Live data from Hacker News

Nothing's iMessage app was a security catastrophe, taken down in 24 hours

arstechnica.com

121–130 of 147 posts

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#121

Earlier quoted context omitted.

AIUI, iMessage was running on legimitate devices. They were using Mac's in a datacenter as a bridge.

I realize this isn't in the realm of trademark law, but the green bubble is a mark that indicates you are talking to someone with an apple device, and not to someone through a shady poorly implemented hack. I am for reverse-engineering, but at some point civilized society invented the trademark, and today it seems necessary to create similar bodies of law that protect companies from charlatan Middleware that abuse ma…

Yes, let's give corporations more power. Image bubble colour indicate the protocol you're using, and nothing more. It don't - and can't - guarantee security (many people learned this lesson with https).

But sure, let's let corporations super-copyright the colour green.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#122
post #58

Apple is almost certainly aware of this at the C-Suite level; I wouldn’t even be surprised if Tim Cook were briefed. Had Apple pulled Sunbird’s access to iMessage before information about their shoddy security coming out via third-party, they would have run the risk of playing into Google’s narrative about Apple being petty about their closed standard. Here’s what I think (and hope) will happen: * Apple will revoke S…

> Had Apple pulled Sunbird’s access to iMessage before information about their shoddy security coming out via third-party, they would have run the risk of playing into Google’s narrative about Apple being petty about their closed standard.

It's not "Google's narrative" (which makes it sound like it's not true), it's the truth and abusing a monopoly, that is being investigated by the EU. We're expecting an EU decision soon if Apple are a gatekeeper with iMessage (as per the DMA/DSA), which they almost certainly are. If that is indeed the case, they'll be forced to open it to competitors anyways. So the whole thing is moot - see also Apple starting to finally adopt RCS, probably trying to anticipate EU regulations and spin them being forced to do the correct thing as "innovation".

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#123
post #27
post #9

Earlier quoted context omitted.

Pretty much useless to self-host your own beeper server since you cannot use their client with your own homeserver. EDIT: forgot to add that there are several beeper specific MSC's that other clients don't render, thus if you want the full experience you either use their service or just stick with a normal matrix instance.

I don’t know what extra features Beeper has, but I’ve been hosting my own Signal/Telegram bridges for 2 years now. And it’s been working fine with Element as client.

As far as I can tell, the Beeper official client is a fork of Element, and there aren’t any huge missing features (other than easily setting up bridges).

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#125

Earlier quoted context omitted.

AIUI, iMessage was running on legimitate devices. They were using Mac's in a datacenter as a bridge.

I realize this isn't in the realm of trademark law, but the green bubble is a mark that indicates you are talking to someone with an apple device, and not to someone through a shady poorly implemented hack. I am for reverse-engineering, but at some point civilized society invented the trademark, and today it seems necessary to create similar bodies of law that protect companies from charlatan Middleware that abuse ma…

> the green bubble is a mark that indicates you are talking to someone with an apple device

The bubble color was and is a signifier of transport layer only; I've personally had situations (generally with spotty or very poor coverage) where individual messages go over SMS even for conversations on all Apple hardware where the rest of the conversation is going over iMessage.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#126
post #68

Earlier quoted context omitted.

Okay, automating Apple account logins on a fleet of macOS VMs is still rarely treaded territory, so it takes some real technical chops, even if it’s mostly stitching together other people’s work. TLS termination on the hand takes <1hr following a guide, if you haven’t done it hundreds of times before…

Naah, if I would to attempt it my first try would be something like VNC (out of the box support) and Automator (out of the box support), or then some other tool to control mouse & keyboard. The hardest part is probably keeping the duct-tapped stuff running.

How are you keeping all those sessions updated in real time? How are you parsing messages sent from others to be able to forward them to the user? How are you handling 'reactions' and 'threaded replies' and attachments?

You are dismissing a very hard problem with handwaving.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#127
post #50

Earlier quoted context omitted.

I work for a company like this right now. About the same number of employees, same mistakes and same time to market on innovative stuff. Here's my two cents on how this can happen: > Which product manager in his/her right mind There is no product manager. There is a project manager. They steer on deadlines and functionality, nothing more. > How do these managers get jobs in these big name companies? Because they talk…

>As a project manager, that's the last thing you want. First, it'll show what you didn't manage well. Secondly, it costs money. Finally, negative findings will delay delivery and means you failed to deliver on time, which is your only priority. And yet FAANGMAULs and other tech-first companies like Mozilla, seem to be doing quite well on security with relatively very few oversights, caused by dev gross negligence. So…

What? Mozilla basically abandoned Servo, because of costs. And spent some money on CEO pay and on ridiculous preach-to-the-choir outreach campaigns and whatnot. And they regularly say no to security features. (eg. TLSA/DANE support https://bugzilla.mozilla.org/show_bug.cgi?id=672600 )

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#128

I still can't fathom why people would care in the slightest what their message bubble color was (I mean as a European I don't get iMessage at all, I use Signal and WhatsApp for the less tech-literate family of mine), it sounds like the most insanely petty thing to grab onto to care about.

The colors functionally denote the features available in the chat. In group chats, having a single non-iMessage user devolves the features available to the group chat to the SMS level. You also lose E2E and high res pictures and video.

The different colors of bubbles are a consequence of iMessage's origin as a protocol that supplanted SMS/MMS messaging while allowing the older protocols as seamless fallbacks; WhatsApp, Signal et al never had a requirement like that, and consequently never had to deal with different feature sets among their users (at least, not to the same extent).

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#129

I still can't fathom why people would care in the slightest what their message bubble color was (I mean as a European I don't get iMessage at all, I use Signal and WhatsApp for the less tech-literate family of mine), it sounds like the most insanely petty thing to grab onto to care about.

iMessage only works on iOS.

If even one non-iOS user joins a chat then all features except for basic texting (SMS and MMS) are dropped.

I don't think I need to tell you how much of todays' social interaction happens in group chats. Not having WhatsApp in the Netherlands when you're younger than 30 would effectively make you a hermit.

It's probably similar with iMessage in the US.

This creates an enormous peer pressure effect, especially for young people, to buy an iOS device.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#130

Earlier quoted context omitted.

I hope this is facetious. Security is everyone’s job, and unencrypted customer data, outside of a locked-down DB, should give one pause.

Well, managers are happy to take responsibility for their project/product when everything goes well. It’s actually the argument for their salaries and bonuses compared to lowly engineers. So why should they not take responsibility when it goes sideways? Particularly when failure affects the whole product like the Sunbird app. You cannot say that the project works because of you, and then turn around and pretend you h…

>You cannot say that the project works because of you, and then turn around and pretend you have nothing to do with its failures.

You'd be surprised. I've been in at least 2 companies where that was the case and had to be the scapegoat for projects going sideways due to poor management.

Humans are shit and would much rather push the blame on someone if the company culture is not blameless.

Post reply on HN