Session does not require a telephone number or email address for account creation. Instead, it utilizes a randomly generated 66-digit alphanumeric number for user identification. Communication between users, including messages, voice clips, photos, and files, is end-to-end encrypted using the Session protocol. Session uses the Loki blockchain network for transmissions. In 2021, an independent review by the third-party Quarkslab verified these claims.2345
Session started as a fork of another messenger, Signal, aiming to build upon its foundation. However, concerns about the centralized structure of Signal Protocol and potential metadata collection led the team to deviate and create their own protocol, called "Session Protocol". This approach prioritized increased anonymity and decentralization. During development, the team encountered various challenges, leading to the necessity of abandoning or modifying many features.67
Session lacks support for two-factor authentication, and its underlying protocols are still in a developmental phase. Following the migration from the Signal Protocol to its internally developed protocol, forward secrecy and deniable authentication were not implemented,8 but according to the developers it is not a security risk.910
Bhattacharjee, Shomik Sen (October 8, 2021). "Session Is a Blockchain-Based Private Messenger That Uses Decentralised Server Nodes To Ensure Anonymity". Gadgets 360. Archived from the original on June 18, 2023. Retrieved June 18, 2023. https://www.gadgets360.com/cryptocurrency/news/session-private-blockchain-messenger-decentralised-nodes-2568208 ↩
Ankush, Das (February 10, 2022). "8 Reasons to Try Session as a Private Messaging App". MakeUseOf. Archived from the original on October 31, 2022. Retrieved December 8, 2022. https://www.makeuseof.com/why-try-session-private-messenger/ ↩
"New WhatsApp Alternative "Session" Works Without Your Phone Number". Fossbytes. March 9, 2020. Archived from the original on May 31, 2023. Retrieved July 31, 2023. https://web.archive.org/web/20230531001331/https://fossbytes.com/open-source-messenger-session-doesnt-even-need-your-phone-number/ ↩
"Session Messenger Review – Best Secure Messaging App?". RestorePrivacy. Archived from the original on October 10, 2021. Retrieved October 11, 2021. https://restoreprivacy.com/secure-encrypted-messaging-apps/session/ ↩
Oxen Session Audit Technical Report (PDF). Quarkslab SAS. 2021. Archived (PDF) from the original on October 23, 2021. Retrieved October 11, 2021. https://blog.quarkslab.com/resources/2021-05-04_audit-of-session-secure-messaging-application/20-08-Oxen-REP-v1.4.pdf ↩
Florence, Eric (January 6, 2022). "Session Messenger Review". SecurityTech. Archived from the original on August 1, 2023. Retrieved August 3, 2023. https://securitytech.org/secure-encrypted-messaging-app/session/ ↩
"The Session Protocol: What's changing — and why - Session Private Messenger". Session. December 16, 2020. Archived from the original on June 4, 2023. Retrieved August 10, 2023. https://getsession.org/session-protocol-explained ↩
Kee Jefferys (December 15, 2020). "Session Protocol: Technical implementation details". Session. https://getsession.org/blog/session-protocol-technical-information ↩