Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

591–600 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#591
post #277

Earlier quoted context omitted.

It's not a super serious comment, it's more about how ridiculous the tone of "We are doing this for YOUR protection" would be. On a more serious note though, in the end Apple absolutely has the power of increasing everyone's capability and security by doing something like setting up a playbook of how iMessage could just use Signal protocol and how other actors could join in, or really anything else but doing this.

> It's not a super serious comment, it's more about how ridiculous the tone of "We are doing this for YOUR protection" would be. Right now I can presume a basic level of device security across all iMessage threads I have. Beeper deranges that: E2EE is still there, but Beeper exposes my correspondence to device security weaknesses from other OEMs, malware, keyloggers, screen scrapers, etc. as a result of lax app marke…

> comes at the cost of increasing the risk to its own users.

iMessage using SMS to communicate with Android devices increases the risk to iOS users. Apple customers are still Apple customers when they communicate with Android users.

Every risk you describe is still present in the current implementation of iMessage when communicating with Android users, except the risks are much greater because SMS is much easier to exploit and intercept than an E2EE protocol would be.

A message platform that forces Apple users to use an insecure protocol when communicating with Android users decreases the security and privacy of Apple users.

So even an imperfect implementation of real E2EE between Apple and Android users, even with all the risks you describe above, is still an improvement in security over what we have right now: a situation where Apple forces iMessage users to use to what is quite possibly the least secure communication method possible when communicating with their friends and family in different ecosystems.

It's not necessarily about helping the users of another competing platform, Apple users who are using normal iPhones are sending unencrypted and unsecured messages to their friends and family members because Apple is more interested in vendor lock-in than it is interested in making sure that its customers are able to communicate securely with their contacts.

The idea that Apple users would suddenly stop caring about security or that they wouldn't want their conversations encrypted just because they're talking to someone else who's on an Android device is very strange to me -- it suggests that Apple is willing to sacrifice security for paying iOS users just to keep Android users from seeing any of the benefits of those security improvements.

Yes, there may exist reasons to distinguish between locked down vendor-controlled devices where users do not have the autonomy to change device settings that could damage encryption, and devices where users do have that autonomy. I understand that concern, even if I think it's usually disengenous. But there is really no reason and no excuse (especially now that we know how easy it would be for Apple to take its encryption multiple-platform) for going beyond distinguishing between those devices, and going so far as to actively drop all security measures and all encryption from those conversations. It's like saying that because a window can be broken we might as well take the door off of its hinges and put up a "burglars welcome" sign -- and, incredibly, it's claiming that anyone who tries to replace the door without permission is somehow decreasing security. Apple doesn't just distinguish between controlled and uncontrolled environments, it removes the door entirely by dropping its users into a messaging format with no end-to-end encryption at all. It's a bad policy that hurts Apple users and decreases their safety.

Re: Apple cuts off Beeper Mini's access

#592
post #30

Earlier quoted context omitted.

And IIRC it used some old OSX binaries to do so? Just terminating the access might be a lucky outcome if that's the case, considring the money involved.

pypush uses the old binary pulled from macOS. Beeper Mini uses another workaround for the device UUID/serial/etc. requirement.

> Beeper Mini uses another workaround for the device UUID/serial/etc. requirement.

Have you got a source on that? As far as I know, there's no workaround possible because the authentication blob is based on the UDID/serial. Put differently: without UDID/serial, there's no way of authenticating with the message servers.

Beeper keeps referring to pypush when it comes to details in their write-up[0], and pypush, in turn, clearly states[1] the need for information like serial and UDID when dealing with the albert server and IDS registration request.

As a “workaround,” they simply stuff fake serials, etc., and cross their fingers that it gets through Apple’s scoring mechanism.

0: https://blog.beeper.com/p/how-beeper-mini-works

1: https://jjtech.dev/reverse-engineering/imessage-explained/

Re: Apple cuts off Beeper Mini's access

#593

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

You need a device key to use an iCloud account, and all Beeper clients were using the same device key. So unsurprisingly, it’s not hard for Apple to block. And this doesn’t mean they peep into the messages.

Re: Apple cuts off Beeper Mini's access

#594

Earlier quoted context omitted.

This should have been obvious to anyone who saw the code where it simply contained the raw literal string `FAIRPLAY_PRIVATE_KEY = b64decode(“…”)`. I suppose now we’ll see how accurate the commenter’s claim “if this becomes a problem, I know how to generate new keys” is. https://github.com/JJTech0130/pypush/blob/main/albert.py#L16

[flagged]

In fairness the dev is a 16 year old. It’s still bad practice but this is a minor mistake all things considered compared to most programming projects by people of that age

Re: Apple cuts off Beeper Mini's access

#595

Earlier quoted context omitted.

I remember another post that was very well-received where an individual hacker wrote his own homebrew iMessage client for his own personal purposes. HN really liked that! I think HN exists at an intersection of individual hackerism and business. If a project is clearly by-hackers-for-hackers it gets a lot more leeway for unsustainable concepts / implementations. But this is building a business on adversarial interope…

youtube-dl, NewPipe, and uBlock Origin exist solely for the purpose of empowering the individual, yet they are constantly attacked on HN as being tools used unfairly to harm Google's profitability. Open-source projects like Matrix, PeerTube, Mastodon, are built to be free and open-source for the benefit of end-users and lack of vendor lockin. Yet each is derided on HackerNews for not being enough like their corporate…

Who doesn’t like the first few tools you mentioned? YouTube-do and ublock origin are great.

Re: Apple cuts off Beeper Mini's access

#596
post #495

Earlier quoted context omitted.

Because "private" here is regarding the cryptography and not regarding the disclosure? How are users supposed to obtain this key to use the service without it being published?

“How can people get into my locked door if I don’t tape a key to it for them to use?” If the private key is public, it does nothing by definition and it may as well not exist! Just use plain text, HTTP, or whatever and stop fooling yourself. It’s like calling an open field a “secure facility”. The name is not the thing, the map is not the territory. Private keys are only private if they’re not public.

This isn't about taping a key to _your_ front door—you're taping a key to Apple's.

Re: Apple cuts off Beeper Mini's access

#598

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

It was the same when Apple banned Fortnite for daring to accept payments outside of their walled garden and the forced 30% cut. People falling over themselves to hate on Epic and defend Apple's forced cut and the total removal of developer freedom. If it was Microsoft the entire tone would be completely different.

You wonder why the company with 95% market share is treated differently than the company with 40% market share.

Re: Apple cuts off Beeper Mini's access

#599

The EU will probably look closely into that.

Wishful thinking.

The EU set up the rules of the game, and it turns out iMessage falls outside the rules (to the EU’s dismay).

Even if it would fall within the rules, EU regulations work on a policy level, not a technical one. In other words, they can force Apple to change their policy and facilitate interoperability, but there’s no legal mechanism to force Apple to allow unauthorized use of their service.

The best you can do, if you're so inclined, is hope that the EU will change the rules of the game, but that would be such a transparent attempt at targeting a specific company (a big no-no in the legal reality within the EU) that the European courts will strike it down before they finish their breakfast.

Re: Apple cuts off Beeper Mini's access

#600

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

> Where is the hacker spirit here? The hacker spirit is the fun of reverse engineering. The hacker spirit is about personal use. It's not expecting to be able to turn it into a business , or a popular app, that wouldn't quickly be shut down. That's just common sense. > Myself for example owns a Macbook, but an Android phone. Am I not allowed to use iMessage? I paid the toll. Of course you can. It's sitting there on y…

>Of course you can. It's sitting there on your Mac

As I am sure we all understood, OP meant on their Android.

Post reply on HN