Skip to main content

Signal isn’t the problem

30/04/2026 · 2 min read

If I still had hair, it would be a right mess by now. Over the last few days, news has emerged of an attack on Signal users – and much of the German media has reflexively labelled it a ‘Signal hack’. It sounds good, it gets clicks, but it’s simply bull$#17.

The problem wasn’t the software. On the contrary: no vulnerability in Signal was exploited. Unless, of course, you count the users themselves as the vulnerability. Because that is precisely the vulnerability that was targeted.

To put it figuratively: there’s a really good door with a damn solid lock. And what happens? The key is simply handed over. Of course someone’s going to get in. That’s not a hack. That’s an open invitation.

And now there are calls – including from Andrea Lindholz (CSU), Vice-President of the Bundestag – for a ban on Signal in the Bundestag. Instead, people are talking about alternatives such as Wire, Threema or other services – don’t get me wrong, they’re good too.

But that completely misses the point. By light years, in fact.

Because even if Signal were to disappear tomorrow, the real vulnerability would remain – the user.

What we need isn’t a debate about bans, but education. How do I recognise social engineering? How do I handle sensitive access credentials? How do I react if someone tries to trick me? That’s exactly where the problem lies – and that’s exactly where far too little is being invested.

We used to call this the ‘Layer 8 problem’. Or, to put it more colloquially: PEBCAK – Problem Exists Between Chair And Keyboard. It’s not the nicest way to put it, but it hits the nail on the head: the attack targets the ‘carbon layer’, not the ‘silicon layer’.

A genuine technical hack is much more difficult. So rather than breaking through the wall, you go through the open door: attackers target people – because that’s the easiest and most promising route.

And that’s exactly what we should be talking about. Not about whether we’re going to regulate the few truly secure tools into oblivion.

A small ray of hope at the end: two media outlets that frame the issue clearly – the taz and Deutschlandfunk.

Originally posted in German on LinkedIn.