Live data from Hacker News

Show HN: Beeper Mini – iMessage client for Android

beeper.com

221–230 of 902 posts

Re: Show HN: Beeper Mini – iMessage client for Android

#221

Earlier quoted context omitted.

So you're saying that if I install WhatsApp on my phone, I can text anyone I want, if I have their phone number? Doesn't matter if they have WhatsApp installed? I just say "send this to 5551212" and it gets there?

They need to install the app, which is free. What they don't need to do is buy an iPhone, which is not free.

So they absolutely segregate users onto their proprietary platform, it just happens not to cost money to use.

Re: Show HN: Beeper Mini – iMessage client for Android

#222

It seems that at least the push notification registration part uses a "leaked/extracted" FairPlay private key [1]. As far as I understand, FairPlay certificates/keys should be unique to each iDevice. Couldn't Apple trivially ban all subscriptions originating from this fake device? The comment says you know how to generate more; does Beeper Mini generate one for each install? Why would Apple believe those certificates…

Snazzy Labs did an overview video [1] about this implementation. According to them, reusing a specific hardware token is such s common practice that Apple would need to "redesign their entire authentication and delivery strategy" to mitigate this problem. I guess we'll see how this statement holds up in the coming weeks/months.

[1] https://youtu.be/S24TDRxEna4?t=5m38s

Re: Show HN: Beeper Mini – iMessage client for Android

#223

From their blogpost: https://blog.beeper.com/p/beeper-cloud-and-product-roadmap > Everything changed in August when a security researcher reverse engineered the iMessage protocol. > At a high level, here’s our product plan for the near future (in very rough order, and very subject to change): > Add support for SMS, WhatsApp and Signal into Beeper Mini, using the same end-to-end encrypted client-side connection archit…

> Signal is the same, they C&D every fork that becomes popular, the only official clients are the CLI and the ones they release This always rubbed me the wrong way and made it seem like it's an NSA operation

The source to Signal is open to analysis if you doubt its security. I suspect they C&D forks because they don't follow coding/security practices as upstream does, and it would be too hard to ensure they would if they just let anyone fork it.

Re: Show HN: Beeper Mini – iMessage client for Android

#225

At this point, why not just wait for Apple to release their RCS implementation? The nicest thing about iMessage (for me, at least) has always been that it was a significant improvement to SMS that just worked, with graceful fallback to SMS for anyone who didn't use it. No installing third party apps, wondering if someone new I wanted to contact would be on that messaging app, etc. A nice bonus, but not something that…

> with graceful fallback Have you ever tried to stop having an Apple device? Hopefully better now, but a few years ago there was no way to unlink iMessage. So say good bye to all your Apple friends, as them texting you goes to the Apple cloud and not your new phone.

> a few years ago there was no way to unlink iMessage

Deregistration[1] has been supported since November 2014.

[1]: https://support.apple.com/en-us/HT203042

Re: Show HN: Beeper Mini – iMessage client for Android

#226

Earlier quoted context omitted.

It’s still a substantial upgrade over SMS or unencrypted (non-Google) RCS, where anybody can snoop on conversations with little effort.

Last time I checked, everyone knows SMS is cleartext and can't take over your phone in the profound way built-in 1st party apps/services you emphatically cannot remove (only toggle) can seize the means of production so to speak.

“Everyone” may be overly broad… just about everybody with any technical inclination knows yes, but for many years now the overwhelming majority of smartphone users have not been particularly technically inclined, and as such I would not expect most of them to be aware of the security and privacy implications that come with use of the various messaging services.

With that in mind, I’d say that most messaging apps don’t go far enough to make that distinction clear. Any app handling SMS or any other unencrypted messages should have ever-present, readily visible warnings when conversations aren’t encrypted.

Re: Show HN: Beeper Mini – iMessage client for Android

#227

Earlier quoted context omitted.

So you're saying that if I install WhatsApp on my phone, I can text anyone I want, if I have their phone number? Doesn't matter if they have WhatsApp installed? I just say "send this to 5551212" and it gets there?

They need to install the app, which is free. What they don't need to do is buy an iPhone, which is not free.

Android phones are free? I have to buy the phone no matter what, so I don't see that as a differentiator.

I don't want multiple ecosystems that don't interoperate at all. I don't want to give my private conversations over to an ad company like Facebook. I like iMessage because it adds features without taking. I don't worry about what app I need to use depending on who I want to talk to, I just send them a message and move on with my life.

Re: Show HN: Beeper Mini – iMessage client for Android

#228
post #112
post #39

Earlier quoted context omitted.

Apple is adopting RCS, and no, that won't solve the green/blue bubble issue. They'll still distinguish RCS and SMS from iMessage. iMessage is Apple's value-add and has its own app ecosystem, apparently/allegedly true E2E. *> Personally if it's a business / marketing advantage unless their hand is forced for business reasons they should never change it.* Yep, that is Apple's intent, according to Apple emails leaked fr…

To the vast majority of people though it will solve the problem. Android to iPhone communication will be close enough to the iMessage experience.

Yeah, maybe it will make some improvement for Android people, who are the majority of the mobile market.

For iPhone users, they'll still be some non-blue bubble people who lack the E2E[1] and tight iMessage app integrations that are popular among iPhone users these days. At least until governments possibly intervene.

1. E2E insofar as not carrier-accessible (unlike RCS), which is a bit of a hot button issue in the US, post-Snowden/PRISM. If carriers have access to RCS payloads or even metadata, they will most definitely harvest it for marketing purposes, as well as ship it off to the US government.

Re: Show HN: Beeper Mini – iMessage client for Android

#229
post #164

Earlier quoted context omitted.

Apple announced that they will support RCS. Presumably they will not charge Android users for sending RCS messages to iPhone users right?

RCS isn't encrypted, doesn't work without phones, doesn't have a single identity across multiple devices, etc so it's not going to replace iMessage.

If only there was an encrypted chat service, that works on multiple devices, has a single identity across all of them, etc. Oh well, guess we'll all have to buy iPhones to use iMessage.

Re: Show HN: Beeper Mini – iMessage client for Android

#230
post #180

Earlier quoted context omitted.

iMessage is offered as a free service. If they would like to 'receive recompense', then they should simply charge people. Do we provide recompense to YCombinator for using hackernews?

iMessage is not free though? Apple's "free" services are all dependent on you having bought apple products. When you buy a device, the "profit" on the hardware (the oft reference BoM only cost) also pays for the software development, the services, etc. Claiming that anyone should be able to use those services because they're "free" is like saying anyone should be able to get free service at Toyota garages because Toy…

I think it's a lot more nuanced than that. Should we, as a society, allow companies to lock people into platforms, and discriminate against those who have decided not to fall prey to that lock-in? Especially when avoiding that lock-in (which is often a passive financial/economic choice, not an active rights/freedom one) actually causes social and emotional harm (the whole "green bubble bullying" is a real thing; yes, I think it's dumb too, but what we think is irrelevant).

Personally, I think the answer is "no", we should not allow that sort of thing. Profit is not the most important thing in the world, by far.

Your car analogy falls flat, as is the case with most car analogies. No one would expect to get free service at any garage, and that is unrelated to the topic at hand. You can go to any garage, and they're mostly not model specific; even when they are, there are plenty of third-party alternatives. (And this is why locking down car hardware/software such that only the manufacturer can provide service is a garbage practice that we should legally disallow.)

Post reply on HN