Live data from Hacker News

Nothing's iMessage app was a security catastrophe, taken down in 24 hours

arstechnica.com

21–30 of 147 posts

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#22
Like the article said, this is particularly bad considering how much they hyped up this feature. I first heard about it through MKBHD’s YouTube channel, in a video with almost 3M views. And they couldn’t even bother to validate that basic security measures had been implemented? Or maybe they just flat out didn’t care and thought nobody would notice, which might be even worse. I viewed Nothing as just an overhyped “Android phone but with lights on the back” but this has shown they’re a bit worse than that.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#23

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

> How do these managers get jobs in these big name companies?

Nothing is very far from what I would consider a "big name company" They are actually a really small joint venture between Carl Pei and Teenage Engineering. This whole iMessage fiasco is exactly why I have such a hard time taking Carl seriously in anything he does. He seems more concerned with creating hype through smoke and mirrors than in releasing anything truly innovative and substantial.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#25

Earlier quoted context omitted.

> Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early access reviewer raised these exact security concerns in public? Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. (To be clear: I'm an engineer, not a PM.)

>Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. EXACTLY! Because it's a known fact all devs make mistakes, and as such, as a product manager/owner you're responsible for the bigger picture of the product and ensuring the right requirements, checks and bound are put in palce and validated for a successful product release. It's not the job of the lowly SW engineers w…

Just yesterday I was protesting unnecessary complexity in my story until my lead had a sidebar chat about an upcoming project. How was I supposed to know that?

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#26

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

> How do these managers get jobs in these big name companies? Nothing is very far from what I would consider a "big name company" They are actually a really small joint venture between Carl Pei and Teenage Engineering. This whole iMessage fiasco is exactly why I have such a hard time taking Carl seriously in anything he does. He seems more concerned with creating hype through smoke and mirrors than in releasing anyth…

> They are actually a really small joint venture between Carl Pei and Teenage Engineering.

That's just 'Nothing' the company making the phone, but the iMessage for Android app was built by Sunbird, a different company. It's written in the article.

Agree that these companies are more like Juicero, built on hype and false trust to sell mediocre products that aren't special.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#27
post #9
post #7

Earlier quoted context omitted.

I don't think Beeper can promise end to end encryption for 3rd party services either. Fundamentally if you're interfacing with a service like iMessage or Whatsapp - even if they offer end to end encryption - the message has to be decrypted and then sent to the 3rd party app. Unless that gateway is running on your phone, the messages have to be decrypted in the cloud somewhere. At that point, you are placing all your…

Pretty much useless to self-host your own beeper server since you cannot use their client with your own homeserver. EDIT: forgot to add that there are several beeper specific MSC's that other clients don't render, thus if you want the full experience you either use their service or just stick with a normal matrix instance.

I don’t know what extra features Beeper has, but I’ve been hosting my own Signal/Telegram bridges for 2 years now.

And it’s been working fine with Element as client.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#28
Reading Sunbird's site makes it all feel like a scam. Their FAQs and Privacy and Security page are just chock full of what appear to be egregious lies. Both repeatedly state that messages are never stored, and end-to-end encrypted. It is not possible they didn't know this was a lie, because it is fundamentally built in a way that can't have E2E encryption (leaving aside the other horrendous security aspects).

https://www.sunbirdapp.com/sunbird-stance-on-privacy-and-sec...

This quote is nice:

> Some of the messaging community believes that software that is open source is more secure. It is our view that it is not. The more visibility there is into the infrastructure and code, the easier it is to penetrate it.

In my opinion, Sunbird Messaging are fraudsters, and Nothing was their mark.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#29
post #24

I find it utterly bizarre that an engineer/team competent enough to reverse engineer iMessage can release such a shitshow. Almost parody level. Is this some sort of weird “they trust me, dumb fucks” social experiment?

There are open source bridges for iMessage. So I’m not convinced they did.

Example: https://github.com/mautrix/imessage

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#30
post #24

I find it utterly bizarre that an engineer/team competent enough to reverse engineer iMessage can release such a shitshow. Almost parody level. Is this some sort of weird “they trust me, dumb fucks” social experiment?

But they didn't reverse engineer anything, afaik. Their Android app is just talking to a Mac Mini somewhere in a closet, logged in with the users Apple account (or so was stated in one of the interviews).
Post reply on HN