Live data from Hacker News

Nothing's iMessage app was a security catastrophe, taken down in 24 hours

arstechnica.com

71–80 of 147 posts

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#71
post #58

Apple is almost certainly aware of this at the C-Suite level; I wouldn’t even be surprised if Tim Cook were briefed. Had Apple pulled Sunbird’s access to iMessage before information about their shoddy security coming out via third-party, they would have run the risk of playing into Google’s narrative about Apple being petty about their closed standard. Here’s what I think (and hope) will happen: * Apple will revoke S…

> Apple is almost certainly aware of this at the C-Suite level

What makes you think this?

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#72
post #67
post #50

Earlier quoted context omitted.

I work for a company like this right now. About the same number of employees, same mistakes and same time to market on innovative stuff. Here's my two cents on how this can happen: > Which product manager in his/her right mind There is no product manager. There is a project manager. They steer on deadlines and functionality, nothing more. > How do these managers get jobs in these big name companies? Because they talk…

> There is no product manager. There is a project manager. They steer on deadlines and functionality, nothing more. A glance at LinkedIn suggests you’re correct: the Sunbird app team seems to include a bunch of business people, a project manager, and no software engineers.

Sounds like the usual scammy juicero-like vaporware unicorns:

1. Pitch some grandiose idea to clueless execs

2. win over big money contracts

3. farm out the actual work to the cheapest body-shop and pocket the rest

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#73

The other story people are missing here is that even if this wasn't a security issue, iMessage is adopting RCS next year, so the whole blue/green bubble thing will become much less relevant.

I'm on Android and don't SMS with hardly anyone these days. I just use telegram channels or signal messenger.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#74

Earlier quoted context omitted.

Does anyone know how many users a single Mac Mini handles? While I admire the hacker mindset, this solution seems incredibly wasteful so I am curious of its carbon footprint.

Why does it seem so wasteful?

Because I assume that Apple put a fairly low limit on the number of accounts that can be tied to a single computer.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#75
post #50

Earlier quoted context omitted.

I work for a company like this right now. About the same number of employees, same mistakes and same time to market on innovative stuff. Here's my two cents on how this can happen: > Which product manager in his/her right mind There is no product manager. There is a project manager. They steer on deadlines and functionality, nothing more. > How do these managers get jobs in these big name companies? Because they talk…

>As a project manager, that's the last thing you want. First, it'll show what you didn't manage well. Secondly, it costs money. Finally, negative findings will delay delivery and means you failed to deliver on time, which is your only priority. And yet FAANGMAULs and other tech-first companies like Mozilla, seem to be doing quite well on security with relatively very few oversights, caused by dev gross negligence. So…

It's too early to play guess the acronym for me.

What is the MAUL part of your FAANGMAUL acronym.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#76
post #58

Apple is almost certainly aware of this at the C-Suite level; I wouldn’t even be surprised if Tim Cook were briefed. Had Apple pulled Sunbird’s access to iMessage before information about their shoddy security coming out via third-party, they would have run the risk of playing into Google’s narrative about Apple being petty about their closed standard. Here’s what I think (and hope) will happen: * Apple will revoke S…

> Apple is almost certainly aware of this at the C-Suite level What makes you think this?

iMessage is one of the primary moats keeping a lot of people on iPhone. I'm not necessarily as sure as the parent comment that the c-suite was briefed or anything, but I do think that iMessage exclusivity is pretty important to Apple

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#77

Reading Sunbird's site makes it all feel like a scam. Their FAQs and Privacy and Security page are just chock full of what appear to be egregious lies. Both repeatedly state that messages are never stored, and end-to-end encrypted. It is not possible they didn't know this was a lie, because it is fundamentally built in a way that can't have E2E encryption (leaving aside the other horrendous security aspects). https:/…

> In my opinion, Sunbird Messaging are fraudsters, and Nothing was their mark.

100% agree with this. `nothing` since its inception has been nothing but a marketing gimmick.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#78
post #33

Apple should probably implement a brown bubble designation for anyone using iMessage and not able to pass device authentication. Kinda surprised the app got taken down so quickly. This is the type of app LE loves. Being able to surveil into conversations by piggybacking off the weak link

AIUI, iMessage was running on legimitate devices. They were using Mac's in a datacenter as a bridge.

I realize this isn't in the realm of trademark law, but the green bubble is a mark that indicates you are talking to someone with an apple device, and not to someone through a shady poorly implemented hack.

I am for reverse-engineering, but at some point civilized society invented the trademark, and today it seems necessary to create similar bodies of law that protect companies from charlatan Middleware that abuse markings of trust for personal profit.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#79
post #75

Earlier quoted context omitted.

>As a project manager, that's the last thing you want. First, it'll show what you didn't manage well. Secondly, it costs money. Finally, negative findings will delay delivery and means you failed to deliver on time, which is your only priority. And yet FAANGMAULs and other tech-first companies like Mozilla, seem to be doing quite well on security with relatively very few oversights, caused by dev gross negligence. So…

It's too early to play guess the acronym for me. What is the MAUL part of your FAANGMAUL acronym.

Microsoft, Uber, Lyft, and AirBnB is what I eventually found.

FAANGMULA in the above case.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#80
post #75

Earlier quoted context omitted.

>As a project manager, that's the last thing you want. First, it'll show what you didn't manage well. Secondly, it costs money. Finally, negative findings will delay delivery and means you failed to deliver on time, which is your only priority. And yet FAANGMAULs and other tech-first companies like Mozilla, seem to be doing quite well on security with relatively very few oversights, caused by dev gross negligence. So…

It's too early to play guess the acronym for me. What is the MAUL part of your FAANGMAUL acronym.

Microsoft, Airbnb, Uber, Lyft.

When will we stop adding companies' acronyms?

Post reply on HN