Why There Is No Cloud Archive

If you use most messaging applications today, there's a good chance your conversations exist somewhere in the cloud.

That has become normal.

It also makes life very convenient.

Buy a new phone, log in, and your conversations reappear.

Use a second device, and everything is already there.

For many people, that's exactly what they want.

When I started designing SecurityNet, I asked myself a different question.

Do I actually need a cloud archive at all?


One of the principles behind SecurityNet was to minimise the amount of information that existed outside the computers of the people involved in the conversation.

The fewer copies that exist, the fewer copies need to be protected.

That sounds obvious.

In practice, it leads to very different design decisions.


SecurityNet doesn't maintain a permanent archive of your messages on my servers.

When you send a file, it moves directly between authorised computers.

When you send a standard chat message, it is transmitted using exactly the same communication model.

Once the message has been delivered and displayed, there is no permanent server-side history waiting to be searched months or years later.

That wasn't an omission.

It was the design.


Of course, removing a cloud archive also removes some conveniences.

You can't simply install SecurityNet on another computer and expect years of conversations to magically appear.

That is a deliberate trade-off.

I believe users should understand that trade-off before deciding which communication tools best suit their own needs.

Convenience and privacy often pull in different directions.

There is nothing wrong with choosing convenience.

I simply chose to optimise for something else.


There is one exception.

Group Chat.

As I explained in the previous article, Group Chat uses temporary encrypted relay storage to support a different communication model.

That difference is clearly documented, the feature is disabled by default, and every participant must explicitly enable it before using it.

I felt it was important to explain where the architecture changes rather than pretending every feature behaves identically.


This article is not really about cloud storage.

It's about copies.

Every additional copy of information becomes another copy that has to be stored, protected and eventually deleted.

Sometimes those copies are necessary.

Sometimes they aren't.

Throughout SecurityNet, I tried to keep asking the same question.

How many copies do I actually need?

The answer, more often than not, was:

Fewer than people expected.