Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

621–630 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#621

I'm guessing the binary they use from Apple (IMDAppleServices) to generate part of the registration information probably adds metadata to the "validation blob" that gets sent to apple when registering beeper mini as an iMessage device. If the metadata includes the OS version, Apple probably blacklisted any new devices registered in the past few days with validation blobs generated from that binary. (The binary was so…

It doesn't look like that binary is used for Beeper Mini, unlike pypush: https://blog.beeper.com/p/how-beeper-mini-works

Re: Apple cuts off Beeper Mini's access

#622

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

> Obviously Mini was using the encryption properly else it wouldn't have worked to begin with.

Just want to point out this isn’t inherently true. For example an insecurely generated session key would work fine but not be secure.

> Of course, it's very unlikely Apple is doing that. Just putting the thought out there.

Apple is doing what? Not using encryption properly? What reason do you have to believe that?

Re: Apple cuts off Beeper Mini's access

#623

One thing which is really confusing is why are Android users obsessed with iMessage? Android users can send text messages to iPhones, the can call iPhone users, and they can use third party messaging apps to communicate with iPhone users. It really isn’t clear to me why so many people are so angry they cannot use iMessage on Android.

Green bubbles means you won't be called back for a second date.

That's a feature, not a bug. Anyone who does that would be a miserable significant other.

Re: Apple cuts off Beeper Mini's access

#624

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

I remember another post that was very well-received where an individual hacker wrote his own homebrew iMessage client for his own personal purposes. HN really liked that! I think HN exists at an intersection of individual hackerism and business. If a project is clearly by-hackers-for-hackers it gets a lot more leeway for unsustainable concepts / implementations. But this is building a business on adversarial interope…

> on adversarial interoperability

In what world is interoperability adversarial? What the actual?

Re: Apple cuts off Beeper Mini's access

#625

Earlier quoted context omitted.

>Of course, it's very unlikely Apple is doing that. Just putting the thought out there. Is making wild claims and then immediately trying to disavow them in the next sentences the hacker spirit? How does it at all follow that Beeper Mini is using encryption properly (or else it wouldn't work) but it's unlikely Apple is? How would Beeper have been able to reverse engineer it if Apple's not using it? Who did they model…

The claim is that (a) both entities are properly encrypting the data _in transit_ and (b) either company could _steal_ the plaintext client-side (after decryption). Trust that a third-party application isn't stealing the decrypted messages requires the same type and amount of trust that Apple is not stealing the decrypted messages (or maybe less trust if the third-party solution is open source, etc.).

Except the stakes for Apple are so much higher. If they’ve lied to everyone and are stealing messages, that’s a multi-billion dollar class action, against very little upside to Apple.

For a tiny company like Beeper, the incentives are different. The upside of being dishonest far outweighs the risks.

Not that I believe Beeper is nefarious. They probably aren’t. But their risk/reward for abusing trust is very different from Apple’s

Re: Apple cuts off Beeper Mini's access

#628

Earlier quoted context omitted.

How are you going to make a case for tortious interference when the would be interferee is profiting by using the interferer’s resources without payment?

From beepers website, there’s no use of apples servers when iMessages are sent from a beeper user to a beeper user. Rather, they only pass through Apple when sent to an iPhone user and in that case it’s the iPhone user that’s utilizing apples resources. And in that case there’s an Apple device owner, who is paid for the right to use iMessage servers.

Well, obviously, if those messages aren't using Apple's servers, then Apple hasn't stopped them, so there's no interference.

Re: Apple cuts off Beeper Mini's access

#629
post #600

Earlier quoted context omitted.

> Where is the hacker spirit here? The hacker spirit is the fun of reverse engineering. The hacker spirit is about personal use. It's not expecting to be able to turn it into a business , or a popular app, that wouldn't quickly be shut down. That's just common sense. > Myself for example owns a Macbook, but an Android phone. Am I not allowed to use iMessage? I paid the toll. Of course you can. It's sitting there on y…

>Of course you can. It's sitting there on your Mac As I am sure we all understood, OP meant on their Android.

The the OP should read what he is buying.

I have a TV from 95 am I not allowed to watch Netflix? It runs on my phone.

Yes the limitations are different but you know them beforehand you just go and say it’s unfair I can’t have everything just the way I want it.

You don’t like iMessage - we have plenty of alternatives.

Re: Apple cuts off Beeper Mini's access

#630
post #65

As usual, Gruber was right on the money. Via Threads yesterday: "My prediction is that Apple will make changes—fixing bugs and/or closing loopholes—that break Beeper Mini. It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. It’s a very nice app, remarkably clever, and for now works like a charm, but if Apple wanted an iMessage client…

His first sentence about privacy and security is nonsense, but his second sentence hits the nail on the head. If the richest company in the world wanted their chat app to run on Android, it would by now. It's strange Apple doesn't sell an iMessage Android app, but I'm sure they've had somebody do the math and found out that it's more money for Apple in the long run if they don't.

Because there are people that buys iphone just to get a blue bubble, why would Apple want to stop that?
Post reply on HN