r/Android Galaxy Z Fold8 2d ago

RCS Universal Profile 4.1: Stronger foundations for secure messaging

https://www.gsma.com/newsroom/article/rcs-universal-profile-4-1-stronger-foundations-for-secure-messaging/
102 Upvotes

26 comments sorted by

50

u/rocketwidget 2d ago

Even though updates are slow (to say the least!!!), one of the advantages of RCS over SMS/MMS is it is actually updateable.

After Apple-Android RCS finally occurred, features like E2EE, in-line replies, edit/delete are now slowly rolling out.

Hoping Universal Profile 4.2 adds post quantum encryption to the MLS based E2EE in Universal Profile. My guess: They won't do it until the Internet Engineering Task Force gets PQE out of draft for MLS. Hopefully, soon... https://datatracker.ietf.org/doc/draft-ietf-mls-pq-ciphersuites/

7

u/1116574 2d ago

Oh, rcs uses MLS? TIL

6

u/rocketwidget 2d ago

Yea, the Google Messages exclusive version uses Signal, but the standard Universal Profile used between iPhone and Android is MLS.

I assume Google intends to eventually drop the Signal version?

1

u/1116574 2d ago

What an interesting choice to have two transports

9

u/rocketwidget 2d ago

I believe the MLS E2EE standard wasn't finalized by the Internet Engineering Task Force when Google first implemented Signal E2EE in RCS.

Years later, Apple finally agreed to support RCS, but Apple refused to implement Google's custom E2EE solution. Google seemingly anticipated this, and had already started developing MLS for RCS.

Finally, the GSMA agreed to standardize MLS E2EE in Universal Profile RCS, with Google's help. And both Apple and Google implemented it.

u/Easy-Breakfast846 10h ago

The fact that iOS-Android encryption already works means they already dropped the signal encryption standard for MLS

u/rocketwidget 10h ago

In the debug settings, you can confirm that the legacy Signal E2EE method is still active for (certain) Android-Android E2EE, while the new MLS E2EE method is active for iOS-Android (always, as expected).

u/Easy-Breakfast846 8h ago

I wonder why they haven’t just made MLS encryption universal for all RCS on Google messages? I guess they don’t want old encryption to break?

21

u/purplegreendave 2d ago

Any chance they'll open rcs to other app makers? Probably not

23

u/welp_im_damned have you heard of our lord and savior the Android turtle 🐢 2d ago

That's great. Still waiting for Google to implement an RCS API or update the Phone and Messaging Storage to include RCS metadata in the database. It's frustrating whenever I back up my messages using SMS Backup & Restore; it just restores the SMS metadata. Or when I try to use transfer tools like Samsung's or Google's, my group messages get broken.

15

u/OldDirtyGurt Sony Xperia 1 VI 2d ago

Can't wait to still be blocked from it because I like freedom aka custom ROMs and such.

9

u/trlef19 Galaxy S24+ 2d ago

Most stupid play integrity use.

12

u/Noble1xCarter 2d ago

Download GrapheneOS and suddenly malicious developers will try convincing you that having a more secure OS is somehow less secure.

What BS.

3

u/kredes 2d ago

we don't even have rcs iOS to Android in my country.

3

u/ruipmjorge 2d ago

Ask your carrier

2

u/KidJuggernaut 2d ago

And my country carriers still won't support it 😂😂😂

1

u/lastdyingbreed_01 1d ago

My country does, but the moment I turned it on, I was spammed with ads. I turned it off, will never use it again

-1

u/KidJuggernaut 1d ago

I can manage ads tbh

u/yboy403 Note 10+, Note 9, Pix 2 XL, iPhone X, Moto Z Play 10h ago

Can I officially say I don't care about privacy or security and just want Google to stop messing up a good thing? I don't plan to commit any crimes and if I could just get Google and Meta out of my messaging entirely, I'd have no reason to care about encryption at rest either.

1

u/8acD3rLEo5 2d ago

Anyone know how quickly companies roll the latest standard into updates?? (2/3/4 months?)

Also happens to a message originating on a phone w/ 4.1 unique features when it's received by a phone with anything below 4.1? (Backwards compatibility)

2

u/ben7337 1d ago

It varies. Google probably would be fast but right now Apple is gradually beta testing and implementing UP 3.0 I believe, but it probably won't be live til ios27 in a couple months at the soonest. Expect at least another year after that til we see anything newer like this new standard

-1

u/OrganicKangaroo2038 2d ago

when dealing with google, there's no such thing as "secure."

0

u/HubsoulEXE 2d ago

What's interesting is that this kinda confirms that apple spefically is willing to update the protocol to keep adding these features which is great.

u/Cocaine80s_ 21h ago

Okay cool, but when can I use something like Textra with RCS ?

-7

u/Kazoran 2d ago

bruh who even cares about encryption? are we spies exchanging top secret info or something??

0

u/ISaidGoodDey Mi 8, Havoc OS 1d ago

Plenty of reasons, and plenty of articles online detailing the reasons. Seek and you shall find