European lawmakers have ruled that users on different platforms should be able to exchange messages with each other. Yet messaging interoperability opens up a Pandora's box of security and privacy challenges. While championed not just as an anti-trust measure but as a means of providing a better experience for the end user, interoperability runs the risk of making the user experience worse if poorly executed. There are two fundamental questions: how to enable the actual message exchange, and how to handle the numerous residual challenges arising from encrypted messages passing from one service provider to another -- including but certainly not limited to content moderation, user authentication, key management, and metadata sharing between providers. In this work, we identify specific open questions and challenges around interoperable communication in end-to-end encrypted messaging, and present high-level suggestions for tackling these challenges.
翻译:欧洲立法者已经裁定,不同平台的用户应该能够相互交换消息。然而,消息互操作性开启了一盒安全和隐私挑战的潘多拉魔盒。虽然不仅作为一种反垄断措施,而且作为为最终用户提供更好体验的手段,互操作性存在执行不当的风险,可能会使用户体验变差。有两个基本问题:如何实现实际消息交换,以及如何处理加密消息从一个服务提供商传递到另一个服务提供商所引发的许多剩余挑战,包括但不限于内容审查、用户认证、密钥管理和提供商之间的元数据共享。在这项工作中,我们确定了有关端到端加密消息中互操作交流的具体未解决问题和挑战,并提出了解决这些挑战的高级建议。