Reason for the fork: https://whispersystems.org/blog/goodbye-encrypted-sms/
Reason for the fork: https://whispersystems.org/blog/goodbye-encrypted-sms/
Signal (as it will be) can't deliver encryption via SMS on iOS due to platform restrictions. Neither can tablets or computers normally send SMS messages. (To say nothing of metadata risks, although TextSecure cannot address that without a decoupling layer, like Tor, and in any case low-latency low-bandwidth mixnet messaging is very hard versus nation-state adversaries with traffic correlation abilities.)
It's also clear that voice and video can't be delivered well or at all by SMS/MMS, and that MMS in particular is a huge pain in the arse.
However, users who have limited/no data plans are up in arms. Whole bunch of 1-star reviews. Clearly quite a few vocal users (not necessarily users in regions you might expect) liked this feature, used it, seemingly needed it. I know that sometimes when travelling even I'm out of data service, but within SMS service.
So it may be that a fork does make semantic sense here. Signal will eventually deliver cross-platform best-in-class secure messaging, group messaging, voice/video/etc - features which cannot be delivered by SMS - and SMSSecure could deliver encrypted SMS messages for users on the Android platform (only).
>> [whispersystems] Can we remove the SMS feature completely?
>> Since the secure SMS option is removed. To reduce the confusion, can we remove insecure SMS option too?
> <insert thread of disagreements>
> Re: [whispersystems] Can we remove the SMS feature completely?
> Everyone can rest assured, we have no plans to do this. I'm pretty committed to an integrated messenger.
> - moxie
(For some reason this Apr 1 message is not in the mailinglist archives. Not sure what's up with that.)
It's one thing to send an email, another thing to send a text, and another thing to use some proprietary messaging protocol, even if all three can be initiated by poking at the same device in slightly different ways, and I want to know which one I'm using so I can pick the right one for the situation.
Indeed, The Pynchon Gate[1] paper indicates that intersection attacks can break any mixnet, to include high-latency mixnet.
The authors' solution is high-latency, high-bandwidth private information retrieval. Sadly, I can't see a way to make this work efficiently with mobile devices.
[1] http://freehaven.net/anonbib/cache/sassaman:wpes2005.pdf
TextSecure is android-only, so I fail to see how this is an issue. Also, (please, correct me if I'm wrong), they also require that you have an SMS-capable line to use it, so I fail to see how that limitation would matter.