register your account, although Signal's optional Registration Lock PIN helps mitigate unauthorized takeovers.
  • State Identification: In many jurisdictions, SIM cards require government-issued photo identification, linking the hardware to a legal identity by default.
  • Contact Discovery: Signal automatically checks your local address book against its user database using secure contact discovery, making onboarding seamless at the cost of associating the app with your personal social graph.

Session discards telephone numbers and personal identifiers entirely. Registration requires no email address, phone number, or payment verification. Instead, the application generates a 66-character alphanumeric string known as a Session ID, derived directly from an Ed25519 public-private key pair generated locally on the device.

Because there is no central database of users, Session cannot automatically scan your address book to show you who already uses the application. Users must exchange Session IDs or scan QR codes manually. This approach renders Session pseudonymous by default, severing the link between telecom records and messaging activity.

Cryptographic Protocols and Metadata Exposure

End-to-end encryption ensures that third parties cannot read the contents of your messages. However, message content is only half of the privacy equation; metadata—who you speak to, when, from which IP address, and how often—can often reveal more actionable intelligence than plaintext text.

Signal pioneered the Signal Protocol, an open cryptographic standard that combines the Double Ratchet Algorithm, pre-keys, and a triple Diffie-Hellman handshake. This design provides end-to-end encryption with both forward secrecy and break-in recovery. To defend against metadata leakage, Signal built Sealed Sender. Under this mechanism, the sender encrypts their own identity alongside the message text. Signal's servers only know the intended recipient's routing token to deliver the packet, unable to see who initiated the message unless the sender permits it.

Session uses a custom derivative called the Session Protocol, adapted from the Signal Protocol codebase. While retaining end-to-end encryption principles, Session modified the architecture to function without centralized user directories. Because Session operates without persistent centralized connections, it abandons certain ratchet operations that rely on immediate server feedback, replacing them with asynchronous session establishment.

Network Routing and IP Address Visibility

Whenever a device sends data across the internet, the target server naturally sees the originating IP address unless an intermediate proxy intervenes. The handling of IP addresses represents the most technical divergence between these two applications.

Under Signal's standard configuration, your device connects directly to Signal's centralized servers. Signal's infrastructure necessarily sees your public IP address to route packets back to you. While Signal has demonstrated in legal responses that it does not retain connection logs or historical IP mappings, users must place operational trust in the foundation's stated policies and infrastructure hygiene. Users requiring IP masking must run Signal behind a VPN, Tor, or use Signal's built-in proxy settings.

Session addresses the IP address problem at the structural protocol level using onion routing, a technique similar to the Tor network. When you send a message through Session:

  1. The client software wraps the message in three separate cryptographic layers.
  2. The message passes through three randomly selected nodes in the Oxen Service Node Network.
  3. The first node (guard node) sees your IP address but cannot read the destination or the payload.
  4. The middle node only sees the preceding and succeeding nodes.
  5. The exit node delivers the message to the recipient's decentralized storage swarm but does not know your originating IP address.

This path ensures that no single server in the network knows both who sent the message and who received it, completely hiding the user's IP address by default without requiring an auxiliary VPN.

Usability, Features, and Reliability Trade-Offs

Architectural choices directly dictate user experience. Signal delivers an experience equivalent to commercial consumer apps like WhatsApp or iMessage. Session sacrifices several performance conveniences to maintain decentralization.

  • Message Reliability: Signal utilizes standard push notification channels (Apple APNs and Google Play Services) alongside direct server delivery, meaning messages arrive almost instantaneously. Session relies on decentralized swarms that temporarily store messages for up to 14 days; delivery can occasionally experience delays or desynchronization across secondary devices.
  • Voice and Video Calls: Signal offers fully encrypted, high-definition group voice and video calls handled through its centralized selective forwarding units. Session supports peer-to-peer audio and video calls, but routing streaming media through decentralized onion nodes introduces latency challenges and requires direct IP connections unless specific relay settings are enabled.
  • Multi-Device Syncing: Signal links desktop apps to mobile devices by scanning a QR code, syncing message history efficiently using local encrypted protocols. Session links devices using seed phrases, but because there is no central archive, history synchronization across multiple installations can be incomplete or slow.

Structural Comparison

Feature Signal Session
Network Model Centralized (Signal Technology Foundation) Decentralized (Oxen Service Node Network)
Primary Identifier Phone number (with optional public usernames) Randomized Session ID (public key)
Routing Mechanism Direct TLS connection with Sealed Sender 3-hop decentralized onion routing
IP Address Shielding Requires external VPN or custom proxy Built-in by default via onion routing
Voice/Video Capabilities Full-featured, low latency, large group calls Peer-to-peer calling, limited group calling
Account Recovery Phone number confirmation plus account PIN 16-word mnemonic recovery phrase

Governance, Funding, and the Trust Boundary

All privacy tools require some degree of trust. The question for consumers is where they prefer to place that trust: in institutional accountability or in economic protocol incentives.

Signal operates under a 501(c)(3) non-profit structure based in the United States. Its funding derives from tax-deductible public donations, individual grants, and early foundation capital. Signal undergoes regular third-party security audits, and its client and server code are open source. However, its jurisdiction within the United States makes it subject to federal legal frameworks, national security letters, and domestic law enforcement subpoenas. To date, Signal's minimal data collection design has successfully prevented it from turning over significant user records when subpoenaed, simply because those records do not exist on its drives.

Session operates under the Oxen Privacy Tech Foundation, based in Australia. Australia maintains strict digital surveillance laws, including the Assistance and Access Act of 2018. However, Session mitigates jurisdictional risk through decentralization: the foundation does not operate the nodes carrying the traffic, nor does it control the servers storing messages. Instead, the network relies on service node operators who must stake Oxen cryptocurrency tokens to participate, creating an economic penalty for malicious behavior. Users who are skeptical of blockchain-adjacent ecosystems may find this economic model unfamiliar, while users skeptical of centralized non-profits view it as an effective mechanism to eliminate operational points of failure.

Choosing between Signal and Session is not a matter of finding the "best" application, but of selecting the appropriate threat model. Signal offers world-class end-to-end encryption wrapped in an accessible, highly reliable interface that suits anyone wanting to shield private conversations from mass surveillance, corporate data miners, and physical eavesdroppers. Session trades away registration convenience and instantaneous speed to eliminate the two vectors Signal still touches: the telephone network and centralized server logging.

[ KEYWORDS ]

signalsessionencrypted messagingprivacy toolsmetadataonion routingsecure messaging