Shine Get

  • 0 Posts
  • 161 Comments
Joined 1 year ago
cake
Cake day: July 1st, 2023

help-circle









  • Only Google’s proprietary extension has encryption. The actual industry standard specification of RCS has no encryption defined at all.

    Edit: It turns out Apple have refused to use Google’s proprietary encryption implementation and are instead working with GSMA to update the RCS Universal Profile specification to finally have encryption defined and standardised so that any RCS client can handle encrypted payloads (whereas only Google Messages today can do encrypted RCS and requires other users to be exclusively using Google Messages otherwise messages are sent unencrypted).



  • Bingo. RCS is yet another proprietary protocol, one controlled by Google (GSMA who originally designed it have practically forgotten about it for a decade) and without an open specification. RCS also doesn’t have a standardised approach to encryption as it’s designed for lawful interception.

    So unless Apple have licensed Google’s implementation and extended version of RCS, this will be a shitty, insecure way to communicate between the Apple Messages and Google Messages apps and nothing more.

    Google did an impressive job applying pressure and suggesting RCS was a perfect solution when in fact it’s just putting more control in Google’s hands. RCS is not an open “industry” standard. You nor I as individuals can implement it without paying license fees to see the specification and fees to have our implementations tested and accredited.

    And Google have extended GSMA’s RCS with their own features (such as encryption) which is not part of the official standard and they haven’t made open either.

    If Apple had been pressuring Google to implement the iMessage protocol or whatever, we’d have been up in arms (and rightfully so).

    But instead of us all collectively hounding Apple and Google to ditch proprietary protocols and move to open ones such as Matrix, Signal, XMPP, etc (ones where we could all implement, use open source software clients, etc) we’ve got this shit:

    Proprietary, insecure, non-private communication protocols baked into the heart of hundreds of millions of devices that everyone is now going to use by default instead of switching to something safer, private, public, open, auditable, etc etc.


  • I doubt it’ll be impossible as Google will be required by many laws around the world to make it clear if something is an advert, especially in the EU. So there will be a mechanism to know if something in the stream is an advert or not.

    Adblockers should be able to adapt but I do think SponsorBlock might be stuffed if users are seeing adverts at different times in the stream.