I can't even get my close friends/family to install something as simple as textsecure. :(
I can't even get my close friends/family to install something as simple as textsecure. :(
The thought is that when everyone is just seeking out the cheapest data deal, not only does is unbundle and disempower the giant telcos (a good thing), but it also gets users and developers in the mindset of a single data tier. This is where real security and privacy gains can be had.
For example, I've gotten some friends using textsecure, but they've ditched it after being confused why turning off their data prevented them from getting timely sms messages. (Encrypted text messages are silently routed through data when conversation partner has textsecure, even though the identifier seems to be a regular phone number to the user, just like with SMS messages.)
When users start using all-data plans, tools will be developed to help users go into a conservation mode akin to turning off data, just as they do now. Instead of turning off data, users will be able to use a simple firewall to block everything but voip/text messaging apps.
As an added bonus, any trend toward making data-only more convenient will also mean that using wifi-only devices and mobile hotspots will be equally convenient. Those who want the manual baseband separation of that setup (unavailable on current full-featured phones with radios), will not have to jump through crazy hoops to get it, and so security will take a big leap forward :)
/rant
[1]: http://hushed.com/
Of course there are alternate ways to allow users to do this--Google circles and Facebook lists come to mind--but they all are a pain to maintain, use.
Both perform dramatically better than data in poor reception, and save power.
They might be scared into paying someone money to make the problem go away, like personal firewall and anti-virus (which as we know makes real applications break more than they block malware from working), or they'll do something therapeutic but useless, like some people used to run defrag every day.
I'm not sure exactly what will happen in the future, and besides ever bigger and more disruptive hacks, I'm sure we'll carry on somehow with sillier and sillier measures, adding layers to the ones that already don't really make sense if you think too hard. People always manage somehow.
As much as I hate this term now a days, some way to gameify the idea of using encryption might help spur people's use of the technology. Once enough people have adopted a specific app or software then it's much easier to bring outsiders onboard.
Right now things like PGP are difficult for even "experienced" users to setup and maintain, let alone the average joe. Setting up encrypted volumes, or directories, etc... it just goes over most people's heads and/or their willingness/amount of effort, so they just don't do it.
I think switching from "you should consider encrypting things" to an "everything is encrypted by default" society, propelled forwards by software that makes it easy, automatic, and default... that's when we will make progress.
I think also for that reason it is that our front doors are easy to open by a locksmith without the need of destroying them completely.
Better option than passwords is keys anyway. Way too many services depend on human memorizable numbers, which we know all too well is a transient thing at best - every year, as computational power rises, the "average" password gets weaker, and nobody uses good passwords.
People just need a personal key to encrypt and decrypt with. They need to protect that key, maybe by password, maybe by printing it out. One good key can easily replace all the horrible password schemes in the world.
But software needs to be written, especially save dialogs, to easily "pick" a key to encrypt with, and when you open files a history of keys used and a browser to open keys to decrypt opened files with.
Of course Windows will never have anything like that, but at least Dolphin and Nautilus can look to adopt those kinds of workflows.
They all just use Snapchat or the built in SMS application.
To the point where friends have been talking to friends on the technical merits of them, and some have chosen to use Telegram, which is… um, not of the same quality of design as TextSecure, I'll say politely. But it's not owned by Facebook, and apparently that counts for a lot because people really do distrust Facebook that much. (Despite saying that on Facebook, I gather. Irony.)
I have the feeling TextSecure/Signal is frustratingly close to perfect. If it gained the ability to do voice and video well, gained a good desktop client (a slim one, without ads!), and could use usernames instead of/as well as phone numbers, it'd be poised to replace most of the common uses of Skype.
Add metadata protection in some form (onion/garlic routing?) and a distributed network (Tox used DHT) and we'd really be onto something. Although metadata protection is a particularly hard set of problems, especially when you want essentially real-time communication and low battery life. Still, we're in interesting times, and we have tools to make a whole new set of interesting design tradeoffs!
IM services in general seem to be going away. really saddening imo.
Support for multiple active endpoints isn't solved, at least for the clients I use, so I have to hope that whoever writes me picks the endpoint I'm actually at or I have to go through a bit of unencrypted back and forth to make them connect to the right one (I think XMPP actually has extensions for mechanisms that could solve this, syncing messages between endpoints, but I've never seen them implemented).
At least some mobile clients only maintain the OTR session while in foreground, leading to massive notification spam on the other end/delays while the session is recreated.
No encrypted offline messages. (Yes, I know, not possible while maintaining the full guarantees of OTR, but it adds complications to the workflow)
All these don't really make for great UX, and many people are not willing to put up with it.
Which users do you speak to?
I have lots of friends who are not technology-minded and zero of them care that WhatsApp is owned by Facebook. Heck most of them don't even know. It doesn't have the FB logo anywhere. I think this is a non-issue.
What's more, my experience has been that most of my friends (on the rare rare occasions when it comes up) trust WhatsApp a lot more than most tech products, because it doesn't have any ads and asks them for money occasionally. Though lots of us don't actually seem to get charged. I keep being given free extensions.
WhatsApp has huge network effects at this point, it's the de-facto standard outside of the USA. So implementing the TextSecure protocol is a huge deal. Not only does it directly help lots of people but it sets a precedent that PFS is not only for nerds and geek products but can be integrated into consumer products too. It raises the bar for everyone else.
Everyone I know who was aware WhatsApp was Facebook-owned brought it up as a strong, overriding negative; others who heard that followed suit.
Perhaps that says more about Facebook's perception amongst that demographic than WhatsApp. (The plural of anecdotes is not data, I hasten to add.)
If there's a lesson from this, perhaps it's: something new and better needs to come from, if not trusted people, then at least not mistrusted people.
I just wrote him to ask if he's blogged about this. Send me a message (in profile) if you'd like more info about this approach.
Unfortunately, it takes at least a little buy-in from the user to make encryption work. We need better tools, for sure, but that final piece of holding the key needs to be taught and the responsibility accepted.