Otherwise they will only see a garbage of letters/numbers.
Otherwise they will only see a garbage of letters/numbers.
I'm ignorant of the process, but is there no way to check that the user has installed SMSSecure first and, if not, fall back to sending unencrypted data? (perhaps that could be toggled via a fail open/closed option)
You can toggle the option to send encrypted sms or not, per contact, so if your contact doesn't support SMSSecure, you just send a regular SMS.
The ability to know who's using SMSSecure is interesting and not currently supported (that I know of)
The detection was actually inherited from TextSecure and works by "tagging" shorter messages with some detectable whitespace after the message contents. A bit of a hack, but it's a limitation of the transport.
Relevant commit: https://github.com/SMSSecure/SMSSecure/commit/93d94f2b7a9fd6...
However, compared to the amount of metadata that's already being leaked over SMS[1], adding the fact that you could[2] be using a specific SMS client that has the ability to encrypt messages doesn't seem too bad.
There was an option in a previous version of TextSecure to disable this tagging, but it was deemed unused and axed[3]. For the same reason, I'm loathe to add it back in, but having the option shoved under the "Advanced" menu may not be too bad.
[1] This is something that TextSecure does much better with. SMS messages (even encrypted) still leak metadata on who you're messaging and when.
[2] There's some element of deniability with whitespace tags (granted, not a lot). On the other hand, if you're registered with TextSecure (which can be checked simply by adding a user your contacts and opening the app), there's only one reason you would be there.
[3] See https://github.com/WhisperSystems/TextSecure/commit/40eca5e0...
> SMSSecure works like any other SMS application. There's nothing to sign up for and no new service your friends need to join.
Made it sound like there's nothing to install. Kind of confusing.