将无缝的后量子密码学加密融入您已有的所有通讯工具中
4 分•作者: kvasilev•3 个月前
大家好!
我是一名坚定的隐私倡导者,我坚信隐私是一项基本人权。
最近,可以说情况相当令人沮丧。过去几个月,Meta 移除了端到端加密,欧盟的“聊天控制”法案仍在辩论中,同时大型科技公司在构建自身人工智能系统时,还在收集海量数据。
最受欢迎的通讯应用之所以方便,是因为大家都已经在使用它们。但它们中的大多数并非真正以隐私为先。
这也是为什么消费者社交应用领域竞争如此激烈的原因。
例如,Telegram 大力宣传其隐私性,但普通的 Telegram 聊天并非端到端加密。用户仍然需要信任 Telegram 在其服务器上创建、存储和管理他们的私钥。
但市面上存在许多我个人在生活中一直使用的、更注重隐私的工具。
Signal 将密钥存储在本地,并将端到端加密设为默认。SimpleX 采取了更去中心化的方法。Meshtastic 支持硬件网络。其中许多项目都是开源的,并解决了真实的隐私问题。
但它们都面临着同一个主要问题:网络效应问题。
只有当您需要交流的人也在使用时,通讯应用才有用。要说服您的朋友、家人、同事或客户放弃他们已经使用的应用并迁移到其他地方,是很难的。
这就是我开始思考一种不同方法来恢复我们日常生活的隐私的原因。
与其创建另一个通讯应用并要求每个人切换,如果我们能将私密加密带入人们已经使用的通讯应用和社交平台,会怎么样?
这就是我正在通过我的副项目实验 Ekko 所做的。
Ekko 存在于您的浏览器扩展或移动键盘中。您正常输入消息,Ekko PQC 在消息到达通讯应用之前在本地对其进行加密,接收者在他们的设备上本地对其进行解密。通讯应用只负责传输加密内容。
PGP 在几十年前就证明了个人可以控制自己的加密密钥。但它也表明,当用户必须手动管理密钥、复制消息、加密它们、粘贴密文,然后重复此过程来解密回复时,加密变得多么困难。
强大的加密技术是不够的,如果普通人无法使用它。
Ekko 的目标是让这个过程与现代、已流行的通讯应用无缝集成。您不需要了解加密算法,也不需要切换到自托管解决方案,或迁移应用。
Ekko 仍处于早期阶段。我们有一个良好的工作原型,我正在早期访问中与朋友一起测试,同时我们正在构建后端基础设施并实现无缝的通讯应用集成。它还没有完美运行,但我们正在积极努力!
这些应用、浏览器扩展和加密代码都将是开源的。
通讯应用可能仍然可以看到元数据,包括谁在通信、何时发送消息以及通信频率。平台可能会阻止加密消息或破坏集成,但我们可以积极地反击,特别是当近十亿欧洲人即将受到积极监控时。
但它可以让用户控制他们消息的实际内容,而无需强迫他们的整个社交圈迁移到另一个平台。
我非常欢迎直接的批评,特别是关于安全模型、密钥交换、多设备支持、元数据、平台限制,以及这种方法是否真的解决了足够多的网络效应问题以至于有用。
我是在两天前公开这个想法的,并开始公开构建,所以任何想法都非常欢迎 :)
https://useekko.app
我很乐意与您交流!如有任何疑问、建议或合作意向,请联系 kirill@useekko.app
让我们为不被压制的隐私权而战!
- Kirill 来自 Ekko
查看原文
Hi everyone!<p>I am a big privacy activist and I strongly believe privacy is a fundamental human right.<p>Lately, things have been quite frustrating to say the least. We have Meta removing end-to-end encryption over the past months, the continuing debate around EU Chat Control, and major technology companies collecting enormous amounts of data while building their own AI systems.<p>The most popular messengers are convenient because everyone already uses them. But most of them are not truly privacy-first.<p>It's also the reason why consumer social apps are such a competitive field.<p>Telegram, for example, markets itself heavily around privacy, but normal Telegram chats are not end-to-end encrypted. Users are still trusting Telegram to create, store and manage their private keys on their own servers.<p>But there are much better privacy-focused tools that I myself have also been a user of throughout my life.
Signal stores keys locally and makes end-to-end encryption the default. SimpleX takes a more decentralized approach. Meshtastic allows hardware networks. Many of these projects are open source and solve real privacy problems.<p>But they all face the same major issue: the network problem.<p>A messenger is only useful when the people you need to talk to are using it. It is difficult to convince your friends, family, coworkers, or customers to leave the applications they already use and move somewhere else.<p>That is why I started thinking about a different approach to restore privacy in our daily lives.
Instead of creating another messenger and asking everyone to switch, what if we could bring private encryption into the messengers and social platforms people already use?<p>That is what I am building with my side project experiment, Ekko.<p>Ekko lives inside your browser extensions or mobile keyboard. You write a message normally, Ekko PQC encrypts it locally before it reaches the messenger, and the recipient decrypts it locally on their device. The messenger only transports the encrypted content.<p>PGP showed decades ago that individuals could control their own encryption keys. But it also showed how difficult encryption becomes when users have to manually manage keys, copy messages, encrypt them, paste ciphertext, and then repeat the process to decrypt a response.<p>Strong cryptography is not enough if normal people cannot use it.<p>The goal with Ekko is to make that process seamless with modern, already popular messengers. You should not need to understand encryption algorithms or switch to self hosted solutions, move applications.<p>Ekko is still early. We have a good working prototype that I am testing with friends in early access while we build out a backend infrastructure and ace the seamless messengers integrations. It does not work perfectly just yet, but we are actively getting there!<p>The applications, browser extensions, and cryptographic code are intended to be open source.<p>The messenger may still see metadata, including who is communicating, when messages are sent, and how frequently people communicate. A platform could block encrypted messages or break an integration, but it could actively be battled back, especially when we have almost a billion Europeans about to be actively surveilled.<p>But it could give users control over the actual contents of their messages without forcing their entire social circle to move to another platform.<p>I would appreciate direct criticism, especially around the security model, key exchange, multi-device support, metadata, platform restrictions, and whether this approach actually solves enough of the network problem to be useful.<p>Just publitised this idea two days ago and started building in public so any thoughts are appreciated :)<p>https://useekko.app<p>I would love to talk! Any inquiries, suggestions or collaborations, kirill@useekko.app<p>Lets fight for the right to privacy to never be suppressed!<p>- Kirill from Ekko