One Protocol to Rule Them All? On Securing Interoperable Messaging

03/24/2023
by   Jenny Blessing, et al.
0

European lawmakers have ruled that users on different platforms should be able to exchange messages with each other. Yet messaging interoperability opens up a Pandora's box of security and privacy challenges. While championed not just as an anti-trust measure but as a means of providing a better experience for the end user, interoperability runs the risk of making the user experience worse if poorly executed. There are two fundamental questions: how to enable the actual message exchange, and how to handle the numerous residual challenges arising from encrypted messages passing from one service provider to another – including but certainly not limited to content moderation, user authentication, key management, and metadata sharing between providers. In this work, we identify specific open questions and challenges around interoperable communication in end-to-end encrypted messaging, and present high-level suggestions for tackling these challenges.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/11/2020

Session: A Model for End-To-End Encrypted Conversations With Minimal Metadata Leakage

Session is an open-source, public-key-based secure messaging application...
research
08/29/2020

A Formal Security Analysis of the pEp Authentication Protocol for Decentralized Key Distribution and End-to-End Encrypted Email

To send encrypted emails, users typically need to create and exchange ke...
research
05/14/2018

AuthStore: Password-based Authentication and Encrypted Data Storage in Untrusted Environments

Passwords are widely used for client to server authentication as well as...
research
02/05/2018

Improving Privacy and Trust in Federated Identity Using SAML with Hash Based Encryption Algorithm

Cloud computing is an upcoming technology that has been designed for com...
research
06/02/2023

Committee Moderation on Encrypted Messaging Platforms

Encrypted messaging services like WhatsApp, Facebook Messenger, and Sign...
research
09/09/2021

Fighting Fake News in Encrypted Messaging with the Fuzzy Anonymous Complaint Tally System (FACTS)

Recent years have seen a strong uptick in both the prevalence and real-w...
research
09/03/2020

Robust Homomorphic Video Hashing

The Internet has been weaponized to carry out cybercriminal activities a...

Please sign up or login with your details

Forgot password? Click here to reset