Perhaps they could use an encryption program that uses the sanctioned app as the transport layer. Like how people used to use PGP with email.

That might satisfy message-privacy and connectivity, but it seems it'd be vulnerable when it comes to identity-privacy and detection.

I suppose you could use an LLM on each end to write superficially plausible messages and use ~sten~ steganography, although then there's still the problem of "Weird, this user types at 500WPM without sleeping."

> stenography

I think you mean steganography[0]. Stenography is shorthand, used for transcription.

[0] https://en.wikipedia.org/wiki/Steganography

That'll eventually get detected and put a massive target on the back of anybody dumb enough to use it. Sorry to burst your bubble.