Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Select an option

  • Save thedavidyoungblood/8dc9b94651c25cc852adcd68c23a38ac to your computer and use it in GitHub Desktop.

Select an option

Save thedavidyoungblood/8dc9b94651c25cc852adcd68c23a38ac to your computer and use it in GitHub Desktop.
PSA -- RCS General Research - Privacy & Security - some concerns....md

RCS General Research - Privacy & Security


[TLDR]: "Do Your Own Due Diligence!"(DYODD)

Ultimately, compared to all of the other available options today, this is one of the most proprietary, restrictive, yet, exposed, and in vulnerable ways, where we trade 'features' and 'functionalities', for our privacy, and data-sovereignty. Find and use something else. Almost anything will do. (Relative to where you're located globally, of course.)



What is RCS? (TL;DR)

Rich Communication Services (RCS) is a modern messaging protocol that replaces traditional SMS/MMS with internet-based features like high-resolution media, read receipts, typing indicators, and group chats. It was developed by the GSMA and aims to bring features similar to WhatsApp or iMessage directly into your phone's native messaging app. gsma

Technical Overview

RCS operates over mobile data or Wi-Fi using IP-based protocols (Session Initiation Protocol and Message Session Relay Protocol). Messages route through either: techtarget

  • Carrier infrastructure (AT&T, Verizon, etc.)
  • Google's Jibe Cloud platform (most common globally)
  • Apple's independent RCS backend (for iOS devices) techtarget

If the recipient doesn't have RCS enabled, messages automatically fall back to SMS/MMS. The protocol supports up to 100MB file transfers and has no character limits like SMS. motive

Everyday User Experience

For consumers, RCS enables:

  • HD photo/video sharing without compression
  • Read receipts and typing indicators (like iMessage)
  • Better group chat functionality
  • Interactive buttons and carousels in messages
  • Location sharing infobip

It works natively in your default messaging app—no separate app download required. However, both sender and receiver must have RCS enabled for features to work; otherwise it defaults to regular SMS. motive

Who Uses It & Where

Default RCS platforms:

  • Google Messages (Android's default on most devices) support.google
  • Apple iMessage/Messages app (iOS 18+, added RCS support in 2024) infobip
  • Samsung Messages (on some Samsung devices)

Global adoption: As of 2026, RCS is supported across 90+ mobile carriers worldwide through Google's Jibe platform, with cross-platform compatibility between Android and iPhone devices. It's becoming the standard replacement for SMS on both Android and iOS native messaging apps. en.wikipedia



On the matters of; Privacy, Security, and Data Sovereignty...

The privacy and data sovereignty implications of RCS are significantly worse than most users realize, especially compared to self-hosted or end-to-end encrypted alternatives.

Limited Encryption Protection

RCS uses only transport encryption (TLS), not end-to-end encryption. This means: reddit

  • Messages are encrypted in transit between your device and Google's Jibe servers, but can be read in plaintext on the server support.google
  • Google, carriers, and any third-party RCS providers can access your message content, attachments, and metadata reddit
  • If carrier-run RCS servers (AT&T, Verizon, etc.) are used instead of Jibe, their security practices are unknown and they may be logging messages or complying with government requests reddit
  • End-to-end encryption exists only between Google Messages users on Android—not with iPhone users, Samsung Messages users, or cross-platform substack

Data Sovereignty and Control Issues

Your RCS messages flow through infrastructure you don't control:

  • Carrier access: Mobile network operators retain "full control over access policies" and can see metadata (and potentially content) messageflow
  • Google intermediary: Most RCS traffic globally flows through Google's Jibe Cloud platform, giving Google access to message routing, metadata, and potentially content infobip
  • Cross-border data flows: Messages may traverse multiple jurisdictions with different privacy laws, creating compliance challenges leapxpert
  • No audit trail: Unlike self-hosted solutions, you cannot verify what data is collected, where it's stored, or who accesses it freemindtronic

Security Vulnerabilities

Independent security researchers found multiple critical RCS vulnerabilities in 2025: autobahn-security

  • Account takeover: Hackers can steal RCS configuration files containing SIP and HTTP credentials to fully control accounts autobahn-security
  • Message interception: Attackers can intercept texts including SMS-based two-factor authentication codes autobahn-security
  • User impersonation and fraud without sophisticated equipment autobahn-security
  • DNS spoofing attacks due to insufficient certificate validation in Android Messages autobahn-security

These vulnerabilities made RCS "as vulnerable to hacking as legacy mobile technologies, such as 2G and SS7" according to security researchers. autobahn-security

Compliance and Regulatory Risks

For businesses and regulated industries, RCS creates serious compliance burdens: leapxpert

  • Rich media content must be preserved in archives alongside regulatory metadata
  • Cross-border transmissions may trigger conflicting jurisdictional requirements
  • GDPR Article 6 & 7 consent requirements are difficult to enforce with cloud-dependent infrastructure freemindtronic
  • European data sovereignty violations: RCS services introduce "extraterritorial dependencies that compromise digital sovereignty" by relying on non-EU infrastructure (primarily Google's US-based servers) freemindtronic

Bottom Line

RCS fundamentally fails data sovereignty requirements because:

  • You cannot control where your data is processed or stored
  • Carriers and Google have unrestricted access to your communications
  • There's no transparency into data retention, access logs, or compliance with privacy laws
  • Messages traverse multiple third-party systems beyond your control reddit

This is why advocates recommend truly end-to-end encrypted alternatives like Signal or self-hosted Matrix for privacy-conscious users. RCS represents a step backward for data sovereignty compared to modern federated or decentralized messaging protocols. reddit




NOTICE:

This is just provided as conceptual research, documentation, for informational-purposes only, etc., and has not been fully battle tested or vetted, however would appreciate hearing and learning about any implementations, and shared learnings. (Unless otherwise explicitly stated by the author.)


@TheDavidYoungblood

🤝 Let's Connect!

LinkedIn // GitHub // Medium // Twitter/X



A bit about David Youngblood...


David is a Partner, Father, Student, and Teacher, embodying the essence of a true polyoptic polymath and problem solver. As a Generative AI Prompt Engineer, Language Programmer, Context-Architect, and Artist, David seamlessly integrates technology, creativity, and strategic thinking to co-create systems of enablement and allowance that enhance experiences for everyone.

As a serial autodidact, David thrives on continuous learning and intellectual growth, constantly expanding his knowledge across diverse fields. His multifaceted career spans technology, sales, and the creative arts, showcasing his adaptability and relentless pursuit of excellence. At LouminAI Labs, David leads research initiatives that bridge the gap between advanced AI technologies and practical, impactful applications.

David's philosophy is rooted in thoughtful introspection and practical advice, guiding individuals to navigate the complexities of the digital age with self-awareness and intentionality. He passionately advocates for filtering out digital noise to focus on meaningful relationships, personal growth, and principled living. His work reflects a deep commitment to balance, resilience, and continuous improvement, inspiring others to live purposefully and authentically.


Personal Insights

David believes in the power of collaboration and principled responsibility in leveraging AI for the greater good. He challenges the status quo, inspired by the spirit of the "crazy ones" who push humanity forward. His commitment to meritocracy, excellence, and intelligence drives his approach to both personal and professional endeavors.

"Here’s to the crazy ones, the misfits, the rebels, the troublemakers, the round pegs in the square holes… the ones who see things differently; they’re not fond of rules, and they have no respect for the status quo… They push the human race forward, and while some may see them as the crazy ones, we see genius, because the people who are crazy enough to think that they can change the world, are the ones who do." — Apple, 1997


My Self-Q&A: A Work in Progress

Why I Exist? To experience life in every way, at every moment. To "BE".

What I Love to Do While Existing? Co-creating here, in our collective, combined, and interoperably shared experience.

How Do I Choose to Experience My Existence? I choose to do what I love. I love to co-create systems of enablement and allowance that help enhance anyone's experience.

Who Do I Love Creating for and With? Everyone of YOU! I seek to observe and appreciate the creativity and experiences made by, for, and from each of us.

When & Where Does All of This Take Place? Everywhere, in every moment, of every day. It's a very fulfilling place to be... I'm learning to be better about observing it as it occurs.

A Bit More...

I've learned a few overarching principles that now govern most of my day-to-day decision-making when it comes to how I choose to invest my time and who I choose to share it with:

  • Work/Life/Sleep (Health) Balance: Family first; does your schedule agree?
  • Love What You Do, and Do What You Love: If you have what you hold, what are YOU holding on to?
  • Response Over Reaction: Take pause and choose how to respond from the center, rather than simply react from habit, instinct, or emotion.
  • Progress Over Perfection: One of the greatest inhibitors of growth.
  • Inspired by "7 Habits of Highly Effective People": Integrating Covey’s principles into daily life.

Final Thoughts

David is dedicated to fostering meaningful connections and intentional living, leveraging his diverse skill set to make a positive impact in the world. Whether through his technical expertise, creative artistry, or philosophical insights, he strives to empower others to live their best lives by focusing on what truly matters.

David Youngblood

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment