{"id":18620,"date":"2022-03-29T10:45:37","date_gmt":"2022-03-29T18:45:37","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/03\/29\/news-12353\/"},"modified":"2022-03-29T10:45:37","modified_gmt":"2022-03-29T18:45:37","slug":"news-12353","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2022\/03\/29\/news-12353\/","title":{"rendered":"Forcing WhatsApp and iMessage to Work Together Is Doomed to Fail"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/62432d8648046e8802c9c4fb\/master\/pass\/032822_WhatsAppiMessage.jpg\"\/><\/p>\n<p><strong>Credit to Author: Matt Burgess| Date: Tue, 29 Mar 2022 16:06:52 +0000<\/strong><\/p>\n<p class=\"BylineWrapper-iiTsTb hAGfXd byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-dbkCxf erRIa-D\"><span data-testid=\"BylineName\" class=\"BylineName-cKXFOb UCAzg byline__name\"><a class=\"BaseWrap-sc-TURhJ BaseText-fFzBQt BaseLink-gZQqBA BylineLink-eZnyPI eTiIvU mEZDb fNdcwQ bKZMMS byline__name-link button\" href=\"\/author\/matt-burgess\">Matt Burgess<\/a><\/span><\/span><\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p><span class=\"lead-in-text-callout\">The newest law<\/span> designed to rein in Big Tech aims to make all your favorite messaging apps work seamlessly together. Sounds great, right? Well, we have some bad news.<\/p>\n<p class=\"paywall\">Every day, billions of messages are sent using <a href=\"https:\/\/www.wired.com\/2014\/11\/hacker-lexicon-end-to-end-encryption\/\">end-to-end encryption<\/a>. Millions of people use iMessage, WhatsApp, and Signal to chat with friends, family, and colleagues, and those conversations are all automatically protected by strong encryption. But it\u2019s not possible to send a message from one encrypted app to another. If you use <a href=\"https:\/\/www.wired.com\/story\/signal-tips-private-messaging-encryption\/\">Signal<\/a> and your friends only use <a href=\"https:\/\/www.wired.co.uk\/article\/whatsapp-tricks-encryption\">WhatsApp<\/a>, someone has to compromise.<\/p>\n<p class=\"paywall\">Under the European Union\u2019s wide-ranging <a href=\"https:\/\/www.wired.com\/story\/digital-markets-act-messaging\/\">Digital Markets Act (DMA)<\/a>, which European lawmakers approved last week and is expected to be implemented this year, the owners of messaging apps will be required to make them interoperable if another company requests that they do so. As a result, the largest messaging platforms\u2014including WhatsApp, Facebook Messenger, and iMessage, which the DMA designates as gatekeepers\u2014will have to open up to rivals.<\/p>\n<p class=\"paywall\">\u201cUsers of small or big platforms would then be able to exchange messages, send files, or make video calls across messaging apps, thus giving them more choice,\u201d the lawmakers <a data-offer-url=\"https:\/\/www.europarl.europa.eu\/news\/en\/press-room\/20220315IPR25504\/deal-on-digital-markets-act-ensuring-fair-competition-and-more-choice-for-users\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.europarl.europa.eu\/news\/en\/press-room\/20220315IPR25504\/deal-on-digital-markets-act-ensuring-fair-competition-and-more-choice-for-users&quot;}\" href=\"https:\/\/www.europarl.europa.eu\/news\/en\/press-room\/20220315IPR25504\/deal-on-digital-markets-act-ensuring-fair-competition-and-more-choice-for-users\" rel=\"nofollow noopener\" target=\"_blank\">said in an announcement<\/a>. Under the plans, Signal could ask to work with Messenger, for instance. Or Meta could request that WhatsApp be made compatible with iMessage\u2014a logistical challenge even if Meta and Apple weren\u2019t <a data-offer-url=\"https:\/\/www.nytimes.com\/2021\/04\/26\/technology\/apple-facebook-feud.html\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.nytimes.com\/2021\/04\/26\/technology\/apple-facebook-feud.html&quot;}\" href=\"https:\/\/www.nytimes.com\/2021\/04\/26\/technology\/apple-facebook-feud.html\" rel=\"nofollow noopener\" target=\"_blank\">actively feuding<\/a>, but one EU lawmakers say is worth solving.<\/p>\n<p class=\"paywall\">Proponents of interoperability say the law will give consumers more choice and will allow third-party clients to build out extra functions. And while MEP Andreas Schwab, the lead negotiator for the DMA, says that the politicians are not looking to weaken encryption, cryptography experts are concerned the proposals will not be technically possible without compromising end-to-end encryption, potentially putting those billions of messages we send each other every day at risk.<\/p>\n<p class=\"paywall\">While end-to-end encryption has become seamless for people using messaging apps, no two apps implement encryption identically. WhatsApp <a data-offer-url=\"https:\/\/www.whatsapp.com\/security\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.whatsapp.com\/security&quot;}\" href=\"https:\/\/www.whatsapp.com\/security\" rel=\"nofollow noopener\" target=\"_blank\">uses a custom version of the Signal encryption protocol<\/a>, for example, but users still can\u2019t message each other across the apps. And while Apple\u2019s iMessage is interoperable with SMS, these standard text messages <a data-offer-url=\"https:\/\/support.apple.com\/en-us\/HT207006\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/support.apple.com\/en-us\/HT207006&quot;}\" href=\"https:\/\/support.apple.com\/en-us\/HT207006\" rel=\"nofollow noopener\" target=\"_blank\">aren\u2019t encrypted<\/a>.<\/p>\n<p class=\"paywall\">Many cryptographers and security experts have already pointed out <a data-offer-url=\"https:\/\/twitter.com\/AlecMuffett\/status\/1507134286255775749\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/twitter.com\/AlecMuffett\/status\/1507134286255775749&quot;}\" href=\"https:\/\/twitter.com\/AlecMuffett\/status\/1507134286255775749\" rel=\"nofollow noopener\" target=\"_blank\">flaws<\/a> <a data-offer-url=\"https:\/\/twitter.com\/alexstamos\/status\/1507145126006587411\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/twitter.com\/alexstamos\/status\/1507145126006587411&quot;}\" href=\"https:\/\/twitter.com\/alexstamos\/status\/1507145126006587411\" rel=\"nofollow noopener\" target=\"_blank\">in Europe\u2019s<\/a> <a data-offer-url=\"https:\/\/twitter.com\/benedictevans\/status\/1507246233181732867\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/twitter.com\/benedictevans\/status\/1507246233181732867&quot;}\" href=\"https:\/\/twitter.com\/benedictevans\/status\/1507246233181732867\" rel=\"nofollow noopener\" target=\"_blank\">plan<\/a>. \u201cInteroperable E2EE [end-to-end encryption] is somewhere between extraordinarily difficult and impossible,\u201d Steve Bellovin, one of the world\u2019s leading cryptographers and a former chief technologist at the Federal Trade Commission, <a data-offer-url=\"https:\/\/twitter.com\/SteveBellovin\/status\/1507375010054348805\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/twitter.com\/SteveBellovin\/status\/1507375010054348805&quot;}\" href=\"https:\/\/twitter.com\/SteveBellovin\/status\/1507375010054348805\" rel=\"nofollow noopener\" target=\"_blank\">tweeted<\/a> on Friday.<\/p>\n<p class=\"paywall\">\u201cWhen you start talking about different companies exchanging encrypted communications with one another, there are many serious considerations here that are extremely difficult to resolve,\u201d says Nadim Kobeissi, an applied cryptographer and founder of decentralized publishing platform Capsule Social. \u201cIt is very likely that there will be a serious degradation of the cryptographic techniques that will be necessary in order to accommodate this proposal,\u201d Kobeissi says.<\/p>\n<p class=\"paywall\">The proposals <a data-offer-url=\"https:\/\/www.europarl.europa.eu\/news\/en\/press-room\/20220315IPR25504\/deal-on-digital-markets-act-ensuring-fair-competition-and-more-choice-for-users\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.europarl.europa.eu\/news\/en\/press-room\/20220315IPR25504\/deal-on-digital-markets-act-ensuring-fair-competition-and-more-choice-for-users&quot;}\" href=\"https:\/\/www.europarl.europa.eu\/news\/en\/press-room\/20220315IPR25504\/deal-on-digital-markets-act-ensuring-fair-competition-and-more-choice-for-users\" rel=\"nofollow noopener\" target=\"_blank\">put forward as part of the DMA<\/a>\u2014which has yet to be fully published\u2014don\u2019t include technical details on how interoperability would work, but officials say the changes should be rolled out over a number of years. Basic features such as messages between two people should be implemented three months after a tech company is asked to provide them; audio and video calls have a four-year deadline.<\/p>\n<p class=\"paywall\">\u201cMaking end-to-end encrypted messaging apps interoperable is technically challenging and creates real risks for privacy, safety, and innovation,\u201d Will Cathcart, Meta\u2019s head of WhatsApp, said in a statement. \u201cChanges of this complexity risk turning a competitive and innovative industry into SMS or email, which is not secure and full of spam,\u201d he says. In an <a data-offer-url=\"https:\/\/www.platformer.news\/p\/three-ways-the-european-union-might?s=w\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.platformer.news\/p\/three-ways-the-european-union-might?s=w&quot;}\" href=\"https:\/\/www.platformer.news\/p\/three-ways-the-european-union-might?s=w\" rel=\"nofollow noopener\" target=\"_blank\">interview with tech journalist Casey Newton<\/a>, Cathcart said the move could cause misinformation problems and moderation issues for WhatsApp. \u201cI have a lot of concerns around whether this will break or severely undermine privacy, whether it&#x27;ll break a lot of the safety work we&#x27;ve done that we&#x27;re particularly proud of, and whether it&#x27;ll actually lead to more innovation and competitiveness,\u201d he said.<\/p>\n<p class=\"paywall\">Apple did not respond to a request for comment about encryption but said it has general concerns that parts of the DMA will create \u201cunnecessary privacy and security vulnerabilities.\u201d Signal did not respond to a request for comment.<\/p>\n<p class=\"paywall\">Not everyone is against interoperability and end-to-end encryption. Matrix, a nonprofit that\u2019s building an open source standard for encryption, has published <a data-offer-url=\"https:\/\/matrix.org\/blog\/2022\/03\/29\/how-do-you-implement-interoperability-in-a-dma-world\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/matrix.org\/blog\/2022\/03\/29\/how-do-you-implement-interoperability-in-a-dma-world&quot;}\" href=\"https:\/\/matrix.org\/blog\/2022\/03\/29\/how-do-you-implement-interoperability-in-a-dma-world\" rel=\"nofollow noopener\" target=\"_blank\">multiple<\/a> <a data-offer-url=\"https:\/\/matrix.org\/blog\/2022\/03\/25\/interoperability-without-sacrificing-privacy-matrix-and-the-dma\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/matrix.org\/blog\/2022\/03\/25\/interoperability-without-sacrificing-privacy-matrix-and-the-dma&quot;}\" href=\"https:\/\/matrix.org\/blog\/2022\/03\/25\/interoperability-without-sacrificing-privacy-matrix-and-the-dma\" rel=\"nofollow noopener\" target=\"_blank\">blog posts<\/a> outlining how it believes the EU&#x27;s proposals could work. \u201cThe main challenge is the trade-off between interoperability and privacy for gatekeepers who provide end-to-end encryption,\u201d the team behind Matrix say.<\/p>\n<p class=\"paywall\">There are broadly two routes that could allow encryption to work across apps operated by different companies. The first involves tech companies allowing access to APIs that connect to their messaging services\u2014this is the option Schwab and lawmakers are leaning toward. The second involves more radical change: All companies would have to adopt and implement one universal encryption standard.<\/p>\n<p class=\"paywall\">Neither is easy.<\/p>\n<p class=\"paywall\">Connecting to an open API could involve a company using a \u201cbridge\u201d that joins the two platforms together. Signal would, for instance, have to implement multiple bridges if it wanted to work with different apps. \u201cEvery device has to speak every language, but at least users have the building blocks to get at each other\u2019s messages, rather than then being arbitrarily locked away by the gatekeepers,\u201d Ian Brown, a visiting professor at Funda\u00e7\u00e3o Getulio Vargas Law School in Rio de Janeiro, <a data-offer-url=\"https:\/\/interoperability.news\/2022\/03\/end-to-end-encrypted-group-chats-and-interoperability\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/interoperability.news\/2022\/03\/end-to-end-encrypted-group-chats-and-interoperability\/&quot;}\" href=\"https:\/\/interoperability.news\/2022\/03\/end-to-end-encrypted-group-chats-and-interoperability\/\" rel=\"nofollow noopener\" target=\"_blank\">wrote for Interoperability News<\/a>.<\/p>\n<p class=\"paywall\">Using a bridge would involve decrypting messages, potentially on someone\u2019s device, and then making them appear in the destination app. Removing the end-to-end encryption would open up a new layer that could be attacked by hackers or malicious actors. \u201cHow do you guarantee that the things sitting next to your messaging app are benevolent and not malicious,\u201d says Robin Wilton, director of internet trust at the Internet Society. Kobeissi adds that it\u2019s unclear under the proposals who would <a href=\"https:\/\/www.wired.com\/2014\/11\/hacker-lexicon-end-to-end-encryption\/\">manage the exchange of public encryption keys<\/a> and how cryptographic metadata would be shared between companies. If Signal and iMessage become interoperable, which one changes its encryption to match the other?<\/p>\n<p class=\"paywall\">One of the biggest unanswered questions is how interoperability would ensure you are chatting with the people you think you are. People use different usernames on each platform, and not knowing who someone is could lead to identity issues, explains Alan Duric, cofounder of encrypted messaging app Wire. \u201cIf you\u2019re communicating across Wire and WhatsApp, how can the Wire user be certain that the person they are talking to on WhatsApp is authentic?\u201d he says. \u201cHow can they be sure the person they&#x27;re talking to is even using WhatsApp at all?\u201d Duric says this can be combated by verifying each user&#x27;s identity, which can then help reduce abuse and spam.<\/p>\n<p class=\"paywall\">Those in favor of interoperability say the best way to do this would be for all companies to adopt one encryption standard and stick to it. These standards already exist\u2014for instance, the <a data-offer-url=\"https:\/\/matrix.org\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/matrix.org\/&quot;}\" href=\"https:\/\/matrix.org\/\" rel=\"nofollow noopener\" target=\"_blank\">Matrix messaging protocol<\/a>, the <a data-offer-url=\"https:\/\/xmpp.org\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/xmpp.org\/&quot;}\" href=\"https:\/\/xmpp.org\/\" rel=\"nofollow noopener\" target=\"_blank\">XMPP<\/a> standard, and the upcoming <a data-offer-url=\"https:\/\/messaginglayersecurity.rocks\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/messaginglayersecurity.rocks\/&quot;}\" href=\"https:\/\/messaginglayersecurity.rocks\/\" rel=\"nofollow noopener\" target=\"_blank\">Messaging Layer Security<\/a>. \u201cIf every player in the field\u2014so the gatekeepers but also the smaller player\u2014all connect to the same standard, it ends up being a big glue between the different services,\u201d says Amandine Le Pape, a cofounder of the Matrix standard. This would avoid companies implementing APIs via a piecemeal process, although this isn\u2019t what the European Union has opted for at the moment. \u201cThe DMA is just the first step,\u201d Le Pape says.<\/p>\n<p class=\"paywall\">Getting all messaging apps to use one standard would be a significant, time-consuming challenge. \u201cPotentially, you could just have a situation where everyone switches to Matrix,\u201d Kobeissi says. \u201cBut Matrix is a fundamentally different security architecture, not just from an end-to-end encryption perspective, but also from a threat modeling perspective.\u201d Each app faces different potential attacks against it\u2014based on its user base and operations\u2014so moving to one model would require companies to reassess how their users could be compromised.<\/p>\n<p class=\"paywall\">Companies would have to rebuild their entire encryption systems and change multiple features in their apps, a process that could take years. Take Meta: In 2019, the company said it was going to make Instagram DMs and Messenger end-to-end encrypted by default and integrate their infrastructure with WhatsApp. Three years later, the company is still trying to <a data-offer-url=\"https:\/\/techcrunch.com\/2021\/12\/01\/meta-explains-its-approach-to-user-safety-following-delayed-rollout-of-end-to-end-encryption\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/techcrunch.com\/2021\/12\/01\/meta-explains-its-approach-to-user-safety-following-delayed-rollout-of-end-to-end-encryption\/&quot;}\" href=\"https:\/\/techcrunch.com\/2021\/12\/01\/meta-explains-its-approach-to-user-safety-following-delayed-rollout-of-end-to-end-encryption\/\" rel=\"nofollow noopener\" target=\"_blank\">untangle its systems and add safety features<\/a>. The transition has been harder than expected\u2014and Meta controls all of the technology involved.<\/p>\n<p class=\"paywall\">Ultimately, how much companies change may come down to the technical realities and the degree of pressure the European Commission, which will enforce the DMA, puts on them. Like <a href=\"https:\/\/www.wired.co.uk\/article\/what-is-gdpr-uk-eu-legislation-compliance-summary-fines-2018\">GDPR<\/a>, the DMA could lead to multimillion-dollar fines for businesses that don&#x27;t comply. However, GDPR has been poorly enforced\u2014including a provision that says people should be able to transport their data from one app to another. Tech companies may have no choice if the European Commission enforces the DMA\u2014but that could be the least of their worries.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/dma-interoperability-messaging-imessage-whatsapp\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/62432d8648046e8802c9c4fb\/master\/pass\/032822_WhatsAppiMessage.jpg\"\/><\/p>\n<p><strong>Credit to Author: Matt Burgess| Date: Tue, 29 Mar 2022 16:06:52 +0000<\/strong><\/p>\n<p>Europe\u2019s Digital Markets Act requires interoperability between popular messaging apps. But experts warn encryption could be compromised.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21382],"class_list":["post-18620","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-privacy"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18620","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18620"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18620\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18620"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18620"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18620"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}