If Jeff Bezos's Texts Aren't Safe, Yours Definitely Aren't

If Jeff Bezos's Texts Aren't Safe, Yours Definitely Aren't

Tech News encryption privacy security signal tech-news

So Jeff Bezos published a blog post on Medium last Thursday. That sentence alone is a little bit funny to me — the richest man in the world, founder of the company that's replaced half of American retail, decided the best venue for what is essentially a legal and PR bombshell was Medium, of all places. Not a press release, not the Washington Post (which he owns), just a Medium post titled "No Thank You, Mr. Pecker."

If you missed it: American Media Inc, the company behind the National Enquirer, ran a story a couple weeks back about an affair Bezos was having, complete with texts between him and Lauren Sanchez. Bezos hired a security consultant, Gavin de Becker, to figure out how AMI got hold of private messages in the first place. According to Bezos's post, AMI then turned around and threatened to publish more intimate photos unless he called off the investigation and made public statements saying he had no reason to believe AMI's coverage was politically motivated. He refused, and instead published their emails. It's a wild read if you haven't sat down with it.

I'm not going to pretend I have some hot take on the tabloid politics of it, or whether the Saudi Arabia angle de Becker floated holds up (Bezos owns the Post, the Post has been unsparing about Khashoggi, connect whatever dots you want to connect there). What I keep coming back to, as someone who writes about tech for a living and not gossip, is the much more boring and much more relevant question underneath all of it: how did anyone get his texts in the first place?

Nobody outside the small circle involved knows for sure yet, and I'd guess we won't for a while. But it doesn't really matter for the point I want to make, which is this: if the richest man on Earth, with presumably the best security money can buy, can have his private messages end up in a supermarket tabloid, what exactly do the rest of us think is protecting ours?

I say this every time something like this happens and I'll say it again: SMS is not secure. It was never designed to be. Regular text messages between iPhones and Android phones travel basically in the clear, sitting on carrier servers, sitting in backups, sitting wherever a phone gets physically handed to someone else for five minutes. iMessage is better if you're staying inside the blue bubble ecosystem, and I'll admit I have a mild, entirely unreasonable grudge against green bubbles that has nothing to do with security and everything to do with vanity, but that's beside the point. The actual fix, if you care about this stuff even a little, is to move sensitive conversations to something end-to-end encrypted by default and not dependent on which phone the other person owns. Signal is free, it's open source, and setting it up takes about four minutes including the part where you convince your one friend who "doesn't believe in encryption apps" to install it too.

None of this would have necessarily saved Bezos, to be clear — plenty of leaks happen the boring way, through a person, not a protocol. A screenshot forwarded by someone who had access. That's usually how these things actually go, and no amount of encryption fixes a human being deciding to share something. But it's worth separating the two problems, because people tend to conflate "my messages could be exposed by someone I trust" with "my messages are technically vulnerable," and they respond to those two things very differently. You can't really engineer your way out of the first one. You absolutely can do something about the second.

Anyway. I don't have a tidy lesson to wrap this up with, and I don't think the story is done unfolding. There's clearly more to come on the who and the why. I just think it's a useful, if uncomfortable, reminder that "I have nothing to hide" was never really the right way to think about any of this. Everybody has texts they'd rather not see printed. Act accordingly.