The only programs I am aware of that do both all have significant limitations in other areas and none have gone through rigorous peer review.
i2p-bote has mobile and desktop applications, can use possible post quantum secure encryption, it's asynchronous and real time, capable of multi party communication, and has optional delays between hops making it global passive adversary secure. Unfortunately it doesn't work well because many messages don't actually make it through. You can't send files greater than 500kb. Also it is not peer reviewed.
Bitmessage has multiparty communication and is asynchronous but has a terrible user interface, is hard to setup, no mobile application, no attachments, no peer review.
Ricochet works well and is easy to use but no attachments, it can't be asynchronous, no multiparty communication, and no peer review.
Haven't played with pond. It looks promising.
My wish list for the ultimate messenger: easy to use, secure by default, hides content and metadata, is multi party, can share arbitrarily large files, is both instantaneous and asynchronous, can be global passive adversary secure, is quantum computer secure, truly multi platform, and supports being signed in on multiple devices at once.
If we have two devices (say Alice's phone and Bob's phone) that are sending messages to each other, how do we make sure nobody knows who is talking to whom? The answer seems non-trivial to me.
Could we use Alice's and Bob's public keys to encrypt the message and then send them to the entire network, relying on the security of the encryption (and acknowledging that a third part can read all messages any way)? Is there a way to look at a public key and an encrypted message and say that yes, this message was encrypted with this key? It seems that we'd be paying through the nose in terms of throughput capacity (and processing capacity as everyone would have to take in everyone else's packets) if we wanted to maintain metadata privacy this way. I'm sure this is not what you had in mind. Can you please elaborate on how we can secure metadata?
I2p-bote routes the messages through multiple intermediaries with layered encryption so that no intermediary knows both the ultimate sender or ultimate recipient.
Pond works by running servers over tor (a mixnet). When you send a message it doesn't go to the server you have service through it goes directly to the recipients server.
Ricochet sets up your own server on tor that you are hosting.
There is also Pir-Tor. It attempts anonymity by using the secure multiparty communication combined with PIR to attain provable anonymity.
By using traffic obfuscating systems like TOR or Mixmaster.
I also agree with khed. Signal needs to hide metadata.
A very brief perusal of the repo didn't turn up any protocol docs, but seem to have been rather thorough about that sort of thing in the past, so I would suspect that the changes to the TS and RedPhone protocol would be fully documented, so you could integrate it with libpurple or whatever.