Live data from Hacker News

Nothing's iMessage app was a security catastrophe, taken down in 24 hours

arstechnica.com

41–50 of 147 posts

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#41

Earlier quoted context omitted.

> Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early access reviewer raised these exact security concerns in public? Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. (To be clear: I'm an engineer, not a PM.)

Are engineers really setting up sentry without it being on the roadmap? PMs direct the engineers.

Depends what the culture is at Sunbird. Potentially it's very bottom-up and eng is making all the technical decisions and PM just steers the overall vision.

However I'd hope this is a case of an overworked team and over zealous management, because the alternative suggests a dangerously incompetent dev team.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#42
post #39

The other story people are missing here is that even if this wasn't a security issue, iMessage is adopting RCS next year, so the whole blue/green bubble thing will become much less relevant.

Even if RCS makes messaging with non-Apple devices more reliable, I‘d assume Apple would continue to use blue for Apple devices only, solely from a branding perspective. Despite all the things regulators are pushing them on, it seems reasonable that a brand can provide aesthetic-only markers for mutual users of the brand.

not to mention that RCS isn’t encrypted.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#43

Earlier quoted context omitted.

>Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. EXACTLY! Because it's a known fact all devs make mistakes, and as such, as a product manager/owner you're responsible for the bigger picture of the product and ensuring the right requirements, checks and bound are put in palce and validated for a successful product release. It's not the job of the lowly SW engineers w…

I hope this is facetious. Security is everyone’s job, and unencrypted customer data, outside of a locked-down DB, should give one pause.

>I hope this is facetious.

Nope, not at all.

>Security is everyone’s job

In theory at well run tech companies ideally yes, but when you're overworked and underpaid and crunching like in a sweatshop to meet some arbitrary deadline coming from above that you did not agree with, then work becomes a chore doing the bare minimum just to get home before dinner, and every other potential issue outside my allotted tickets that's not part of my KPIs becomes "not my job" and "someone else's problem" because "fuck it, I'm already overworked and I won't get any extra recognition for doing even more overtime on security topics nobody seems to care about".

In short, as a dev, you don't care about the outcome of the product because you're not paid or empowered enough to care.

Shit rolls uphill. If you want devs to actually give a fuck about the product as a whole instead of just mindlessly punching Jira tickets, then you need to empower them, pay them well and respect them and their WLB, which the vast majority of companies worldwide do not (HNers are a priviledged bubble that's the exception). Otherwise you get what you se before you, a shitshow, because most tech companies are run like crap.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#44

Reading Sunbird's site makes it all feel like a scam. Their FAQs and Privacy and Security page are just chock full of what appear to be egregious lies. Both repeatedly state that messages are never stored, and end-to-end encrypted. It is not possible they didn't know this was a lie, because it is fundamentally built in a way that can't have E2E encryption (leaving aside the other horrendous security aspects). https:/…

> Open source vulnerabilities typically stem from poorly written code that leave gaps, which attackers can use to carryout malicious activities.

And closed source code never had any "gaps" whatsoever, eh.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#45

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

> Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early access reviewer raised these exact security concerns in public? Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. (To be clear: I'm an engineer, not a PM.)

They may have had a "Nothing to see here" culture.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#46

Earlier quoted context omitted.

>Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. EXACTLY! Because it's a known fact all devs make mistakes, and as such, as a product manager/owner you're responsible for the bigger picture of the product and ensuring the right requirements, checks and bound are put in palce and validated for a successful product release. It's not the job of the lowly SW engineers w…

I hope this is facetious. Security is everyone’s job, and unencrypted customer data, outside of a locked-down DB, should give one pause.

Everyone here is to blame. Not just the PM, not just the engineers. I'd also blame the hiring manager.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#47
post #33

Apple should probably implement a brown bubble designation for anyone using iMessage and not able to pass device authentication. Kinda surprised the app got taken down so quickly. This is the type of app LE loves. Being able to surveil into conversations by piggybacking off the weak link

AIUI, iMessage was running on legimitate devices. They were using Mac's in a datacenter as a bridge.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#48
post #41

Earlier quoted context omitted.

Are engineers really setting up sentry without it being on the roadmap? PMs direct the engineers.

Depends what the culture is at Sunbird. Potentially it's very bottom-up and eng is making all the technical decisions and PM just steers the overall vision. However I'd hope this is a case of an overworked team and over zealous management, because the alternative suggests a dangerously incompetent dev team.

>PM just steers the overall vision

So, they're useless?

Product managers should ideally be the technical voice of reason between the tech illiterate visionaries and the engineers in the trenches, steering the visionaries on what's technically feasible within the available resources.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#49

Earlier quoted context omitted.

Without commenting on the purpose and goal of the organizing, it is a display of worker leverage gained through organizing

Yeah, but it kind of taints the picture that they rally under the banner of a Lord.

Consider he may not be a lord but a friend and colleague they value and may feel was treated unfairly.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#50

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

I work for a company like this right now. About the same number of employees, same mistakes and same time to market on innovative stuff. Here's my two cents on how this can happen:

> Which product manager in his/her right mind

There is no product manager. There is a project manager. They steer on deadlines and functionality, nothing more.

> How do these managers get jobs in these big name companies?

Because they talk well and they've delivered before. Have they delivered something good and secure? Nobody cares, deadlines were met and functionality was shipped.

I notice the same in IT sales. Sell too much for too little, collect bonus and move on. Nobody comes back to you if the project fails or becomes too expensive and if they do, you blame the one engineer you had glance over the proposal before sending it to the client.

> It's the best way to uncover shoddy dev and security practices

As a project manager, that's the last thing you want. First, it'll show what you didn't manage well. Secondly, it costs money. Finally, negative findings will delay delivery and means you failed to deliver on time, which is your only priority.

Maybe I sound overly cynical, but I've seen this exact thing happen everywhere, from small firms to Fortune 500 to government.

Post reply on HN