Live data from Hacker News

Nothing's iMessage app was a security catastrophe, taken down in 24 hours

arstechnica.com

101–110 of 147 posts

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#101
post #68

Earlier quoted context omitted.

But they didn't reverse engineer anything, afaik. Their Android app is just talking to a Mac Mini somewhere in a closet, logged in with the users Apple account (or so was stated in one of the interviews).

Okay, automating Apple account logins on a fleet of macOS VMs is still rarely treaded territory, so it takes some real technical chops, even if it’s mostly stitching together other people’s work. TLS termination on the hand takes <1hr following a guide, if you haven’t done it hundreds of times before…

Naah, if I would to attempt it my first try would be something like VNC (out of the box support) and Automator (out of the box support), or then some other tool to control mouse & keyboard.

The hardest part is probably keeping the duct-tapped stuff running.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#102
post #76

Earlier quoted context omitted.

> Apple is almost certainly aware of this at the C-Suite level What makes you think this?

iMessage is one of the primary moats keeping a lot of people on iPhone. I'm not necessarily as sure as the parent comment that the c-suite was briefed or anything, but I do think that iMessage exclusivity is pretty important to Apple

Outside the US it's rarely used, I doubt they care that much.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#103
post #35

Earlier quoted context omitted.

> How do these managers get jobs in these big name companies? Nothing is very far from what I would consider a "big name company" They are actually a really small joint venture between Carl Pei and Teenage Engineering. This whole iMessage fiasco is exactly why I have such a hard time taking Carl seriously in anything he does. He seems more concerned with creating hype through smoke and mirrors than in releasing anyth…

Is Teenage Engineering actually a part of a joint venture or are they just design consultants used to pump brand appeal?

They're part of the venture and some of their design team seems to have moved over to lead design there.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#104
post #76

Earlier quoted context omitted.

> Apple is almost certainly aware of this at the C-Suite level What makes you think this?

iMessage is one of the primary moats keeping a lot of people on iPhone. I'm not necessarily as sure as the parent comment that the c-suite was briefed or anything, but I do think that iMessage exclusivity is pretty important to Apple

The funny thing is that exclusivity would have been broken by the digital markets act if it actually were a moat here in Europe. But it's not, nobody cares about iMessage here. Even iOS users.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#105

Earlier quoted context omitted.

> Apple will revoke Sunbird’s access How do your expect that they will do this? IIUC they are basically logging in to real Apple hardware with the users credentials. There is nothing concrete that can be used to identify these sessions. (Obviously things like shared IPs, reused machines and other patterns can be used, but these aren't 100% accurate). That being said it surprises me that this can be profitable. If the…

Considering their security practices, I would bet that they virtualised macOS more or less legally and hoped nobody would look too closely.

Sounds like if you were running more than a couple of customers on the same hardware it would be easy for Apple to swat you. Since IIRC iMessage is authenticated with device keys so all VMs on the device would share the same key. Maybe they are betting that A) Apple doesn't care enough B) They aren't technically breaking any rules C) Enough "real" people do have multiple VMs signed into iMessage that they don't stand out enough to get blocked.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#106
post #22

Like the article said, this is particularly bad considering how much they hyped up this feature. I first heard about it through MKBHD’s YouTube channel, in a video with almost 3M views. And they couldn’t even bother to validate that basic security measures had been implemented? Or maybe they just flat out didn’t care and thought nobody would notice, which might be even worse. I viewed Nothing as just an overhyped “An…

Just regarding the MKBDH video, he does explicitly call out the security issues inherent with the design at around 5:53, and credits it as a reason not to try this feature. So, yeah, it's wild that they considered this ready to ship.

[1] https://youtu.be/ji5HwS3bhlU?t=352

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#107

Earlier quoted context omitted.

Considering their security practices, I would bet that they virtualised macOS more or less legally and hoped nobody would look too closely.

Sounds like if you were running more than a couple of customers on the same hardware it would be easy for Apple to swat you. Since IIRC iMessage is authenticated with device keys so all VMs on the device would share the same key. Maybe they are betting that A) Apple doesn't care enough B) They aren't technically breaking any rules C) Enough "real" people do have multiple VMs signed into iMessage that they don't stand…

I entirely agree.

> Maybe they are betting that A) Apple doesn't care enough B) They aren't technically breaking any rules C) Enough "real" people do have multiple VMs signed into iMessage that they don't stand out enough to get blocked.

We seem to get a scam startup à la Psystar every couple of years. Some of them seem to believe that they’re too small and not worth Apple’s lawyers’ time, and other seem to be convinced that they are within their rights and Apple an evil monopolist.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#108

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

This has the overall feeling of something developed by a team where leadership sincerely believes that security is everyone's job. Because it's everyone's job and they hire good people, they don't need specialists.

When there are deadlines to hit, average quality non-specialist management will generally prioritize keeping promises to leadership over meeting security requirements. It takes a rare manager with a strong grasp of the importance of security to stand up and tell their VP "We're not shipping, the security isn't there".

So how do these managers get there? They cut the corners that don't matter and hit the ship date. It gets them the promotion.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#109

Earlier quoted context omitted.

I'll stick with the ~1T market cap software/service ones: Facebook, Apple, Amazon, Microsoft, Google/Alphabet: FAAMG; But in discussions I'll include any company that has similar tech/business requirements or behavior.

I think I’ve heard MAGMA for this :)

If we're using (M)eta for FB, shouldn't we use (A)lphabet rather than G? MAAMA

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#110

Earlier quoted context omitted.

> Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early access reviewer raised these exact security concerns in public? Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. (To be clear: I'm an engineer, not a PM.)

Because it's the PM's job to oversee the whole project end to end.

Does your PM know the difference between HTTP and HTTPS? Mine doesn't. They manage tickets and expenses, not technical details.
Post reply on HN