8 ms·
So essentially, it's not really an Apple thing, it's more that the universal RCS profile just didn't have encryption, and Google RCS was a non-standard extensio
by oneplane 2y ago
So essentially, it's not really an Apple thing, it's more that the universal RCS profile just didn't have encryption, and Google RCS was a non-standard extension that nobody else was allowed to use.
The real news is the update to GSMA RCS, because without that, none of this matters. What I'm missing in the article is who's going to own the keys and why this is probably going to default to the telcos as if it's MMS. Are they going back to the days of charging per message?
With iMessage you'd be putting your trust in Apple, with Google RCS you'd be putting your trust in Google. For WhatsApp that'd be Meta and for Signal that's Signal. But with GSMA RCS?
- she46BiOmUerPVj 2y agoIs there anything that shows "no one was allowed to use it" or was it that it wasn't an accepted standard?
- oneplane 2y agoYes, Google only made it available for Google Messages. They don't have an SDK or API you can use to make your own clients or servers. Google also didn't put it up for standards with the GSMA or any other standards body, at least not publicly. There are no records of it. There are some older submissions here you can probably find using one of the HN search sites about this, but IIRC those didn't really have any internal Google policy about this, they kept it all pretty private. The only 'leak' I remember about this was the thing where manufacturers that preload Google Android have to ship Google Messages to get RCS support from Google, otherwise they can't have it. Also means you can't have RCS without Play Services.
- jauntywundrkind 2y agoThe destruction of third party apps has been totally wild. I'm very curious how long this OS-coupled status quo is going to go on for.
- acdha 2y agoLook at Google’s documentation: they explicitly state that only their Messages app is allowed to talk to their key exchange server. The entire marketing campaign they ran about RCS was predicated on nobody reading their docs or noticing all of the Android developers begging for permission to use RCS for years. https://www.gstatic.com/messages/papers/messages_e2ee.pdf https://www.gstatic.com/messages/papers/messages_e2ee.pdf > E2EE is implemented in the Messages client, so both clients in a conversation must use Messages, otherwise the conversation becomes unencrypted RCS. In rare situations where the conversation starts as E2EE, then one of the clients migrates to a different RCS client or an older Messages client that does not support E2EE, Messages might be unable to detect the change immediately. If the Messages user sends a new message, it’s still E2EE, however the recipient client may render the encrypted base64 payload directly as message content.
- g-b-r 2y agohttps://news.ycombinator.com/item?id=43368471 https://news.ycombinator.com/item?id=43368471
- MBCook 2y agoIt was just released in the last day or two. There had been drafts I think but now it’s real. So someone asked Apple and they said “sure we’ll support that”. I think the big news is that RCS can now be encrypted without relying on Google, but that’s not what gets you headlines.
- throawayonthe 2y ago[dead]
- stephenr 2y agoI understand your point that the "news" part is that RCS standard now includes E2EE, rather than about Apple's support for said standard. But I don't think it's fair to suggest or imply that this development is unrelated to Apple either. RCS has been a thing for nearly a decade, and Google's RCS backend has been doing non-standard E2EE for half that time. Within 8 months of Apple publicly announcing they would adopt RCS and work with GSMA to support standardised E2EE, there is suddenly a standard for it...
- OneDeuxTriSeiGo 2y agoIt is worth noting that the E2EE system they are using (MLS/RFC9420) was only finalised as a standard as of mid 2023 and has had errata from the last few months. They basically added E2EE to RCS more or less as soon as the protocol they are using standardized with IETF.
- hocuspocus 2y agoGoogle has been working on replacing the ad-hoc Signal protocol with MLS since before Apple announced they'd support RCS, it would have happened anyway. It's more likely Apple was made aware of the spec/Jibe/Messages roadmap when they finally got on board, decided not to target the latest UP version for some reason, and realized implementing the current E2EE scheme would be wasted effort given it would need to be revamped within a year. The iOS RCS client is still pretty far from being provisioned worldwide.
- jeroenhd 2y agoThe encryption is based on MLS: https://www.rfc-editor.org/rfc/rfc9420.html https://www.rfc-editor.org/rfc/rfc9420.html I don't think Google wanted to gatekeep their E2EE implementation. They have some generic documentation about how it works: https://www.gstatic.com/messages/papers/messages_e2ee.pdf https://www.gstatic.com/messages/papers/messages_e2ee.pdf The thing about RCS is that no messengers seem to care at all about implementing RCS themselves. Part of that is probably because depending on the carrier, RCS may require access to certain SIM card information, which only pre-installed apps can do, and part of it is that many developers are waiting for Google to add RCS to the same API that SMS/MMS already exposes because they don't want to implement RCS themselves. Realistically, the target demographic for their documentation is 1) Apple (who they'd happily supply with details to get rid of the green bubble problem) and maybe 2) government officials looking into antitrust concerns. In theory someone working for LineageOS can implement an RCS client, though, but for those developers I don't think reverse engineering the remaining unknowns about the protocol (mostly "what server" and "what message contents") aren't that difficult. I'm not cryptographer, but I haven't heard any major issues from actual cryptographers about MLS. It's encryption principles seem to be similar to those of Signal. Google is actually already using MLS in their proprietary E2EE implementation. Ideally, MLS would be combined with MIMI so that messaging apps become interoperable, but that's probably a pipe dream.
- acdha 2y agoThe protocol is open but key exchange is not: even on Android, third-party messengers can’t interoperate with Google Messages. See page 11 of that PDF.
- RataNova 2y agoGiven how telcos historically handled messaging (like MMS), skepticism is understandable