Hacker News new | ask | show | jobs
by llm_nerd 930 days ago
Yes, it does. RCS without E2E is following the SMS model and putting your telco in charge. It uses transport encryption but that is basically meaningless when every relay sees the entire contents of the message.
1 comments

Does that mean Stingrays and just regular old SDRs can still pick up RCS messages?
RCS uses transport encryption and I honestly have no idea if it uses cert pinning or server certs or the like. The bigger concern to me is that it puts your telco in charge, just like the old days of SMS. Without E2E they get to see all of the contents of messages and to share it with whoever they deem they want to share it with, which history has shown is too many people. Telcos were very willing partners in the development of RCS for a reason. And there's a reason the base spec doesn't include E2E. Telcos want a return to the good old days.

SMS is insecure and no one should use it. RCS isn't that much better and history is a lesson that it returns to a partner that isn't trustworthy.