Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

411–420 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#411
post #300

Earlier quoted context omitted.

Besides the obvious attention play, he might be going for an acquisition play... "Why bother writing our own iMessage for Android when we can just buy this little company that's already done it?" There's obvious issues with that plan, but that doesn't keep delusional founders from being delusional.

Apple chose not to support Android on purpose. They know iMessage exclusivity drives hardware sales. The emails have come out proving as much. It's the same reason they dragged their feet supporting RCS, until regulatory pressure started mounting.

exclusivity is all Apple runs on after it's tech succeeds

Re: Apple cuts off Beeper Mini's access

#412

Earlier quoted context omitted.

Good grief! No one is spitting on people with Android phones. If you really feel this way you need to put your screen down and spend time talking to people in real life. No one is persecuting you.

No one is literally spitting, but Apple intentionally creates enough friction that Android users really do regularly get excluded from group chats in the US where iMessage is the convention for group chats.

Chat app friction is not being spat on which is what the OP literally said. Perceived inconvenience is not persecution.

Re: Apple cuts off Beeper Mini's access

#413

This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…

Yes, totally understandable that this would be blocked within our legal system... but its a proof of concept that it would not be burdensome for apple to enable interoperability. We should be demanding support for open standards for messaging from mono/duopolists like Apple/Google.

In my experience, incoming SMS are mostly spam, and other low trust notifications, while incoming iMessages, even if unknown to me, are likely to be real people. Buying an Apple device is an expensive signal, and Apple will quickly shut down abusers, maintaining that relatively high bar.

Letting (actual) Android users use iMessage probably wouldn’t affect that, but the open source hack/reversing of it opened the door to iMessage spam that Apple, for the sake of reputation, and customer satisfaction, is obliged to close.

Anyway, I guess my point is that there are some “burdens” that are less obvious than others.

Re: Apple cuts off Beeper Mini's access

#414

Earlier quoted context omitted.

If an "unsanctioned" client can compromise iMessage security, then there was no actual security other than obscurity.

I didn't compromise the security of iMessage as a whole, it just exploited a way to get people into the system that was not planned. Imagine there is a theme park that has normal ticket booths and some requirements there to get in. Then there comes a Beeper that finds a hole in the fence on the perimeter and sets up their ticket booths there. It's in theme park's best interest to close that hole and cut off the reven…

Except they charge a thousand dollars to enter and then let everyone else in for free but they have to wear a badge and the pictures they get from the roller coaster photo booth are 240p.

Re: Apple cuts off Beeper Mini's access

#415

Earlier quoted context omitted.

Good grief! No one is spitting on people with Android phones. If you really feel this way you need to put your screen down and spend time talking to people in real life. No one is persecuting you.

Yes in fact they are. I have the amazing ability to recognize a problem even if I don't have it myself*. If you really can't do that, perhaps you should try. * Android user in the US where this dynamic primarily exists, but I just don't care because I'm not 20 any more. I only very occasionally need to send a video or picture to anyone, and in those cases, I know enough to use email or a google photos link or somethi…

[flagged]

Re: Apple cuts off Beeper Mini's access

#416
post #273
post #210

Earlier quoted context omitted.

>It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. I don't follow this logic at all. Shouldn't supporting thirdparty clients be desirable if security is a primary feature in the interest of transparency? Especially if the reference client is proprietary and undocumented.

We've really done one over on ourselves by adopting the mental model that only a vertically integrated corp can deliver privacy and security to users. This rigid tendency towards homogeneity is bound to suffer a tragic systemic failure before too long. It would be healthier to assume multi-polarity and lean into it.

> We've really done one over on ourselves by adopting the mental model that only a vertically integrated corp can deliver privacy and security to users. This rigid tendency towards homogeneity is bound to suffer a tragic systemic failure before too long.

Look no further than the other news that came out this week re: government spying via push notifications. (https://www.reuters.com/technology/cybersecurity/governments...) Consumers rationally trust the few big companies which are incentive-aligned to protect their data and government then goes after those few big companies. I thought this was particularly galling:

> In a statement, Apple said that Wyden's letter gave them the opening they needed to share more details with the public about how governments monitored push notifications.

> "In this case, the federal government prohibited us from sharing any information," the company said in a statement. "Now that this method has become public we are updating our transparency reporting to detail these kinds of requests."

Re: Apple cuts off Beeper Mini's access

#417
post #186

Earlier quoted context omitted.

Won't spammers just continue using the macos bridged other services instead of the direct to Apple way ?

What do you mean? There are no services bridged to iMessage.

Beeper Cloud, their other product, does exactly this...

https://help.beeper.com/en_US/chat-networks/imessage

Re: Apple cuts off Beeper Mini's access

#418
post #403

Earlier quoted context omitted.

I recently switched from Android to iOS just for iMessage. SMS is quite unreliable even in 2023. SMS messages don't have the same delivery guarantees as IP-based messaging services. And often I have internet access, but spotty cellular service. The thing that pushed me over the edge was that my carrier happened to block all my SMS for a day. I only found out about it later in the day, after I had missed many (unrecov…

I don't get why Americans cling so dearly to SMS.

As a European living in the US, it's been baffling to me. Everywhere else in the world people use WhatsApp, Telegram, Signal, etc. This iMessage green/blue bubble nonsense just isn't a thing outside the US.

Re: Apple cuts off Beeper Mini's access

#419

I'm guessing the binary they use from Apple (IMDAppleServices) to generate part of the registration information probably adds metadata to the "validation blob" that gets sent to apple when registering beeper mini as an iMessage device. If the metadata includes the OS version, Apple probably blacklisted any new devices registered in the past few days with validation blobs generated from that binary. (The binary was so…

My suspicion is this is going to be a cat-mouse situation for a while. Apple would've found some easy way to identify these users and Beeper will likely release a patch to fix it.

Agreed. I think Apple wins easily though. If they can break it once a month for a day or two, I think that makes it inconvenient for beeper mini users.

Maybe not though, who knows

Re: Apple cuts off Beeper Mini's access

#420
post #177

Earlier quoted context omitted.

> It's high time we demand open-source messaging standards across all platforms. What, like this https://github.com/signalapp ? The only thing holding this back are end users. Not corporations or governments. A safe, vetable 'standard' exists, it just needs ratifying by a standards body. It is available cross platform and is free of charge and free-as-in-beer (mostly AGPL I believe). Messages app exists to send SMS,…

Signal isn't a protocol; it's a centralized service that wants you to use their official client only. The Signal Foundation gets weird and starts making trademark threats whenever someone makes moves towards interoperability (see e.g. https://github.com/LibreSignal/LibreSignal/issues/37#issueco... ).

It isn't weird, its completely straightforward why this is a problem.
Post reply on HN