💾 Archived View for ebc.li › rambling › security.gmi captured on 2021-12-05 at 23:47:19. Gemini links have been rewritten to link to archived content
⬅️ Previous capture (2021-11-30)
-=-=-=-=-=-=-
2021-01-07
On many privacy-oriented communities, you'll see people advocating for Signal, a chat service, praising how secure it is, while not seeming to realize it's yet another walled garden with a single central server, and with developers actively discouraging alternative clients AND distribution of their own clients outside the walled gardens of other big tech corporations. (in the name of security)
Both of these are solveable problems, yet Moxie (and most likely the rest of the team at Signal) seem to not care about it, pushing people towards the proprietary silos of Google and Apple by discouraging downloading Signal outside their stores, and locking in the most important part of a chatting application (the people) to themselves, while throwing some code on GitHub every once in a while to be able to call themselves "open".
(Oh also, the Signal APK you get is not completely "open". The Signal team seem perfectly fine with using proprietary libraries.)
. . .
You'll see people advocating for Tutanota, an e-mail service, while not seeming to realize they don't care about mail standards one bit, and have intentionally NOT been supporting IMAP, SMTP, or any kind of communication protocol that isn't what they are using in their own applications, which are just web pages wrapped in platform-specific embedded browsers.
Reddit search on r/tutanota for "smtp"
Most mails sent to/from Tutanota mail accounts will be in clear text, so there is no extra security in this, given they can always snoop on your mails when they're being sent or received. (And in fact, this is what they seem to be doing in response to legal "stuff")
And for the specific encrypted communication they have, how hard would it be to either make a fancy interface to an already existing standard, or create your own standard and share it with the wider world?
. . .
Have we not learned that walled gardens aren't that nice? They are one of the reasons why "Big Tech" is "big" after all. They are one of the reasons why you /(have struggled|are struggling)/ to get your friends and family to switch off of WhatsApp and Gmail. Do we really want a repeat of this all again?
Yesterday, we sacrificed our freedom in exchange for "usability". Now, do we want to sacrifice our freedom for "security" instead? I believe we can have all three (freedom, usability, AND security), but I don't expect it to come from the types of people behind Tutanota, Signal, and many other similar services I don't currently have in mind.
🐺 · CC BY-SA 4.0 · me@ecmelberk.com