Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

281–290 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#281
post #256

Earlier quoted context omitted.

Won't spammers just continue using the macos bridged other services instead of the direct to Apple way ?

If they have to use real Apple hardware, and those devices are blocklisted by Apple when the spam is reported, spamming stays cost prohibitive.

With how many "rent a mac mini stuffed in a datacenter" services are out there, I wonder how cost-prohibitive blacklisting specific devices really is.

Re: Apple cuts off Beeper Mini's access

#282
post #52

This is what Snazzy Labs said about Beeper Mini... hilarious: > This doesn't appear to be some easy thing Apple can just turn off. > It will require a complete redesign of their entire authentication and delivery strategy for not just iMessage but Apple ID account access as a whole.

This is why people shouldn’t listen to tech YouTubers who don’t actually work in tech as engineers.

They’re tech fans, not experts but act like they know the domain space enough to make strong authoritative claims since that’s what gives them an audience.

Re: Apple cuts off Beeper Mini's access

#283

Earlier quoted context omitted.

(1) is exactly what that quote is pointing out. If Apple actually cared about its users' security, they would see this as a gap, and would have addressed it already. The fact that they haven't means that, despite all their posturing about being a security-first platform, they care more about lock-in and marketing than they do about user security.

Putting aside that I count at least two glaring examples from this list[^1] in your reply, I suspect Apple would argue that it is in fact _solely_ preoccupied with its users' security: that's why iMessage is end to end encrypted and Apple does not offer 2FA / OTPs via SMS. Apple does not generally try to mitigate security issues which are beyond its control (e.g. non-Apple devices, protocols). [^1]: https://en.wikipe…

They do offer 2FA via SMS. This is AFAIK the ONLY option for Android/non-Mac users. Why are those users less deserving of decent security? Apple still sells and offers services outside their platforms, so they're still customers potentially with hundreds or thousands of dollars worth of purchases and CCs attached. FFS Nintendo has better 2FA options than Apple for non-Apple platforms.

Re: Apple cuts off Beeper Mini's access

#284

Do sms/mms received from iMessage users on Android look anything in particular? Because a possible move for Google would be to reject them by default in some future version (hm hm, "security reasons"). End of "yes you're still in but you look like a cripple" and begin of "this app doesn't allow me to talk to that person, if I want to reach him I need to switch to something that supports Android".

SMS is handled by carriers, so google couldn't really block messages from iPhone users specifically. And that's not considering what an incredibly bad move it would be for them if they could somehow reject only iPhone texts.

Do the SMSes come straight from the other users' phones, or are they relayed via some Apple server?

> what an incredibly bad move it would be for them

I don't see it very different from Apple's choice to degrade arbitrarily the experience of messaging with android users. There are infinitely better alternatives to sms for private messaging, Google could say it's encouraging its users to move on them.

Re: Apple cuts off Beeper Mini's access

#285

Earlier quoted context omitted.

Putting aside that I count at least two glaring examples from this list[^1] in your reply, I suspect Apple would argue that it is in fact _solely_ preoccupied with its users' security: that's why iMessage is end to end encrypted and Apple does not offer 2FA / OTPs via SMS. Apple does not generally try to mitigate security issues which are beyond its control (e.g. non-Apple devices, protocols). [^1]: https://en.wikipe…

> and Apple does not offer 2FA / OTPs via SMS Last time I checked, Apple still used security questions any hacker can get answers to on Facebook. I'm not all that confident about Apple's approach to account security. Apple has the ability to control security issues on Android: they can release an Android app, like every other E2EE messenger out there. Apple chooses not to, and it's their choice, of course. It doesn't…

Those security questions are now very much optional. I made sure to lock down my Apple account. If I lose either my password or access to all my devices, the only thing that can unlock my account is a long printed code or permission from a trusted family member. My account no longer has security questions.

Apple is doing it optionally because they're trying to balance two opposing forces here: helping its users access a locked account, and giving users tightly locked accounts.

Re: Apple cuts off Beeper Mini's access

#286
post #49

An open source client for iMessage is going to be used for fraud and spam. Before this, a device being blocked by Apple because it was used for fraud or spam would increase the cost of business for fraudsters and spammers. But now it's a matter of picking a new phone number. Of course Apple would try hard to stop this.

This is exactly why Signal closed their source code: if you allow access to your network, you're only accepting spam. For their users' security, it's essential that they must guard access to their network as much as possible.

Re: Apple cuts off Beeper Mini's access

#288
post #202

Do sms/mms received from iMessage users on Android look anything in particular? Because a possible move for Google would be to reject them by default in some future version (hm hm, "security reasons"). End of "yes you're still in but you look like a cripple" and begin of "this app doesn't allow me to talk to that person, if I want to reach him I need to switch to something that supports Android".

You think it would be a good idea for android to reject all SMSes?

No, obviously not, that's why I specified "if it's possible to tell apart those coming from iMessage".

Re: Apple cuts off Beeper Mini's access

#289
post #52

This is what Snazzy Labs said about Beeper Mini... hilarious: > This doesn't appear to be some easy thing Apple can just turn off. > It will require a complete redesign of their entire authentication and delivery strategy for not just iMessage but Apple ID account access as a whole.

The guy is a fine youtuber but i think he was talking about stuff outside of his area of competence wrt to this specific matter.

Re: Apple cuts off Beeper Mini's access

#290
This was the obvious outcome. People were being willfully blind about how this "hack" works.

Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate Apple device data that isn't plainly evident to any random user-mode app.

Why would they block it? Every service has some sort of gate on who can message or it will be overrun by bad actors and spammers. Signal, Telegram and others make you validate your cell phone number -- there's a finite number of those, and they can blacklist them as necessary. Online services make you validate an email, do bot checks, etc. Beeper, and more importantly the technique they used, offers none of those gates. It was a plainly problematic free for all that was guaranteed to be closed.

Post reply on HN