Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

481–490 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#481

This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…

Yes, totally understandable that this would be blocked within our legal system... but its a proof of concept that it would not be burdensome for apple to enable interoperability. We should be demanding support for open standards for messaging from mono/duopolists like Apple/Google.

Also WhatsApp, Facebook Messenger, WeChat, Telegram, LINE, and a handful of others with more than a half-billion users. Are those heptopolists or septopolists?

The word "monopolist" in 2023 seems to mean "a company whose corporate values are different than my personal ones and/or whose pricing and packaging don't match my consumption function and/or who has a lot of money and of whom I am jealous".

Re: Apple cuts off Beeper Mini's access

#482
post #107

Earlier quoted context omitted.

These assertions need those quotes around 'nobody' because I work with a bunch of apple device owners across Europe and they certainly do use Apple messages. At scale yes, signal, telegram and whatsapp are perhaps more significant than the apple ecology and the ratio of android to apple outside the USA and canada probably shows why.

Is anyone aware of actual statistics on this?

Beeper had a good approximation

Re: Apple cuts off Beeper Mini's access

#483

This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…

> Signal, Telegram and others make you validate your cell phone number

For what it's worth Beeper Mini did support using Apple's iMessage registration system to use your phone number.

Re: Apple cuts off Beeper Mini's access

#484

Earlier quoted context omitted.

There's no monopoly. Messengers hardly have any lock-in and there's plenty of competition available. Entire continents will switch messengers essentially overnight once the current market leader becomes too enshittified and there's something better. Remember how AOL, ICQ, MSN, Skype, etc. died? WhatsApp is the current leader because it's no-nonsense and works everywhere. The moment Facebook fucks that up even a littl…

There is major lock-in. If I want to move Signal but everybody I message uses WhatsApp then I can't message them unless they switch.

I can use multiple messengers in parallel without issue, as I did each time in those transitional periods.

The last messages on a dying messenger are always instructions on how to move on to the next thing. In skype, my status and most recent messages are just informing people of my discord handle. I accept that I may not be the norm, because generally I don't reach out to people and don't initiate contact, meaning that the onus is on them to use the appropriate channel to reach me.

Maybe it's worse for people who voluntarily stay in contact with many others using different messengers, but I don't see the problem with just having multiple messaging apps, especially since modern phones just consolidate all messaging services's contacts into your contacts app (at least on Android). You don't even need to remember who is reachable where.

Re: Apple cuts off Beeper Mini's access

#485

Earlier quoted context omitted.

And Apple didn't even need to block any device identifiers, just the IPs Beeper Mini was using to connect to the APN service. This could have been blocked in minutes. The delay was likely to get approval from Legal.

I think you've got Beeper Mini mixed up with other iMessage bridges. The whole thing with Beeper Mini (vs other iMessage bridges) was that it was entirely client side on the phone, no server to block. So the "IPs Beeper Mini was using to connect to the APN service", those IPs were just the IP addresses of every individual phone with Beeper Mini installed on it, no centralized place to block.

If it were purely client based, why did I leave to log in with Google to something then?

Re: Apple cuts off Beeper Mini's access

#486

Earlier quoted context omitted.

I remember another post that was very well-received where an individual hacker wrote his own homebrew iMessage client for his own personal purposes. HN really liked that! I think HN exists at an intersection of individual hackerism and business. If a project is clearly by-hackers-for-hackers it gets a lot more leeway for unsustainable concepts / implementations. But this is building a business on adversarial interope…

youtube-dl, NewPipe, and uBlock Origin exist solely for the purpose of empowering the individual, yet they are constantly attacked on HN as being tools used unfairly to harm Google's profitability. Open-source projects like Matrix, PeerTube, Mastodon, are built to be free and open-source for the benefit of end-users and lack of vendor lockin. Yet each is derided on HackerNews for not being enough like their corporate…

The projects you listed are overwhelmingly celebrated on Hacker News! I'm sure you can find a critical post if you look hard enough—HN isn't a hive mind—but it's not a common sentiment.

Re: Apple cuts off Beeper Mini's access

#487
post #65

As usual, Gruber was right on the money. Via Threads yesterday: "My prediction is that Apple will make changes—fixing bugs and/or closing loopholes—that break Beeper Mini. It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. It’s a very nice app, remarkably clever, and for now works like a charm, but if Apple wanted an iMessage client…

Easy to be right on the money here. This is the default MO. Regardless of if you are paying for it or are licensed or are doing it despite the tech giant whose toe you are tickling. Twitter API springs to mind.

Re: Apple cuts off Beeper Mini's access

#488

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

Apple wouldn't even exist if not for this type of hacking. One of Steve Jobs and Steve Wozniak's first projects was selling blue boxes[1] to play around on AT&T's telephone system. [1] https://en.wikipedia.org/wiki/Blue_box

> One of Steve Jobs and Steve Wozniak's first projects was selling blue boxes

Which didn’t scale because it doesn’t scale because the blue box stopped working. Sort of like Beeper.

Re: Apple cuts off Beeper Mini's access

#489
post #459
post #440

Earlier quoted context omitted.

No need for transparency here. Just know that no one has broken the encryption is all you need. Also you likely will not know if beeper sends a copy of your messages to their servers to sell, but who would you trust more won’t sell your info, beeper or Apple?

I'm trying to figure out if this post is sarcasm. The first half definitely made me think sarcasm, then the second half... I mean I know some people actually believe this... Then I noticed you said "encryption" instead of "protocol". Breaking an encryption standard is obviously very hard, breaking a protocol is obviously not nearly so hard. On the other hand, taking this stance would be insane given the post we're ta…

I wasn’t being sarcastic, I mean you do know there exist closed source for a reason whatever that is. For Apple to open their protocol would mean your messages sent to 3rd party clients, which means they could sell your messages for ad targeting or worse.

Re: Apple cuts off Beeper Mini's access

#490

Earlier quoted context omitted.

I didn't compromise the security of iMessage as a whole, it just exploited a way to get people into the system that was not planned. Imagine there is a theme park that has normal ticket booths and some requirements there to get in. Then there comes a Beeper that finds a hole in the fence on the perimeter and sets up their ticket booths there. It's in theme park's best interest to close that hole and cut off the reven…

Except they charge a thousand dollars to enter and then let everyone else in for free but they have to wear a badge and the pictures they get from the roller coaster photo booth are 240p.

And no one is obligated to come to the Theme park. There's an entire world of people who never visit the theme park, mock the people who do, and couldn't care less about it. But some people want to be included as going to the park, when they don't. Some people are very judgy and don't want to talk to people who don't go to the park...

Okay, I've stretched the metaphor out enough.

Post reply on HN