Why There Are No Phone Numbers
On first installing SecurityNet, one of the things that surprises the most is what isn't there.
It doesn't ask for a phone number.
That wasn't an oversight.
It was a deliberate design decision.
Today, most communication apps begin by asking for your mobile number. Once they have it, they can identify you, find people already in your address book and make it easier to connect with others.
It's convenient.
It also creates a permanent identifier that follows you wherever you go.
When I began designing SecurityNet, I asked myself a simple question.
Why should secure communication depend on a phone number at all?
I wasn't trying to build another messaging application.
I was trying to create a private communication system.
Those are not the same thing.
If two authorised users already know each other, why should they need to exchange mobile numbers before they can exchange encrypted files?
I couldn't find a convincing answer.
Instead, SecurityNet uses its own identity system.
Each installation has its own SecurityNet ID, chosen by the user
You decide what that identity will be.
Only one rule – it must be unique.
Authorisation is a deliberate process.
You decide who you trust.
You decide who can contact you.
No address book is uploaded.
No contacts are automatically discovered.
No attempt is made to tell you who else you might know.
Some people will see that as less convenient.
They're right.
It is.
But convenience has a habit of collecting information.
Once an application knows your phone number, it often knows far more than just a number.
It can become a bridge between your communications, your contacts and your identity.
That may be perfectly acceptable for many people.
I simply chose a different path.
Removing phone numbers also changed the way I thought about trust.
SecurityNet doesn't assume that everybody should be able to discover everybody else.
Relationships are created deliberately.
Not automatically.
That makes the software feel a little different.
I believe that's a good thing.
Now I am thinking about it, I realise this wasn't really an article about phone numbers.
It was an article about identity.
Every system has to decide how people recognise one another.
I wanted SecurityNet to do that without asking users to surrender more personal information than was genuinely necessary.
That philosophy runs through the entire application.
Not because phone numbers are inherently bad.
But because I kept asking the same question throughout the project.
What information do I actually need to make this work?
Sometimes the most important design decision isn't what you include.
It's what you decide you never needed in the first place.