Live data from Hacker News

Nothing's iMessage app was a security catastrophe, taken down in 24 hours

arstechnica.com

31–40 of 147 posts

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#31
post #24

I find it utterly bizarre that an engineer/team competent enough to reverse engineer iMessage can release such a shitshow. Almost parody level. Is this some sort of weird “they trust me, dumb fucks” social experiment?

iMessage just stores messages in SQLite on macOS. They have a server process that runs on macOS and reads that database. So it’s not like they reverse engineered the protocol; they just read a local database in a standard, open-source format.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#32
post #24

I find it utterly bizarre that an engineer/team competent enough to reverse engineer iMessage can release such a shitshow. Almost parody level. Is this some sort of weird “they trust me, dumb fucks” social experiment?

Some of the early research found "BlueBubbles"[1] mentions in some places, and the lack of TLS is almost definitely because BlueBubbles currently doesn't support TLS on its own.

1: https://bluebubbles.app/

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#33
Apple should probably implement a brown bubble designation for anyone using iMessage and not able to pass device authentication. Kinda surprised the app got taken down so quickly. This is the type of app LE loves. Being able to surveil into conversations by piggybacking off the weak link

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#35

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

> How do these managers get jobs in these big name companies? Nothing is very far from what I would consider a "big name company" They are actually a really small joint venture between Carl Pei and Teenage Engineering. This whole iMessage fiasco is exactly why I have such a hard time taking Carl seriously in anything he does. He seems more concerned with creating hype through smoke and mirrors than in releasing anyth…

Is Teenage Engineering actually a part of a joint venture or are they just design consultants used to pump brand appeal?

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#36

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

> How do these managers get jobs in these big name companies? Nothing is very far from what I would consider a "big name company" They are actually a really small joint venture between Carl Pei and Teenage Engineering. This whole iMessage fiasco is exactly why I have such a hard time taking Carl seriously in anything he does. He seems more concerned with creating hype through smoke and mirrors than in releasing anyth…

It is a big name company though. Not a lot of companies have access to a supply chain and logistics to design and ship products like they do worldwide.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#37

Earlier quoted context omitted.

> Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early access reviewer raised these exact security concerns in public? Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. (To be clear: I'm an engineer, not a PM.)

>Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. EXACTLY! Because it's a known fact all devs make mistakes, and as such, as a product manager/owner you're responsible for the bigger picture of the product and ensuring the right requirements, checks and bound are put in palce and validated for a successful product release. It's not the job of the lowly SW engineers w…

I hope this is facetious. Security is everyone’s job, and unencrypted customer data, outside of a locked-down DB, should give one pause.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#38

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

> Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early access reviewer raised these exact security concerns in public? Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. (To be clear: I'm an engineer, not a PM.)

Are engineers really setting up sentry without it being on the roadmap? PMs direct the engineers.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#39

The other story people are missing here is that even if this wasn't a security issue, iMessage is adopting RCS next year, so the whole blue/green bubble thing will become much less relevant.

Even if RCS makes messaging with non-Apple devices more reliable, I‘d assume Apple would continue to use blue for Apple devices only, solely from a branding perspective. Despite all the things regulators are pushing them on, it seems reasonable that a brand can provide aesthetic-only markers for mutual users of the brand.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#40

Earlier quoted context omitted.

So interesting that the same event has several spins right now: - OpenAI is nothing without Sam Altman - OpenAI is nothing without its workers (following Sam Altman) - OpenAI is nothing without its workers (Sam Altman is just a figurehead) A glitch in the Matrix?

Without commenting on the purpose and goal of the organizing, it is a display of worker leverage gained through organizing

Yeah, but it kind of taints the picture that they rally under the banner of a Lord.
Post reply on HN