Nothing's iMessage app was a security catastrophe, taken down in 24 hours
21–30 of 147 posts
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#22Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#23>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…
Nothing is very far from what I would consider a "big name company" They are actually a really small joint venture between Carl Pei and Teenage Engineering. This whole iMessage fiasco is exactly why I have such a hard time taking Carl seriously in anything he does. He seems more concerned with creating hype through smoke and mirrors than in releasing anything truly innovative and substantial.
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#24Is this some sort of weird “they trust me, dumb fucks” social experiment?
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#25Earlier quoted context omitted.
> Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early access reviewer raised these exact security concerns in public? Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. (To be clear: I'm an engineer, not a PM.)
>Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. EXACTLY! Because it's a known fact all devs make mistakes, and as such, as a product manager/owner you're responsible for the bigger picture of the product and ensuring the right requirements, checks and bound are put in palce and validated for a successful product release. It's not the job of the lowly SW engineers w…
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#26>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…
> How do these managers get jobs in these big name companies? Nothing is very far from what I would consider a "big name company" They are actually a really small joint venture between Carl Pei and Teenage Engineering. This whole iMessage fiasco is exactly why I have such a hard time taking Carl seriously in anything he does. He seems more concerned with creating hype through smoke and mirrors than in releasing anyth…
That's just 'Nothing' the company making the phone, but the iMessage for Android app was built by Sunbird, a different company. It's written in the article.
Agree that these companies are more like Juicero, built on hype and false trust to sell mediocre products that aren't special.
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#27Earlier quoted context omitted.
I don't think Beeper can promise end to end encryption for 3rd party services either. Fundamentally if you're interfacing with a service like iMessage or Whatsapp - even if they offer end to end encryption - the message has to be decrypted and then sent to the 3rd party app. Unless that gateway is running on your phone, the messages have to be decrypted in the cloud somewhere. At that point, you are placing all your…
Pretty much useless to self-host your own beeper server since you cannot use their client with your own homeserver. EDIT: forgot to add that there are several beeper specific MSC's that other clients don't render, thus if you want the full experience you either use their service or just stick with a normal matrix instance.
And it’s been working fine with Element as client.
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#28https://www.sunbirdapp.com/sunbird-stance-on-privacy-and-sec...
This quote is nice:
> Some of the messaging community believes that software that is open source is more secure. It is our view that it is not. The more visibility there is into the infrastructure and code, the easier it is to penetrate it.
In my opinion, Sunbird Messaging are fraudsters, and Nothing was their mark.
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#29I find it utterly bizarre that an engineer/team competent enough to reverse engineer iMessage can release such a shitshow. Almost parody level. Is this some sort of weird “they trust me, dumb fucks” social experiment?
Example: https://github.com/mautrix/imessage
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#30I find it utterly bizarre that an engineer/team competent enough to reverse engineer iMessage can release such a shitshow. Almost parody level. Is this some sort of weird “they trust me, dumb fucks” social experiment?