Apple is apparently working with GSMA to add encryption to the standard though. (They probably wouldn't add RCS otherwise.)
https://www.macrumors.com/2024/02/21/iphones-top-7-best-sell...
Too bad the other vendors don’t bother keeping up.
You should instead look at Market share. https://www.statista.com/statistics/272698/global-market-sha...
So you can either say Apple is reserving this development for a subset of the market, or Google is withholding it from a massive portion of the market share.
Coordination with even Google would not be necessary for Apple to offer encrypted conversations with users on other devices. There's no rule saying they need to use an open standard or a Google standard or be cross-compatible with another app. It's not that Apple is trying desperately to get iMessage onto other phones and failing because Google and Samsung just won't let them do it.
Of course, Google has its own problems[0]. But the inability to use the Messages app to communicate securely with Android users[1], is solely 100% Apple's decision. Apple does not need to ask permission or coordinate with any other company to increase that security, they would just need to throw a messaging app up on the app store.
Heck, they wouldn't need to support iMessage on Android. They could throw a messaging app up that had no encryption other than that it worked over HTTPS and data instead of SMS when messaging iOS users, changed nothing about the capabilities or features that they supported for non-iMessage users, and even only doing that -- if Android users could download it and set it as their default SMS client on Android then iPhone security would be better.
----
As a comparison here, if Signal dropped support for iOS tomorrow, would you blame Apple for not building support for Signal into iOS? No, that would be absurd to suggest. No one would claim that Apple had some obligation to support the Signal protocol or make Signal compatible with iMessage, or to build an open protocol -- we would all correctly point out that Signal decides where to make its app available. The same is true of Apple. The fact that you literally can't make many Messages conversations secure without completely abandoning the app and using a separate 3rd-party service for those conversations -- it is purely and entirely the result of a decision that Apple has made.
----
[0]: And in fact their proprietary encryption standard is no better than Apple's and they're pulling the exact same crap as Apple is for the same flimsy reasons.
[1]: Note that I don't say non-Apple users, you can have an iMessages account through other devices and you still won't be able to use it with an Android phone number.
There is such a thing as 'too much' choice:
* https://en.wikipedia.org/wiki/Overchoice
* https://en.wikipedia.org/wiki/Decision_fatigue
* https://www.behavioraleconomics.com/resources/mini-encyclope...
Unless your goal is to make money on the platform, then you should look at wallet share, not market share.
You should look at the percentage of smartphone owners. It does not matter in the slightest how many dollars they have in their pockets. The question is: is the average user going to have a significant number of Android contacts, with which Messages requires plain-text communication to contact.
And the answer for most people is: undoubtedly yes. I would say that most people who are using Messages as their primary messenger for all of their contacts are sending unencrypted messages on the regular.
Your point stands.
https://www.counterpointresearch.com/insights/iphone-hits-re...
That's not the point if you're talking about who you can have an encrypted conversation with, but it matters if you want to know if you can afford building an encryption tool to serve phone buyers.
But even I send 'green bubble' from iPhone to iPhone sometimes. If there is no good internet coverage.
In India, nobody used anything other than WhatsApp till a few years ago. Now, teenagers use Instagram's chat feature and WhatsApp, and middle-aged adults use FB Messenger and WhatsApp.
It's already incredibly hard to get people to use secure messaging systems. Downgrading to SMS isn't necessarily wrong (it's become harder to get people to use Signal now that it's dropped support for SMS), but it's a huge hole and effectively means that many customers will never have a significant number of their conversations encrypted.
That's a boring security hole, sure. But at some point you have to think about UX as being a part of security, and a messaging system that isn't cross-platform is hard to call secure, because good luck trying to get your contacts to all use it. People get upset about this, but the reality is it does not matter what encryption scheme a messenger is using if it's impossible for you to get your contacts to use it. The same way that it does not matter how secure your 2FA system is if you can't get people to turn it on.
I felt like on net Signal's support for SMS was a boon for security more than a hindrance because it made it easier for me to get people to sign up for Signal. In contrast, Signal's take was that having a secure and insecure service bundled up into the same messenger would on average make people more lax about security and would make it harder for them to make strong security guarantees. They viewed SMS support essentially as a security vulnerability.
I do wish Signal had kept SMS and tried harder on the UX, I honestly feel somewhat strongly that removing support made secure messaging harder -- but while we can debate the security downsides and the onboarding downsides, I also have grown to kind of see their point? And iMessage falls very squarely into that problem, except with Signal I can at least tell my contacts how to get it.
I don't know, it feels petty but like... if you have secure encryption but it doesn't get turned on for a bunch of messages, then that does seem like it has a security impact. I don't think that's a complicated or controversial thing to say, it's no different from calling out that some chat services require E2EE to be opt-in instead of opt-out. Good security requires thinking about that kind of stuff.
It's the wrench problem. You're not going to get spied on by a quantum computer. You're going to get spied on because there's a decent chance that ~50% of your contacts or more aren't on iPhone and you'll be talking to them in plain text. And realistically for most users, switching to a cross-platform E2EE messenger that allows them to use one consistent service for all of their encrypted conversations is going to be meaningfully more secure even if it doesn't have quantum-resistant encryption. The most important problem for any secure messenger to solve is how to get people to use it. Sometimes that means compromising on other security standards, sometimes it means being harsher about security standards that would otherwise be optional. Sometimes it means caring about availability and onboarding, and not sending the majority of messages in an easily intercepted plain-text format.
I'll take that one step further; it's the trusting trust problem. In the words of Ken Thomson, "To what extent should one trust a statement that a program is free of Trojan horses?"
You're not going to be spied on by a quantum computer because intelligence agencies already use classical computing for that. Some governments write Apple or Google a strongly worded email, others install a backdoor using iMessage. There's no need to crack your encryption because you're not going up against quantum adversaries; those people all have better options than bruteforcing Apple's lock. Sufficiently-motivated actors skip the wrench and pay Bob or Alice for your password.
There's no perfect solution to this issue. Apple would sooner die than lower the drawbridge to iMessage, and Google can't be bothered to write an altruistic RFC to save their life. Now we get the worst of both worlds; divided and surveilled.
Still unencrypted though, because the RCS standard does not include encryption.
They aren’t even going to use the developed encrypted RCS protocol.
Apple, when it comes to their values, is all lip service.
I have intimate experience here with them both openly lying and purposefully deceiving their user base in this case.
End-to-end RCS encryption is via proprietary Google extension and not even available to other Android RCS messaging apps.
Beeper was explicitly told it was not available to others when they wanted to implement Google's encrypted RCS on their Android client.
If Google's strategy was anything other than "get Apple to adopt, then screw them", Google would have contributed the enhancements back to the standard.
Google's proprietary closed source fork of RCS?
> Google's version of RCS... is definitely proprietary, by the way. If this is supposed to be a standard, there's no way for a third-party to use Google's RCS APIs right now. Some messaging apps, like Beeper, have asked Google about integrating RCS and were told there's no public RCS API and no plans to build one.
If you want to implement RCS, you'll need to run the messages through some kind of service, and who provides that server? It will probably be Google... So the pitch for Apple to adopt RCS isn't just this public-good nonsense about making texts with Android users better; it's also about running Apple's messages through Google servers. Google profits in both server fees and data acquisition.
https://arstechnica.com/gadgets/2022/08/new-google-site-begs...
FaceTime is not really true either. This was a convenient mistruth. There were several way to remedy that situation.
Also your misremembering iMessage there was no such issue.
> Yes but that would have meant giving up sales in exchange for actually backing up their words.
What word did they not back up with respect to iMessage? When did they ever say they'd open it up?
I saw that you moved the goalposts in your reply, but anyway: which words?
> They aren’t even going to use the developed encrypted RCS protocol.
The protocol that was designed by Google and in which Google’s infrastructure is crucial? It’s not Apple’s fault that RCS does not have mandatory end-to-end encryption.
> I have intimate experience here with them both openly lying and purposefully deceiving their user base in this case.
Do you mean that they lied to you personnally? You should write about that, it sounds much more interesting.
Encrypted RCS was. And it is proprietary.
They often presented specs that clearly showed security holes then simply would deny they were there or say “that’s secure”. It was a truly wild experience.
1) This tier of work is roundly invisible to almost everyone in the field. Many in the field are so confident in their knowledge of 'how things work.' that they simply can't accept the real 'in the room' realities of whats going on. Often engineers most of all, who are often deceived by their executives on the real goals. Are you and eng? Have you ever had that feeling of being gaslit by your VP? Yea you probably were, and you didn't know why.
2) Even at that level, I had a limited picture and a good extrapolation of what was going on in other rooms, but nothing I can say fully factually
3) No one wants to know. People love the just-so stories of these companies and really genuinely seem to get hurt/be in denial when they are faced with the reality that they are made up of ultra-selfish, shark like people with very little invested in the consumer, the company, or really anyone else. It's a game played to win for personal satisfaction. I've found that most people, simply cannot accept this.