Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

431–440 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#431

This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…

This is actually a great point I didn’t originally consider. People could easily infiltrate the iMessage fort with spam and other stuff which at the moment requires a genuine Apple device.

Wouldn't your iPhone still receive spam SMS text messages with Apple Messages? And isn't Apple Messages commonly exploited by NSO Group (Zero-clicks)? Maybe I'm wrong, but this does not appear to be very fort-like.

Re: Apple cuts off Beeper Mini's access

#432
post #277

Earlier quoted context omitted.

It's not a super serious comment, it's more about how ridiculous the tone of "We are doing this for YOUR protection" would be. On a more serious note though, in the end Apple absolutely has the power of increasing everyone's capability and security by doing something like setting up a playbook of how iMessage could just use Signal protocol and how other actors could join in, or really anything else but doing this.

> It's not a super serious comment, it's more about how ridiculous the tone of "We are doing this for YOUR protection" would be. Right now I can presume a basic level of device security across all iMessage threads I have. Beeper deranges that: E2EE is still there, but Beeper exposes my correspondence to device security weaknesses from other OEMs, malware, keyloggers, screen scrapers, etc. as a result of lax app marke…

The whole underlying point is that Apple will do anything to virtue signal when in reality they are making a decision on improving their profit regardless if it decreases security of its customers and other people. It is undeniable and silly to argue against.

Re: Apple cuts off Beeper Mini's access

#433

Earlier quoted context omitted.

Keep in mind that this is spin — Erik's statement is ridiculous, and he knows it. To think that Apple would somehow not treat Beeper like any other bad actor hacking iMessage protocols is delulu.

Sure, that's fair. But if he knows that, why spend the time to build this app in the first place? Is it a marketing play? It did buy them a whole lot of attention.

But what kind of attention did it garner? Now, we all know that these folks are pretty delusional. They spent time developing an app that everyone except them knew was not long for the world. A rational company would realize that it wouldn't live long enough to recoup any money. Releasing such a still born product doesn't make me feel warm and fuzzy about it. Hell, Google releases products that live longer than this.

Re: Apple cuts off Beeper Mini's access

#434
post #49

An open source client for iMessage is going to be used for fraud and spam. Before this, a device being blocked by Apple because it was used for fraud or spam would increase the cost of business for fraudsters and spammers. But now it's a matter of picking a new phone number. Of course Apple would try hard to stop this.

This is exactly why Signal closed their source code: if you allow access to your network, you're only accepting spam. For their users' security, it's essential that they must guard access to their network as much as possible.

> if you allow access to your network, you're only accepting spam.

Well no; spam yes, only spam no.

Re: Apple cuts off Beeper Mini's access

#435
post #133

Earlier quoted context omitted.

Are you a lawyer because Apple stopping third parties from using their service being in any way illegal sounds extremely hard to believe

> The CFAA prohibits intentionally accessing a computer without authorization or in excess of authorization, but fails to define what “without authorization” means. - From the National Association of Criminal Defense Lawyers Other way around. If anything, it sounds to me like Beeper Mini was acting illegally by accessing Apple’s servers in a way they didn’t give permission for. The CFAA is ripe for abuse. I’m not say…

I think that’s certainly an argument that Apple would make. However, it seems that this app was simply sending requests and receiving responses that there was no code injection or compromise of Apple servers, or of credentials, or anything of that sort.

Re: Apple cuts off Beeper Mini's access

#436
post #153

Earlier quoted context omitted.

Since apple has no control over your fire extinguisher, they sent a man to securely take it from your house and dispose of it. It could have been a bomb for all you know.

What? Does a fire extinguisher connect to Apple servers? Does a fire extinguisher secretly being a bomb affect the security of others? I don’t know if you could have come up with a worse metaphor.

It does work as a metaphor because if Apple could force you to use their iExtinguisher and ban others they absolutely would, with the argument that they are improving fire safety.

Re: Apple cuts off Beeper Mini's access

#437

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

> Where is the hacker spirit here? The hacker spirit is the fun of reverse engineering. The hacker spirit is about personal use. It's not expecting to be able to turn it into a business , or a popular app, that wouldn't quickly be shut down. That's just common sense. > Myself for example owns a Macbook, but an Android phone. Am I not allowed to use iMessage? I paid the toll. Of course you can. It's sitting there on y…

It’s also at severe risk of ruining the fun for numerous other hacker-spirit communities like hackintosh or opencore. Apple can come down on this in ways that potentially make it much more difficult for hackintosh to operate, or for people to update their legitimate apple systems after the end of official support. Which was pointed out in those threads too.

See also geohot taking some other PS3 exploits that were already published and combining them into a piracy kit that caused Sony to come down on them and patch the exploits, ruining it for the rest of the homebrew community.

There’s a reason homebrew people try to keep it low-key, it doesn’t take many assholes to ruin it for everyone. Let alone turning it into an app on their own platform lmao.

A decent number of other hobbies also involve some collective good-behavior and self-control lest the hammer come down for everyone. Doesn’t take many assholes doing donuts on quads before you’ll find motor access to that area removed or prohibited, etc. Drones also ruined in like 5 years what r/c airplanes had been safely doing for decades. Etc

Re: Apple cuts off Beeper Mini's access

#438

One thing which is really confusing is why are Android users obsessed with iMessage? Android users can send text messages to iPhones, the can call iPhone users, and they can use third party messaging apps to communicate with iPhone users. It really isn’t clear to me why so many people are so angry they cannot use iMessage on Android.

My mother sends me videos from her phone and I literally can't see what she's trying to show me.

Re: Apple cuts off Beeper Mini's access

#439

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

>Of course, it's very unlikely Apple is doing that. Just putting the thought out there. Is making wild claims and then immediately trying to disavow them in the next sentences the hacker spirit? How does it at all follow that Beeper Mini is using encryption properly (or else it wouldn't work) but it's unlikely Apple is? How would Beeper have been able to reverse engineer it if Apple's not using it? Who did they model…

The claim is that (a) both entities are properly encrypting the data _in transit_ and (b) either company could _steal_ the plaintext client-side (after decryption).

Trust that a third-party application isn't stealing the decrypted messages requires the same type and amount of trust that Apple is not stealing the decrypted messages (or maybe less trust if the third-party solution is open source, etc.).

Re: Apple cuts off Beeper Mini's access

#440
post #210
post #65

As usual, Gruber was right on the money. Via Threads yesterday: "My prediction is that Apple will make changes—fixing bugs and/or closing loopholes—that break Beeper Mini. It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. It’s a very nice app, remarkably clever, and for now works like a charm, but if Apple wanted an iMessage client…

>It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. I don't follow this logic at all. Shouldn't supporting thirdparty clients be desirable if security is a primary feature in the interest of transparency? Especially if the reference client is proprietary and undocumented.

No need for transparency here. Just know that no one has broken the encryption is all you need. Also you likely will not know if beeper sends a copy of your messages to their servers to sell, but who would you trust more won’t sell your info, beeper or Apple?
Post reply on HN