Cryptographic communication tools have a network effect (just like any other communication system), so it's kinda pointless if only the few high-profile activists use it. Also, that would make them stick out, thus reducing their security in some ways. If you can detect the important people by the communications protocol that they are using, you already have the most important part of the information without any need to decrypt anything. Them being buried among bad cryptoraphy most likely won't work - making cryptography indistinguishable is one of the hard parts, so it's one of the properties that bad tools are unlikely to have.
Also, a part of the social/political problem is that people tend to not know that the crypto they are using is bad, and political activists tend to not necessarily be cryptography experts either, so how would they know that they are in danger when everyone around them tells them that the broken crypto they are using is the thing to use?
Your first paragraph seems to be more or less agreeing with what I said - maybe I misunderstand.
Also, a part of the social/political problem is that
people tend to not know that the crypto they are using is
bad, and political activists tend to not necessarily be
cryptography experts either, so how would they know that
they are in danger when everyone around them tells them
that the broken crypto they are using is the thing to use?
But there is always going to be a problem with telling people "use our software and you can organise the overthrow of your government without fear". There is no way around the fact that people who are doing that need to understand the risks better than most people do.
I at least did not intend to agree ;-) - my point is that cryptographic communication tools are kindof useless for activists unless they are used by a large number of people in general, both because otherwise they are isolated and can not actually communicate with anyone using the system (except for a few other activists), and because using the tool would make them stick out, which is why they are also indirectly somewhat useless for the general public, because part of the function of a secure cryptographic communication tool is to give the general public the benefits of the activism by making the general public help in hiding the activists. So, I guess my point kindof is that "crypto for <x>" doesn't actually work because using it marks you as <x> - secure crypto has to be used by everybody in order to provide protection to those who need it the most.
As for the fact that people who do risky things need to be a bit more cautious anyway: Well, yes, but that does not mean that they would not benefit if everyone knew which crypto tools are secure and how to use them, and in contrast to most of physical security, there really is not that much need to distinguish between "professional" and "end customer" tools - proofing your vault against bombs might be a bit more expensive than proofing it against a burglar, but secure cryptography does not need more expensive computers or anything like that.
Comments
Cryptographic communication tools have a network effect (just like any other communication system), so it's kinda pointless if only the few high-profile activists use it. Also, that would make them stick out, thus reducing their security in some ways. If you can detect the important people by the communications protocol that they are using, you already have the most important part of the information without any need to decrypt anything. Them being buried among bad cryptoraphy most likely won't work - making cryptography indistinguishable is one of the hard parts, so it's one of the properties that bad tools are unlikely to have.
Also, a part of the social/political problem is that people tend to not know that the crypto they are using is bad, and political activists tend to not necessarily be cryptography experts either, so how would they know that they are in danger when everyone around them tells them that the broken crypto they are using is the thing to use?
Your first paragraph seems to be more or less agreeing with what I said - maybe I misunderstand.
But there is always going to be a problem with telling people "use our software and you can organise the overthrow of your government without fear". There is no way around the fact that people who are doing that need to understand the risks better than most people do.
(How are you supposed to blockquote text on HN?)
I at least did not intend to agree ;-) - my point is that cryptographic communication tools are kindof useless for activists unless they are used by a large number of people in general, both because otherwise they are isolated and can not actually communicate with anyone using the system (except for a few other activists), and because using the tool would make them stick out, which is why they are also indirectly somewhat useless for the general public, because part of the function of a secure cryptographic communication tool is to give the general public the benefits of the activism by making the general public help in hiding the activists. So, I guess my point kindof is that "crypto for <x>" doesn't actually work because using it marks you as <x> - secure crypto has to be used by everybody in order to provide protection to those who need it the most.
As for the fact that people who do risky things need to be a bit more cautious anyway: Well, yes, but that does not mean that they would not benefit if everyone knew which crypto tools are secure and how to use them, and in contrast to most of physical security, there really is not that much need to distinguish between "professional" and "end customer" tools - proofing your vault against bombs might be a bit more expensive than proofing it against a burglar, but secure cryptography does not need more expensive computers or anything like that.
And also no clue how you to quote here ... ;)