Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

381–390 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#381

This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…

Not disagreeing, but I do not think Beeper Mini used the binary method for registering accounts. I think that was the way to do it for non-mobile devices that couldn't receive SMS, but there is also a way to register an account using SMS which I believe Beeper Mini uses.

Re: Apple cuts off Beeper Mini's access

#383

Earlier quoted context omitted.

There's a bunch of reasons why this is unlikely to be tortious interference, but one of the obvious ones is the contractual Terms & Conditions that apply between Apple and its users; I doubt Beeper is liable here, but if interference was a thing, my bet (not a lawyer!) is that the liability would point the other direction.

My read of GP's comment was that the claim of tortious interference would be by Beeper against Apple (for interfering with Beeper's relationship with Beeper's customers).

Yes. And I'm saying, were this a live issue (I don't think it is), the graver liability might be for Beeper interfering with Apple's contracts with its users.

Re: Apple cuts off Beeper Mini's access

#384

This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…

This is actually a great point I didn’t originally consider. People could easily infiltrate the iMessage fort with spam and other stuff which at the moment requires a genuine Apple device.

Still need a valid phone number with a SIM that can do the special SMS needed for this, so it's hardly going to produce a big spam farm too fast.

Re: Apple cuts off Beeper Mini's access

#385
post #49

An open source client for iMessage is going to be used for fraud and spam. Before this, a device being blocked by Apple because it was used for fraud or spam would increase the cost of business for fraudsters and spammers. But now it's a matter of picking a new phone number. Of course Apple would try hard to stop this.

Is spam a good reason for Apple to keep their iMessage garden exclusive? SMS is also widely used for spam.

I’m in Asia, my phone number has been with me for almost a decade. I haven’t received spam in a blue bubble, only on SMS (green). Just want to give you a perspective in the other part of the world.

This are not just spam but most are sms phishing with links. We have poor, inadequate cyber laws, so we are glad Apple is doing its part sealing this off.

Re: Apple cuts off Beeper Mini's access

#386

This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…

Yes, totally understandable that this would be blocked within our legal system... but its a proof of concept that it would not be burdensome for apple to enable interoperability. We should be demanding support for open standards for messaging from mono/duopolists like Apple/Google.

Re: Apple cuts off Beeper Mini's access

#387

Earlier quoted context omitted.

Sure, that's fair. But if he knows that, why spend the time to build this app in the first place? Is it a marketing play? It did buy them a whole lot of attention.

They didn't spend much time building this feature. It was an acquihire involving a 16 year old who was doing it for fun.

Except they didn't hire him? He gave them some kind of info about the sms verifications, which they then had their devs implement.

Re: Apple cuts off Beeper Mini's access

#388

Earlier quoted context omitted.

but the real problem some of use have with Apple's behavior is the real underlying reasons they're doing this I am reasonably sure that their main driver is profit which really means exploitation of people; I consider their public arguments lies made up to cover up the fact that what they account for as profit comes from what are in the end some really ugly historical and traditional imperialistic (colonial, neocolon…

> I am reasonably sure that their main driver is profit which really means exploitation of people Just wondering if you've forgotten what site you're on. This is YC which exists to build companies whose main driver will always be profit.

There are companies who have come out of YC who have main drivers other than profit.

Re: Apple cuts off Beeper Mini's access

#389

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

>Of course, it's very unlikely Apple is doing that. Just putting the thought out there.

Is making wild claims and then immediately trying to disavow them in the next sentences the hacker spirit?

How does it at all follow that Beeper Mini is using encryption properly (or else it wouldn't work) but it's unlikely Apple is? How would Beeper have been able to reverse engineer it if Apple's not using it? Who did they model their correct implementation of Apple's protocol off of?

Re: Apple cuts off Beeper Mini's access

#390

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

It was the same when Apple banned Fortnite for daring to accept payments outside of their walled garden and the forced 30% cut. People falling over themselves to hate on Epic and defend Apple's forced cut and the total removal of developer freedom. If it was Microsoft the entire tone would be completely different.
Post reply on HN