Google to Implement IETF's Message Layer Security (MLS) Specification RFC 9420
security.googleblog.com
security.googleblog.com
> Messaging applications are increasingly making use of end-to-end security mechanisms to ensure that messages are only accessible to the communicating endpoints, and not to any servers involved in delivering messages. Establishing keys to provide such protections is challenging for group chat settings, in which more than two clients need to agree on a key but may not be online at the same time. In this document, we specify a key establishment protocol that provides efficient asynchronous group key establishment with forward secrecy (FS) and post-compromise security (PCS) for groups in size ranging from two to thousands.
So, it’s just the end-to-end encryption stuff with double ratcheting and such, not anything about a particular message format. This makes it a very valuable element for interoperability, and I think might make bridging work better?; but it’s not sufficient for mixing messaging services in any way, nor is Google proposing anything like XMPP of “implement this and you can federate with our service”.
(Much of this how-useful-is-it stuff is implied by the name Message Layer Security (MLS), by analogy to Transport Layer Security (TLS) and the functionality of layers inside it like HTTP/1.1.)
There's ongoing work at the IETF to create a new protocol called MIMI (More Instant Messaging Interoperability)[0], which will use MLS as its E2E crypto layer.
There are Google reps on the working group, amongst others.
I reviewed Matrix's https://arewemlsyet.com/ recently, after getting again curious about MLS. Activity definitely trailed off after some initial excitement. But they did have some chatting about how they wanted a decentralized MLS, https://gitlab.matrix.org/matrix-org/mls-ts/-/blob/decentral...
Also, note this article here is from July 19, 2023. Have we seen any further activity since this announcement?
Matrix however is decentralised, and decentralised MLS is live and well and in active development - we need to update arewemlsyet.com.
I watched an ietf video of meeting, second last maybe? And they were discussing types of users.
Companies, like Google WhatsApp
Corporates. Govt.
End users with own servers.
The idea was end users should not be part of the decentralized network as you cant ask FB to network with a 1 person server but isnt matrix.org already able to do that? Why take that functionality away when it works without problems? Yes spam but it can be managed
This seems to be based on the same sentiment as expressed in XKCD-927[1]. We will fix a standardization mess by introducing a new standard that covers all the existing use cases. Dunno if efficient end to end encrypted groups with thousands of users actually counts as an existing use case. There doesn't seem to be any way to make such a thing practical in actual use.
Also, strangely enough, this post is by “Privacy Engineering Director”, but google’s messaging is not implemented by privacy team, so is this going to be “privacy team developed proof-of-concept abandonware” to be never picked up by the product team?
Google has a long history of abandoning products that aren't ads or search, especially messaging products. Nearly forty messaging products by my count.
As a counterpoint, the DMA is requiring “Gatekeepers” like Google to enable interoperability for their messaging systems, so this protocol (or some other alternative implementation) is likely required to avert billions of dollars of fines.