Urgent.News

What's breaking now, across thousands of outlets.

AI

Secure Messaging and AI Remain In Conflict Despite the Promise of TEEs

Secure messaging platforms, like Signal, WhatsApp, and recently, encrypted RCS , operate on a straightforward assumption: the content at each end of a conversation is private to the participants in the conversation. End-to-end encryption helps provide the mathematical guarantees that the companies who operate these messaging platforms cannot access the contents of messages. But there’s no way to…

Secure Messaging and AI Remain In Conflict Despite the Promise of TEEs

Secure messaging apps such as Signal and WhatsApp rely on end-to-end encryption to ensure that only the participants can access the contents of their conversations. However, when AI features are added to these apps, the content may be processed on servers, potentially compromising privacy. Trusted execution environments (TEEs) are designed to keep such processing private, with implementations like Apple's Private Cloud Compute and WhatsApp's Private Processing.

While TEEs offer more security than clear text processing, they are fundamentally different and do not provide the same level of privacy and security. Although TEEs provide encryption key separation, they remain vulnerable to side channel attacks, where attackers can deduce encryption keys by measuring electrical impulses or timing variations.

This makes TEEs less secure than mathematically robust encryption methods. Therefore, users should not automatically send data to TEEs, as the security provided by these environments is not equivalent to mathematically proven encryption.

Written by urgent.news from EFF Deeplinks's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at eff.org →

More in AI

More from Friday 18 September →