Live data from Hacker News

Nothing's iMessage app was a security catastrophe, taken down in 24 hours

arstechnica.com

91–100 of 147 posts

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#91
post #75

Earlier quoted context omitted.

It's too early to play guess the acronym for me. What is the MAUL part of your FAANGMAUL acronym.

Microsoft, Airbnb, Uber, Lyft. When will we stop adding companies' acronyms?

I'll stick with the ~1T market cap software/service ones: Facebook, Apple, Amazon, Microsoft, Google/Alphabet: FAAMG; But in discussions I'll include any company that has similar tech/business requirements or behavior.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#92

Earlier quoted context omitted.

I hope this is facetious. Security is everyone’s job, and unencrypted customer data, outside of a locked-down DB, should give one pause.

Everyone here is to blame. Not just the PM, not just the engineers. I'd also blame the hiring manager.

All the way to the CEOs. I find it hard to believe that someone at this position in a tech company did not see any red flags, particularly as all the tech forums I have seen pointed out the potential issues within minutes of the announcement.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#93
post #76

Earlier quoted context omitted.

> Apple is almost certainly aware of this at the C-Suite level What makes you think this?

iMessage is one of the primary moats keeping a lot of people on iPhone. I'm not necessarily as sure as the parent comment that the c-suite was briefed or anything, but I do think that iMessage exclusivity is pretty important to Apple

The risk here has never gotten near a point of being about Sunbird slowing down iPhone sales by allowing iMessage on Android. Beeper already has been doing a workaround for sending iMessages from other platforms for a while.

The issue is Sunbird's shoddy implementation in particular compromising the security of a bunch of their users' accounts, with a real Android OEM vouching for their service and shipping it on their new phone, giving Sunbird a big publicity boost in the process.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#94

Earlier quoted context omitted.

Are engineers really setting up sentry without it being on the roadmap? PMs direct the engineers.

Yes... Why would a PM put Sentry on the roadmap, unless that PM has some reasonable level of technical understanding, but at that point the same PM should have been aware of many of the security implications of the overall project. A not unreasonable guess would be that Sunbird doesn't have a great number of senior engineers on staff, either do to cost, or because very few wanted to take on such a project. So it cobb…

> I questioned the point of the Nothing Phone and Nothing Phone 2 when they where both released, they are nothing more than Android phones with a few gimmick but everyone was loosing their minds over those things and now ArsTechnica writes: "Nothing has always seemed like an Android manufacturer that was more hype than substance"

I think there is a perception issue. Ars is not a person. I don’t know who was hyped when the phone was released, but Ron Amadeo sounds like someone who would indeed have been skeptical about Nothing’s pitch.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#95

Earlier quoted context omitted.

True, but at the same time, it’s a very small attack vector. I’d say the vast majority of users could really care less that an iMessage is decrypted for a brief period in-memory on some Mac VM in a data center. You place your trust in 3rd party cloud servers for so many things. Email, as an example, is far more confidential / important, but most people never have it encrypted. It’s still a fair criticism, but I still…

> I’d say the vast majority of users could really care less that an iMessage is decrypted for a brief period in-memory on some Mac VM in a data center. And yet, that's precisely where I would go if I were law enforcement or a secret service. Tell them they're being used by terrorists/drug kingpins/CSAM peddlers, slap a gag order on 'em, and scoop up everything. And unlike Apple, Whatsapp or Telegram whoever hosts suc…

Law enforcement doesn't need to do that. They can go direct to Apple because Apple's iCloud backup breaks iMessage end-to-end encryption for almost all people anyway (few enable the advanced protection program that fixes this blatant hole and both sides need it enabled to preserve the encryption). This isn't a conspiracy theory, it's documented behavior from Apple. People don't know or care.

Use Signal if you want end-to-end encryption and don't feel bad about using Beeper for people stuck on iMessage.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#96
post #76

Earlier quoted context omitted.

> Apple is almost certainly aware of this at the C-Suite level What makes you think this?

iMessage is one of the primary moats keeping a lot of people on iPhone. I'm not necessarily as sure as the parent comment that the c-suite was briefed or anything, but I do think that iMessage exclusivity is pretty important to Apple

That's probably a fact, and still a very interesting fact because it seems mostly US-related. In central europe, not tha many people use iMessage or even know that it exists.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#97

Earlier quoted context omitted.

Microsoft, Airbnb, Uber, Lyft. When will we stop adding companies' acronyms?

I'll stick with the ~1T market cap software/service ones: Facebook, Apple, Amazon, Microsoft, Google/Alphabet: FAAMG; But in discussions I'll include any company that has similar tech/business requirements or behavior.

I think I’ve heard MAGMA for this :)

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#98
post #75

Earlier quoted context omitted.

It's too early to play guess the acronym for me. What is the MAUL part of your FAANGMAUL acronym.

Microsoft, Airbnb, Uber, Lyft. When will we stop adding companies' acronyms?

I just keep using the term Big Tech. FAANG was nice but it's too annoying to keep acronyms up to date.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#99
post #58

Apple is almost certainly aware of this at the C-Suite level; I wouldn’t even be surprised if Tim Cook were briefed. Had Apple pulled Sunbird’s access to iMessage before information about their shoddy security coming out via third-party, they would have run the risk of playing into Google’s narrative about Apple being petty about their closed standard. Here’s what I think (and hope) will happen: * Apple will revoke S…

> Apple will revoke Sunbird’s access How do your expect that they will do this? IIUC they are basically logging in to real Apple hardware with the users credentials. There is nothing concrete that can be used to identify these sessions. (Obviously things like shared IPs, reused machines and other patterns can be used, but these aren't 100% accurate). That being said it surprises me that this can be profitable. If the…

Considering their security practices, I would bet that they virtualised macOS more or less legally and hoped nobody would look too closely.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#100

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

> Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early access reviewer raised these exact security concerns in public? Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. (To be clear: I'm an engineer, not a PM.)

Because it's the PM's job to oversee the whole project end to end.
Post reply on HN