A better alternative exists for SMS - if players can be persuaded to use it
A more secure standard is available in the form of RCS; Google is its biggest champion
Yong Jun Yuan
Singapore
FROM personal digital assistants (PDAs) to digital video discs (DVDs), many of the technological inventions of the 1990s have changed dramatically or been replaced today.
Yet, the SMS, or short message service, has lived on mostly unchanged for decades. No wonder, then, that the technology has become embroiled in scams that have cost hundreds of customers millions of dollars.
Think of SMS as sending an open letter without a sealed envelope. SMSes are unencrypted, which means they can be read by someone other than the intended recipient. And when they are delivered, the sender has no way of knowing if the message was read.
Also, in the same way a letterhead can be imitated, or the sender impersonated, the "from" section of an SMS message requires no authentication.
On Friday (Jan 28), the Infocomm Media Development Authority (IMDA) said that it is considering making it mandatory for all organisations to register with the Singapore SMS SenderID Protection Registry. Telcos and Tier 1 SMS aggregators, or companies that handle commercial SMS traffic, are also required to participate.
As The Business Times had earlier reported, pre-registration with the registry is an insufficient guarantee against sender ID spoofing.
This ability to impersonate a sender was one reason why scammers were able to hoodwink some OCBC customers into giving away passwords late last year.
In fact, this was not the first time that the vulnerabilities of SMS have been exploited. On Sep 15, 2021, the Monetary Authority of Singapore had worked with the IMDA and the police on a case that saw fraudsters intercepting and diverting one-time passwords (OTPs) sent by banks via SMS.
The telcos were directed to introduce additional safeguards to monitor and block suspicious diversions of SMS.
Given the weaknesses of SMS, why is it still so widely used around the world?
Old and vulnerable
Mobile phone companies connect to each other using something called Signalling System No 7 (SS7). This is what allows calls and messages to be passed from one user to another.
The SS7 protocols were designed and came into use as part of a closed network, so encryption, authorisation and authentication were never major considerations. According to a report by SOS Intelligence, a dark web intelligence company, the SS7 protocols' primary security defence was its use on a closed system.
Unfortunately, the SS7 network has become increasingly open over the years. There are multiple points at which hackers can access the network - among them the signalling transport (Sigtran) protocol. Among other things, Sigtran enables voice over Internet protocol calls and connects the SS7 protocol to the Internet.
The SS7 network continues to evolve, and holes are patched - with different levels of consistency across countries - as hackers reveal them.
But calls are also growing to ditch SS7 altogether. In March last year, IMDA issued a public consultation to seek feedback on the phasing out of equipment and technologies based on the SS7 protocol and the implementation of its IP-based replacement.
New standard could help
A specific solution to the SMS problem already exists, however, in the form of RCS. Short for rich communications services, this set of standards was developed by telco industry organisation GSMA to replace SMS.
RCS had been touted as a way for telcos to hit back at messaging services like WhatsApp, which had eaten into SMS revenues. The service might have had more legs if it had been billed as a badly needed update to the incredibly outdated SMS instead.
According to a Gadget Hacks article last updated in June 2021, RCS Universal Profile, the latest iteration of the standards, has only been implemented in 20 telcos worldwide. It is also unclear if end-to-end encryption has been enabled for messages sent across these networks.
M1, StarHub and Singtel have all said at some point over the last decade that they were either considering or had built RCS services with their servers, although none are operational today. TPG has not announced any RCS plans.
Possibly the biggest champion of RCS today is Google, which has implemented RCS on its servers. Android users who use the preloaded Android Messages app on their phones can verify their phone numbers to activate "chat features", which routes messages over Google servers using mobile data or WiFi - much like how WhatsApp works.
Android Messages offers end-to-end encryption using the well-established Signal protocol, which means not even Google or the telcos delivering these messages would be able to view a message's contents.
The app is also backwards compatible, which means recipients can still receive old-fashioned SMS messages. Such messages would be identified as being less secure in distinct light blue bubbles instead of the dark blue bubbles with a small lock next to the timestamp for end-to-end encrypted messages.
End-to-end encryption can reduce the risk of impersonation scams. In the case of a bank and its customer, a unique "fingerprint" of 16 5-digit codes will be generated and shared between both parties. Banks can then ask customers to paste and match these codes in their banking apps to verify that neither of them are being impersonated.
Google has lit up its own servers to route RCS messages as telcos continue to drag their feet, although it has said that it is open to working with telcos to incorporate their servers instead. Still, it is facing trouble integrating its service with Apple's.
Apple has not adopted the RCS standard, preferring instead to favour its own iMessage service that is only available to iOS users. Google has launched a campaign to apply public pressure on Apple to protect its users' security and privacy, and enable RCS.
Profits to be made?
Given the advantages of RCS, why haven't more telcos adopted it?
The incentives for telcos to introduce RCS are not obvious at first glance. As SMS revenue has diminished over time, it would make little business sense for companies to improve on this underutilised service.
In 2018, GSMA's own research had suggested that the RCS business messaging market could be worth over US$74 billion by 2021. But it is unlikely that such a value has been reached, considering the tepid response from telcos.
The telcos may be missing out on an opportunity to support multiple commercial applications.
For instance, RCS has standards governing the use of chatbots. This could open the door to smarter and more interactive ways of getting things done on our phones, if companies and telcos have the creativity to seize the opportunity.
Although messaging services like WhatsApp have integrated similar business features, government agencies like Mindef may prefer to use services hosted on local servers instead of relying on overseas providers to send sensitive messages like National Service call-ups.
The Smart Nation and Digital Government Group (SNDGG) announced on Friday that it would explore the use of the Singpass app to disseminate information while it re-examines its use of SMS.
But an improved RCS network could be a viable alternative to the use of an app.
While telcos consider how they can best upgrade their messaging systems, consumers and businesses will need to adapt and find better ways to communicate with each other too.
Banks, for instance, should clearly communicate to users that using SMS OTPs is less secure than using soft or physical tokens to generate OTPs. They should also begin the process of phasing out the use of SMS OTPs if possible.
Similarly, consumers should be wary of anything sent via SMS. While local banks have committed to not sending any links, scammers could still push phone numbers and lead unsuspecting people to call them.