{"id":51029,"date":"2024-04-19T06:38:15","date_gmt":"2024-04-19T10:38:15","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=51029"},"modified":"2024-04-19T06:38:15","modified_gmt":"2024-04-19T10:38:15","slug":"whatsapp-interop-other-messengers-risks","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/whatsapp-interop-other-messengers-risks\/51029\/","title":{"rendered":"Messaging other platforms via WhatsApp: the pros and cons"},"content":{"rendered":"<p>The EU\u2019s Digital Markets Act (DMA) requires major tech companies to make their products more open and interoperable in order to increase competition. Thanks to the DMA, iOS <a href=\"https:\/\/www.kaspersky.com\/blog\/ios-alternative-app-stores-and-browsers-security\/50777\/\" target=\"_blank\" rel=\"noopener nofollow\">will soon permit third-party app stores<\/a> to be installed on it, and major messaging platforms will need to allow communication with other similar apps \u2014 creating cross-platform compatibility. <a href=\"https:\/\/engineering.fb.com\/2024\/03\/06\/security\/whatsapp-messenger-messaging-interoperability-eu\/\" target=\"_blank\" rel=\"nofollow noopener\">Meta (Facebook) engineers recently detailed<\/a> how this compatibility will be implemented in its WhatsApp and Messenger. The benefits of interoperability are clear to anyone who\u2019s ever texted or emailed. You\u2019ll be able to send or receive messages without worrying about what phone, computer, or app the other person is using, or what country they\u2019re in. However, there are downsides: first third parties (from intelligence agencies to hackers) often have access to your correspondence; second, such messages are prime <a href=\"https:\/\/securelist.com\/spam-phishing-report-2023\/112015\/\" target=\"_blank\" rel=\"noopener\">targets for spam and phishing<\/a>. So, will the DMA be able to ensure provision of interoperability and its benefits, while eliminating its drawbacks?<\/p>\n<p>It\u2019s important to note that while the DMA\u2019s impact on the iOS App Store will only affect EU users, cross-platform messaging will likely impact everyone \u2014 even if it will be only EU partners that connect to the WhatsApp infrastructure.<\/p>\n<h2>Can you chat on WhatsApp with users of other platforms?<\/h2>\n<p>Theoretically, yes, but not yet in practice. Meta has published specifications and technical requirements for partners who want their apps to be interoperable with WhatsApp or Messenger. It\u2019s now up to these partners to climb aboard and develop a working bridge between their service and WhatsApp. To date, no such partnerships have been announced.<\/p>\n<p>Owners and developers of other messaging services may be reluctant to implement such functionality. Some consider it insecure; others are unwilling to invest resources into rather complex integration. Meta requires potential partners to implement <a href=\"https:\/\/www.kaspersky.com\/blog\/what-is-end-to-end-encryption\/37011\/\" target=\"_blank\" rel=\"noopener nofollow\">end-to-end encryption (E2EE)<\/a> no weaker than in WhatsApp, which is a significant challenge for many platforms<\/p>\n<p>Even when (or if) third-party services show up, only those WhatsApp users who explicitly opt-in will be able to message across platforms. It won\u2019t be enabled by default.<\/p>\n<h2>What will such messaging look like?<\/h2>\n<p>Based on <a href=\"https:\/\/wabetainfo.com\/whatsapp-beta-for-android-2-23-19-8-whats-new\/\" target=\"_blank\" rel=\"nofollow noopener\">WhatsApp beta versions<\/a>, messages with users on other platforms will be housed in a separate section of the app to distinguish them from chats with WhatsApp users.<\/p>\n<p>Initially, only one-on-one messaging and file\/image\/video sharing will be supported. Calls and group chats won\u2019t be available for at least a year.<\/p>\n<p>User identification remains an open question. In WhatsApp, users find each other by phone number, while on Facebook, they do it by name, workplace, school, friends of friends, or other similar identifiers (and ultimately by a unique ID). Other platforms might use incompatible identifiers, like short usernames in <a href=\"https:\/\/www.kaspersky.com\/blog\/malware-in-discord\/42846\/\" target=\"_blank\" rel=\"noopener nofollow\">Discord<\/a>, or alphanumeric IDs in <a href=\"https:\/\/www.kaspersky.com\/blog\/7-threema-vulnerabilities\/46772\/\" target=\"_blank\" rel=\"noopener nofollow\">Threema<\/a>. This is likely to impede automatic search and user matching, and at the same time facilitate impersonation attacks by scammers.<\/p>\n<h2>Encryption challenges<\/h2>\n<p>One of the key challenges with integrating different messaging platforms is implementing reliable encryption. Even if two platforms use the same encryption protocol, technical issues arise regarding storage and agreement of keys, user authentication, and more.<\/p>\n<p>If the encryption method differs significantly, a bridge \u2014 an intermediary server that decrypts messages from one protocol and re-encrypts them into another \u2014 will likely be needed. If it seems to you that this is a <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/man-in-the-middle-attack\/\" target=\"_blank\" rel=\"noopener\">man-in-the-middle (MITM)<\/a> attack waiting to happen, where hacking this server would allow eavesdropping, you\u2019re misgiving would be on the money. The failed <a href=\"https:\/\/www.kaspersky.com\/blog\/nothing-chats-imessage-for-android-security-disaster\/49895\/\" target=\"_blank\" rel=\"noopener nofollow\">Nothing Chats<\/a> app, which used a similar scheme to enable iMessage on Android, recently demonstrated this vulnerability. Even Meta\u2019s own efforts are illustrative: encrypted messaging between Messenger and Instagram was announced over five years ago, but <a href=\"https:\/\/engineering.fb.com\/2023\/12\/06\/security\/building-end-to-end-security-for-messenger\/\" target=\"_blank\" rel=\"nofollow noopener\">full-scale encryption in Messenger only arrived<\/a> last December, and seamless E2EE in Instagram remains not fully functional to this day. As <a href=\"https:\/\/www.wired.com\/story\/meta-messenger-instagram-end-to-end-encryption\/\" target=\"_blank\" rel=\"nofollow noopener\">this in-depth article<\/a> explains, it\u2019s not a matter of laziness or lack of time, but rather the significant technical complexity of the project.<\/p>\n<p>Cryptographers are generally <a href=\"https:\/\/www.wired.co.uk\/article\/dma-interoperability-messaging-imessage-whatsapp\" target=\"_blank\" rel=\"nofollow noopener\">highly skeptical<\/a> about the idea of cross-platform E2EE. Some experts <a href=\"https:\/\/matrix.org\/blog\/2022\/03\/25\/interoperability-without-sacrificing-privacy-matrix-and-the-dma\/\" target=\"_blank\" rel=\"nofollow noopener\">believe the problem can be solved<\/a> \u2014 for example, by placing the bridge directly on the user\u2019s computer or by having all platforms adopt a single, decentralized messaging protocol. However, the big fish in the messaging market aren\u2019t swimming in that direction at all. It\u2019s hard to accuse them of idleness or inertia \u2014 all practical experience demonstrates that reliable and user-friendly message encryption within open ecosystems is difficult to implement. Just look at the <a href=\"https:\/\/www.cryptologie.net\/article\/487\/a-history-of-end-to-end-encryption-and-the-death-of-pgp\/\" target=\"_blank\" rel=\"nofollow noopener\">saga<\/a> of PGP encryption in email, and the <a href=\"https:\/\/moxie.org\/2015\/02\/24\/gpg-and-me.html\" target=\"_blank\" rel=\"nofollow noopener\">confessions of top cryptography experts<\/a>.<\/p>\n<p>We\u2019ve compiled information on the WhatsApp\/Messenger integration plans of major communication platforms, and assessed the technical feasibility of cross-platform functionality:<\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"12%\"><strong>Service<\/strong><\/td>\n<td width=\"44%\"><strong>Statement on WhatsApp compatibility<\/strong><\/td>\n<td width=\"44%\"><strong>Encryption compatibility<\/strong><\/td>\n<\/tr>\n<tr>\n<td width=\"12%\">Discord<\/td>\n<td width=\"44%\">None<\/td>\n<td width=\"44%\">No E2EE support, integration unlikely<\/td>\n<\/tr>\n<tr>\n<td width=\"12%\">iMessage<\/td>\n<td width=\"44%\">None<\/td>\n<td width=\"44%\">Uses own encryption \u2014comparable in strength to WhatsApp<\/td>\n<\/tr>\n<tr>\n<td width=\"12%\">Matrix<\/td>\n<td width=\"44%\"><a href=\"https:\/\/matrix.org\/blog\/2023\/03\/15\/the-dma-stakeholder-workshop-interoperability-between-messaging-services\/\" target=\"_blank\" rel=\"nofollow noopener\">Interested<\/a> in technical integration with WhatsApp, and supports the DMA in general<\/td>\n<td width=\"44%\">Uses own encryption \u2014comparable in strength to WhatsApp<\/td>\n<\/tr>\n<tr>\n<td width=\"12%\">Signal<\/td>\n<td width=\"44%\">None<\/td>\n<td width=\"44%\">Uses the <a href=\"https:\/\/www.kaspersky.com\/blog\/signal-privacy-security\/40377\/\" target=\"_blank\" rel=\"noopener nofollow\">Signal<\/a> protocol, as does WhatsApp<\/td>\n<\/tr>\n<tr>\n<td width=\"12%\">Skype<\/td>\n<td width=\"44%\">None<\/td>\n<td width=\"44%\">Uses the <a href=\"https:\/\/www.kaspersky.com\/blog\/signal-privacy-security\/40377\/\" target=\"_blank\" rel=\"noopener nofollow\">Signal<\/a> protocol, as does WhatsApp, but for private conversations only<\/td>\n<\/tr>\n<tr>\n<td width=\"12%\">Telegram<\/td>\n<td width=\"44%\">None<\/td>\n<td width=\"44%\">Most chats are unencrypted, and private conversations are <a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-why-nobody-uses-secret-chats\/46889\/\" target=\"_blank\" rel=\"noopener nofollow\">encrypted with an unreliable algorithm<\/a><\/td>\n<\/tr>\n<tr>\n<td width=\"12%\">Threema<\/td>\n<td width=\"44%\">Concerned about privacy risks associated with WhatsApp integration. Integration unlikely<\/td>\n<td width=\"44%\">Uses own encryption \u2014comparable in strength to WhatsApp<\/td>\n<\/tr>\n<tr>\n<td width=\"12%\">Viber<\/td>\n<td width=\"44%\">None<\/td>\n<td width=\"44%\">Uses own encryption \u2014comparable in strength to WhatsApp<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Security concerns<\/h2>\n<p>Beyond encryption issues, integrating various services introduces additional challenges in protecting against spam, phishing, and other cyberthreats. Should you receive spam on WhatsApp, you can block the offender there and then. After being blocked by several users, the spammer will have limited ability to message strangers. To what extent such anti-spam techniques will work with third-party services remains to be seen.<\/p>\n<p>Another issue is the moderation of unwanted content \u2014 from pornography to fake giveaways. When algorithms and experts from not one but two companies are involved, response speed and quality are bound to suffer.<\/p>\n<p>Privacy concerns will also become more complex. Say you install the Skype app \u2014 in doing so, you share data with Microsoft, which will store it. However, as soon as you message someone on WhatsApp from Skype, certain information about you and your activity will land on Meta\u2019s servers. Incidentally, WhatsApp already has a so-called <a href=\"https:\/\/www.whatsapp.com\/legal\/dma-notice-non-users\" target=\"_blank\" rel=\"nofollow noopener\">guest agreement<\/a> in place for this case. It\u2019s this issue that the Swiss team behind Threema finds unsettling, for fear that messaging with WhatsApp users could lead to the de-anonymization of Threema users.<\/p>\n<p>And let\u2019s not forget that the news of cross-platform support is music to the ears of malware authors \u2014 it will be much easier to lure victims with \u201c<a href=\"https:\/\/www.kaspersky.com\/blog\/why-messenger-mods-are-dangerous\/45788\/\" target=\"_blank\" rel=\"noopener nofollow\">WhatsApp mods for messaging with Telegram<\/a>\u201d or other fictitious offerings. Of all the issues, however, this one is the easiest to solve: just install apps only from official stores and use <a href=\"https:\/\/www.kaspersky.com\/premium?icid=gl_bb2023-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener nofollow\">reliable protection on your smartphones and computers<\/a>.<\/p>\n<h2>What to do?<\/h2>\n<h4>If you use WhatsApp and want to message users of other services<\/h4>\n<p>Count up roughly how many non-WhatsAppers there are in your circle who use other platforms that have announced interoperability with WhatsApp. If there aren\u2019t many, it\u2019s better <a href=\"https:\/\/wabetainfo.com\/whatsapp-beta-for-android-2-24-6-2-whats-new\/\" target=\"_blank\" rel=\"nofollow noopener\">not to enable<\/a> support for any and all third-party messengers: the risks of spam and unwanted messages outweigh the potential benefits.<\/p>\n<p>If there are many such people, consider whether you discuss confidential topics. Even with Meta\u2019s encryption requirements, cross-platform messaging through a bridge should be considered vulnerable to interception and unauthorized modification. Therefore, it\u2019s best to use the same <a href=\"https:\/\/www.kaspersky.com\/blog\/33c3-private-messenger-basics\/13820\/\" target=\"_blank\" rel=\"noopener nofollow\">secure<\/a> messenger (such as <a href=\"https:\/\/www.kaspersky.com\/blog\/signal-privacy-security\/40377\/\" target=\"_blank\" rel=\"noopener nofollow\">Signal<\/a>) for confidential communication.<\/p>\n<p>If you decide that <em>WhatsApp + third-party messenger<\/em> is the winning formula, be sure to max out the privacy settings in WhatsApp, and be wary of odd messages, especially from strangers, but also from friends on unusual topics. Try to double-check it\u2019s who they claim to be, and not some scammer messaging you through a third-party service.<\/p>\n<h4>If you use another messenger that has announced interoperability with WhatsApp<\/h4>\n<p>While gaining access to all WhatsApp users within your favorite messenger is appealing, if you use a different messenger for increased privacy, connecting to WhatsApp will likely diminish it. Meta services will collect <a href=\"https:\/\/www.whatsapp.com\/legal\/dma-notice-non-users\" target=\"_blank\" rel=\"nofollow noopener\">certain metadata<\/a> during conversations, potentially leading to account de-anonymization, and the encryption bridge may be vulnerable to eavesdropping. In general, we don\u2019t recommend activating this feature in secure messengers, should it ever become available.<\/p>\n<h4>Tips for everyone<\/h4>\n<p>Beware of \u201c<a href=\"https:\/\/www.kaspersky.com\/blog\/why-messenger-mods-are-dangerous\/45788\/\" target=\"_blank\" rel=\"noopener nofollow\">mods<\/a>\u201d and <a href=\"https:\/\/www.kaspersky.com\/blog\/nothing-chats-imessage-for-android-security-disaster\/49895\/\" target=\"_blank\" rel=\"noopener nofollow\">little-known apps<\/a> that promise cross-platform messaging and other wonders. Lurking behind the seductive interface is probably <a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-signal-malware-in-google-play\/48937\/\" target=\"_blank\" rel=\"noopener nofollow\">malware<\/a>. Be sure to install <a href=\"https:\/\/www.kaspersky.com\/premium?icid=gl_bb2023-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener nofollow\">protection on your computer and smartphone<\/a>\u00a0to prevent attackers from <a href=\"https:\/\/www.kaspersky.com\/blog\/telegram-signal-malware-in-google-play\/48937\/\" target=\"_blank\" rel=\"noopener nofollow\">stealing your correspondence<\/a> right inside legitimate messengers.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-geek\">\n","protected":false},"excerpt":{"rendered":"<p>In response to EU regulations, WhatsApp will soon offer interoperability with other messengers. Do we need it? And is it secure?<\/p>\n","protected":false},"author":2722,"featured_media":51030,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1789,9],"tags":[4026,3937,3856,3231,607,43,835,1532,345,611,609,608,546],"class_list":{"0":"post-51029","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-technology","8":"category-tips","9":"tag-discord","10":"tag-e2e","11":"tag-end-to-end-encryption","12":"tag-imessage","13":"tag-messengers","14":"tag-privacy","15":"tag-settings","16":"tag-signal","17":"tag-skype","18":"tag-telegram","19":"tag-threema","20":"tag-viber","21":"tag-whatsapp"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/whatsapp-interop-other-messengers-risks\/51029\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/whatsapp-interop-other-messengers-risks\/27338\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/whatsapp-interop-other-messengers-risks\/22652\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/whatsapp-interop-other-messengers-risks\/11653\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/whatsapp-interop-other-messengers-risks\/30014\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/whatsapp-interop-other-messengers-risks\/27492\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/whatsapp-interop-other-messengers-risks\/27322\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/whatsapp-interop-other-messengers-risks\/29983\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/whatsapp-interop-other-messengers-risks\/28789\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/whatsapp-interop-other-messengers-risks\/37296\/"},{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/whatsapp-interop-other-messengers-risks\/12295\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/whatsapp-interop-other-messengers-risks\/21811\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/whatsapp-interop-other-messengers-risks\/22572\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/whatsapp-interop-other-messengers-risks\/31215\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/whatsapp-interop-other-messengers-risks\/36291\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/whatsapp-interop-other-messengers-risks\/27648\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/whatsapp-interop-other-messengers-risks\/33498\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/whatsapp-interop-other-messengers-risks\/33143\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/messengers\/","name":"messengers"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/51029","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2722"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=51029"}],"version-history":[{"count":5,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/51029\/revisions"}],"predecessor-version":[{"id":51041,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/51029\/revisions\/51041"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/51030"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=51029"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=51029"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=51029"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}