Latest apps promising encryption show that security should only be trusted if tested and proven over time
but consumers shouldn't automatically trust the many new encryption apps being offered: https://eff.org/r.taru Christopher Soghoian / @csoghoian : Excellent op-ed on encryption apps by @zenalbatross (h/t @headhntr) http://america.aljazeera.com/ ... http://twitter.com/...
Context & Ripple Effects
This 2015 op-ed lands in the immediate aftermath of the post-Snowden encryption boom, when a wave of newly launched secure-messaging apps competed for users on security claims alone. Christopher Soghoian's push — including his September FTC complaint — was that encryption was becoming a mainstream consumer question faster than any of these products had been tested.
The decade of coverage since validates the caution: Google shipped file-based encryption in Android while still trailing Apple's lock-screen security, Zoom debated offering end-to-end encryption only to paying customers, and by December 2024 US officials were formally telling Americans to rely on encrypted messaging during the Salt Typhoon intrusions. The through-line is exactly what the op-ed argued — trust accrues only after years of scrutiny.
First-order effects
- Consumers picking among unproven encryption apps face a market where marketing outpaces verification, which is why Soghoian and EFF pushed independent testing rather than launch-day assurances.
- App vendors claiming security without audits now risk regulatory attention — Soghoian's FTC complaint set the precedent that exaggerated privacy claims are an enforcement matter, not just a technical critique.
Second-order effects
- Platform incumbents gain an advantage over startup encryption apps because their crypto ships as a default with years of exposure — Google's Android file-based encryption and Apple's lock-screen work compete precisely on accumulated testing, not feature lists.
- Compromise designs like Alex Stamos' argument that Zoom offer end-to-end encryption only to paying customers show vendors pricing authentication and support into trustworthiness, splitting the market between free unverified apps and audited paid tiers.
Third-order effects
- If the pattern holds, consumer encryption consolidates around platforms whose implementations have survived years of attack, while policy fights — like Ray Ozzie's backdoor architecture quest — get judged against whether any implementation has actually been proven safe at scale.
- Official endorsements, such as the government's advice to use encrypted messaging amid the Salt Typhoon hacks, mark the endpoint of the trend the op-ed flagged: encryption shifts from a consumer choice among vendors to public infrastructure whose reliability is established by track record.
The trend: Consumer encryption is maturing from a crowded field of untested apps toward platform-default features whose credibility comes from years of adversarial testing rather than vendor promises.