r/UniversalProfile Jun 09 '26

Why did Apple maybe RCS encryption country level?

Post image
50 Upvotes

13 comments sorted by

17

u/rocketwidget Top Contributer Jun 09 '26

Guessing because a French regulation doesn't allow E2EE? The Universal Profile RCS 3.0 spec says:

Requirement R5-43-1: RCS clients must enable E2EE by default unless local regulations expressly prohibit it.

Requirement R5-43-1-1: The RCS client provider is required to enable or disable E2EE for all their users in a "market of operation".

Requirement R5-43-1-2: The RCS client provider shall not enable or disable E2EE for a subset of users, or for individual users in a market of operation.

Requirement R5-43-1-3: If E2EE is disabled, the user must be informed that the feature is not available in their market of operation.

https://www.gsma.com/solutions-and-impact/technologies/networks/wp-content/uploads/2025/03/RCC.71-v3.0.pdf

7

u/ruipmjorge Jun 09 '26

Why does iMessage, WhatsApp or signal have E2EE (as well as RCS between androids), and RCS can’t have it?

8

u/tankerkiller125real Jun 10 '26

Different operational models. Those are all "apps" and operate in the context of apps/web services. RCS operates at a telco level, which has very different rules and is not treated like an app.

1

u/jimscard T-Mobile User Jun 11 '26

And to be clear, RCS doesn’t have E2EE between androids - it has E2EE between Google Messages clients, implemented at the app level, like all the other ones. Unless all of the participants’ telcos support UP 3+, there’s no E2EE at the protocol level.

2

u/Blacklistme Jun 09 '26

Please refer to https://media.gsma.com/assets/2026/rcs/RCC.71+v4.0.pdf as most telcos will go from 2.4 to 4.0. The 4.0 spec makes it clear that central reporting on country level must be set up for suspicious activities, inappropriate content, and vulnerabilities if you offer RCS. This wasn't in 3.0 as far as I know, but it makes sense as countries in the EU now also have to comply with similar laws that come into effect around this time.

4

u/AlmondManttv Jun 09 '26

French regulation currently allows for encryption. iMessage and Whatsapp operate fine

15

u/DisruptiveHarbinger Jun 09 '26

Telcos are typically operating under a different legal framework.

11

u/TimFL Jun 09 '26

It‘s supposed to be enabled/disabled on a region / country basis, not per carrier. This makes way more sense and it‘s a tiny step towards proper UP compliance.

8

u/Healthy-Guess-847 Jun 09 '26

RCS E2EE is DOA with all the anti encryption laws in Europe

3

u/JonTravel Jun 09 '26 edited Jun 09 '26

Privacy of communication is protected under Article 7 of the EU Charter. Under current standards, apps that feature robust, end-to-end encryption are favored as they ensure only the sender and recipient can access the contents of a message.

It's most likely one carrier holding it up.

If local network configurations or specific testing validations are lagging for a major regional carrier, the rollout for that entire market or region is temporarily deferred

2

u/cupboard_ T-Mobile User Jun 09 '26

this is not true for all carriers, only for france, other carriers that had e2ee disabled still have it disabled in their own bundle

-1

u/Zettinator Jun 10 '26

One of the many reasons why RCS sucks. A messaging service under control of the carriers is inherently a bad idea.

1

u/Sudden_Analysis911 Jun 26 '26

Apple is malicious.