Privacy is priceless, but Signal is expensive
Signal’s own figures show it now costs roughly $50 million a year to run the privacy-focused messaging service, with SMS-based phone number verification alone consuming more than $6 million and telecom bandwidth and cloud hosting adding heavily to the bill. Commenters debate whether Signal should decouple identities from phone numbers, move off expensive cloud and SMS providers, or introduce paid tiers or alternative revenue models, while others defend its current design as key to usability and spam prevention. The thread also highlights concerns about executive-level salaries at a nonprofit, trust issues around past initiatives like MobileCoin, and broader trade-offs between strong privacy, decentralization, usability, and financial sustainability.
Overall reaction to Signal’s cost breakdown
- Many readers appreciate the rare financial transparency and see ~$50M/year (projected 2025) as reasonable at global scale, especially vs ad‑funded competitors.
- Others are surprised how high some lines are (especially SMS and staff), and question whether architecture and vendor choices are cost‑optimal.
Infrastructure, bandwidth, and cloud vs bare metal
- Infra costs cited:
$1.3M storage, ~$2.9M servers, ~$2.8M bandwidth, plus ~$1.7M of that 2.8M just for call relaying (20 PB/year). - Several argue these numbers are high because of big‑cloud pricing (AWS/GCP/Azure) and egress fees; they suggest moving more to cheaper providers or rented bare‑metal/colo.
- Others note operational complexity, global scale, and reliability/security requirements likely justify sticking with major clouds, at least partly.
SMS verification and phone-number identity
- Registration SMS (~$6M/year) is seen as both the biggest pure waste and a core anti‑abuse mechanism.
- Many want phone numbers to become optional or eliminated, seeing them as a privacy and anonymity flaw and a barrier for some users; they point to emerging username and phone‑number‑hiding features but note numbers are still mandatory under the hood.
- Pro‑phone‑number arguments: very low signup friction, automatic social-graph bootstrap, and substantial friction against mass bot creation.
- Alternatives proposed: paid no‑phone accounts, external “identity clearinghouses,” users texting in to verify, or email‑based flows; critics respond these either don’t cut SMS costs, are easier to spoof, or harm growth.
Salaries and nonprofit governance
- Staff costs (~$19M for ~50 people) prompt debate: some see ~$350–400k/employee fully loaded as excessive for a 501(c)(3); others argue this is at or below big‑tech rates for scarce security/crypto talent, especially with no equity.
- Public 990 filings showing several $400–700k compensation packages spark questions about non‑profit norms and whether more could be done via remote hiring in lower‑cost regions.
Product choices, UX, and feature scope
- Users praise Signal for strong E2EE, good media quality, and cross‑platform support; some families and communities have largely standardized on it.
- Common complaints:
- Mandatory phone numbers and lack of iOS backups.
- Desktop client instability/re‑linking, history loss.
- Removal of SMS integration, which for some destroyed its “one messaging app” value.
- There is criticism of “non‑core” efforts (stories, MobileCoin) versus long‑requested basics (usernames, backup controls).
Centralization, federation, and trust
- Some want federated/self-hosted Signal or a Matrix/XMPP‑style model to reduce systemic and censorship risk; Signal’s leadership has historically defended centralization as critical for agility, spam control, and UX.
- Concerns resurface about SGX‑based contact discovery, PIN‑related cloud storage of metadata, and the MobileCoin integration episode; a subset of commenters view these as serious trust regressions, while others point to legal cases where Signal could only supply minimal metadata.