European lawmakers have ruled that users on different platforms should be able to exchange messages with each other. Yet messaging interoperability opens up a Pandora's box of security and privacy challenges. While championed not just as an anti-trust measure but as a means of providing a better experience for the end user, interoperability runs the risk of making the user experience worse if poorly executed. There are two fundamental questions: how to enable the actual message exchange, and how to handle the numerous residual challenges arising from encrypted messages passing from one service provider to another -- including but certainly not limited to content moderation, user authentication, key management, and metadata sharing between providers. In this work, we identify specific open questions and challenges around interoperable communication in end-to-end encrypted messaging, and present high-level suggestions for tackling these challenges.
翻译:欧洲立法者已裁定,不同平台的用户应能相互发送消息。然而,消息传递的互操作性打开了安全与隐私挑战的潘多拉魔盒。尽管互操作性不仅被作为反垄断措施,还被视为改善终端用户体验的手段,但若执行不当,反而可能使用户体验恶化。这带来两个根本性问题:如何实现实际的消息交换,以及如何处理加密消息从一个服务提供商传递到另一个时产生的诸多剩余挑战——包括但不限于内容审核、用户认证、密钥管理以及提供商之间的元数据共享。在本研究中,我们明确了端到端加密消息传递中围绕可互操作通信的具体未解决问题与挑战,并提出了应对这些挑战的高层次建议。