How YGOOW compares

We will not tell you YGOOW is the only secure messenger — that claim is how you spot marketing. Several excellent projects solve overlapping problems, and some are more mature than we are today. Here is an honest map of where YGOOW sits, and where it does not.

At a glance

YGOOW Signal Session Briar
No phone number or email ✓ ✗ (phone) ✓ ✓
No server-side account ✓ ✗ ~ (key ID) ✓
Tor / onion transport built in ✓ (default) ✗ ~ (own network) ✓ (default)
Works offline over local mesh ✗ ✗ ✗ ✓
Key can be any file or password ✓ ✗ ✗ ✗
A different key per message ✓ ✗ ✗ ✗
Quorum (K-of-N) unlock ✓ ✗ ✗ ✗
Hardware key (YubiKey) as a second factor ✓ ✗ ✗ ✗
Choose protection per chat — no insecure default ✓ ✗ ✗ ✗
Content key independent of the channel ✓ ✗ ✗ ✗
Multiple identities in one install ✓ ✗ ✗ ✗
Open-after / burn / lifetime conditions ✓ ✗ ✗ ✗
Duress decoy — a hidden real profile ✓ ✗ ✗ ✗
One-time note for someone without the app ✓ ✗ ✗ ✗
Padded size + rotating relay address ✓ ~ ~ ~
Forward secrecy ~ ✓ ✗ ✓
Post-compromise security (DH ratchet) ✗ ✓ ✗ ~
Post-quantum hybrid key exchange ✗ ✓ ✗ ✗
Independent audit planned ✓ ✓ ✓
Side-channel measurements of the shipped code, published ✓ ~ ~ ~
Open source (license) ✗ ✓ ✓ ✓
Reproducible / verifiable builds ✗ ✓ ✓ ~
Platforms Android all all Android + desktop

✓ yes · ✗ no · ~ partial or qualified. Where we wrote planned, we mean exactly that — and we say so again in the whitepaper and our security policy. Our forward secrecy is ~ because used message keys are erased, but a conversation’s starting key can still be re-derived from the two identities (whitepaper §5). Post-compromise security and the post-quantum hybrid are built and tested in our libraries but not yet in live conversations, so they are ✗ until they ship — the progress page tracks them. The side-channel row means timing measurements of the shipped code on its target hardware, with the unfixed findings published alongside the fixed ones. The others rely on cryptographic libraries built to be constant-time and on external audits — a stronger guarantee than a measurement, and we say so; ~ only because raw measurements of the shipped build are not published as such.

What is genuinely different about YGOOW

No single row is the point — the combination is:

Where the others are ahead — today

We would rather say this than have you discover it:

YGOOW is younger than all three. We have no independent audit yet, and we are Android-only. Our live conversations have per-message forward secrecy but not yet post-compromise security or post-quantum protection; both are built and waiting to be wired in, and we don’t claim them until they are. When they ship, one edge stays: because there is no prekey server, the very first chain of a conversation is derived from the secret you already share, so it becomes post-compromise-fresh only after one full round-trip. Signal’s prekey server buys that freshness from the first message; we trade it for a relay that holds nothing. That is a real trade-off, not a free win. None of this is buried — it is in the whitepaper and on our security page.

How to choose

Your key, your rules — everything else is redacted.