Security versus Interoperability: Real Tension or False Dichotomy?
Technology companies cite security risks to push back against antitrust regulation. Are these real risks or just efforts to evade regulation?
The recent introduction of the Digital Markets Act in the European Union kicked off a series of proceedings involving mandated interoperation. As Apple described it, “The basic idea is that developers should have access to the same tools in iOS and iPadOS as Apple, in order to ensure a level playing field.” The company pushed back on these remedies in a public-facing document. Interoperability, Apple argued, “would put users at risk, requiring them to open their devices—and their most sensitive data—to companies with a track record of violating their privacy.” Similarly, in the U.S. context, Google stated that “[t]he [interoperation] requirement … effectively requir[es] Google to endorse stores that might be full of harmful content, ranging from malware that can scam or extort users to pornography and hate speech,” in reference to the requirement that Google allow third-party app stores.
Technology companies are right that the potential for harm exists. But does this mean regulators should drop their antitrust efforts because of the grave security harm that Google and Apple argue will result? Not necessarily.
A small class of technology companies has consolidated power in Western markets, prompting a sustained wave of regulatory pushback in the European Union and the United States. Often, this regulatory pushback is in the form of interoperation mandates, which require companies to facilitate greater integration with third-party products. In the example of Apple, the mandates require Apple to make specific functionalities of their phones accessible to third-party developers, such as the hardware that enables tap-and-go payments. Some tech companies have responded to this regulation by pointing to concerns that the interoperation will pose a security risk to users.
It is true that interoperation, if not executed carefully, can create security and privacy risks. Companies have strong incentives to spotlight or even exaggerate these risks—especially when speaking to policymakers and a general public that often cannot directly evaluate the technical implications. At the same time, regulators see healthy competition as a paramount goal and are unlikely to curtail their efforts. Rather than break up companies altogether, some regulators prefer interoperation as a means to preserve the current form of companies while still giving third parties greater access to markets. However, the potential security concerns of this lighter touch approach should not be wholly discounted.
In a multidisciplinary collaboration between experts on antitrust and computer security, we have written a paper to clarify the security considerations and trade-offs involved in interoperation, aiming to help regulators identify and respond to genuine security challenges while preventing the misuse of the “security bogeyman.” Highlighting this distinction is critical to enable the security community and policymakers to make informed decisions about the risks (and benefits) of interoperation.