The problem lies not in encryption or key exchange itself. It’s in the fact that to make/use a solution that doesn’t suck in real life, you need a budget comparable to the entire crime you commit. As a developer, you may [help] create few keys and set up the encrypted scene for sending emails or even insecure chat messages, but your gang will fail even at groceries. All these apps are selling turnkey security in app stores, not something brand new.
can't you just tell your friend a key and exchange it offline and then communicate freely with no middleman
Yes, keywords are pubkey, fingerprint, diffie hellman. It’s easy to use, just run:
openssl genrsa -des3 -out private.pem 2048
to generate a key pair, then export pubkey via:
openssl rsa -in private.pem -outform PEM -pubout -out public.pem
Once you have you exchanged pubkeys and checked fingerprints offline, simply create a new secret key:
openssl rand -base64 32 > key.bin
and encrypt that new key and also your message with it:
openssl rsautl -encrypt -inkey id_rsa.pub.pem -pubin -in key.bin -out key.bin.enc
openssl enc -aes-256-cbc -salt -in message.txt -out message.enc -pass file:./key.bin
Now just send .enc files over the wire. It is trivial to decrypt at their side, even my grandma can do that. She usually leaves raw files in her downloads folder though, but it’s easy to remove them via local crontab job.