Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

551–560 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#551

Earlier quoted context omitted.

youtube-dl, NewPipe, and uBlock Origin exist solely for the purpose of empowering the individual, yet they are constantly attacked on HN as being tools used unfairly to harm Google's profitability. Open-source projects like Matrix, PeerTube, Mastodon, are built to be free and open-source for the benefit of end-users and lack of vendor lockin. Yet each is derided on HackerNews for not being enough like their corporate…

I pretty much found out about all these from HN. I think most of their traffic / downloads comes from this site.

This is extremely false.

Re: Apple cuts off Beeper Mini's access

#552
post #282
post #52

This is what Snazzy Labs said about Beeper Mini... hilarious: > This doesn't appear to be some easy thing Apple can just turn off. > It will require a complete redesign of their entire authentication and delivery strategy for not just iMessage but Apple ID account access as a whole.

This is why people shouldn’t listen to tech YouTubers who don’t actually work in tech as engineers. They’re tech fans, not experts but act like they know the domain space enough to make strong authoritative claims since that’s what gives them an audience.

There were a number of similar comments on HN when they announced. The real lesson? The internet is a shit show.

Re: Apple cuts off Beeper Mini's access

#553
post #545

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

> since Mini was entirely client-side it would be feasible for a free version to exist. It uses a server for bridging APNs to GCM. Sure, that could be maintained on a donation basis, but it’s not completely infrastructure-free in any case.

If you think about it, it's actually not even a technological requirement. It's plenty possible to use an Android system service which maintains a connection for Beeper Mini persistently from the phone. After all that's what GCM does too. Yes, it would require backgrounding permissions, but that is something pretty justifiable for a messaging app, and when using the right UI practices, you can explain this to the user before they grant it.

So yes, it's absolutely possible for this app to be 100% client side and I wish Beeper would've done that to start, if for no other reason than to dispel the misinformation around that BPNs is somehow required for the core operation of the app.

To be fair, they probably thought making this explicit in their How It Works article would be sufficient.

Re: Apple cuts off Beeper Mini's access

#554

Earlier quoted context omitted.

Is implicitly trusting authority the hacker spirit?

And by implicitly trusting authority, you mean trusting the device manufacturer with billions of sales and intense scrutiny from security researchers and state actors spanning decades, right? You mean trusting the entire of the security industry to have managed not to miss this glaring and easy to detect invasion or privacy? This isn’t “it’s not happening because Apple promises it’s not”. This is one of the most scru…

Going back to the original claim:

> Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted?

The answer here is no. Yes, making a wild claim afterwards is lazy, but the fact remains: there is no system in place to get anywhere close to "proof".

The best we have is researchers reporting trust violations when they find them, escalating those violations in the media, and sometimes forcing the company to change behavior. Relying on (ever more skilled!) unpaid volunteer work to verify the claims of the largest company in the world seems like an appeal to authority. It also doesn't scale as they make more claims and build more complex software.

Yes, breaking E2EE for everyone is so large that it would be impossible to do at scale without anyone noticing. Breaking it selectively to target individuals (the threat people are actually worried about!) is much harder to detect, no?

Re: Apple cuts off Beeper Mini's access

#556
post #157

Earlier quoted context omitted.

> Either because they just don’t care enough to install another browser… Why does so many people have this attitude that Safari sucks and the only people who use it are idiots who don’t know better? It’s so incredibly insulting. Not that putting native Mac in quotes implies anything nice either.

I don’t use Mac, nor care what browser people use on it. I use safari on iOS because I too don’t care enough to install another browser. It’s absolutely baffling that you could read my post as saying safari sucks or that people who use it are idiots. Let me try to be more clear… there are two reasons someone uses Safari on macOS, in my experience: 1. They like it better. Usually, the reason they like it better is bec…

> Either because they just don’t care enough to install another browser

The way this is written implies to me you think they should install something else, but obviously they just don’t care.

Whenever there are discussions about Safari on hacker news they tend to be a lot of people who seem to have the opinion it should die and that anyone with a brain uses chrome.

Between your word choice and that seemingly common sentiment here that’s what I thought you were saying. I’m sorry if I misunderstood.

Re: Apple cuts off Beeper Mini's access

#557

Apple could have been a lot meaner about this. If they really wanted to discourage 3rd-party clients they could just _subtly_ break them for users of Beeper Mini: Late messages. Truncated messages. A blue bubble that slowly turns brown. The wrong font. Zalgo text.

That’s something that Microsoft would do in the 90s.

Apple’s MO clearly is breaking something and refusing to elaborate further.

Re: Apple cuts off Beeper Mini's access

#558
post #157

Earlier quoted context omitted.

> Either because they just don’t care enough to install another browser… Why does so many people have this attitude that Safari sucks and the only people who use it are idiots who don’t know better? It’s so incredibly insulting. Not that putting native Mac in quotes implies anything nice either.

Why do you care about other peoples' opinion on a fricking browser? Did you write it to feel insulted? I'm trying to understand the reason for the white knight HN commenters NPC reactions coming with their "stop insulting my favorite trillion dollar corporation".

I really like safari and have used it ever since the day it was released. It’s my favorite browser.

There’s a very common sentiment on HN and other technical places that safari is a serious problem that needs to be removed from the web so that things can be “better”.

That’s why I’m insulted. Not because someone is insulting Apple, do that all you want if they deserve it. Because I’m tired of people implying that the browser I like is shit because it’s not chrome and its only used because people have no choice or can’t figure out how to switch.

Re: Apple cuts off Beeper Mini's access

#559

this comment predicted it: https://news.ycombinator.com/item?id=38536577

I'm pretty sure everyone predicted it. It was exceptionally clear to anyone that Apple would block this and patch the hole that allows it to work.

I actually thought that Apple might not care for now and that they’d just wait and see what happens.

Re: Apple cuts off Beeper Mini's access

#560

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

Their house, their rules.
Post reply on HN