Every Feature Has a Privacy Cost

People often assume that adding features is always a sign of progress.

The more features a product has, the better it must be.

As a software developer, I've learned that isn't always true.

Every new feature changes a system.

Sometimes it makes the software easier to use.

Sometimes it makes it more powerful.

But every feature also asks for something in return.

It may require collecting more information, storing more information, trusting another service, or changing the way people interact with the software.

In privacy-focused software, those costs matter.

So whenever somebody suggested a new feature, my first question wasn't:

"Can I build it?"

It was:

"What will this cost?"

Not in time.

Not in money.

In privacy.


One feature taught me that lesson more clearly than any other.

Group Chat.

On the surface it sounds like an obvious addition.

People work together. Teams need to collaborate. Real-time conversations are useful.

I agreed with all of that.

The difficulty wasn't whether Group Chat was a good idea.

The difficulty was that it couldn't honestly be implemented in exactly the same way as SecurityNet's direct one-to-one communication.

It required a different communication model.

That meant it also had different privacy characteristics.


At that point I had a choice.

I could hide those differences and make Group Chat behave like every other feature.

Or I could explain them.

I chose the second option.

Group Chat is disabled by default.

Every user must deliberately enable it in their own password-protected settings before it even becomes available.

Joining a group does not automatically enable Group Chat.

Being invited to a group does not automatically enable Group Chat.

Every participant makes that decision individually.

Only then does the feature appear.


That wasn't done to make the software more complicated.

It was done because enabling Group Chat changes the communication model.

Whenever software changes the privacy assumptions, I believe users should know that.

More importantly, I believe they should choose.

The documentation explains exactly how Group Chat differs from SecurityNet's standard person-to-person communication.

Nothing is hidden.

Nothing is implied.

The trade-off is visible.


Some people might see that as unnecessary.

I see it differently.

Privacy isn't achieved by pretending every feature is identical.

Privacy is achieved by being honest about the differences.

Sometimes the right answer isn't to reject a feature.

Sometimes the right answer is simply to explain it.


This idea influenced far more than Group Chat.

It became part of the way I approached every design decision.

I wasn't trying to build software with the longest feature list.

I was trying to build software where users understood what each feature did, what it changed, and could decide for themselves whether they wanted to use it.

To me, that is what privacy-by-design really means.

Not removing choice.

Providing informed choice.


When should software ask the user to stop and think?

The most honest privacy software isn't the software with the fewest compromises. It's the software that explains its compromises and lets the user decide.


Next: One practical example of that philosophy—why SecurityNet doesn't ask for your phone number.