I spent a chunk of Wednesday afternoon with the Google I/O keynote open in one tab and actual work open in another, which is basically how I watch every keynote now. Shoreline Amphitheatre, the big outdoor venue they always use, packed with developers in free t-shirts. You know the drill.
The headline stuff is exactly what you'd expect me to write about. Google Home, the little speaker thing that's obviously aimed straight at the Echo. Duo, a dead-simple video calling app with that "Knock Knock" preview so you can see who's calling before you pick up, which is a genuinely nice touch I didn't expect to like as much as I do. And Allo, the new messaging app with Google Assistant baked right into the conversation and a Smart Reply feature that reads your texts and suggests responses for you. All of that got covered to death within about six hours of the keynote ending, so I'm not going to rehash it.
What's actually been sitting with me since Wednesday is one paragraph buried in the Allo announcement. By default, your chats in Allo are encrypted in transit but not end-to-end. If you want the real thing, the Signal-protocol level encryption where not even Google can read the message, you have to manually switch into "Incognito Mode." Its a toggle. Its not the default state of the app.
And look, I get why. Smart Reply and the Assistant integration need to actually read what you're typing to do anything useful, and you cant do that if the message is locked up in end-to-end encryption the server cant see through. Its a real tradeoff, not a lazy one. But its still a choice Google made, and it's the kind of choice that lands differently in May 2016 than it would have three years ago. We're what, ten weeks out from Apple and the FBI going back and forth in court over unlocking a phone. Encryption isnt some niche cypherpunk topic anymore, its front page stuff, and Google rolled out a flagship messaging app where the privacy-respecting option is opt-in instead of the default.
The privacy and security crowd online noticed within about a day, unsurprisingly, and there's already a decent amount of "wait, why isnt this just on by default" going around. I dont think its some sinister plot, honestly. I think its a product team that wanted the AI features to be the headline and figured the encryption stuff could be a checkbox for people who care. But I also think that's a little bit of a cop-out, because most people wont ever find that toggle. Default settings are the product for like 95% of users. Whatever ships turned on is the app, full stop.
(Small tangent, but it bugs me every time: I now have SMS, Hangouts, Facebook Messenger, and WhatsApp all installed, and apparently Allo and Duo are about to make that six. Every big company wants to own my messaging habits and none of them want to just make the other ones better. My mom still just texts me. I dont think any of this changes that.)
None of this is a reason to write Allo off before its even out — it's not shipping till later this summer, so plenty can change between now and then. And to be fair to Google, at least they built real end-to-end encryption into the app at all, using the actual Signal protocol, which is more than a lot of the messaging apps on my phone can say. Facebook Messenger doesnt have anything like it. Neither does SMS, obviously.
But I keep coming back to the framing of it. The Assistant and Smart Reply stuff got the big demo moment on stage, the "look how smart this is" applause line. The privacy mode got a slide and a mention. That ordering tells you something about what the product is actually optimized for, and its not privacy first. Maybe that's fine. Maybe most people genuinely dont care and would rather have the clever autocomplete jokes. I just dont think Google gets to have it both ways, showing up in every post-Snowden panel talking about how seriously they take user trust, and then shipping the un-encrypted mode as the one everybody actually uses without ever touching a setting.
Anyway. Home looks neat too. We'll get to that one another day.