Secure messaging platforms, like Signal, WhatsApp, and recently, encrypted RCS , operate on a straightforward assumption: the content at each end of a conversation is private to the participants in the conversation. End-to-end encryption helps provide the mathematical guarantees that the companies who operate these messaging platforms cannot access the contents of messages. But there’s no way to guarantee what happens once the message arrives on a phone. As more devices and services introduce more artificial intelligence (AI) features into messaging apps, that line begins to blur. When AI features are computed entirely on device, it’s less concerning. Yet sometimes the computing requirements are heavy enough that the computation has to be done on a company server. Tech companies tell us they have a solution for this: trusted execution environments (TEEs). But do server-side TEEs really solve the problem? TEEs exist to serve many different functions, ranging from digital rights management (DRM) content protections to securely storing information in your phone’s mobile wallet, but for our purposes, we’ll be focusing on how tech companies use them for their AI tools. The basic idea is straightforward: most consumer devices aren’t powerful enough to handle the sorts of AI features companies want
Read More
Secure Messaging and AI Remain In Conflict Despite the Promise of TEEs

Secure Messaging and AI Remain In Conflict Despite the Promise of TEEs