Earlier quoted context omitted.
If you don’t trust Apple, then obviously you don’t use it. If you do, then it shouldn't be possible for a 3rd party client to break that trust. Users only see iMessage vs no-iMessage and have no other way to identify the client to decide for themselves whether to trust it.
Not what he said. He said he doesn’t trust them (safe). The question you should be asking is why do you?
Apple cuts off Beeper Mini's access
331–340 of 1001 posts
Re: Apple cuts off Beeper Mini's access
#332This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…
This is actually a great point I didn’t originally consider. People could easily infiltrate the iMessage fort with spam and other stuff which at the moment requires a genuine Apple device.
but I don't think it's their main reason, if anything I see that argument as convenient posturing which aids in covering the uglier underlying reasons
Re: Apple cuts off Beeper Mini's access
#333Earlier quoted context omitted.
Keep in mind that this is spin — Erik's statement is ridiculous, and he knows it. To think that Apple would somehow not treat Beeper like any other bad actor hacking iMessage protocols is delulu.
Sure, that's fair. But if he knows that, why spend the time to build this app in the first place? Is it a marketing play? It did buy them a whole lot of attention.
It was an acquihire involving a 16 year old who was doing it for fun.
Re: Apple cuts off Beeper Mini's access
#334Also, the whole use case is funny to me since everyone in my country (including iPhone users) use WhatsApp.
Re: Apple cuts off Beeper Mini's access
#335Earlier quoted context omitted.
It looks to me like there is an advantageous business relationship between Beeper and their customers. As a general rule, Apple is free to change their programs and how they work. However, I think there’s a plausible argument for tortious interference here if the sole purpose was to prevent interoperability.
Not sure why this is getting downvoted – IAAL and this is definitely something worth considering. This particular type of law varies from state to state, and can be quite broad. I've talked with other lawyers about it in the past, and my understanding is that it's frequently asserted when companies make counterclaims in business litigation. That doesn't mean it's a sure winner, just that it's a live question until mo…
Re: Apple cuts off Beeper Mini's access
#336Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have to have for Apple is approximately the same for any other iMessage client. Obviously Mini was using the encryption properly else it wouldn't have worked to begin with. Of course, it's very unlikely Apple is doing that. Just putting the thought out there.
One other point raised that I saw was about how iMessage costs Apple money to run, and non-product owners should not have access since they haven't contributed. This falls apart if you own any Apple devices. Myself for example owns a Macbook, but an Android phone. Am I not allowed to use iMessage? I paid the toll.
Re: Apple cuts off Beeper Mini's access
#337This is what Snazzy Labs said about Beeper Mini... hilarious: > This doesn't appear to be some easy thing Apple can just turn off. > It will require a complete redesign of their entire authentication and delivery strategy for not just iMessage but Apple ID account access as a whole.
The guy is a fine youtuber but i think he was talking about stuff outside of his area of competence wrt to this specific matter.
Re: Apple cuts off Beeper Mini's access
#338Earlier quoted context omitted.
It looks to me like there is an advantageous business relationship between Beeper and their customers. As a general rule, Apple is free to change their programs and how they work. However, I think there’s a plausible argument for tortious interference here if the sole purpose was to prevent interoperability.
That's like getting upset after getting bad dating advice from a vending machine.
Re: Apple cuts off Beeper Mini's access
#339Earlier quoted context omitted.
Do you really consider Apple's control over a proprietary protocol which they invented and maintain to be comparable to a scenario in which Apple "sends a man" to take "your fire extinguisher […] from your house"? I've re-written this comment five or six times in an attempt to find the most charitable interpretation, but I just cannot comprehend how it made it through your filter and out onto the internet.
i am just flabbergasted that we are living in a timeline where the phrase "proprietary protocol" is a real thing
Re: Apple cuts off Beeper Mini's access
#340Earlier quoted context omitted.
Putting aside that I count at least two glaring examples from this list[^1] in your reply, I suspect Apple would argue that it is in fact _solely_ preoccupied with its users' security: that's why iMessage is end to end encrypted and Apple does not offer 2FA / OTPs via SMS. Apple does not generally try to mitigate security issues which are beyond its control (e.g. non-Apple devices, protocols). [^1]: https://en.wikipe…
They do offer 2FA via SMS. This is AFAIK the ONLY option for Android/non-Mac users. Why are those users less deserving of decent security? Apple still sells and offers services outside their platforms, so they're still customers potentially with hundreds or thousands of dollars worth of purchases and CCs attached. FFS Nintendo has better 2FA options than Apple for non-Apple platforms.
Because they don't own an Apple device or have iMessage, which is the entire point of this discussion?