Live data from Hacker News

Nothing's iMessage app was a security catastrophe, taken down in 24 hours

arstechnica.com

11–20 of 147 posts

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#11
post #4

> Authentication tokens were sent over unencrypted HTTP Wow! How do such fundamental errors make it into these apps? Did _nobody_ who was working on it have an previous experience? Or is this another case of upper management ignoring the experts and pushing terrible ideas regardless?

I bet this was outsourced to some offshore boiler room next door to the tech support scam call centre.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#12
post #4

> Authentication tokens were sent over unencrypted HTTP Wow! How do such fundamental errors make it into these apps? Did _nobody_ who was working on it have an previous experience? Or is this another case of upper management ignoring the experts and pushing terrible ideas regardless?

Under strict hierarchies of business, workers must do what they’re told and lack organization with their peers to gain leverage over bad direction from ownership/exec

This is by design.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#13
post #12

Earlier quoted context omitted.

Under strict hierarchies of business, workers must do what they’re told and lack organization with their peers to gain leverage over bad direction from ownership/exec

This is by design.

Of course

hopefully workers start to wake up to the leverage they can have over just about anything after seeing the “openai is nothing without its workers” organizing going on

Because these hierarchies ultimately aren’t in their interest or the interest of customers, and are only as inflexible as workers allow them to be

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#14
post #12

Earlier quoted context omitted.

This is by design.

Of course hopefully workers start to wake up to the leverage they can have over just about anything after seeing the “openai is nothing without its workers” organizing going on Because these hierarchies ultimately aren’t in their interest or the interest of customers, and are only as inflexible as workers allow them to be

So interesting that the same event has several spins right now:

- OpenAI is nothing without Sam Altman

- OpenAI is nothing without its workers (following Sam Altman)

- OpenAI is nothing without its workers (Sam Altman is just a figurehead)

A glitch in the Matrix?

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#15

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

> Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early access reviewer raised these exact security concerns in public?

Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day.

(To be clear: I'm an engineer, not a PM.)

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#16
post #4

> Authentication tokens were sent over unencrypted HTTP Wow! How do such fundamental errors make it into these apps? Did _nobody_ who was working on it have an previous experience? Or is this another case of upper management ignoring the experts and pushing terrible ideas regardless?

Why would anyone even build a product on top of unencrypted HTTP these days? I don't even use my NAS over HTTP in my local network when I can use HTTPS instead.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#17

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

> Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early access reviewer raised these exact security concerns in public? Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. (To be clear: I'm an engineer, not a PM.)

>Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day.

EXACTLY! Because it's a known fact all devs make mistakes, and as such, as a product manager/owner you're responsible for the bigger picture of the product and ensuring the right requirements, checks and bound are put in palce and validated for a successful product release.

It's not the job of the lowly SW engineers who have little visibility in the product as a whole and who just sprint to punch out Jira tickets handed to them from above, to check your product works as intended, it's your job as a PM/PO to ensure the work of all the devs integrates nicely into a cohesive product as per the requirements/vision.

Kind of like that famous story of that intern who got fired for deleting the production DB by mistake on his first day. Was it the intern's fault for the mistake or the fault of all the seniors and managers who should have placed the proper checks and bounds in place so that nobody can so easily delete the production DB?

So the buck for the product success/fail stops with those at the top who orchestrate the band, not with the individual SW engineers at the bottom.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#18

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

The product manager was overridden by the board / CEO who emphasized hyperaccurate metrics and time to market. Product managers are usually caught in the crossfire between a dev team who can't left-pad without 400 packages, and a C-suite who does not give a flying french fry about technical details.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#19
post #16
post #4

> Authentication tokens were sent over unencrypted HTTP Wow! How do such fundamental errors make it into these apps? Did _nobody_ who was working on it have an previous experience? Or is this another case of upper management ignoring the experts and pushing terrible ideas regardless?

Why would anyone even build a product on top of unencrypted HTTP these days? I don't even use my NAS over HTTP in my local network when I can use HTTPS instead.

"Nobody had time to figure out how to patch the letsencrypt runner to work with the only docker image that was compatible with the whatever web engine we run"

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#20

Earlier quoted context omitted.

Of course hopefully workers start to wake up to the leverage they can have over just about anything after seeing the “openai is nothing without its workers” organizing going on Because these hierarchies ultimately aren’t in their interest or the interest of customers, and are only as inflexible as workers allow them to be

So interesting that the same event has several spins right now: - OpenAI is nothing without Sam Altman - OpenAI is nothing without its workers (following Sam Altman) - OpenAI is nothing without its workers (Sam Altman is just a figurehead) A glitch in the Matrix?

Without commenting on the purpose and goal of the organizing, it is a display of worker leverage gained through organizing
Post reply on HN