Salt Typhoon: US cybersecurity watchdog urges switch to Signal-like messaging apps

A woman holding a mobile phone in front of the Signal logo displayed on a computer screen
(Image credit: Getty Images)

The US cybersecurity watchdog is urging citizens to use only secure end-to-end encrypted messaging apps like Signal to secure mobile communications.

The Cybersecurity and Infrastructure Security Agency (CISA) shared a series of best practices on Wednesday, December 18, 2024, in the wake of the Salt Typhoon attack. This "unprecedented cyberattack" is thought to be the biggest intelligence compromise in US history, hacking at least eight US telecom companies to spy on citizens.

While the latest CISA announcement is aimed at highly targeted individuals who possess information of interest to Chinese hackers, everyone can benefit from these security tips. These tips include avoiding unsecured virtual private network (VPN) apps.

Signal and more security tips

"Highly targeted individuals should assume that all communications between mobile devices – including government and personal devices –and internet services are at risk of interception or manipulation," wrote the US cybersecurity watchdog.

With this in mind, the experts urge switching to Signal-like communications apps. These services encrypt all the data in transit to ensure your messages remain private between the sender and the receiver (end to end).

CISA recommends finding a service compatible with both Android and iPhone, allowing text message interoperability across platforms. These may also include features like disappearing messages and images, which can enhance privacy even further.

Most importantly, "When selecting an end-to-end encrypted messaging app, evaluate the extent to which the app and associated services collect and store metadata," said CISA.

Metadata refers to all the information that is not the content, such as IP address, timestamps, data file size, and more. Metadata collection, for instance, is one of the reasons why the likes of Signal or Session are considered more secure than WhatsApp.

CISA also suggests enabling phishing-resistant forms of two-factor authentication to ensure hackers cannot bypass this extra layer of protection. Experts recommend enabling Fast Identity Online (FIDO), which includes biometrics (like fingerprints or facial recognition) and physical security keys.

As a rule of thumb, you should avoid using SMS as a second factor for authentication as these aren't phishing-resistant. "SMS messages are not encrypted – a threat actor with access to a telecommunication provider’s network who intercepts these messages can read them," explain the experts.

US citizens are also urged to use strong password manager tools to store all login details and find strong combinations. The likes of LastPass, Apple Passwords App, and Google Password Manager Proton Pass are all free to use and automatically alert on weak, reused, or leaked passwords.

Experts also recommend regularly updating devices' operating system software to patch any vulnerabilities. They also advise against the use of unsecured commercial VPN services as "many free and commercial VPN providers have questionable security and privacy policies."

This is why it's important to choose the best VPN apps with a reputable reputation, strict no-log policy, and strong security features – even better when independently audited. At the time of writing, TechRadar's top premium recommendation is NordVPN, while Privado VPN and Proton VPN are the most secure free VPNs.

Chiara Castro
News Editor (Tech Software)

Chiara is a multimedia journalist committed to covering stories to help promote the rights and denounce the abuses of the digital side of life – wherever cybersecurity, markets, and politics tangle up. She writes news, interviews, and analysis on data privacy, online censorship, digital rights, cybercrime, and security software, with a special focus on VPNs, for TechRadar and TechRadar Pro. Got a story, tip-off, or something tech-interesting to say? Reach out to chiara.castro@futurenet.com

Read more
A wall of data on a large screen.
“It's the same doors that the good guys use, that the bad guys can walk through” - former White House tech advisor on data-centric security in the wake of Salt Typhoon
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Young woman using mobile phone
Best encrypted messaging app for Android of 2025
Young woman holds a smartphone with a beam of light obscuring her eyes
Privacy powerhouses: 5 apps to take your online security to the next level
Collage of hand with a key and a smartphone
Is it possible to send a truly anonymous message?
QR Code
Hackers are targeting Signal with new QR code-linked cyberattack
Latest in Cyber Security
Dark Web monitoring
How users benefit from Dark Web monitoring
The X logo next to a silhouette of Elon Musk
Who was really behind the massive X cyberattack? Here’s what experts say about Elon Musk’s claims
A person holding a phone looking at a scam text with warning signs around
A massive SMS toll fee scam is sweeping the US – here’s how to stay safe, according to the FBI
View on National Assembly building in Paris, France, with French and European flags flying.
France rejects controversial encryption backdoor provision
ignal messaging application President Meredith Whittaker poses for a photograph before an interview at the Europe's largest tech conference, the Web Summit, in Lisbon on November 4, 2022.
"We will not walk back" – Signal would rather leave the UK and Sweden than remove encryption protections
Man uses a laptop in a hotel room
4 ways to avoid misinformation on social media and retain control of your newsfeed
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)