* I urge nobody to trust a protest tool that is closed. Where is the source? Where is the documentation on its architecture? The official line is:
"It has always been our plan to make the code open source. Security is paramount and we feel it would benefit from being released to the public after each protest."
I'm sorry but retrospective release of source code is simply not good enough. Security software (which this is, essentially) needs to be out in the open from the start. Not after a protest has happened and all data collected. The wider community must be able to audit this software before it can be trusted. No exceptions.
* If the security depends on secrecy before a protest, is it dependant on a random seed? Can this seed be extracted from a binary (IPA, for example)?
* Sukey has one of the worst pages on "security" I have ever read (see http://sukey.org/security). To paraphrase:
"The team members involved on the security side are a mix of commercial information security experts and computer nerd under/post graduates who love nothing better than a complex algorithm."
That scares me. Complex algorithms are not normally conducive to secure applications. I want to hear about cryptographers - not computer nerds. I want to know what crypto implementations you are using.
Continuing:
"One of our key team members has technical commercial data security patents in his name and has provided information security consultancy to IBM, Lockheed Martin, and to the NHS."
Let's have a citation then please. Who is this expert and what (where?) are the granted patents?
"Your data is safe with Sukey."
Okay, prove it.
* How can we prove the application distributed on the App Store matches that which we (hopefully, in future) have the source for? Is there a mechanism for which we could compare checksums - if the provisioning certificates were also published? This needs to be considered. There is more to trust than merely publishing a source tree.
Let me finally restate my original point: I commend the effort (and I was once involved in a similar application). However, these are serious concerns that need to be addressed.