Online privacy is on a lot of minds these days. But what’s actually worth worrying about? And how can we help non-technical folks navigate these questions?
Let's start with personal communication. Because...well...it's personal. And every time you text someone, you’re giving the contents of your message—every word—to multiple internet companies, unknown other parties, and potentially the governments of one or more countries.
AI product-design principle #1: Keep the user in the driver’s seat.
Users need a sense of control, and want confidence that your product is working for them rather than calling the shots. Which might seem strange: AI is about automating our lives, taking things out of our hands; keeping the user in the driver’s seat seems to pull in the opposite direction.
This is the first of six posts exploring the AI-centric product-design principles crystallizing as we design and build Tiptap Flex (https://flex.tiptap.dev).
In recent weeks, Apple has taken heavy criticism for its failures around Apple Intelligence. While those missteps might seem like a typical strategic blunder, it could reflect a fundamental challenge with AI products—and a trap companies like Google and Figma have fallen into as well: the AI 80/20.
..and other things that, to be fair, I didn't fully spell out in the article. I suppose I could have said "periodically confuses your friends" because a lot of it has to do with switching phones, switching numbers, having more than one number, etc.—-things that aren't everyday affairs but also aren't that uncommon.
To be fair, when I said "millions of others worldwide" I was making a (pretty safe) assumption. As the default messaging service on every phone, and with literally billions of phones out there, it seems pretty likely that in the entire non-US world there are millions of people using it.
The thing with email is it's only encrypted (even in transit) sometimes. So it kinda has the same issue as iMessage. If you're a Gmail user using Gmail's web app to email another Gmail user, you get encryption in transit (and it sounds like you might be able to implement E2EE as well). But if you email [email protected], you won't know until you send the message whether it's encrypted.
As for envelopes and wax seals--it's an interesting question. It requires a lot less technical knowledge for someone to open that envelope than to spy on messaging traffic. On the other hand, a lot more people have access to the messaging traffic and can bring scripts to bear on it at scale.
To clarify: I'm not suggesting you trust Telegram more than mobile providers--if SMS were encrypted in transit I'd have a much weaker case against it. But the point is, with Telegram you're placing trust in Telegram. With SMS you're placing trust in your mobile provider, AND your friends' mobile providers, AND an unknown collection of other entities. At a minimum, that's a lot more points of weakness, even if each individual one is equally trustworthy.
iMessage is indeed more secure than Telegram. Dunno vs. WhatsApp, but unlike WhatsApp it has a central message archive (and as of a few weeks ago, you can end-to-end encrypt that, too, I think).
It pained me not to be able to recommend iMessage but because it's not supported on Android, Windows, or Linux, you fall back to SMS (for Android) or nothing at all (for Linux/Windows) and then it's far worse than Telegram.
I didn't talk much about Google Chat in the article, but I think it's a fine example of a non-E2EE messenger in the same bucket as Telegram, from a company that tends to demonstrate a better-than-average respect for user data (with the disclosure that I worked there at one point).
If you're using it and liking it, I personally wouldn't recommend switching. I didn't recommend it because at this point I don't trust Google to continue investing in it given multiple incarnations of Hangouts, prior Chat products, Allo, etc.
> Moreover, despite all of the hate, iMessage actually works great.
That hasn't been my experience. Often it does. And then sometimes it doesn't. My sense is that when it doesn't, it's because of the interdependence on SMS.
Yep. As you say, the vast majority of people have no problem with SMS. I wrote the article in the hopes of convincing at least a few more people to have a problem with it.
I take your point. It wasn't intentional in terms of hiding the truth; it was intentional in terms of opening with something strong and not too nuanced. I had hoped getting into the nuance a couple paragraphs later would suffice, but given your comment I've updated the article with a hint of it up front.
And as I argue in the article, it's not essential that ALL your friends switch. Most of us deal with fragmented communication in one form or another (unfortunately). I'm probably 20% email, 40% iMessage / SMS, 30% Telegram, 10% a smattering of other things. It's not ideal but it is reality and, if nothing else, I think starting small is an effective switching strategy.
As far as I can tell, Google Messages defaults to E2EE when possible when RCS is enabled, but RCS is disabled by default. Which basically means 80% of users don't have it turned on.
I fully agree the best outcome here would be a cross-platform, E2EE standard supported as the default across a variety of platforms. (Where iMessage would be a great option if Apple would play ball.) I'm just not holding my breath...and in the absence of that the best I could think to do is explain to whoever would listen why they can take action on their own behalf and that of their community.
Much as I would love an open standard to win here, their track record has not been great with respect to messaging. If someone (looking at you, Google) were to jump on board with one, that could change stuff.
But to be fair, most consumers aren't going to care about an open standard directly; they'll care about finding and chatting with their friends. An open standard is a great way to get there when it works, but, for example, WhatApp being a de facto standard in much of the world accomplishes the same thing in those regions.
Although note that with SMS, you're consenting to multiple phone companies knowing your phone number, name, and definitely other information in the form of all your messages. Possible I should have made that clearer in the original article: it doesn't make sense to me that someone would stick with SMS because they don't want Meta/Google/Apple/whoever to have their info, unless they truly believe that AT&T/T-Mobile/Verizon/etc. are better stewards of our data. (And I don't mean to dunk on that latter group of companies here...I just don't have any reason to believe either group is better than the other.)
(Original author here) I agree with everything you said. SMS is popular for excellent reasons that are hard to overcome at this point. I wrote the article not because I expect it to create a behavioral shift at scale, but for the folks who, if they knew more, might care enough to do something—who agree with me that while sticking with SMS is easier than switching, maybe the benefits of switching are great enough to justify it.
Suppose you had two choices when chatting with your friends. The first will give you a great messaging experience, but you’ll need to sign up for a new app. The second requires no sign-up, but sometimes fails to deliver messages; sends tiny, blurry photos and videos; only works on your phone; confuses all your friends; and offers no privacy whatsoever.
That choice is real. And if you’re like most people in the US (and millions of others worldwide), you choose that second option every day by using SMS.
Let's start with personal communication. Because...well...it's personal. And every time you text someone, you’re giving the contents of your message—every word—to multiple internet companies, unknown other parties, and potentially the governments of one or more countries.