The Surveillance Architect Running Signal Engineering

Signal just rolled out centralized backups, and the guy who announced it has quite the resume. Jim O'Leary, Signal's VP of Engineering since 2019, spent the previous eight years building surveillance infrastructure at Twitter and Facebook.

The Surveillance Architect Running Signal Engineering

At Twitter from 2011-2015, O'Leary built behavioral anomaly detection systems—essentially surveillance to track and flag "unusual" user activity. Perfect timing for the Arab Spring when governments desperately needed to track protesters. Then he went straight to Facebook during their worst privacy scandals from 2015-2019, managing security teams with multimillion-dollar budgets and running their "Privacy IMOCs"—the damage control teams that handled Cambridge Analytica, the Onavo VPN spying operation that Apple banned, and the $5 billion FTC fine.

"One of the first things that happened when I was confirmed as CIA director was Signal was loaded onto my computer at the CIA as it is for most CIA officers."

- CIA Director Ratcliffe, 2025, During Senate testimony - https://abcnews.go.com/Business/what-is-signal-messaging-encryption/story?id=120129513

This is the same guy who helped Facebook eliminate competition by absorbing WhatsApp and Instagram into their surveillance machine. When Facebook bought WhatsApp for $19 billion, O'Leary was there ensuring they could properly surveil those 2 billion new users. He literally managed the fake privacy tool Onavo VPN that secretly spied on teenagers to track competing apps.

Now he's implementing Signal's new backup system that stores your entire message history on their servers, protected by a single key you're supposed to write down somewhere. No local backup option. Just centralized storage with paid tiers creating financial records through payment processors.
Signal knew their desktop encryption keys were stored in plaintext for six years and only fixed it after public outrage.

Commercial forensics tools routinely decrypt Signal databases from seized devices. Yet instead of fixing these fundamental security issues, they're building centralized repositories of user communications under the guidance of Facebook's former surveillance architect.

The revolving door between surveillance capitalism and "privacy" organizations couldn't be more obvious.

Sources:

Here are the sources supporting the video's claims:

Jim O'Leary's Background:

  • Jim O'Leary - VP of Engineering at Signal | The Org - https://theorg.com/org/signal-org/org-chart/jim-oleary
  • Industry perspective: How Signal built private messaging - https://transcend.io/blog/industry-perspective-signal/

Signal Desktop Plaintext Key Vulnerability:

  • Signal Desktop Leaves Message Decryption Key in Plain Sight - https://www.bleepingcomputer.com/news/security/signal-desktop-leaves-message-decryption-key-in-plain-sight/
  • Signal downplays encryption key flaw, fixes it after X drama - https://www.bleepingcomputer.com/news/security/signal-downplays-encryption-key-flaw-fixes-it-after-x-drama/
  • Signal Enhances Desktop Client Security After Six-Year Delay - https://www.blackhatethicalhacking.com/news/signal-enhances-desktop-client-security-after-six-year-delay-on-encryption-key-issue/

Facebook Onavo VPN Scandal:

  • Facebook pays teens to install VPN that spies on them - https://techcrunch.com/2019/01/29/facebook-project-atlas/
  • Facebook will shut down its spyware VPN app Onavo - https://techcrunch.com/2019/02/21/facebook-removes-onavo/
  • Onavo - Wikipedia - https://en.wikipedia.org/wiki/Onavo
  • Apple bans Facebook's Research app that paid users for data - https://techcrunch.com/2019/01/30/apple-bans-facebook-vpn/

Cambridge Analytica Timeline:

  • Facebook–Cambridge Analytica data scandal - Wikipedia - https://en.wikipedia.org/wiki/Facebook–Cambridge_Analytica_data_scandal
  • Facebook-Cambridge Analytica: A timeline of the data hijacking scandal - https://www.cnbc.com/2018/04/10/facebook-cambridge-analytica-a-timeline-of-the-data-hijacking-scandal.html
  • Cambridge Analytica - Wikipedia - https://en.wikipedia.org/wiki/Cambridge_Analytica

Cellebrite Signal Extraction:

  • Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer - https://signal.org/blog/cellebrite-vulnerabilities/
  • Helping Law Enforcement Lawfully Access The Signal App - https://cellebrite.com/en/cellebrites-new-solution-for-decrypting-the-signal-app/
  • Cellebrite UFED - Wikipedia - https://en.wikipedia.org/wiki/Cellebrite_UFED

Natalie Edwards WhatsApp Case:

  • Natalie Edwards Sentenced For Giving Fincen Documents To BuzzFeed News - https://www.buzzfeednews.com/article/davidmack/fincen-natalie-mayflower-sours-edwards-sentencing
  • FinCEN Files source sentenced to six months in prison - https://www.icij.org/investigations/fincen-files/fincen-files-source-sentenced-to-six-months-in-prison/
  • Former Senior FinCEN Employee Sentenced To Six Months In Prison - https://www.justice.gov/usao-sdny/pr/former-senior-fincen-employee-sentenced-six-months-prison-unlawfully-disclosing

Signal Payment Methods:

  • Donate to Signal Private Messenger - https://signal.org/donate/
  • Signal encrypted messenger now accepts donations in Bitcoin - https://cointelegraph.com/news/signal-encrypted-messenger-enables-donations-in-bitcoin
  • Privacy Chat App Signal Now Takes Donations in Bitcoin, Other Crypto - https://decrypt.co/61473/signal-bitcoin-crypto-donations

Signal New Backup Announcement:

  • Signal adds secure cloud backups to save and restore chats - https://www.bleepingcomputer.com/news/security/signal-adds-secure-cloud-backups-to-save-and-restore-chats/
  • Introducing Signal Secure Backups - https://signal.org/blog/introducing-secure-backups/
  • Signal Introduces Encrypted Chat Backup with Paid Media Storage Option - https://reclaimthenet.org/signal-introduces-encrypted-chat-backup-with-paid-media-storage-option
Coins by Cryptorank