The Difference Between Security and Privacy

When I first started writing security software, I thought encryption was the answer.

If nobody could read the data, the problem was solved.

At least, that's what I believed.

Years spent working in banking gradually taught me otherwise.

Encryption protects content.

Privacy is much broader than that.


Consider an ordinary envelope.

You cannot read the letter inside.

But you can still learn an astonishing amount from the outside.

Who sent it.

Who received it.

When it was posted.

Where it travelled.

How often two people correspond.

Even without opening the envelope, a great deal has already been revealed.

Digital communication is remarkably similar.


During the years I worked on Security Blanket, my focus was protecting information while it travelled.

The contents were encrypted.

The integrity was verified.

Only authorised recipients could decrypt the data.

For banking systems, that was exactly the right solution.

But the world changed.


Communication moved onto smartphones.

Cloud services became normal.

People started carrying computers in their pockets that constantly announced where they were.

Applications became more secure.

Devices became more revealing.

That distinction took me a long time to appreciate.


When people talk about secure messaging, they usually mean encryption.

That's important.

It is not the whole story.

Even if the message itself remains unreadable, questions still remain.

Who is talking?

When?

How often?

From where?

Using which device?

Sometimes those answers reveal almost as much as the message itself.


That was the moment SecurityNet changed.

It stopped being simply another secure communications application.

It became an attempt to minimise unnecessary information wherever possible.

That meant asking different questions.

Do we need cloud storage?

Do we need permanent message archives?

Do we need phone numbers?

Do we need mobile devices at all?

Every feature became a privacy decision.


It is reasonable to ask: Why SecurityNet is desktop-only?

The assumption is that I simply haven't written the mobile version yet.

The reality is rather different.

I deliberately chose not to.

Modern smartphones are extraordinary devices.

They are also extraordinary generators of metadata.

For many people, that trade-off is perfectly acceptable.

For others, it isn't.

SecurityNet was designed for those who wanted another option.


One lesson has stayed with me throughout my career.

Security and privacy are closely related.

They are not the same thing.

Security protects information from unauthorised access.

Privacy limits how much information exists in the first place.

The less information created, the less information there is to steal, analyse or misuse.

That simple idea has shaped every major design decision within SecurityNet.

It continues to shape how I think about software today.