Privacy Isn't About Hiding
When I was working with ING Bank in Amsterdam, I noticed something that seemed very different from life in the UK.
Many houses and apartments had no curtains.
Walking through residential streets in the evening, you could often see directly into people's living rooms.
At first I found it rather surprising.
Eventually someone explained that many Dutch people simply felt they had nothing to hide.
Whether that explanation represented everyone or not, it made me think.
Privacy isn't a fixed idea.
Different societies - and different people - think about it in different ways.
That memory stayed with me.
Over the years I often heard a familiar argument:
"If you have nothing to hide, you have nothing to fear."
The more I thought about it, the more I realised the phrase misses the point entirely.
Privacy isn't about hiding. It's about choosing what we reveal.
Most of us close the bathroom door.
Most of us have curtains.
Most of us don't publish every conversation we have with our family, our doctor or our solicitor.
Not because we're hiding wrongdoing.
Because privacy is a perfectly normal part of everyday life.
Digital privacy is no different.
When people talk about privacy software, the conversation usually begins with encryption.
Encryption is essential.
But encryption only protects one thing.
The contents.
It doesn't prevent information being collected about the communication itself.
Who contacted whom.
When.
How often.
From where.
Using which device.
Sometimes those details reveal almost as much as the conversation itself.
Over the years I gradually realised something that changed the way I thought about software.
Applications became more secure.
Devices became more revealing.
That single observation changed the direction of SecurityNet.
The challenge was no longer simply protecting messages.
It was reducing unnecessary information wherever possible.
That doesn't mean everyone should make the same choices.
Many people are perfectly comfortable storing photographs in the cloud.
Others aren't.
Many people are happy to link every service to their mobile phone.
Others would rather not.
Neither approach is inherently right or wrong.
People simply have different privacy requirements.
That's one of the reasons SecurityNet looks different from many modern communication platforms.
Some of the decisions probably appear unusual.
- No cloud storage.
- No permanent message archive.
- No phone numbers.
- Desktop rather than mobile.
Those weren't technical limitations.
They were deliberate privacy decisions.
A natural question to ask is whether SecurityNet is more secure than other applications.
I think that's the wrong question.
Many modern applications use excellent encryption.
The better question is:
How much information exists before the encryption even begins?
That question has shaped almost every design decision I've made over the last twenty years.
Today I no longer think of privacy as the ability to hide information.
I think of it as the ability to choose what I reveal.
To me, that's the difference.
And that's the principle on which SecurityNet was built.