Recent years have clearly shown us that our rights as free citizens are being circumvented and often even unceremoniously trampled on in the name of the "security" so beloved by all those in power (the quotation marks are intentional).
Heads of developed countries dream of having the means to eavesdrop on every citizen in real time and spend a lot of taxpayer money to do so - in many cases without much opposition, because it's all in the name of "public security". The Prime Minister of Great Britain even went so far as to talk quite unceremoniously about his plans to introduce legislation that would make illegal all forms of communication that cannot be eavesdropped on by his wards. And if this statement sounds more like a totalitarian leader than a dystopian novel, the truth is that more and more governments are using the mantra of "protection from terrorism" to take away more and more freedoms from the individual. Just in case.
“Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety.” -- B. Franklin
However, it is clear to any sober-minded person that such preventive measures cannot prevent crimes. On the contrary, they concentrate even more power in the hands of the repressive apparatuses of totalitarian states, as well as security agencies of legal (on paper) states and help to commit other crimes and repress more and more people. Even in civilized societies we are witnessing corruption at all levels, so whether the information obtained in this way is abused is a question that has long had its unambiguous answer. What would happen if the eavesdroppers were given even more powers also needs no comment.
Protecting our right to privacy of personal correspondence is in the hands of each of us, and now, more than ever, it is important for a person to be aware of the dangers they face.
In the following paragraphs, I will illustrate the weaknesses of the communication channels many people use today and provide easily implementable protection options that require almost no effort on the part of the user; regardless of their level of technical knowledge.
Why is eavesdropping so easy?
The main thing that everyone should be aware of is that any message that is not sent using explicit techniques to hide the content and its accompanying information is extremely easy to intercept and read by all participants in the chain. Namely - from people with access to the sending device (phone, tablet, computer), through connection service providers (telecom, network operators, employer) and communication service providers (e-mail provider, Facebook, etc.) to government agencies that - justified or not - eavesdrop on it. This is the case with too many communication channels today.
Encryption, in turn, provides protection for communication from eavesdropping and tracking by changing the content of the message so that, even if intercepted, it becomes unintelligible to anyone except the recipient, who has the mechanism to decrypt it. Most channels for exchanging information have two weak points in relation to eavesdropping -- a. the path of messages as they are sent from one user to another and b. their storage in different locations during their delivery and after their receipt.
The good news is that many of the widely used service providers and technology companies are starting to realize the importance of the privacy of correspondence and are investing resources in protecting the first mentioned link - the transfer of information, i.e. the path from point A to point B. Just as it is completely normal for a user to expect a secure (encrypted) connection when accessing their bank account online or when making a purchase from an online store, more and more providers are now trying to offer the same level of security when exchanging messages of a personal nature (email, chat, etc.). Then, even if intercepted during transfer, the information sent is in most cases unreadable.
However, the issue of information storage is another. When a message is sent by a user, it passes through multiple servers and is temporarily or long-term stored on them - for example, while waiting to be delivered. When it arrives at its recipient, it is in many cases actively stored again by the recipient himself - in the email archive, or on any other service (chat, Skype, Viber). Often this happens in unencrypted form on the provider's servers. Each technology company takes care to create copies of the data from its servers to protect against technical malfunctions, disasters, and so on, so it may turn out that a message is cloned in dozens of places around the world, even though it was sent by a user meters from the recipient. All this data can also be requested at any time, legally or not, by investigative authorities.
When is our communication reliably protected?
The only option for complete protection is the so-called end-to-end encryption. In this case, the message (regardless of its format - text, images, audio, video) is encrypted on the sender's device, with an encryption key that does not leave this device (i.e., it is not stored on someone's server and therefore does not have the physical possibility of being intercepted by third parties) and is decrypted on the recipient's device again with a key that also does not leave it.
What can each of us do to protect our correspondence?
Here I will focus on three of the most popular communication channels - phone, chat and email - and some of the most common technologies and products, and the possibilities for using end-to-end encryption in each of them. The list does not claim to be exhaustive, but it is a sufficient basis for changing communication habits.
In e-mail communication, it is perhaps the most difficult to provide the ability to encrypt messages from the point of view of ease of use. Most people use free web-based e-mail services (G-mail, Yahoo Mail, Outlook.com, ABV.bg and the like), which do not offer this, and even if they do, encryption of e-mails requires the sender to have a publicly provided key to the recipient. No matter how much a provider makes it easier for the user, encryption in this form is a difficulty for a large part of e-mail users and it would be naive to think that this will change soon. Providers offer good solutions in this direction for business customers, but they seem to be in no hurry to do so for private users. One of the reasons is that services that are based on the content of e-mails (targeted advertising, translation, automatic reminders and so on) could not function if the content of the message was not automatically readable by the system.
What can be done in view of the above:
- Do not use e-mail to send sensitive information unless the entire message or at least the information in the form of attachments is encrypted (for example, with an archiving program). You would not want the administrators of the postal service or bored office workers to find out the results of medical tests, for example.
- Do not use email from providers that cannot guarantee a basic level of privacy of correspondence. Consider transferring your personal email to a provider that prioritizes the right to privacy of its customers over advertising revenue. Examples of such companies are Tutanota and ProtonMail, which specialize in providing encrypted email services. Tutanota also has mobile applications for Android and Apple that are not inferior to the popular others.
- In Bulgaria, for many years, several providers have offered Universal Electronic Signature, one of the options of which is to encrypt the mail you send to other users of the service. Using it requires a little more effort and, in most cases, the presence of a desktop email client (Outlook or Mozilla Thunderbird), but the providers offer decent documentation on their websites and have associates who will be happy to assist you with the configuration of the email client.
Telephony
Telephone conversations have been eavesdropped on since the first telephones were introduced. Encrypting the connection on landline phones is a difficult challenge for the average user and would require special equipment on both sides, the details of which are beyond the scope of this article.
Unlike landlines, mobile phones are extremely easy to protect, as their platforms allow the use of various applications, including encryption. One of the easy and free options for end-to-end encryption of telephone calls are the products of Open Whisper Systems - RedPhone (for Android) and Signal (for Apple). If both parties in the conversation have the app installed, the conversation automatically switches to encrypted mode over an available internet connection. Users register with their mobile number, which means that all subscribers who use the app are automatically recognized in the address book.
Chat
Almost everyone with a smartphone has a chat application installed. Some of them are known to be eavesdropping (Skype), others handle personal data (such as contacts, addresses) quite aggressively for advertising purposes. In both cases, the confidentiality of user information is at risk. The solution to the problem is again the use of products and services that clearly define how they handle user information and that offer the possibility of end-to-end encryption of information. There are a number of similar ones on the market, I will mention only a few of them here.
- TextSecure for Android and Signal for Apple offer the same messaging security as the company's voice encryption apps. Both are free and work based on the user's mobile number, which automatically identifies subscribers from the contact list who also have the app.
- Threema is another alternative, developed in Switzerland, which offers the same security. Identification is not with a number, but with a generated ID, but if the user enters their number or email address in their profile, automatic recognition in the address book is also possible. The application costs between 1 and 3 Euros in different catalogs.
- WhatsApp announced that it is starting a cooperation with Open Whisper Systems, the creators of TextSecure, and will use their end-to-end encryption technology in the application of the same name. Their intention deserves admiration, but how much its implementation brings complete security cannot be said, since WhatsApp (unlike TextSecure) is not an open source application.
Conclusion
It is extremely easy to eavesdrop on the correspondence of an average and even technically literate person. However, protecting yourself is just as easy and in most cases - a matter of a few minutes of work. Changing your mindset is laborious - namely, that we should not blindly trust everything that is offered on the market, because free facilities in some cases carry risks, not only for us, but also for the people around us. And by protecting yourself, you also protect the right to privacy of the people you communicate with.
EKIP– Expert Club for Economics and Politics A Different Opinion

