The One Person You Can Trust With Your Private Messages (And It’s Not a Company)

Someone is reading your messages. Maybe not today. Maybe not by a hacker in a hoodie. But somewhere, in some server room, a log file is recording the fact that you said ‘I love you’ or ‘I’m scared’ or ‘I’m quitting.’ The encryption? It’s a promise. And promises are only as good as the person making them.

I’ve been staring at a Hacker News thread where someone asked a brutal question: What would convince you that a closed-source messaging app is secure? The top answer was a knife to the gut: ‘Nothing. I barely trust open source after it’s been in use for decades.’ That’s a person who has seen the code, the audits, the battle testing — and still doesn’t believe. So what hope does a closed-source app have?

Then came the second answer. And it changed everything I thought about trust.

‘Someone widely respected as a super-competent programmer and known to be somewhat of a self-directed loner. If Fabrice Bellard suddenly decided secure messaging was what he was committed to doing, I wouldn’t care if he did it closed-source.’

Read that again. The most security-conscious person in the thread said: I’d trust a lone genius over a company with a dozen auditors. Why? Because trust isn’t about code. It’s about incentives.

Think about it. A company has shareholders, board meetings, revenue targets, government subpoenas, and a legal team that can be compelled. Their code could be perfect — but the entity running it has every reason to betray you when the pressure hits. A self-directed loner? They have nothing to lose except their reputation. And for someone like Fabrice Bellard, that reputation is the most valuable asset they own.

This is the twisted truth of digital security: the strongest signal isn’t the code at all — it’s the absence of institutional motives. A lone genius has no one to sell you out to. No one to force a backdoor. No quarterly earnings call to satisfy. Their only incentive is to keep their word, because their word is their entire brand.

So the next time you pick a messaging app, stop asking: ‘Is it open source?’ Start asking: ‘Who is behind it, and what do they have to lose?’ If the answer is ‘a corporation with a PR team,’ you’re betting on a careful lie. If the answer is ‘a brilliant, slightly obsessive programmer who values their name more than money,’ you might have found the only real security on the internet.

In a world of zero-days and silent breaches, the most trustworthy encryption is the one bound to a person’s reputation — not a company’s balance sheet.

FAQ

Q: Isn't open source always more secure than closed source because anyone can audit the code?

A: In theory, yes. In practice, most people don't audit code. The security of open source depends on a community of reviewers — and that community can be bought, distracted, or co-opted. A closed-source app from a respected lone developer can be more secure because the developer's entire reputation is on the line, and they have no external pressure to compromise.

Q: What does this mean for me as a regular user?

A: Stop choosing apps based on whether they're open source. Start looking at the person or small team behind the app. Research their history, their independence, and their incentives. If they have no corporate overlords and a track record of integrity, that's a stronger signal than a GitHub repo full of stars.

Q: So you're saying we should trust a single developer over a company like Signal or WhatsApp?

A: Not necessarily — Signal is open source and has a strong reputation. But the point is that a single brilliant developer with no institutional ties can be <em>more</em> trustworthy than a company with a billion-dollar valuation. The ultimate security guarantee is a person who has nothing to gain by betraying you, and everything to lose if they do.

📎 Source: View Source