Live data from Hacker News

EU will require Apple to open up iMessage (2022)

protocol.com

471–480 of 645 posts

Re: EU will require Apple to open up iMessage (2022)

#471
post #299

Earlier quoted context omitted.

Also I am quite sure that such a law would be unconstitutional in a lot of places.

yup. https://en.wikipedia.org/wiki/Bill_of_attainder

It would only be a bill of attainder if it used arbitrary characteristics not relevant to the stated purpose of the bill to target specific companies. The definition cited is not arbitrary in that sense - it targets large companies in specific markets, and there's an obvious rational connection with the stated purpose.

Re: EU will require Apple to open up iMessage (2022)

#472
post #363
post #258

Earlier quoted context omitted.

What security guarantees do Apple currently provide? I can't imagine much more than E2EE & maybe encrypted-at-rest (which is not a protocol-level feature anyway).

Well, the security coprocessor on every iPhone and Mac runs a formally verified operating system that manages the at-rest encrypted messages. Also, all software running on the phone is vetted before being allowed to hit consumer devices, which adds an extra level of security between malicious developers and kernel APIs. There's no way Android will support that stuff across its entire ecosystem, so I guess it means th…

1. I don't think "formally verified" means what you want it to here. You mean there a hardware checks signature chain from boot to kernel, secure boot. Apple's software has too many security vulnerability to be considered "formally verified".

2. Android does support device attestation and secure boot. I 100% would love to see our future SMS replacement require frequent signatures from device attestation hardware (why not every message) and require E2EE messages.

Re: EU will require Apple to open up iMessage (2022)

#473
post #288

Earlier quoted context omitted.

The ones that created cookie popups everywhere. It’s horrible. It’s the worst. Everyone can see how horrible it is. Nobody understands why this is still a thing.

The regulations never mandated cookie popups. Companies who decided to continue their invasive policies chose to implement those popups to provide legal cover. Non-invasive companies don't need to do that. The issue is with the companies, not the regulation.

The issue is with both. It is not exactly surprising that for-profit companies implement the regulation in a way that minimizes their expenses, and the outcome this produces could have been anticipated when the legislation was written. The outcome matters more than the intent.

Re: EU will require Apple to open up iMessage (2022)

#474
post #453

Earlier quoted context omitted.

> Because there's absolutely no downside to telling Apple it can't artificially make its iMessage platform restricted to Apple devices. I would assume one downside is a higher amount of spam. Currently you need to have an Apple device to send an iMessage. So sending spam is an expensive proposition.

Spam operations have so much money that buying a bunch of iPhones is not an issue, even if they didn't, they could buy older, used iPhones for pennies.

Well then why haven't they? I get zero iMessage spam.

Re: EU will require Apple to open up iMessage (2022)

#476
post #461

Earlier quoted context omitted.

> Because there's absolutely no downside to telling Apple it can't artificially make its iMessage platform restricted to Apple devices. I would assume one downside is a higher amount of spam. Currently you need to have an Apple device to send an iMessage. So sending spam is an expensive proposition.

I've never understood the origins of this argument. I'm pretty sure it's rooted in deep misunderstanding. If I want to spam you I buy a bunch of numbers on Plivo and start sending your number messages with SMS, the existing standard. They show up in iMessage on your phone. The only difference is they're green instead of blue. So, how do I need an iPhone to send you spam? iMessage doesn't do anything related to spam o…

Please note I’m responding to the claim that there is “absolutely no downside” to making Apple devices more interoperable. I’m not saying whether or not that is a good enough reason not to.

I know the difference between SMS and iMessage. Currently I get plenty of SMS spam. I get pretty much zero iMessage spam. I’m pretty sure that I would get more spam if iMessage was made interoperable, even if device attestation was implemented as you described. Some Googling suggests that RCS, the competing standard for messaging, does not implement device attestation.

Re: EU will require Apple to open up iMessage (2022)

#477
post #409

Earlier quoted context omitted.

> Isn't this going to kill features that only some apps have or offer? What if one day Signal, Telegram or WhatsApp want to implement something "different" that could make messaging better but this policy is making things harder to implement because it would be impossible to make it interoperate with other messaging apps? Just open the standard/api/protocol, document it, and it'll get integrated into pidgin or some o…

But also, you generally want to iterate faster than "write a new spec and wait 2 years for implementations to support half of it". The alternative to which is just implementing it and hoping the other party can somehow make sense of it. Emoji reactions being supported by only a few activitypub implementations is an example of it. This is incidentally the reason moxie cited for not making Signal federated.

Why "hoping"? Just bake the ability to advertise and query for capabilities into the protocol. This is an issue that has been solved many times before.

And yes, it might mean that only one client would support a shiny new feature for a while. But that's exactly the situation with iMessage, s/for a while/forever/.

Re: EU will require Apple to open up iMessage (2022)

#478
post #457

Earlier quoted context omitted.

Regulations can disproportionately affect small businesses and still be worthwhile by virtue of preventing the thing they're regulating. For example, might be harder to start a train company with rigid safety standards but not spilling toxic chemicals over small towns is ideal. I think USB-C's relatively flimsily implemented open standard is kind of evidence of why Apple is hesitant to things like RCS. Good luck char…

Nintendo Switch AFAIR is not USB-C standard comply, they just use the same connector.

You just proved their point.

Re: EU will require Apple to open up iMessage (2022)

#479
post #224

A convenient first step for European governments towards killing effective end-to-end cryptography usage in everyday messaging. It used to be checks notes „terrorism“ and „child safety“ and now the hot new thing is „interoperability“. Who would have thought, that of all the above, „interoperability“ would be the one that makes it into legislation.

I'm curious about this too. At least now I have fairly decent confidence that when I send an iMessage to someone, Apple protects their identity to whatever standard they have. Whatever trust I put in Apple, at least it's a single point of failure. What happens if interoperability is enforced and messages have to be end-to-end encrypted? Wouldn't that mean that any side-loaded Android app would have to be able to get…

Why would a side-loaded Android app get a hold of a binary blob owned by another app, without the user granting such access explicitly?

Re: EU will require Apple to open up iMessage (2022)

#480

Earlier quoted context omitted.

> people who have no dollars get no vote and deserve nothing? On how messaging works on thousand-dollar phones? Yes.

Nice If your were in charge when the telephone network was designed, poor people would not even be able to make a phonecall to their middleclass neighbour or senator, they'd have to buy a special Rich People phone

Your hypothetical would make sense if iPhones didn't support regular phone calls, SMS, and every other messaging app out there. All people without iPhones can't do is send blue bubble messages to iPhone users. That's literally it.
Post reply on HN