Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

661–670 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#661
post #612

Earlier quoted context omitted.

Yearly reminder that a long time ago, chat services used XMPP and we were on the verge of having GChat interoperability with FB messages and I think Yahoo or something similar at the time. None of them really wanted to do it for business reasons, so they could “add value” (and charge for it)….same reason RSS has fallen out of favor (no good way to inject ads and tracking). IRC and Matrix still exist.

There is hope. The European Union's Digital Markets Act allows new messaging platforms to demand interoperability with the existing walled gardens. All it takes is for other jurisdictions to follow suit.

You can't use regulations to change physics, and (demands or no) it is unclear what sort of interoperability is really possible.

What will really happen is that there will be some subpar common denominator. An existing "walled garden" (WeChat?) would add support for this as well.

But this would wind up being rather insecure, because messaging services tend to use email addresses they don't control or phone numbers they don't control as identifiers. We'd have to wait for carriers and email providers to be regulated with the burden of solving this mess (for markets they aren't in).

Re: Apple cuts off Beeper Mini's access

#662

Earlier quoted context omitted.

This should have been obvious to anyone who saw the code where it simply contained the raw literal string `FAIRPLAY_PRIVATE_KEY = b64decode(“…”)`. I suppose now we’ll see how accurate the commenter’s claim “if this becomes a problem, I know how to generate new keys” is. https://github.com/JJTech0130/pypush/blob/main/albert.py#L16

What's the link between this repo and Beeper?

> What's the link between this repo and Beeper?

https://news.ycombinator.com/item?id=38531759

Re: Apple cuts off Beeper Mini's access

#663

Earlier quoted context omitted.

> Are these iMessage group chat really a thing? For some, but everyone knows and has the capacity to download WhatsApp. The root issue is there is a lot of judgment about Android users, hence wanting to restrict chats to iMessage. It’s a signal that you are part of the in group vs out group. Although, it is objectively convenient to have a group of all iMessage users at events, because any pics/video get shared at hi…

Walled garden development practices sold under the guise of privacy and security. It's a very tired and old playbook that has real societal damage. So. Tired. Of. It.

[dead]

Re: Apple cuts off Beeper Mini's access

#664

Earlier quoted context omitted.

With how many "rent a mac mini stuffed in a datacenter" services are out there, I wonder how cost-prohibitive blacklisting specific devices really is.

If a serial number of the mac mini is blacklisted by apple from registering for example with apple updates or any other apple connected services, then probably it's in datacenters' best interest to keep spammers out of them.

Cutting anyone off from security updates is a step too far.

Re: Apple cuts off Beeper Mini's access

#665

Earlier quoted context omitted.

Wouldn't your iPhone still receive spam SMS text messages with Apple Messages? And isn't Apple Messages commonly exploited by NSO Group (Zero-clicks)? Maybe I'm wrong, but this does not appear to be very fort-like.

Yes. I believe people are just saying that they assume unknown-contact SMS is spam and that sort of sounds like Apple's SMS spam filtering isn't very good.

For iPhone there are two tiers - the carrier provided SMS spam filtering, and apps written to provide such filtering[1].

1: https://developer.apple.com/documentation/sms_and_call_repor...

Re: Apple cuts off Beeper Mini's access

#666

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

> Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted?

Actually it is documented by Apple themselves that they receive the encrypted messages and the key to decrypt them when iCloud backup is used (unless you and the person you are messaging have specifically enabled their "advanced data protection" feature). They have decrypted messages in response to law enforcement requests.

Re: Apple cuts off Beeper Mini's access

#667

Earlier quoted context omitted.

In fairness the dev is a 16 year old. It’s still bad practice but this is a minor mistake all things considered compared to most programming projects by people of that age

Perfectly understandable, at that age I only had the vaguest notion of how cryptography works. Unfortunately, nobody else seems to either, which is why my comment is getting downvoted. "Why is this a problem?" say people when the publishing of a private key is inherently the wrong thing to do, and will always lead to a bad consequence. It doesn't matter who's key it is, how it was generated, how it was obtained, etc.…

The repo is a proof of concept. The key provided is used for illustration purposes and worked for the proof of concept. Nobody believes Apple would not revoke that key. But you don't need to talk down to the author for their age like this when they've made clear this is a proof of concept.

Re: Apple cuts off Beeper Mini's access

#668

Earlier quoted context omitted.

> 2. Since Apple has no control over the Beeper mini client, they would not consider it safe, it could easily be spying on users without their knowledge. Since I have no control over iMessage, I would not consider it safe. It could easily be spying on me without my knowledge.

"they would not consider it safe" is from Apple's perspective, which is the only thing that matters when Apple is the steward of legally and technically enforcing who can use their APIs.

Sure. They have every right to do what they're doing. I'm just mocking Apple because I think their implication that they're the only trustworthy entity is ridiculous. We have no reason to trust them any more than we do Beeper or any other company.

If Apple actually cared about security they'd implement an open protocol that is provably secure. Imagine if they supported something like Matrix. But that's clearly not their primary concern here. It's just a convenient excuse to maintain their walled garden.

Re: Apple cuts off Beeper Mini's access

#669

Earlier quoted context omitted.

In fairness the dev is a 16 year old. It’s still bad practice but this is a minor mistake all things considered compared to most programming projects by people of that age

Perfectly understandable, at that age I only had the vaguest notion of how cryptography works. Unfortunately, nobody else seems to either, which is why my comment is getting downvoted. "Why is this a problem?" say people when the publishing of a private key is inherently the wrong thing to do, and will always lead to a bad consequence. It doesn't matter who's key it is, how it was generated, how it was obtained, etc.…

I believe users are downvoting your comments because they are breaking the site guidelines. If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html and posting more in the intended spirit, we'd appreciate it, and your comments should get fewer downvotes too. See also https://news.ycombinator.com/item?id=38579013.

Re: Apple cuts off Beeper Mini's access

#670

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

> siphoning the messages from the client once it's been decrypted?

If you got iCloud backup enabled then they absolutely siphone everything that happens on your phone. And the disgusting part is that when enabling a new iphone it automatically has it switched on. I remember the case with some terrorists that Apple have to the US authorities everything on the dude's iCloud backups, but the authorities weren't content with only the backups and wanted to crack the phone - so backups have their keys managed by Apple.

Post reply on HN