From Article 7:
"The level of security, including the end-to-end encryption, where applicable, that the gatekeeper provides to its own end users shall be preserved across the interoperable services."
I can't imagine much more than E2EE & maybe encrypted-at-rest (which is not a protocol-level feature anyway).
There's no way Android will support that stuff across its entire ecosystem, so I guess it means the law is toothless? Maybe it means it will be up to each hardware manufacturer to ensure interoperability?
2. Android does support device attestation and secure boot. I 100% would love to see our future SMS replacement require frequent signatures from device attestation hardware (why not every message) and require E2EE messages.
https://people.cs.ksu.edu/~danielwang/BAS/klein-2014-microke...
This is not the kernel that runs on the host CPU. It is the one that handles keys in the security coprocessor. I don’t know of many hacks of that, in practice. There was one where you could guess the pin, and use a timing attack to power down the chip before it persisted the “bad guess” count, which let people brute force pins (with special hardware).
It’s worth noting that the kernel Apple ships is a fork of L4; no idea if they’ve introduced bugs since the paper was written.
[0]: https://theconversation.com/what-if-the-fbi-tried-to-crack-a...
What happens if interoperability is enforced and messages have to be end-to-end encrypted? Wouldn't that mean that any side-loaded Android app would have to be able to get hold of my friend's private iMessage key?
On iOS I guess you could still keep the key private through Apple's SDK, but what about other platforms?
It's such a huge win for Facebook and Google - I'm not worried about "sideloaders", it lets them crack open the privacy of iMessage by simply having a view on conversations they can't see under the guise of interoperability.
The EU are just rolling a surveillance capitalist's wet dream with rulings like these.