Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

401–410 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#401

Reminder that BlueBubbles and AirMessage both are working and fairly robust. I've used them daily over a year. The downside being that they need a Mac and iPhone to run. But in the spirit of self hosting, you do run the server yourself and don't share your credentials. I don't see a more viable path in the near future.

> The downside being that they need a Mac and iPhone to run.

Then why would anyone use BlueBubbles? If you already need the hardware, and presumably an Apple account, what advage would there be? Legitimately curious.

Re: Apple cuts off Beeper Mini's access

#402

This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…

And Apple didn't even need to block any device identifiers, just the IPs Beeper Mini was using to connect to the APN service. This could have been blocked in minutes. The delay was likely to get approval from Legal.

I think you've got Beeper Mini mixed up with other iMessage bridges. The whole thing with Beeper Mini (vs other iMessage bridges) was that it was entirely client side on the phone, no server to block. So the "IPs Beeper Mini was using to connect to the APN service", those IPs were just the IP addresses of every individual phone with Beeper Mini installed on it, no centralized place to block.

Re: Apple cuts off Beeper Mini's access

#403

One thing which is really confusing is why are Android users obsessed with iMessage? Android users can send text messages to iPhones, the can call iPhone users, and they can use third party messaging apps to communicate with iPhone users. It really isn’t clear to me why so many people are so angry they cannot use iMessage on Android.

I recently switched from Android to iOS just for iMessage. SMS is quite unreliable even in 2023. SMS messages don't have the same delivery guarantees as IP-based messaging services. And often I have internet access, but spotty cellular service. The thing that pushed me over the edge was that my carrier happened to block all my SMS for a day. I only found out about it later in the day, after I had missed many (unrecov…

I don't get why Americans cling so dearly to SMS.

Re: Apple cuts off Beeper Mini's access

#404
post #337
post #289

Earlier quoted context omitted.

The guy is a fine youtuber but i think he was talking about stuff outside of his area of competence wrt to this specific matter.

Usually the correct course of action is to just... say nothing then ? Or at least take some caution. But hey, it makes for a less sensationalist headline. The thing is that trustworthiness is typically something you look for in a reviewer, clearly not something that can be found there.

Say nothing? They can't do that, what else are they going to talk about in the next video that they have to release to appease the Youtube Algorithm?!

/s obviously!

Re: Apple cuts off Beeper Mini's access

#405

One thing which is really confusing is why are Android users obsessed with iMessage? Android users can send text messages to iPhones, the can call iPhone users, and they can use third party messaging apps to communicate with iPhone users. It really isn’t clear to me why so many people are so angry they cannot use iMessage on Android.

It's just become a meme among tech enthusiasts (on Reddit, HN, etc) and tech journalists that "blue bubbles" are a real social problem. The origin of the meme was this amusing post by Paul Ford 8 years ago [1]. They took it and ran with it for their own purposes. For some it was to explain away the iPhone's success versus Android and for some interested actors like Epic it was part of their antitrust campaigning to i…

Even if this was a meme at some point in the past, it’s a very real issue now.

I know multiple people who have switched to iPhone just for iMessage. And the kids these days won’t accept anything but the blue bubble. This is no longer a meme. Or if it is, it’s also real.

Re: Apple cuts off Beeper Mini's access

#406
post #81

> "if Apple truly cares about the privacy and security of their own iPhone users, why would they stop a service that enables their own users to now send encrypted messages to Android users, rather than using unsecure SMS?" - Eric Migicovsky 1. If Apple sees this as a gap, it is very obvious that they would address that themselves, rather than by allowing a hack to exploit loopholes in their architecture 2. Since Appl…

Spam. Spam is the reason and the Beeper guys know it.

Re: Apple cuts off Beeper Mini's access

#407

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

>Of course, it's very unlikely Apple is doing that. Just putting the thought out there. Is making wild claims and then immediately trying to disavow them in the next sentences the hacker spirit? How does it at all follow that Beeper Mini is using encryption properly (or else it wouldn't work) but it's unlikely Apple is? How would Beeper have been able to reverse engineer it if Apple's not using it? Who did they model…

Is implicitly trusting authority the hacker spirit?

Re: Apple cuts off Beeper Mini's access

#408

Earlier quoted context omitted.

And Apple didn't even need to block any device identifiers, just the IPs Beeper Mini was using to connect to the APN service. This could have been blocked in minutes. The delay was likely to get approval from Legal.

I think you've got Beeper Mini mixed up with other iMessage bridges. The whole thing with Beeper Mini (vs other iMessage bridges) was that it was entirely client side on the phone, no server to block. So the "IPs Beeper Mini was using to connect to the APN service", those IPs were just the IP addresses of every individual phone with Beeper Mini installed on it, no centralized place to block.

No, the BPN server is a server side service that persistently recieves APNs to forward to the phone (that don't contain the message data) since unlike iPhones, Android phones can't persistently check for APNs (at least that's what I understood from the announcement article). AIUI that's what you're paying for. But that wouldn't explain why sending is broken.

Re: Apple cuts off Beeper Mini's access

#409

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

It has nothing to do with a lack of spirit. It's a 800lbs of reality crashing down. There's nothing wrong with trying to hack the Gibson. However, this wasn't just a hack, but a severe threat to Apple's walled garden. As long as they are allowed to have it, they will protect it at all costs. Thinking any differently is just naive. So of course this is the ultimate result.

Re: Apple cuts off Beeper Mini's access

#410

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

> Where is the hacker spirit here?

The hacker spirit is the fun of reverse engineering. The hacker spirit is about personal use.

It's not expecting to be able to turn it into a business, or a popular app, that wouldn't quickly be shut down. That's just common sense.

> Myself for example owns a Macbook, but an Android phone. Am I not allowed to use iMessage? I paid the toll.

Of course you can. It's sitting there on your Mac where you can use it as much as you like.

Post reply on HN