Live data from Hacker News

EU will require Apple to open up iMessage (2022)

protocol.com

251–260 of 645 posts

Re: EU will require Apple to open up iMessage (2022)

#251
post #224

A convenient first step for European governments towards killing effective end-to-end cryptography usage in everyday messaging. It used to be checks notes „terrorism“ and „child safety“ and now the hot new thing is „interoperability“. Who would have thought, that of all the above, „interoperability“ would be the one that makes it into legislation.

Fact check: The Digital Markets Act explicitly calls out end-to-end encryption as a feature that MUST be preserved if the platform supports it. From Article 7: "The level of security, including the end-to-end encryption, where applicable, that the gatekeeper provides to its own end users shall be preserved across the interoperable services."

Is there more on this? Can this as is really be enough to maintain the security guarantees Apple currently provides?

Re: EU will require Apple to open up iMessage (2022)

#252

Earlier quoted context omitted.

> The only antidote to this is regulations. Well, I respectfully disagree, I'm a firm believer that regulations disproportionately hurt smaller businesses in the long run because those giants that have the monopoly move way faster than governments and they usually have thousands of smart lawyers ready to find holes and exploit/get around regulations made, usually, by people that does not understand the subject enough…

> Well, I respectfully disagree, I'm a firm believer that regulations disproportionately hurt Yeah you made the point very clear already in all your other posts, no need to repeat it everywhere. Other point errors in your arguments like this being for 75b corps completely nullifying your core arguments, lets just say most of the forum including me, EU and indeed world doesn't share your view at all. In fact, some hea…

I did not make the case that ALL regulations must be erased to a zero, at all. I do believe that there must be a minimum of regulations that actually make everyone prosper and go along with each other. Unfortunately, regulating messaging so that anyone can have just a single app on their phone for that specific task is beyond unnecessary, but that's just my useless opinion I guess.

Re: EU will require Apple to open up iMessage (2022)

#254

Earlier quoted context omitted.

There is a signal api already

Sure but that's completely different from requiring the Signal app to allow exchanging messages with Facebook/WhatsApp/iMessage/…

I read a while ago that the regulation will require them to build an API that other apps can access it, so you could use an alternative app if you want to. I'm not sure if they will force them to receive messages from other services.

Re: EU will require Apple to open up iMessage (2022)

#255
post #253

And then Apple makes it so certain encryption/features require a proprietary apple chip feature

I’d argue that is already the case, with the secure enclave. They don’t need to ‘make it so’. Allowing other apps must not cause the protocol to be less secure

Re: EU will require Apple to open up iMessage (2022)

#256

Earlier quoted context omitted.

There is no bubble because literally everyone has whatshapp. It's even available on "dumb phones". I've never met anyone of any age who doesn't have it.

Hello there, nice to meet you. Life without Whatsapp is not easy in the Netherlands, but is possible. The "super bubble" exists though, and it sucks. Most problems come from the "literally everyone has whatshapp" crowd like you, by the way, the people who deny the existence of the bubble. Could you please stop making my life harder? No, not "literally everyone" has Whatsapp: I don't. Agreeing to T&C of some foreign c…

Well, the reliance on Whatsapp is a serious accessibility issue that governments should be working on.

At the same time, the OP is not in a "bubble". You can't call something a bubble if almost everybody is inside it.

Re: EU will require Apple to open up iMessage (2022)

#257

There was a brief period of time where I was able to use IRC, Facebook and MSN from the same client: Pidgin https://pidgin.im/

It was not the client but all the companies using Jabber/XMPP protocol for their products. Many clients including Empathy and Kopete allowed this at the time.

These were all multi-protocol clients supporting more than XMPP because MSN, Yahoo Messenger, and AIM all had their own thing. I believe Facebook was always its own thing but they exposed an XMPP proxy. Only Google Talk really relied on XMPP from the start but it was pretty much a token player in the market until two things happened: 1. They integrated with Gmail making Google Talk readily available to Google’s entire Gmail user base without installing a separate Windows-only client (or finding a compatible messenger, iChat ended up natively supporting XMPP within a couple of years) and 2. Instant Messaging went into rapid decline as users switched to mobile-first messengers (IMing was always a desktop-centric experience and the various pre-existing protocols were not battery efficient and you typically had to have the client open and active to be signed in).

Re: EU will require Apple to open up iMessage (2022)

#258

Earlier quoted context omitted.

Fact check: The Digital Markets Act explicitly calls out end-to-end encryption as a feature that MUST be preserved if the platform supports it. From Article 7: "The level of security, including the end-to-end encryption, where applicable, that the gatekeeper provides to its own end users shall be preserved across the interoperable services."

Is there more on this? Can this as is really be enough to maintain the security guarantees Apple currently provides?

What security guarantees do Apple currently provide?

I can't imagine much more than E2EE & maybe encrypted-at-rest (which is not a protocol-level feature anyway).

Re: EU will require Apple to open up iMessage (2022)

#259
post #70
post #66

Earlier quoted context omitted.

That's not true. They were at over 40% and growing at that time: https://gs.statcounter.com/press/google-gained-market-share-...

That's assuming sites/users in China use statcounter, completely misleading data. According Wikipedia and at least 2 different sources they quote, Google peaked in China at 29-35% and even that seems way too optimistic, if you ask anyone who used search in China back then or have been there. By my experience from years ago was Google search in Chinese language useless. https://en.wikipedia.org/wiki/Google_China

Happy to go by your numbers, that was just the first search result. 35% is still very significant, so your initial claim about it having no traction and this being just a face-saving gesture was not correct.

Re: EU will require Apple to open up iMessage (2022)

#260
post #174

Earlier quoted context omitted.

> [...] without actually realising that it is actually going to make things worse, that's what regulation does in most cases. Feels like a uniquely american take. Companies that are maliciously compliant are not the norm. Leaving behind that most is an ambiguous enough term that means you could basically discredit anything I come up with, how do you feel about regulations that limit the use of harmful or toxic chemic…

>Companies that are maliciously compliant are not the norm. How do you explain all these damn GDPR pop ups on every site that make it as difficult as possible to disagree?

On that note, I think the GDPR banner problem won't be solved until the UI is shown at the browser level, just like tracking permission dialogs on mobile: having the same UI for all sites would prevent tricking users into over-complicated form because at least it would be the same form everytime.

Right now, too many end users get fatigue fooled into blaming the EU rather than the companies tracking them, whereas on mobile they are aware that it's Facebook triggering the dialog, not the EU: just see how many users end up refusing Facebook tracking when they have a clear choice that doesn't push them one way or the other.

It would even help companies who currently delegate handling GDRP to thirdparty services that prey on small companies worried about being non-compliant.

Post reply on HN