Has there been any news on whether or not E2EE will be enabled by default for iMessage ā RCS communication once this is fully released?
I know this feature rollout depends on carrier support also, but it would be cool to see E2EE for iMessage ā RCS enabled by default on supported carriers.
Pretty bitter sweet. Obviously encryption is better than no encryption. Though this will likely mean the end of being able to use a GrapheneOS phone without play services always running - at least while telling yourself youāre not giving up anything privacy/security wise.
To get RCS to work, you need Play Services and Google Messages both installed on your Owner profile. You need to also hand over network, phone, and, SMS permissions, and likely device identifiers to Google (depending on carrier).
If you intend to know whoās texting you, then you need to provide permission to contacts as well. It would be pretty ridiculous declare contact scopes for each person that you message. Iād have to declare hundreds just to read old Messages.
At that point, why even bother storing your contacts outside of Google if youāre going to let them see your contacts anyway. Even without signing into an account for Google Messages, theyāll still be able fingerprint you off your phone number, device identifiers, IP addresses etc.
Might as well use Google Voice at that point due to already trusting Google with your contacts, phone, and messages.
And just like that, youāre back in the Google ecosystem.
This might be a usage difference, but instead of handing over the entire contact permission Iāve generally found it suitable to instead use the contact scopes feature to limit my exposed contacts in Google Messages/other SMS or instant/internet messengers.
This way I know if one of my ātrusted contactsā is trying to text me, but I donāt have to hand over my entire phone book.
Of these issues I think having to expose your persistent device identifiers to Google is possible the worst issue.
Whilst any enhancements to privacy (or at least finally adopting e2eeā¦), itās still not something Iāll be turning on and using. Iām not comfortable with Google at all. Further, it will collect metadata in the same way that WhatsApp does - and I donāt have WhatsApp for this reason, either - coupled with you having to trust closed source proprietaries.
Great if people are using it as it is an enhancement, just not for me nor those in the U.K.
OFF TOPIC
Largely off-topic as this has nothing to do with e2ee (per se - but it does when it concerns Apple in the U.K.), but Apple doesnāt currently allow automatic deletion of messages for less than 30 days. Iām not sure how this would differ with RCS in fairness, but I donāt like this time period. All of my Signal chats ādisappearā within hours and prior to typical backup periods.
For U.K. users, and whilst appreciating you cannot change things beyond your control and rely on your contacts settings, it is worth considering your threat model - particularly as ADP is no longer available in the U.K. due to the totalitarian government. If your contact backs-you-up, you have an issue.
IMO Apple should make deletion of messages customisable and applicable to the specific chat not the user settings.