That, for me, makes it a nonstarter.
That, for me, makes it a nonstarter.
I'm a gigantic privacy advocate and probably senselessly cautious about tons of technologies, but that's the result of a conscious choice. Set and forget encryption, or programs that advertise they can skip the first step, are dangerous in my opinion/experience. It can give the wrong impression about security and lead to dangerous decisions/actions or lack thereof.
The concept behind thoughtless encryption is noble, but for all encryption models/schemes I know of, it has to be a concentrated and intentional decision else you end up with:
- Lost data due to key mismanagement (not a bad thing, but extremely inconvenient)
- Incomplete or ineffective encryption
- Vehicles for intentional deception that allow bad actors to get you to share sensitive/personal data under the impression that it's protected
and much much more.
Steve Yegge said it best when he said that Security and Usability are constantly at odds, and from my perspective, this is a good thing to some degree. With so many FUD apps that promise security, for the time being is a very convenient litmus test for laypersons to know "how much should I trust this app?"
I know that it's popular on HN to shit on Telegram, but in my current country of residence, Telegram is the most popular messenger program...for normal non-secretive messaging. It is extremely well known not to trust TG for secret conversations, illegal purchases or any other illegal activities, and so on. Not even on the basis of the security model of secret chats, but the discoverability of them. Basically the thought is "If you could find it without being a member of some ring of trust, so can the police". It's one reason why the conversations that frequently happen on HN about Telegram feel so misguided to me -- those who have conversations that may put themselves at risk __aren't using the app for such conversations__. They're not using any such apps, and either doing disposable communications (burner phones, pen and paper convos, etc), or they're arranging meetings in other ways.
Encryption/security has been commoditized by app and platform creators and packaged into a marketing tool. I wouldn't trust Telegram or Signal any more than I'd trust WhatsApp, Messenger, Messages, or whatever Google's monthly name for their chat app is to have such conversations in most countries.
To wrap it back to the GP's comment, I get the complaint about Apple Notes not being E2E encrypted -- but, if you've got sensitive data that needs to be recorded, why are you cloud-syncing it in the first place with a company that has frequently been investigated/prodded by the US Government, and even more frequently probed/violated by data exfiltration companies that work directly with the aforementioned government?
I'm very conscious of this now when I'm talking on the phone. Not that I really have anything to hide, but I'm always wondering how something would be perceived by someone who is listening in.
It's not a nice feeling at all. This is one of the reasons I hate mass-surveillance so much. Just that feeling that everything I do or say is on the record.
Sure, we're normal citizens with "nothing to hide" - but I've become wary of any possible channel of data collection, regardless of whether the end consumers are private parties or state agencies.
It's dystopian, that I'm having to consciously censor my speech in case anyone is listening. Same with HN - I doubt my comments are of any value to outsiders, but it's possible that someone will associate my real-life identity with this online account, and dig through (i.e., put the data through some extractive process) to assign various values, for unknown consumers - probably advertisers, but maybe even some "good citizen index".
Thankfully I live in the EU (oops, another data point leaked), where there's at least some level of privacy protected by law.
Sometimes I send a postcard where anybody that handles the card can read the message. If I want a little more privacy, I'll send the note in an envelope.
Unless you have a really short memory, I think you mean POTUS 39→45.
And while by a lot of measures POTUS 45 has been a disaster, POTUS 44 did far more damage to privacy than 45 has (yet).
So singling out Trump isn't really relevant or even useful.
"NSA offering 'billions' for Skype eavesdrop solution" (2009) — https://www.theregister.com/2009/02/12/nsa_offers_billions_f...
"Microsoft Buys Skype for $8.5 Billion. Why, Exactly?" (2011) — https://www.wired.com/2011/05/microsoft-buys-skype-2/
For the last part: Standard Notes, Joplin, jrnl, FS Notes (possibly), nvAlt (not actively developed) etc.
This means that Apple has the ability to decrypt them at all times without your knowledge or involvement, and can and does so via the PRISM program for US military intelligence to access the plaintext data, the same as they do for the CCP in iCloud users in China.
End to end encryption is not the same thing as transit encryption.
For the record: PRISM is not "sniffing" or any other type of bulk surveillance program that would be thwarted by TLS. It's an API/app-driven program, run by and within large tech companies, that permits the US military intelligence organizations to pull the decrypted contents of the account of anyone on the service, directly from the storage systems of those tech companies. The majority of the data that the IC processes is the result of PRISM. I encourage you to read Bart Gellman's book Dark Mirror for more information and specifics.
When I'm backing up to an Apple server, I think of the two ends in the end-to-end encryption scheme as my computer and Apple's computer.
When done properly, the places the data sits/transits in-between have no ability to read or decrypt the information; it's indistinguishable from random data to those intermediate storage/relay services or nodes, because they never have access to the keys to decrypt it.