
The supposed invulnerability of encrypted messaging apps is once again under scrutiny after it was revealed that The FBI managed to recover deleted Signal messages on an iPhone. without needing to break the encryption. The discovery is not related to a breach in the Signal protocol or to flaws in the contact key verificationbut with a little-seen feature of iOS: how it manages and stores push notifications.
What has been revealed in a trial in the United States shows that, even if a conversation self-disappears within the app and even Uninstall Signal from your iPhonePartial copies of these messages may remain in an internal system notification database. This is an unwelcome reminder for anyone who trusts the iPhone as an absolute bastion of privacy, including users in Spain and Europe who use Signal for sensitive communications.
The Prairieland case: a terrorism trial that exposes the FBI's methods
The technique came to light in the well-known Prairieland caseA federal trial in the United States is underway related to an attack on the ICE Prairieland detention center in Alvarado, Texas. In July, a group of people set off fireworks, damaged the facility, and one of the incidents resulted in a police officer being shot in the neck, leading to accusations of domestic terrorism.
During the trial, the FBI special agent Clark Wiethorn She testified about how incoming Signal messages had been obtained from the iPhone of one of the defendants, Lynette Sharp, and presented as evidence in Exhibit 158. According to the summary of that evidence, the Signal application had already been removed from device when the forensic extraction was carried out.
People present in the room explained that the FBI did not ask Signal for help nor did it hack its servers, but instead resorted to a forensic analysis of the iPhone itselfThe phone was examined using specialized tools, such as commercial solutions like Cellebrite, which allow access to layers of the operating system beyond the reach of the average user.
The key detail noted in those notes is that the recovered messages They did not come from Signal's internal databasebut rather from Apple's push notification system. The test revealed that "the signal was removed, but incoming notifications were retained in internal memory," and that only messages received, not sent.
The case has also taken on a strong political dimension in the United States, presented as an example of action against alleged activities linked to “Antifa.” Beyond the ideological debate, what is relevant for digital privacy is that the procedure evidence of new forensic capabilities on iOS devices that affect anyone using encrypted messaging.
What does iOS actually do with Signal notifications?
To understand why the FBI was able to read those messages, we need to look at a layer beneath the app: How iOS processes and saves push notificationsEach time a new Signal message arrives, the operating system locally decrypts the content on the device to generate the preview we see on the lock screen or in pop-up notifications.
That decrypted content—sender's name and part or all of the message text, depending on the configuration—is stored in a internal notification cache iOS keeps this information separate from the application container. In other words, it's the operating system that stores this information, not Signal. And the exact policies regarding how long it remains there and under what conditions are also in place. are not public.
This produces three effects with clear forensic implications: firstly, the cache can survive app uninstallationbecause it resides in the system's data area. Furthermore, messages configured to self-destruct in Signal can leave traces in those previews for days or weeks. And also, the mechanism only generates logs of incoming messagesbecause the notification is created when the device receives the message.
The trial described cases where messages that had already disappeared from Signal due to disappearing timers were displayed. However, Extracts from those same messages remained accessible by extracting the internal iOS notification database, which confirms that the app fulfilled its function, but the operating system kept a secondary copy.
It is worth highlighting a point that experts repeat time and time again: Signal's end-to-end encryption was not brokenThe interception occurred later, after the message was already in readable text within the device and iOS decided to store it to display it as a notification. This isn't a "backdoor" in the Signal protocol, but rather a typical vulnerability in the system's architecture.
Is it Signal's fault or the iOS settings?
The question many users are asking is whether the problem lies with Signal, Apple, or both. Most analysts agree that the Direct responsibility does not lie with Signal's encryption.but in the combination of the app's notification options and iOS's design decisions when saving that data.
Signal has long offered a specific setting to protect against this vector: in the app's internal settings, you can activate the mode "No name, no preview"With that configuration, notifications no longer include the contact name or message content, so what iOS stores is, in practice, a simple generic alert, without any useful data that can be retrieved later.
This is very different from limiting previews from the iPhone's general settings (Settings > Notifications > Show Previews). That system setting can hide the preview on the lock screen, but does not necessarily prevent the content from having been previously processed and stored through the notification infrastructure.
In the case analyzed in the trial, everything indicates that the person under investigation had full message previews enabled in Signal, allowing iOS to receive and save the entire text of incoming messages. Had the message preview mode been used, the the exposure window would have been much smaller or, directly, non-existent at the level of readable content.
The situation doesn't seem unique to this app either: other messaging platforms like WhatsApp or Telegram offer similar settings regarding what they show in notifications, and it's reasonable to think that They all rely on the same iOS notification system. (see the Security differences between iMessage and TelegramThe underlying problem is not a specific app, but how the operating system manages the convenience of notifications versus privacy.
What information might be at risk and who could access it
In light of what has been revealed, any iPhone user who uses Signal (or similar apps) with previews enabled should assume that part of the content of incoming messages It may have been stored in the system at some point. This includes messages that have already been manually deleted or that expired via disappearance timers.
However, this is not a flaw that allows just anyone to spy on a phone remotely. Exploiting this method requires... physical access to the device and use forensic extraction tools capable of reading those internal databases, something that in practice is in the hands of security forces with a court order or very sophisticated actors with temporary access to the unlocked terminal.
Another sensitive point is that of the iCloud backupsIf your iPhone backs up to Apple's cloud, some notification information may be included in the backups, extending the potential exposure beyond the physical device. In highly sensitive environments, several experts recommend disabling iCloud backups or enabling Apple's Advanced Data Protection to strengthen access.
For high-risk profiles such as investigative journalists, activists, lawyers, whistleblowers, or management teams that share strategic information, this case demonstrates that The real attack surface goes beyond the messaging appThe security of communication also depends on the operating system, backups, and small usability details that we often take for granted.
Even so, this is not a form of massive, silent surveillance in the style of traditional wiretapping. Reports point to a more specific use of commercial forensic tools within a specific criminal investigation, with the device in custody and a court order authorizing its removal.
Impact for users in Spain and Europe
Although the specific example comes from a trial in the United States, the implications directly affect iPhone users in Spain and the rest of Europe. Anyone who uses Signal on a daily basis—whether for work communications, personal contacts, or political coordination— is affected by the way iOS handles notifications.
In the European context, where the General Data Protection Regulation (GDPR) sets a high standard for information protection, this type of operating system behavior reopens the debate about the extent to which data generated by convenience functions (such as message previews) should be considered sensitive personal information subject to greater safeguards.
Law enforcement agencies in various EU countries also use forensic solutions on mobile phones seized in criminal investigations. Although the technical details vary depending on the jurisdiction and provider, the precedent set by the Prairieland case indicates that Internal notification databases are a priority target in this type of analysis.
For European companies, tech startups, or professional firms that rely on Signal to handle confidential matters, this situation forces them to Review internal messaging usage policiesIt is not enough to "use an encrypted app", it is also advisable to define standards for configuring notifications and managing devices to avoid surprises in a hypothetical registration.
It also opens the door to potential questions for regulators and data protection authorities in the EU regarding the Apple's transparency Regarding the retention and processing of notification data, this is an area that is not very visible to the end user but has clear consequences in terms of privacy.
Practical recommendations for securing conversations on iPhone
Based on what has been learned, privacy communities and organizations such as the Electronic Frontier Foundation or specialized forums have disseminated a series of practical guidelines designed to reduce risk without needing to be a cybersecurity expert.
In Signal, the most effective step is to activate the option "No name, no preview" For notifications, the usual procedure is to open the app, go to Settings > Notifications, and choose the most restrictive option under "Display." This prevents the message content from leaving Signal's encrypted environment and reaching the notification system in plain text.
The next step involves coordinate the settings with your contactsTaking extra precautions is pointless if your contacts have full message previews enabled: in that case, the messages you send could be stored in their iPhone's notification cache. It's advisable to agree on a consistent level of protection, at least among those handling sensitive information.
In situations where a device has been held by third parties (for example, a border seizure or detention), some experts recommend assessing a factory reset without restoring from a cloud backupThis operation removes any forensic artifacts that may remain in internal storage, although restoring from a backup could reintroduce them if the backup already contained that data.
Finally, we mustn't forget the most basic layer: a strong passcode On the iPhone, this remains a significant barrier. A four-digit numeric code offers limited resistance against brute-force attacks supported by specialized hardware. Opting for longer or alphanumeric codes substantially complicates these types of access attempts.
In parallel, it can be helpful to review your general iOS notification settings, minimizing on-screen previews and limiting which apps can display content on the lock screen. It's not a complete solution to the problem, but it helps. minimize the amount of exposed data in case of loss, theft or confiscation of the device.
The legal position and the standoff between Apple, Signal and the security forces
From a legal standpoint, the technique used by the FBI in the Prairieland case falls under a classic scenario of forensic extraction with a court order on a confiscated device. No mass remote access mechanism or special collaboration by Signal to weaken its encryption has been described.
The controversy stems more from the realization that commercial forensic tools for iOS are far more advanced than many users realize. The line between what we consider a "deleted message" and what a forensic analyst considers "recoverable data" has become quite thin, and this case has made that abundantly clear.
Neither Apple nor Signal have offered anything yet. detailed explanations about the exact behavior from the notifications database, despite attempts by specialized media outlets to obtain their perspective. This silence, combined with recent changes in notification token management in modern iOS versions, suggests that the issue is being discussed within the company.
This wouldn't be the first time Apple has responded to forensic advancements by strengthening system security. In the past, features like the inactivity reset The evolution of the Secure Enclave has closed off avenues previously exploited by analysis labs and security agencies. It's reasonable to expect that future versions of iOS will adjust how notifications are stored and purged.
In any case, the situation reinforces the idea that the Digital privacy is a layered practiceIt's not a switch that's flipped by installing a single app. Robust encryption is a central piece, but the operating system architecture, backups, notifications, and daily usage habits complete the puzzle.
What this FBI and iOS episode shows is that, although Signal remains one of the most robust options for private messaging, the actual protection of a conversation also depends on how the iPhone is configured, what is allowed to be shown in notifications, and how much it is assumed that a "deleted message" has disappeared forever, when technical reality shows that this is not always the case.

