Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why aren't politicians and their staff using end-to-end encrypted VOIP?


The same reason you aren't. The same reason PGP has been around for 25 years and only a miniscule fraction of people ever encrypt their email.

I.e., it's because none of this privacy technology is built-in as the default into our communications infrastructure. Therefore, for the average person (and even for privacy-conscious techies), it is inconvenient and difficult, and you have to convince the party you're talking with to also install and configure something that is inconvenient and difficult for them.

I'm convinced that the question of why end-to-end crypto isn't the default is a political one; i.e., there is pressure not to do it.


There's a big discussion about PGP here and why so many fail to use it: https://news.ycombinator.com/item?id=13114538

Some of the comments are worth reading if not for the sheer size of the discussion. It could take an afternoon or two to fully digest that thread.

The comments are in response to this: https://blog.filippo.io/giving-up-on-long-term-pgp/


Shifting people onto E2E encrypted VOIP as we move off analog phone lines would be far easier than moving peoples existing email to PGP. Much like how it was pretty seemless for WhatsApp to turn it on.

Email is a special case because of the various semantics like searching and federated clients.


It's really not that hard. Mumble works quite well in TCP mode, via Tor onion service. That gives you end-to-end encryption plus some anonymity. Except for the voiceprint issue, anyway. And you get cellular-level sound quality. Latency isn't problematic if you run in press-to-transmit mode.


Mumble is not end to end encryption, at least if the setup isnt one of a party of two running a server.


It's easy to run your own server in Whonix. Friends can run clients in Whonix.


Politicians and their staff should not be ignorant; they ought be very acutely aware of the risks and that they are a target, and ought be highly motivated to fix this for themselves by securing their own systems.


They often are definitely doing so, at least for sensitive calls. Did I miss something in the article indicating otherwise?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: