Latest News

9 apps to encrypt calls, SMS and messages on your mobile

After the revelations of the Snowden case and the mass espionage programs , users have become aware of the importance of the secrecy of our communicationsand, therefore, we begin to take into consideration the degree of privacy when using one service or another.

Google announced the end-to-end encryption between Gmail users, precisely, to guarantee the users of its service the secret of their communications. Following this path have emerged extensions such as ShadowCrypt to encrypt messages or the development of projects such as Dark Mail to implement a secure email system and “immune” to spying and unauthorized intrusions.

If we take into account that through telephone conversations, or even through messaging services, we can get to exchange sensitive information, it makes sense that we take into consideration the privacy of our conversations and, therefore, that we look for applications and services that ensure “end-to-end” encryption on the devices we use on a daily basis.

The EFF (Electronic Frontier Foundation) published, last November, a report in which evaluated the security of the messaging services most used by smartphoneusers, which, precisely, did not leave in too good a place the most used services (WhatsApp, PGP Blackberry Messenger, etc.).

That a service offers an encrypted channel between our terminal and its servers does not guarantee the secrecy of our communications, there must be an encrypted channel “end to end” (from terminal to terminal), that is, in the servers of the service should not be accessible our conversation.

Another important detail is the possibility of auditing the services we use, if the source code is accessible, at least it can be reviewed by independent third parties and verify that the declared specifications are met and that there are no “hidden functionalities” not declared.

Calls encrypted from the mobile: Android and iOS

Fortunately, we have more and more options available for both iOS and Android.

Signal is one of the products that have developed from Open Whisper Systems and is aimed at making secure phone calls between iOS devices (based on end-to-end encrypted communication).

The use is extremely simple: install the application and indicate our phone number. Then the application exports our contact list to verify which contacts use the service and, from there, we can call them (although, yes, it will be a communication on the data network since it is an IP call on a secure channel).

In the case that we use an Android device, the same company offers us the RedPhone application so that we can also make voice calls on a secure communications channel (using, likewise, our data connection or through a Wi-Fi connection). ).

And what happens if we want to establish a communication between iOS and Android? There is no problem, Signal and RedPhone are interoperable ; therefore, from Signal you can make calls to RedPhone users and vice versa. In both cases, the code of the applications is available for auditing and communications are supported by the secure ZRTP protocol, which is why, a priori, it is a reliable service.

Encrypted messaging both from desktop and mobile devices

There are several options to protect our messages, some as well known as Telegram which, in its secret chat mode , offers end-to-end encryption and in this option the conversations are not accessible from the Telegram servers.

Another known option, and extended in the market, are Apple’s iMessage and FaceTime services ; available on OS X and iOS, these messaging services and video calls also offer end-to-end encryption, although the source code is not accessible to third parties, and we must trust Apple for its secrecy.

RedPhone is the option for Android of Open Whisper Systems. It also allows us to make voice calls through an encrypted channel but, to exchange text messages, it is necessary to combine its use with TextSecure

If what we want to encrypt are SMS, a third alternative to communicate securely from Android is Text Secure although, yes, it is only aimed at instant messaging via text.

In the case of iOS, Signal includes both calls and written messaging; in Android, you have to resort to two different applications, on the one hand RedPhone for calls and, on the other hand, Text Secure for text messages (since this application replaces the SMS container of the terminal to use a secure and encrypted store and which requires a password to access the stored messages).

If we have an iOS device and desktop computers, with Cryptocat we can establish chat sessions through a secure channel

Another interesting service, and also multiplatform, is CryptoCat . Available for both iOS and desktop browsers, this chat service (written messaging) allows us to encrypt the messages that are exchanged by users (they are encrypted and can not be deciphered until the information reaches the destination client) and, in addition, it is a project in open code so it can be audited to verify its functionality. In principle, the communication channel is safe although from the service they try to be somewhat conservative and clearly warn that “it is not an infallible tool to which you should entrust your life” (a fact to be taken into account).

Cryptocat launched a crowdfunding campaign last year with the aim of extending its functionalities but, finally, it achieved the amount that had been marked (so, for now, the audio and video chats and the Android application will have to wait ).

BitTorrent has been developing a secure and decentralized instant messaging system for a long time that, since it does not depend on the cloud, makes information circulate directly among users without having to go through intermediate servers. Bleep , which is what this service is called, aims to be a safe and decentralized alternative to WhatsApp or Telegram, offering end-to-end encryption and available in both iOS and Android.

That the communication is direct between the users and, in addition encrypted, they place Bleep as one of the best options to take into account when using an application to establish secure communications (by not passing through intermediate servers).

Finally, users of Android devices should consider Surespot that could be considered a kind of combination between WhatsApp and Snapchat with communications encryption. The service allows us to exchange images, text or voice messages through a secure channel (point-to-point encrypted communications with 256-bit AES-GCM symmetric key using keys created with 521 bits ECDH) and with the possibility to erase, at will, messages that we have already sent (always keeping control of the information we exchange).

The Surespot service relies on intermediate servers, therefore, it is a factor to take into account when evaluating its use.