Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

271–280 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#271

Earlier quoted context omitted.

Not sure that's worth much congratulation. Is there anyone that didn't think the exact same thing as soon as they saw the story?

I heard/saw quite a few people saying Apple either couldn't or wouldn't cut them off—and that even if they did, it would take a while. They were ridiculous takes, yes, but apparently made in earnest.

While it would ruin the experience in practice (not being able to receive any notifications), I don't see why someone couldn't perfectly reverse engineer the protocol.

Beeper made several design decisions that made the app super easy to use (i.e. using a single certificate that wasn't supplied by a user's phone), but if you extract the necessary source material from an old jailbroken iDevice, you could create an iMessage clone that Apple can't ban without either legal action or breaking compatibility with all easily jailbroken iOS devices.

Back in the days of AIM and MSN, even large companies used reverse engineering to get chat interoperability, and it was so successful that AIM left open an RCE vulnerability to push shellcode so that Microsoft couldn't chat through their service.

Re: Apple cuts off Beeper Mini's access

#272
post #210
post #65

As usual, Gruber was right on the money. Via Threads yesterday: "My prediction is that Apple will make changes—fixing bugs and/or closing loopholes—that break Beeper Mini. It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. It’s a very nice app, remarkably clever, and for now works like a charm, but if Apple wanted an iMessage client…

>It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. I don't follow this logic at all. Shouldn't supporting thirdparty clients be desirable if security is a primary feature in the interest of transparency? Especially if the reference client is proprietary and undocumented.

How would third-party clients _increase_ security (other than indirectly, by people using SMS less)? On the contrary, third-party clients is a gigantic security hole, since Apple can't even know if a client app is spying on users.

Re: Apple cuts off Beeper Mini's access

#273
post #210
post #65

As usual, Gruber was right on the money. Via Threads yesterday: "My prediction is that Apple will make changes—fixing bugs and/or closing loopholes—that break Beeper Mini. It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. It’s a very nice app, remarkably clever, and for now works like a charm, but if Apple wanted an iMessage client…

>It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. I don't follow this logic at all. Shouldn't supporting thirdparty clients be desirable if security is a primary feature in the interest of transparency? Especially if the reference client is proprietary and undocumented.

We've really done one over on ourselves by adopting the mental model that only a vertically integrated corp can deliver privacy and security to users. This rigid tendency towards homogeneity is bound to suffer a tragic systemic failure before too long.

It would be healthier to assume multi-polarity and lean into it.

Re: Apple cuts off Beeper Mini's access

#274
post #153
post #81

> "if Apple truly cares about the privacy and security of their own iPhone users, why would they stop a service that enables their own users to now send encrypted messages to Android users, rather than using unsecure SMS?" - Eric Migicovsky 1. If Apple sees this as a gap, it is very obvious that they would address that themselves, rather than by allowing a hack to exploit loopholes in their architecture 2. Since Appl…

Since apple has no control over your fire extinguisher, they sent a man to securely take it from your house and dispose of it. It could have been a bomb for all you know.

[flagged]

Re: Apple cuts off Beeper Mini's access

#275
post #97

My guess is Beeper calculated this was likely to happen eventually (maybe not this fast), but that they would get good press on the initial launch and on the shutdown announcement and that press would be worth the technical investment they made. They do have a different service they still offer and some percentage of people are looking at that now.

Yah, this is a great runway to launch a chat app with real encryption.

They already sell a wide ecosystem based on Matrix. The whole point of this app was to connect without relying on Matrix bridges.

Re: Apple cuts off Beeper Mini's access

#276

Earlier quoted context omitted.

If signal would officially allow third party clients, non-phone-number-bound users and maybe federation that'd be great. It does not.

Signal does allow third party clients, Beeper is one. I agree about other things, and would expand on the list.

They do not officially and discourage it. Moxie and the rest of the company has been extremely clear that all third party clients are not considered supported or allowed, regardless if they can and do interact with signal services.

Re: Apple cuts off Beeper Mini's access

#277
post #153

Earlier quoted context omitted.

Since apple has no control over your fire extinguisher, they sent a man to securely take it from your house and dispose of it. It could have been a bomb for all you know.

Do you really consider Apple's control over a proprietary protocol which they invented and maintain to be comparable to a scenario in which Apple "sends a man" to take "your fire extinguisher […] from your house"? I've re-written this comment five or six times in an attempt to find the most charitable interpretation, but I just cannot comprehend how it made it through your filter and out onto the internet.

It's not a super serious comment, it's more about how ridiculous the tone of "We are doing this for YOUR protection" would be.

On a more serious note though, in the end Apple absolutely has the power of increasing everyone's capability and security by doing something like setting up a playbook of how iMessage could just use Signal protocol and how other actors could join in, or really anything else but doing this.

Re: Apple cuts off Beeper Mini's access

#278
post #153

Earlier quoted context omitted.

Since apple has no control over your fire extinguisher, they sent a man to securely take it from your house and dispose of it. It could have been a bomb for all you know.

What? Does a fire extinguisher connect to Apple servers? Does a fire extinguisher secretly being a bomb affect the security of others? I don’t know if you could have come up with a worse metaphor.

[flagged]

Re: Apple cuts off Beeper Mini's access

#279
post #256

Earlier quoted context omitted.

Won't spammers just continue using the macos bridged other services instead of the direct to Apple way ?

If they have to use real Apple hardware, and those devices are blocklisted by Apple when the spam is reported, spamming stays cost prohibitive.

I also assume there are iMessage rate limits in place, that if exceeded, trigger some analysis. If that's true, then hardware costs would also be proportional to rate.

I suspect there's some dark market for broken iPhones, and perhaps some rate limit for activations within a city block/building. The last time I had iMessage spam was years ago, so maybe it's not so practical.

Re: Apple cuts off Beeper Mini's access

#280
So does this also now break iMessage for older iOS devices too?

I thought someone said something about that to block beeper mini, Apple would have to also block older iOS devices as that’s the method they were using that wasn’t as locked down.

Post reply on HN