Earlier quoted context omitted.
Given the risk of xyz agency, there seem to be only a couple options to me: - side-load a peer reviewed apk so you can check the sigs and make sure all crypto is being done locally (and to make sure that the implementation is solid) - manage your own keys like you would with traditional pgp emails. Give your public to your friend. Force them to send anything sensitive using it. Maybe change to symmetric keys from asy…
> side-load a peer reviewed apk Signal has open sourced clients with reproducible builds (on Android) and their encryption library has been reviewed by multiple 3rd parties to great acclaim. PGP lacks forward secrecy, meaning if a key does get compromised all of your past correspondence is now also compromised.
Edit: As someone that has heard of forward secrecy but not how it relates to pgp, these were helpful reads: