Live data from Hacker News

Nothing's iMessage app was a security catastrophe, taken down in 24 hours

arstechnica.com

61–70 of 147 posts

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#61

Earlier quoted context omitted.

Yeah, but it kind of taints the picture that they rally under the banner of a Lord.

Consider he may not be a lord but a friend and colleague they value and may feel was treated unfairly.

I value all my 500 friends.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#62
post #24

I find it utterly bizarre that an engineer/team competent enough to reverse engineer iMessage can release such a shitshow. Almost parody level. Is this some sort of weird “they trust me, dumb fucks” social experiment?

But they didn't reverse engineer anything, afaik. Their Android app is just talking to a Mac Mini somewhere in a closet, logged in with the users Apple account (or so was stated in one of the interviews).

Does anyone know how many users a single Mac Mini handles? While I admire the hacker mindset, this solution seems incredibly wasteful so I am curious of its carbon footprint.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#63

Earlier quoted context omitted.

> Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early access reviewer raised these exact security concerns in public? Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. (To be clear: I'm an engineer, not a PM.)

Are engineers really setting up sentry without it being on the roadmap? PMs direct the engineers.

Observability is a good engineering practice. Sentry is invaluable to get app crashes in prod, and I wouldn't want any PM deciding whether we set up sentry or not. The real issue is the lack of control of what is logged and what logs go to sentry

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#64

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

Project managers are often confused for product managers

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#65

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

As a security researcher, bad security practices are prevalent in mobile by big companies and governments alike. They are just hoping that no one will reverse engineer their apps and APIs.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#66
post #39

Earlier quoted context omitted.

Even if RCS makes messaging with non-Apple devices more reliable, I‘d assume Apple would continue to use blue for Apple devices only, solely from a branding perspective. Despite all the things regulators are pushing them on, it seems reasonable that a brand can provide aesthetic-only markers for mutual users of the brand.

not to mention that RCS isn’t encrypted.

google has added e2ee in their implementation but it's not part of the standard, i think they use the signal protocol

rcs is too controlled by carriers for my liking. it's very much an sms replacement, rather than a protocol that treats the cell network as merely a data layer

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#67
post #50

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

I work for a company like this right now. About the same number of employees, same mistakes and same time to market on innovative stuff. Here's my two cents on how this can happen: > Which product manager in his/her right mind There is no product manager. There is a project manager. They steer on deadlines and functionality, nothing more. > How do these managers get jobs in these big name companies? Because they talk…

> There is no product manager. There is a project manager. They steer on deadlines and functionality, nothing more.

A glance at LinkedIn suggests you’re correct: the Sunbird app team seems to include a bunch of business people, a project manager, and no software engineers.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#68
post #24

I find it utterly bizarre that an engineer/team competent enough to reverse engineer iMessage can release such a shitshow. Almost parody level. Is this some sort of weird “they trust me, dumb fucks” social experiment?

But they didn't reverse engineer anything, afaik. Their Android app is just talking to a Mac Mini somewhere in a closet, logged in with the users Apple account (or so was stated in one of the interviews).

Okay, automating Apple account logins on a fleet of macOS VMs is still rarely treaded territory, so it takes some real technical chops, even if it’s mostly stitching together other people’s work. TLS termination on the hand takes <1hr following a guide, if you haven’t done it hundreds of times before…

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#69

Earlier quoted context omitted.

But they didn't reverse engineer anything, afaik. Their Android app is just talking to a Mac Mini somewhere in a closet, logged in with the users Apple account (or so was stated in one of the interviews).

Does anyone know how many users a single Mac Mini handles? While I admire the hacker mindset, this solution seems incredibly wasteful so I am curious of its carbon footprint.

Why does it seem so wasteful?

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#70

Earlier quoted context omitted.

Of course hopefully workers start to wake up to the leverage they can have over just about anything after seeing the “openai is nothing without its workers” organizing going on Because these hierarchies ultimately aren’t in their interest or the interest of customers, and are only as inflexible as workers allow them to be

So interesting that the same event has several spins right now: - OpenAI is nothing without Sam Altman - OpenAI is nothing without its workers (following Sam Altman) - OpenAI is nothing without its workers (Sam Altman is just a figurehead) A glitch in the Matrix?

That's a bit of a false dichotomy - just because they follow Sam Altman doesn't mean they can be incompetent. OpenAI was successful because of the rare mix of leadership with a vision and competent workers to back it up. Sam leaves, the vision dies. Workers leave, the product dies.
Post reply on HN