Live data from Hacker News

Nothing's iMessage app was a security catastrophe, taken down in 24 hours

arstechnica.com

51–60 of 147 posts

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#51
post #50

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

I work for a company like this right now. About the same number of employees, same mistakes and same time to market on innovative stuff. Here's my two cents on how this can happen: > Which product manager in his/her right mind There is no product manager. There is a project manager. They steer on deadlines and functionality, nothing more. > How do these managers get jobs in these big name companies? Because they talk…

>As a project manager, that's the last thing you want. First, it'll show what you didn't manage well. Secondly, it costs money. Finally, negative findings will delay delivery and means you failed to deliver on time, which is your only priority.

And yet FAANGMAULs and other tech-first companies like Mozilla, seem to be doing quite well on security with relatively very few oversights, caused by dev gross negligence.

So it's definetly possible to deliver airtight products if that's your goal and part of your dev culture, instead of just "ship it by Christmas at any cost".

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#52
post #4

> Authentication tokens were sent over unencrypted HTTP Wow! How do such fundamental errors make it into these apps? Did _nobody_ who was working on it have an previous experience? Or is this another case of upper management ignoring the experts and pushing terrible ideas regardless?

That’s what ChatGPT generated for us. There was a note saying something like „this is just an example. In a production environment please ensure proper encryption,“ but we ignored that.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#53
post #50

Earlier quoted context omitted.

I work for a company like this right now. About the same number of employees, same mistakes and same time to market on innovative stuff. Here's my two cents on how this can happen: > Which product manager in his/her right mind There is no product manager. There is a project manager. They steer on deadlines and functionality, nothing more. > How do these managers get jobs in these big name companies? Because they talk…

>As a project manager, that's the last thing you want. First, it'll show what you didn't manage well. Secondly, it costs money. Finally, negative findings will delay delivery and means you failed to deliver on time, which is your only priority. And yet FAANGMAULs and other tech-first companies like Mozilla, seem to be doing quite well on security with relatively very few oversights, caused by dev gross negligence. So…

Sure, they have product managers.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#54

Earlier quoted context omitted.

> How do these managers get jobs in these big name companies? Nothing is very far from what I would consider a "big name company" They are actually a really small joint venture between Carl Pei and Teenage Engineering. This whole iMessage fiasco is exactly why I have such a hard time taking Carl seriously in anything he does. He seems more concerned with creating hype through smoke and mirrors than in releasing anyth…

It is a big name company though. Not a lot of companies have access to a supply chain and logistics to design and ship products like they do worldwide.

Worldwide? Nothing Phone 1 wasn't even available for purchase in the U.S and I've yet to see any of their other products being sold throughout latam. They operate like the infamous street fashion brand Supreme with limited "drops" in carefully chosen markets to generate hype through manufactured scarcity.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#55
post #19
post #16

Earlier quoted context omitted.

Why would anyone even build a product on top of unencrypted HTTP these days? I don't even use my NAS over HTTP in my local network when I can use HTTPS instead.

"Nobody had time to figure out how to patch the letsencrypt runner to work with the only docker image that was compatible with the whatever web engine we run"

Oh... oh, that hurt so much to read because it just rings so damn true.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#56
post #35

Earlier quoted context omitted.

> How do these managers get jobs in these big name companies? Nothing is very far from what I would consider a "big name company" They are actually a really small joint venture between Carl Pei and Teenage Engineering. This whole iMessage fiasco is exactly why I have such a hard time taking Carl seriously in anything he does. He seems more concerned with creating hype through smoke and mirrors than in releasing anyth…

Is Teenage Engineering actually a part of a joint venture or are they just design consultants used to pump brand appeal?

According to this old article they are much more than simple consultants: https://www.theverge.com/2021/2/24/22298802/nothing-teenage-...

"Pei says that Teenage Engineering is one of Nothing’s founding partners, and will drive the design aesthetic at his new company."

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#57

The other story people are missing here is that even if this wasn't a security issue, iMessage is adopting RCS next year, so the whole blue/green bubble thing will become much less relevant.

The whole blue/green bubble thing is how Apple got something like 80% market share in probably the most valuable demographic in the world - US teenagers. They are no going to let it become less relevant without a desperate fight.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#58
Apple is almost certainly aware of this at the C-Suite level; I wouldn’t even be surprised if Tim Cook were briefed.

Had Apple pulled Sunbird’s access to iMessage before information about their shoddy security coming out via third-party, they would have run the risk of playing into Google’s narrative about Apple being petty about their closed standard.

Here’s what I think (and hope) will happen:

* Apple will revoke Sunbird’s access and/or will sue them; they can almost certainly detect them via fingerprinting and other techniques

* Apple will take steps to further protect the iMessage standard

The interesting thing here is that Sunbird’s marketing and PR execution, at a casual glance, appear to be as impressive as their engineering implementation dismal, thereby suggesting the usefulness of cautious maneuvering by Apple.

Google Cloud would ideally have a role in protecting users here, too; ie blocking Sunbird from its platform on account of exposing users to such formidable risk while so blatantly misrepresenting their security posture. Apple could implore Google to consider, which could look good for GCP; while extending a mutual commitment to implementing RCS together in the interest of users at a moment when skepticism of large tech is at an all-time high.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#59

The other story people are missing here is that even if this wasn't a security issue, iMessage is adopting RCS next year, so the whole blue/green bubble thing will become much less relevant.

As far as I've read so far Apple is adding RCS support to the Messages app, aka alongside SMS & MMS: https://www.theverge.com/2023/11/16/23964171/apple-iphone-rc...

It's not clear if iMessage will interoperate via RCS, which is what would make blue/green bubbles less relevant. My assumption would be no as they'd cede moat, and there isn't much of a network effect for them to gain from.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#60
post #7
post #2

Beeper seems a lot better then. Based on Matrix, so at least you know there is a foundation of security there.

I don't think Beeper can promise end to end encryption for 3rd party services either. Fundamentally if you're interfacing with a service like iMessage or Whatsapp - even if they offer end to end encryption - the message has to be decrypted and then sent to the 3rd party app. Unless that gateway is running on your phone, the messages have to be decrypted in the cloud somewhere. At that point, you are placing all your…

True, but at the same time, it’s a very small attack vector. I’d say the vast majority of users could really care less that an iMessage is decrypted for a brief period in-memory on some Mac VM in a data center.

You place your trust in 3rd party cloud servers for so many things. Email, as an example, is far more confidential / important, but most people never have it encrypted.

It’s still a fair criticism, but I still see Beeper + iMessage as more privacy-friendly than like FB Messenger (which has way more users).

Post reply on HN