Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

461–470 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#461
post #277

Earlier quoted context omitted.

It's not a super serious comment, it's more about how ridiculous the tone of "We are doing this for YOUR protection" would be. On a more serious note though, in the end Apple absolutely has the power of increasing everyone's capability and security by doing something like setting up a playbook of how iMessage could just use Signal protocol and how other actors could join in, or really anything else but doing this.

> It's not a super serious comment, it's more about how ridiculous the tone of "We are doing this for YOUR protection" would be. Right now I can presume a basic level of device security across all iMessage threads I have. Beeper deranges that: E2EE is still there, but Beeper exposes my correspondence to device security weaknesses from other OEMs, malware, keyloggers, screen scrapers, etc. as a result of lax app marke…

> a basic level of device security across all iMessage threads I have

Is that really true though? Jailbroken phones, iMessage may still work. Any device security gets thrown out the window.

You also can't expect everyone to have an Apple device for security, which we've seen time and time again SS7 being weak - So is the requirement to remove SS7, for everyone to jump on the Apple train?

I see Beeper as doing Apple a service, not so much a competing platform, but a gateway to the iMessage ecosystem - 'Hey, this would be pretty cool to use without this app and have it native' vs the 'Only Apple devices can use this.'

Re: Apple cuts off Beeper Mini's access

#462

Earlier quoted context omitted.

How are you going to make a case for tortious interference when the would be interferee is profiting by using the interferer’s resources without payment?

From beepers website, there’s no use of apples servers when iMessages are sent from a beeper user to a beeper user. Rather, they only pass through Apple when sent to an iPhone user and in that case it’s the iPhone user that’s utilizing apples resources. And in that case there’s an Apple device owner, who is paid for the right to use iMessage servers.

Wow that’s a hell of a stretch, but A+ for effort I guess. By that logic, they’re only stealing 50% of Apple’s iMessage resources for iPhone users.

Re: Apple cuts off Beeper Mini's access

#463

This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…

This should have been obvious to anyone who saw the code where it simply contained the raw literal string `FAIRPLAY_PRIVATE_KEY = b64decode(“…”)`. I suppose now we’ll see how accurate the commenter’s claim “if this becomes a problem, I know how to generate new keys” is. https://github.com/JJTech0130/pypush/blob/main/albert.py#L16

[flagged]

Re: Apple cuts off Beeper Mini's access

#464
post #449

Earlier quoted context omitted.

You're allowed to admire the technical implementation while denouncing the business model at the same time.

Is letting our hearts bleed for trillion dollar companies really the best way to spend our finite compassionate bandwidth?

Observing that a particular business model is very likely to fail because of the conflict with another business model that happens to have much more powerful backing requires no compassion spend.

But also, it seems to me that compassion is an involuntary reaction.

Re: Apple cuts off Beeper Mini's access

#465

Earlier quoted context omitted.

Yes, totally understandable that this would be blocked within our legal system... but its a proof of concept that it would not be burdensome for apple to enable interoperability. We should be demanding support for open standards for messaging from mono/duopolists like Apple/Google.

Yearly reminder that a long time ago, chat services used XMPP and we were on the verge of having GChat interoperability with FB messages and I think Yahoo or something similar at the time. None of them really wanted to do it for business reasons, so they could “add value” (and charge for it)….same reason RSS has fallen out of favor (no good way to inject ads and tracking). IRC and Matrix still exist.

On the Google side the XMPP federation got killed when Google Hangouts and Google+ became the core strategy. The company wanted to focus on "social" (but their own social network) and didn't care about other chat. Back then I worked on the App Engine team which had a XMPP Chat API. When GChat killed XMPP Federation that API lost the majority of target users as a result. I tried to make the case for maintaining XMPP support - taking it up with some VP of Engineering. Alas, nobody cared about the opinion of this random guy in developer support (~2012, early days of Google Cloud)

Re: Apple cuts off Beeper Mini's access

#466

Earlier quoted context omitted.

Not sure why this is getting downvoted – IAAL and this is definitely something worth considering. This particular type of law varies from state to state, and can be quite broad. I've talked with other lawyers about it in the past, and my understanding is that it's frequently asserted when companies make counterclaims in business litigation. That doesn't mean it's a sure winner, just that it's a live question until mo…

I’m not a lawyer, but I do know how computers work. I’d bet the farm on the very safe assumption that any protocol change that blocks a third-party client at the very least can plausibly be claimed to be in service of security, and most likely be a legitimate claim in reality. It is probably being downvoted because it’s incredibly far-fetched.

I agree that this would be their argument. But as other commenters mention, this area could be a minefield for Apple due to their dominance in various markets. It's possible they wouldn't want to get sucked into a lawsuit about this, even if they thought they could win, since they might end up making statements that would have a larger detrimental effects in other cases/potential cases.

Re: Apple cuts off Beeper Mini's access

#467

Earlier quoted context omitted.

Yes, totally understandable that this would be blocked within our legal system... but its a proof of concept that it would not be burdensome for apple to enable interoperability. We should be demanding support for open standards for messaging from mono/duopolists like Apple/Google.

Yearly reminder that a long time ago, chat services used XMPP and we were on the verge of having GChat interoperability with FB messages and I think Yahoo or something similar at the time. None of them really wanted to do it for business reasons, so they could “add value” (and charge for it)….same reason RSS has fallen out of favor (no good way to inject ads and tracking). IRC and Matrix still exist.

Can we make XMPP popular again? We really could need an universal internet standard for IM.

Re: Apple cuts off Beeper Mini's access

#468

Earlier quoted context omitted.

Yes, totally understandable that this would be blocked within our legal system... but its a proof of concept that it would not be burdensome for apple to enable interoperability. We should be demanding support for open standards for messaging from mono/duopolists like Apple/Google.

In my experience, incoming SMS are mostly spam, and other low trust notifications, while incoming iMessages, even if unknown to me, are likely to be real people. Buying an Apple device is an expensive signal, and Apple will quickly shut down abusers, maintaining that relatively high bar. Letting (actual) Android users use iMessage probably wouldn’t affect that, but the open source hack/reversing of it opened the door…

Huh, I used to receive spam on iMessage with blue bubbles. In fact the only blue bubbles I receive are spam.

Re: Apple cuts off Beeper Mini's access

#470
post #79

Earlier quoted context omitted.

I mean, if everyone is using Whatsapp, that is effectively a monopoly. I am curious as to what the runner ups are in the EU however. Meanwhile, wait until Mr. Zuckerberg looks for new ideas to monetize their messaging ecosystem.

There's no monopoly. Messengers hardly have any lock-in and there's plenty of competition available. Entire continents will switch messengers essentially overnight once the current market leader becomes too enshittified and there's something better. Remember how AOL, ICQ, MSN, Skype, etc. died? WhatsApp is the current leader because it's no-nonsense and works everywhere. The moment Facebook fucks that up even a littl…

There is major lock-in. If I want to move Signal but everybody I message uses WhatsApp then I can't message them unless they switch.
Post reply on HN