No thanks. We should push toward services which offer end-to-end encryption.
No thanks. We should push toward services which offer end-to-end encryption.
That's the difference between this being a SERVICE and STANDARD.
The RCS standard has to work even in those countries that forbid e2e encryption for this sort of comms. Even if it's a minority of countries, I think it would be very difficult to convince carriers in more liberal societies to adopt the standard if it means they won't be able to interoperate with carriers in those more restricted countries.
Progress is incremental; the RCS standard, while imperfect, adds a bunch of really desirable features that will help interoperability between platforms and services globally.
Apps that integrate with RCS could still offer e2e within their applications; think how iOS does both iMessage (encrypted) and SMS (unencrypted) within the same app. It's just a major improvement to SMS.
The question at hand is whether any major company would allow consumers to send messages the company can’t harvest for data. The answer is yes. Apple does.
Are you saying they don’t? —That they actually have backdoored their E2E messaging app already?
If you are just saying that it’s not entirely impossible for them to do backdoor, I don’t see what bearing that has on the discussion.
Apple does, but as far as trust goes, they are on the same level as WhatsApp (also E2E).
You’ve actually got one set of keys for each device you add to iCloud, and each iMessage is encrypted independently for each device. So if you have two devices — say, an iPad and an iPhone — each message sent to you is actually encrypted (AES-128) and stored on Apple’s servers twice. Once for each device. When you pull down a message, it’s specifically encrypted for the device you’re on.
The thing is: it is valid to trust a company to keep their explicit word. That’s a different issue from trusting a company who never explicitly said they wouldn’t listen to your data: companies can be held liable for these sorts of public statements. If Facebook silently (knowingly) subverts Whatsapp E2E, they’re in trouble. But reading regular Facebook messages for ads? Storing them plain text? They never said they wouldn’t.
This is why Apple explicitly stating they E2E iMessage is a data point with value. It is valid to trust Apple more now, simply because they’ve upped the stakes for themselves.
Compare this to a bar bet: someone makes a claim, I am sceptical. They say, honest! Still sceptical. They say ok, bet you £300. I suddenly am much more inclined to believe them. No money changed hands :)
Before you start downvoting spree, read this:
For Apple: https://mashable.com/2013/10/17/apple-nsa-imessage
http://bgr.com/2015/08/06/iphone-fbi-imessage-facetime-backd...
https://www.tripwire.com/state-of-security/latest-security-n...
For WhatsApp: https://tobi.rocks/
(encrypt data with random key with symmetric encryption algorythm (AES,...), which is then encrypted and stored with the mesage twice. Once encrypted with recipient public key (asymmetric: RSA,ECC) and once encrypted with apple public key. This way you can say that you are having end to end encryption while you can still read everything and you can also use all the nice words in marketing material, AES, end2end, RSA/ECC,...).
I will tell you another case: Skype. It had a p2p protocol, highly encrypted and obfuscated, also the application was armored. The communication wasn't going through Skype servers but directly between devices. Once Microsoft bought it, the next version was using Microsoft servers and p2p was gone. Interesting, right?
Open source. And for really impossible also open hardware.
But they don't federate. Which I think is a pretty clear example of why not having one true solution isn't a technical problem, it's a political problem. Companies don't want to make it easy to compete with their products.
That's a well developed thing already:
* https://en.wikipedia.org/wiki/OMEMO
Common OMEMO supporting XMPP clients are Conversations[1] for Android, ChatSecure[2] for iOS and Gajim[3] for the desktop.
[1] https://en.wikipedia.org/wiki/Conversations_(software)
[2] https://en.wikipedia.org/wiki/ChatSecure
[3] https://en.wikipedia.org/wiki/Gajim
You can see the OMEMO status of the various XMPP clients here:
Look at what's happening to Telegram with Russia; I don't think Google is interested in participating in such a battle. They want just to have a simple messaging app and to have a compelling competitive messaging app to WhatsApp et. al. (They don't care about Messages since it's locked to iOS devices)
But to do Encryption, that means taking a stand against many big governments controlling some big markets. I don't see Google as ready to fight with the likes of Russia, China, Turkey, etc. If they just hand over the keys, what good is the E2E encryption?
Open, secure, usable by ordinary people: choose two.
Insecure, open, usable: Google Chat
Secure, centralised, usable: WhatsApp
Secure, open, poor UX: PGP.
If you're building a consumer-grade service, rather than a niche service usable only by security geeks, and you're arguing for end-to-end encryption, then you're knowingly or unknowingly arguing for centralisation and against interoperability.
Agreed but I feel like there is some confusion here - this sounds more like a extension to SMS to make it less crummy.
Good secure solutions already exist, we should push for people to actually use them.
I don't want my chat messages routed through some foreign jurisdiction, encrypted or not, so carrier-owned sounds good to me.
Though it will feature client-server encryption, so at least in this respect it's more secure than SMS.