Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

631–640 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#631
post #65

As usual, Gruber was right on the money. Via Threads yesterday: "My prediction is that Apple will make changes—fixing bugs and/or closing loopholes—that break Beeper Mini. It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. It’s a very nice app, remarkably clever, and for now works like a charm, but if Apple wanted an iMessage client…

His first sentence about privacy and security is nonsense, but his second sentence hits the nail on the head. If the richest company in the world wanted their chat app to run on Android, it would by now. It's strange Apple doesn't sell an iMessage Android app, but I'm sure they've had somebody do the math and found out that it's more money for Apple in the long run if they don't.

Completely agreed about the nonsensical first claim. We have many third-party clients for other messaging platforms where privacy and security are a primary feature. It's completely tenable, especially for a player like Apple.

Or put another way: If the privacy and security of imessage is compromised by someone building another client, I'd argue that you never had either to begin with.

Re: Apple cuts off Beeper Mini's access

#632

Earlier quoted context omitted.

> Where is the hacker spirit here? The hacker spirit is the fun of reverse engineering. The hacker spirit is about personal use. It's not expecting to be able to turn it into a business , or a popular app, that wouldn't quickly be shut down. That's just common sense. > Myself for example owns a Macbook, but an Android phone. Am I not allowed to use iMessage? I paid the toll. Of course you can. It's sitting there on y…

No. Hacker spirit is owning your machine to its full extent. For fun, for profit or just for mayhem. Apple using instant messaging, where no meaningful innovation happened for decades to build their moat is pathetic and disgusting.

If your mayhem requires communicating with third party servers, who owns those computers?

Re: Apple cuts off Beeper Mini's access

#633

Earlier quoted context omitted.

In my experience, incoming SMS are mostly spam, and other low trust notifications, while incoming iMessages, even if unknown to me, are likely to be real people. Buying an Apple device is an expensive signal, and Apple will quickly shut down abusers, maintaining that relatively high bar. Letting (actual) Android users use iMessage probably wouldn’t affect that, but the open source hack/reversing of it opened the door…

Who is talking about SMS? Not I.

I mention SMS as a natural contrast to iMessage and to illustrate the annoyances which may burden iMessage if opened up blindly to any bot — a different variety of burdensome.

Re: Apple cuts off Beeper Mini's access

#634

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

It has nothing to do with a lack of spirit. It's a 800lbs of reality crashing down. There's nothing wrong with trying to hack the Gibson. However, this wasn't just a hack, but a severe threat to Apple's walled garden. As long as they are allowed to have it, they will protect it at all costs. Thinking any differently is just naive. So of course this is the ultimate result.

It’s identical to a jailbreak which gets patched ASAP so not sure what is has to do with walled garden as much.

I’ve played with the same idea of making an Android client but I would never build a product on that because I know the limitations on my side.

As a company you are 100% allowed to break 3rd party client when they don’t have an agreement with you. It’s your product after all. Heck even with an agreement APIs don’t support old versions.

Re: Apple cuts off Beeper Mini's access

#635

I'm pretty sure this quote from the founder is wrong on multiple levels: > “That means that anytime you text your Android friends, anyone can read the message. Apple can read the message. Your phone carrier can read the message. Google… literally, it’s just like a postcard. Anyone can read it. So Beeper Mini actually increases the security of iPhones,” he [the founder of Beeper] had told TechCrunch. The phone carrier…

Push notifications

Are you sure? So if I disable cellular data, I won't receive a notification for an incoming SMS?

I would assume that text message notifications are generated locally on the device when it receives an SMS message.

Re: Apple cuts off Beeper Mini's access

#636

Earlier quoted context omitted.

No thanks, iMessage is much better and not owned by Facebook.

How is iMessage better? WhatsApp is a great app.

Apple's business model is predicated on me buying things from them.

Facebook's business model is predicated on being able to sell access to me to third parties.

I can control the first one directly.

Re: Apple cuts off Beeper Mini's access

#637

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

Apple wouldn't even exist if not for this type of hacking. One of Steve Jobs and Steve Wozniak's first projects was selling blue boxes[1] to play around on AT&T's telephone system. [1] https://en.wikipedia.org/wiki/Blue_box

This should be the top comment

Re: Apple cuts off Beeper Mini's access

#638

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

It was the same when Apple banned Fortnite for daring to accept payments outside of their walled garden and the forced 30% cut. People falling over themselves to hate on Epic and defend Apple's forced cut and the total removal of developer freedom. If it was Microsoft the entire tone would be completely different.

Does Epic Games give developers "total freedom" with Unreal Engine or will they insist upon their royalty when applicable? You can read their FAQ and there's literally a section titled "Why does Epic think it’s fair to ask for a percentage of a developer’s product revenue?"

What's good for the goose, etc.

Re: Apple cuts off Beeper Mini's access

#639

This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…

This should have been obvious to anyone who saw the code where it simply contained the raw literal string `FAIRPLAY_PRIVATE_KEY = b64decode(“…”)`. I suppose now we’ll see how accurate the commenter’s claim “if this becomes a problem, I know how to generate new keys” is. https://github.com/JJTech0130/pypush/blob/main/albert.py#L16

What's the link between this repo and Beeper?

Re: Apple cuts off Beeper Mini's access

#640
post #210

Earlier quoted context omitted.

>It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. I don't follow this logic at all. Shouldn't supporting thirdparty clients be desirable if security is a primary feature in the interest of transparency? Especially if the reference client is proprietary and undocumented.

No. This is an entirely self-centred view. The only people that equate this sort of transparency with genuine security are computer nerds. These tend to be the sorts of people that don’t sit very highly on my internal list of “people who stand to benefit the most from increased privacy measures”. For…literally every other member of society, this sort of implementation detail doesn’t mean anything^. They hear some (fr…

> You know what is a much more realistic threat? Some stupid third-party client on the Play store that exfiltrates all messages sent and received.

One way to avoid that outcome would be to have a first-party client on the Play store.

Instead, Apple drops all message security entirely from cross-platform communications for iOS users, allowing anyone to read those messages whether or not they have a crowbar. This is security 101: users do dangerous crap when the secure options don't have affordances for their use-cases. Users are lazy. If an official 1st-party secure client exists that meets their needs, they won't install a 3rd-party client. Users resort to dangerous and unsupported options when the safe, obvious options either don't work or aren't available.

And thankfully, we now know that it would be entirely possible for Apple to fix that problem and to move its own users off of SMS for communication with Android contacts, and we know that because a 16 year-old high-schooler was able to build that support with zero documentation. Presumably Apple is capable of doing the work of a 16 year-old. We now know that it would in fact be entirely possible for Apple using a 1st-party controlled, proprietary client with a proprietary protocol, to encrypt virtually every message that Apple users send to every one of their contacts, rather than what Apple does today where it encrypts... some of them.

None of this requires Apple to Open Source anything or to document or make available any of their protocols. The only reason Apple is in this position right now of needing to deal with 3rd-party clients is because of a lack of support from their 1st-party client.

Post reply on HN