European lawmakers have ruled that users on different platforms should be able to exchange messages with each other. Yet messaging interoperability opens up a Pandora's box of security and privacy challenges. While championed not just as an anti-trust measure but as a means of providing a better experience for the end user, interoperability runs the risk of making the user experience worse if poorly executed. There are two fundamental questions: how to enable the actual message exchange, and how to handle the numerous residual challenges arising from encrypted messages passing from one service provider to another -- including but certainly not limited to content moderation, user authentication, key management, and metadata sharing between providers. In this work, we identify specific open questions and challenges around interoperable communication in end-to-end encrypted messaging, and present high-level suggestions for tackling these challenges.
翻译:欧洲立法者已裁定,不同平台上的用户应能够相互交换消息。然而,消息互操作性打开了安全与隐私挑战的潘多拉魔盒。尽管互操作性不仅被视为反垄断措施,更是为终端用户提供更好体验的手段,但如果执行不当,互操作性可能反而使用户体验恶化。这里存在两个根本性问题:如何实现实际的消息交换,以及如何处理加密消息从一个服务提供商传递到另一个服务提供商时产生的众多残留挑战——包括但不限于内容审核、用户身份验证、密钥管理以及提供商之间的元数据共享。在本工作中,我们识别了端到端加密消息中围绕可互操作通信的具体开放问题和挑战,并提出了应对这些挑战的高层次建议。