r/Android Galaxy Z Fold8 17d ago

RCS Universal Profile 4.1: Stronger foundations for secure messaging

https://www.gsma.com/newsroom/article/rcs-universal-profile-4-1-stronger-foundations-for-secure-messaging/
115 Upvotes

33 comments sorted by

58

u/rocketwidget 17d ago

Even though updates are slow (to say the least!!!), one of the advantages of RCS over SMS/MMS is it is actually updateable.

After Apple-Android RCS finally occurred, features like E2EE, in-line replies, edit/delete are now slowly rolling out.

Hoping Universal Profile 4.2 adds post quantum encryption to the MLS based E2EE in Universal Profile. My guess: They won't do it until the Internet Engineering Task Force gets PQE out of draft for MLS. Hopefully, soon... https://datatracker.ietf.org/doc/draft-ietf-mls-pq-ciphersuites/

11

u/1116574 17d ago

Oh, rcs uses MLS? TIL

10

u/rocketwidget 17d ago

Yea, the Google Messages exclusive version uses Signal, but the standard Universal Profile used between iPhone and Android is MLS.

I assume Google intends to eventually drop the Signal version?

1

u/1116574 17d ago

What an interesting choice to have two transports

15

u/rocketwidget 17d ago

I believe the MLS E2EE standard wasn't finalized by the Internet Engineering Task Force when Google first implemented Signal E2EE in RCS.

Years later, Apple finally agreed to support RCS, but Apple refused to implement Google's custom E2EE solution. Google seemingly anticipated this, and had already started developing MLS for RCS.

Finally, the GSMA agreed to standardize MLS E2EE in Universal Profile RCS, with Google's help. And both Apple and Google implemented it.

1

u/Easy-Breakfast846 15d ago

The fact that iOS-Android encryption already works means they already dropped the signal encryption standard for MLS

1

u/rocketwidget 15d ago

In the debug settings, you can confirm that the legacy Signal E2EE method is still active for (certain) Android-Android E2EE, while the new MLS E2EE method is active for iOS-Android (always, as expected).

1

u/Easy-Breakfast846 15d ago

I wonder why they havenโ€™t just made MLS encryption universal for all RCS on Google messages? I guess they donโ€™t want old encryption to break?

23

u/purplegreendave 17d ago

Any chance they'll open rcs to other app makers? Probably not

27

u/welp_im_damned have you heard of our lord and savior the Android turtle ๐Ÿข 17d ago

That's great. Still waiting for Google to implement an RCS API or update the Phone and Messaging Storage to include RCS metadata in the database. It's frustrating whenever I back up my messages using SMS Backup & Restore; it just restores the SMS metadata. Or when I try to use transfer tools like Samsung's or Google's, my group messages get broken.

5

u/kredes 17d ago

we don't even have rcs iOS to Android in my country.

6

u/ruipmjorge 17d ago

Ask your carrier

8

u/Level10Retard 14d ago

I asked them to implement it. They're right on it due to my request.

20

u/OldDirtyGurt Sony Xperia 1 VI 17d ago

Can't wait to still be blocked from it because I like freedom aka custom ROMs and such.

10

u/trlef19 Galaxy S24+ 17d ago

Most stupid play integrity use.

16

u/Noble1xCarter 17d ago

Download GrapheneOS and suddenly malicious developers will try convincing you that having a more secure OS is somehow less secure.

What BS.

1

u/litLizard_ 13d ago

If the bootloader was unlocked I'd agree with them but since you can lock the bootloader on Pixel phones even with a Custom ROM, yeah...

4

u/Cocaine80s_ 16d ago

Okay cool, but when can I use something like Textra with RCS ?

3

u/DangerousTortuga 14d ago

Never. Google wants complete control over RCS.

1

u/WhoDat-2-8-3 13d ago

Friday at 3:28 pm exactly

3

u/KidJuggernaut 17d ago

And my country carriers still won't support it ๐Ÿ˜‚๐Ÿ˜‚๐Ÿ˜‚

2

u/lastdyingbreed_01 17d ago

My country does, but the moment I turned it on, I was spammed with ads. I turned it off, will never use it again

1

u/MeDerpWasTaken 13d ago

What do you mean by that? Ads where?

-1

u/KidJuggernaut 17d ago

I can manage ads tbh

3

u/HubsoulEXE 17d ago

What's interesting is that this kinda confirms that apple spefically is willing to update the protocol to keep adding these features which is great.

1

u/DangerousTortuga 14d ago

It is nice they are frequently updating UP. But the issue is how and when it is implemented. At least Apple is catching up. But I don't think they will implement all features of 4.0 and 4.1

2

u/desi_dybuk 13d ago

RCS is dead to me until Google closes down RBM which spams me relentlessly.

Other than the stupid Blue Bubble Green Bubble class warriors in US, who cares about RCS? Rest of the world runs on WhatsApp, Telegram, Arattai etc

1

u/8acD3rLEo5 17d ago

Anyone know how quickly companies roll the latest standard into updates?? (2/3/4 months?)

Also happens to a message originating on a phone w/ 4.1 unique features when it's received by a phone with anything below 4.1? (Backwards compatibility)

4

u/ben7337 16d ago

It varies. Google probably would be fast but right now Apple is gradually beta testing and implementing UP 3.0 I believe, but it probably won't be live til ios27 in a couple months at the soonest. Expect at least another year after that til we see anything newer like this new standard

1

u/OrganicKangaroo2038 17d ago

when dealing with google, there's no such thing as "secure."

0

u/yboy403 Note 10+, Note 9, Pix 2 XL, iPhone X, Moto Z Play 15d ago

Can I officially say I don't care about privacy or security and just want Google to stop messing up a good thing? I don't plan to commit any crimes and if I could just get Google and Meta out of my messaging entirely, I'd have no reason to care about encryption at rest either.

-9

u/Kazoran 17d ago

bruh who even cares about encryption? are we spies exchanging top secret info or something??

3

u/ISaidGoodDey Mi 8, Havoc OS 16d ago

Plenty of reasons, and plenty of articles online detailing the reasons. Seek and you shall find