/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Security experts worry that the EU's DMA, which mandates messaging app interoperability, will undermine the end-to-end encryption on WhatsApp and other services

Big names in internet security have been fiercely critical of the new DMA legislation  —  On March 24th, EU governing bodies announced …

The Verge Corin Faife

Context & Ripple Effects

The DMA agreement paired messaging interoperability with broader limits on bundling and self-preferencing, making cross-service communication a regulatory requirement rather than a voluntary product feature. Security experts’ objection centers on whether that access requirement can coexist with end-to-end encryption.

The concern later became operational when Meta outlined WhatsApp and Messenger interoperability using Signal’s protocol. It also fits a wider European policy conflict: Signal’s president subsequently argued that proposed upload moderation would undermine messaging encryption.

First-order effects

  • WhatsApp and other covered messaging services must reconcile interoperability requirements with the security design of their encrypted services, placing their protocol choices under regulatory and expert scrutiny.
  • Third-party messaging providers gain a route to connect with incumbent services, but must meet the technical conditions set for encrypted exchanges.

Second-order effects

  • Meta’s eventual use of Signal’s protocol makes encryption protocol compatibility a practical gatekeeper for third-party access, not merely a back-end implementation detail.
  • The debate increases pressure on EU rulemakers to distinguish interoperability obligations from measures that would require access to message content or weaken encryption guarantees.

Third-order effects

  • If interoperability is implemented through common secure protocols, competitive advantage in messaging shifts partly from closed user networks toward the governance and adoption of shared technical standards.
  • European digital rules are forming a recurring test of whether platform openness and privacy protections can be enforced together, as shown by the separate dispute over upload moderation.

The trend: European platform regulation is pushing encrypted messaging toward interoperable standards while turning encryption-preserving implementation into the central policy constraint.

Discussion

  • @benedictevans Benedict Evans on x
    Going through the final draft of the EU's Digital Markets Act, I am making a list of how many times it says you must do something that weakens privacy or security without weakening privacy or security. Apparently trade-offs can just magically disappear if you say so https://twitt…
  • @benedictevans Benedict Evans on x
    If I install a third-party Facebook messenger app, it can see all of my chats with you and all of your data that I can see. So your data goes to a third-party company where Facebook has no control - and where you didn't give me any consent. How does that work?
  • @dymaxion Eleanor Saitta on x
    In particular, the EU DMA will effectively prevent end to end encryption of popular commercial instant messaging platforms. This was not intended, but it is as far as I can tell a necessary correlate of the required features. This is catastrophically dumb.
  • @jason_kint Jason Kint on x
    Lol. I see the Facebook-complex is now officially freaking out about the DMA - much of the text which has been negotiated and tweaked over the last year - and threatens them. 1/3
  • @jessicalennard Jessica Lennard on x
    @benedictevans Competition policy, inc. digital markets & open data are always going to pose problems for privacy & security. EU is only region really pushing for both, so we are going to see these tensions play out here first. They're all important aims.
  • @reneritchie Rene Ritchie on x
    I'm more concerned about my data going to Facebook, tbh Conflating “open” with choice and “closed” with no choice gaslights those for whom “closed” was a deliberate choice Big tech should absolutely have gotten ahead of this but big media should have been more nuanced as well htt…
  • @benedictevans Benedict Evans on x
    Of course, nobody will actually approve all of this all these swarms of consent notifications, so none of the third-party apps will be able to get any traction. And all you've actually done is move a network effect from the app install to the privacy consent.
  • @dymaxion Eleanor Saitta on x
    There is a world where everyone switches to federated open source e2e messaging tools, but between network effects, marketing, and the level of usability polish required to make something scale, it's unlikely to be this one. E2E in commercial messengers is harm reduction.
  • @dymaxion Eleanor Saitta on x
    It'd be nice if the EU talked to the engineers who built a technology in good faith (on both sides) and then took those considerations into account before regulating it. It'd also be nice if tech companies didn't try to extract money at any possible cost to society. Sadly...
  • @evefavretto @evefavretto on x
    Cry me a river https://twitter.com/...
  • @gripusa Usman Bashir on x
    This is such a bad excuse, encryption is/should be peer to peer which means you can ensure if keys can be exchange that encryption can be sustain. Even in worse case, it's user choice to use a destination which isn't secure . Scaremongering is being done to push this legislation …
  • @dymaxion Eleanor Saitta on x
    It's one thing to pass laws that upset current business models and force changes — that can be great, unless you forget to enforce them or fail to understand the implications. It's another thing to pass laws that are technically incoherent and unimplementable in reality.
  • @futureidentity Robin Wilton on x
    If by ‘interoperability’ the European Commission means that otherwise secure systems agree to talk to each other over a lowest-common-denominator, insecure side channel, I will, as they say, follow their future progress with great curiosity. https://twitter.com/...
  • @corintxt @corintxt on x
    On the other side of the debate, I also heard from Matthew Hodgson (@ara4n) of @matrixdotorg - an open source project working on secure decentralized messaging. Read his pro-interoperability blog post here: https://matrix.org/... https://twitter.com/...
  • @mshelton @mshelton on x
    Well this looks bad. While smaller encrypted messengers like Signal should not be affected, the Digital Markets Act's interoperability requirements necessarily mean dismantling WhatsApp's encryption promises. https://www.theverge.com/...
  • @corintxt @corintxt on x
    I spoke to @alexstamos, @AlecMuffett + @SteveBellovin about their concerns with the EU's new #DMA legislation, which mandates interoperability between messaging apps. https://twitter.com/...
  • @jason_kint Jason Kint on x
    aka “I spoke to two previous Facebook security execs during a period where Facebook widely abused massive amounts of consumer data and covered it up...” 2/3 https://twitter.com/...
  • @riptari Natasha on x
    For a more nuanced take: “On balance, we think that the benefits of mandating open APIs outweigh the risks that someone is going to run a vulnerable large-scale bridge and undermine everyone's E2EE” https://matrix.org/...
  • @matrixdotorg @matrixdotorg on x
    Lots of excitement today with confirmation of the EU's breakthrough #DMA legislation, mandating that big tech must provide documented open comms APIs. 🎉🎊😱 But there's also been concern that open APIs could undermine E2E encryption: our viewpoint is at https://matrix.org/...
  • @benedictevans Benedict Evans on x
    The most likely outcome - if you install a new Facebook messenger app, all the 500 people you have friended get a consent banner the next time they open the app. Cookie banners x 1000
  • @benedictevans Benedict Evans on x
    @JessicaLennard Everyone understands that we want both. The EU is writing laws that claim there's no trade-off
  • @benedictevans Benedict Evans on x
    Meanwhile, how does a messaging service address any of the things we scream at them for, around harmful content, toxic behaviour and misinformation, if they are no longer able to control the user interface?
  • @runasand Runa Sandvik on x
    Good article about the security and privacy implications of mandating interoperability in messaging apps. https://www.theverge.com/...
  • @alecmuffett Alec Muffett on x
    > “iMessage already has interop: it's called SMS, and users really dislike it,” said @AlexStamos. “And it has really bad security properties that aren't explained by green bubbles.” https://twitter.com/...
  • @benedictevans Benedict Evans on x
    This one still honestly baffles me. How does a messaging app give any third-party that asks unrestricted access to user data on the same basis as an internal team, and yet also a guarantee of security and data protection. What does that mean? https://twitter.com/...
  • @can @can on x
    speaking of WhatsApp, their horny ads in downtown SF is a...vibe [WhatsApp ad: “Took out cash for tonight, see you soon"]
  • @caseynewton Casey Newton on x
    No one seems to know exactly what the EU is going to require messaging apps to do to become interoperable. But there's a lot to worry about — I talked to WhatsApp's @wcathcart about some of the big concerns https://www.platformer.news/ ... https://twitter.com/...
  • @marietjeschaake @marietjeschaake on x
    Strong conclusions without concluded texts even available (!) Yet: claims the EU not understanding, experts not having been consulted, while there are always public consultations ahead of legislation by the EC, EP, and there's been no lack of lobbying ↘️ https://www.platformer.ne…
  • @caffar3cristina Cristina Caffarra on x
    Three days into #DMA & already back to US tech writers & Big Tech operatives saying competition & privacy are irreconcilable (that old chestnut) & silly Europeans have no clue & don't talk to real “experts”. Oh the solution “has not been built” YET. So let's do nothing shall we. …
  • @s8mb Sam Bowman on x
    “Writing the law to say ‘You should allow for total interoperability without creating any privacy or security risks’ is like just ordering doctors to cure cancer.” https://www.platformer.news/ ...
  • @tjdonegan T.J. Donegan on x
    @CaseyNewton @wcathcart These are at least good, salient points but it's not different from how voice or text phone service operates now and we don't tolerate AT&T being unable to call Verizon phones, or being unable to email somebody because they're on a Mac vs a PC.
  • @b_t_walsh @b_t_walsh on x
    from the group that brought you cookie acceptance dialogs and GDPR cementing the dominance of large players, the EU's latest hit is demanding “total interoperability without creating any privacy or security risks” https://www.platformer.news/ ... @platformer @CaseyNewton
  • @agraham999 Alan Graham on x
    @CaseyNewton @wcathcart For us devs, many of their decisions will create more work for little benefit. As users it may open us up to greater risk. Like GDPR, which was well meaning, has suddenly turned into a nightmare of now having to manage cookies which often trick us into giv…
  • @suldrew @suldrew on x
    Maybe the EU wants spam to overrun encrypted platforms so people switch to something easier to spy on https://twitter.com/...
  • @adamkovac Adam Kovacevich on x
    .@CaseyNewton on EU pols: “It's unclear the extent which regulators realize that [privacy &competition] are often in conflict. But...they are on an absolute collision course, and...the future of end-to-end encryption hangs in the balance.” https://www.platformer.news/ ...
  • @jason_kint Jason Kint on x
    Lol. This entirely overlooks that cookie pop ups predate GDPR and were due to facebook and google lobby's implementation of eprivacy directive and failure to update for GDPR. Any cementing of dominance is due to failure by Facebook and google to properly follow laws. 3/3 https://…