What to know
- Google Contact Keys is building automatic checks that compare RCS server keys with keys originating on participants’ devices.
- The new status screens cover successful checks, pending comparisons, mismatches, verification history, and possible man-in-the-middle attacks.
- We found the unreleased feature in code from Google Contact Keys v1.443.978654235, but could not surface it in the app.
Manual contact-key verification for encrypted RCS conversations is already public through Android System Key Verifier and Google Messages. Google Contact Keys is now developing a separate automatic transparency layer that checks the origins of the encryption keys tracked by the RCS server.
We found the new status and warning strings in Google Contact Keys v1.443.978654235. They describe checks for individual conversations as well as a self-audit that compares the server’s keys with those created on the current device.
About APK teardowns — An APK teardown works by reading the not-yet-shipped code inside a beta build, which lets us preview features a developer is working on before they’re announced. But work-in-progress code can change, stay hidden behind a server-side flag, or be scrapped before it ever reaches your phone.
Automatic checks confirm where RCS keys originated
The new “Key transparency status” screen explains that the RCS server tracks whether the encryption keys used between you and a contact originate on your devices. A successful check produces a “Key origins confirmed” message, while another string records when the keys were last verified.
The interface also accounts for checks that are still pending or unsuccessful. When some key origins cannot be confirmed, Google Contact Keys advises the user to check again later and use manual encryption verification for extra security.
contactkeys_kt_status_btn = "Key transparency status"
contactkeys_kt_status_title = "Key transparency status"
contactkeys_kt_status_desc = "Your RCS messages between you and %1$s are always encrypted. The RCS server tracks that all encryption keys between you originate on your devices."
contactkeys_kt_status_desc_contact_name_unknown = "Your RCS messages between you and your contact are always encrypted. The RCS server tracks that all encryption keys between you originate on your devices."
contactkeys_kt_status_success_headline = "Key origins confirmed"
contactkeys_kt_status_failed_headline = "Some key origins could not be confirmed"
contactkeys_kt_status_failed_advice = "\"Check status later.\nUse manual encryption verification for extra security.\""
contactkeys_kt_status_pending_headline = "Key origins confirmation pending…"
contactkeys_kt_status_last_verified = "Last verified: %1$s"
contactkeys_kt_status_last_verified_today = "Today at %1$s"
contactkeys_kt_status_last_verified_yesterday = "Yesterday at %1$s"
contactkeys_kt_how_it_works_link = "How it works"
contactkeys_kt_learn_more_link = "Learn more"
A self-audit warns about server keys from another device
Google Contact Keys is also preparing an “Encryption key origins” self-audit. Its description says the encryption keys created on the device should equal those stored on the RCS messaging server. If they differ, the app says the phone number was used on a different device.
The matching state says the server and device keys match. The mismatch state is more direct: “Some server keys not from this device.” Its accompanying advice tells the user to check again later and warns that a persistent difference could indicate a man-in-the-middle attack.
contactkeys_kt_self_audit_title = "Encryption key origins"
contactkeys_kt_self_audit_desc = "The encryption keys created on this device should be equal to the encryption keys stored on RCS messaging server. If there is a difference, that means that your phone number was used on a different device."
contactkeys_kt_self_audit_match_headline = "Server and device keys match"
contactkeys_kt_self_audit_mismatch_headline = "Some server keys not from this device"
contactkeys_kt_self_audit_mismatch_advice = "Check status later. If this persists, it is possible that you are under a man-in-the-middle attack."
contactkeys_kt_self_audit_missing_keys_title = "Missing keys"
contactkeys_kt_self_audit_pending_headline = "Key comparison is pending"
Older RCS protocols may not support the check
The code includes unavailable states for both contact checks and the device self-audit. These messages say an older RCS protocol may not support encryption-key origin checking and that the function may become available as the carrier updates its RCS protocols.
contactkeys_kt_self_audit_unavailable_title = "Encryption keys not available"
contactkeys_kt_self_audit_unavailable_desc = "\"The RCS messaging on this device is using an older RCS protocol that does not support encryption key origin check.\n\nThis function may become available to you in the future as your carrier updates RCS protocols.\""
contactkeys_kt_status_unavailable_title = "\"Key transparency status not\navailable\""
contactkeys_kt_status_unavailable_desc = "\"The RCS messaging between you and %1$s is using an older RCS protocol that does not support encryption key origin check.\n\nThis function may become available to you in the future as your carrier updates RCS protocols.\""
contactkeys_kt_status_unavailable_desc_contact_name_unknown = "\"The RCS messaging between you and your contact is using an older RCS protocol that does not support encryption key origin check.\n\nThis function may become available to you in the future as your carrier updates RCS protocols.\""
These automatic RCS key-origin checks are not available to users yet; we’ll watch future Google Contact Keys builds for their rollout.
Related guides
Leave a Reply