Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

671–680 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#671

Earlier quoted context omitted.

If signal would officially allow third party clients, non-phone-number-bound users and maybe federation that'd be great. It does not.

As very recently made evident, Signal spends a significant amount of money maintaining their phone-number-bound infrastructure, with an entirely plausible, reasonable, user-focused reason for doing so. As a Signal user, and donator, I’m 100% okay with the trade-off they’ve made, and would hate to see it reversed just to appeal to some nerdy pipe-dream for how services should work.

I'll continue to restate the thing that made me immediately quit Signal forever - I made an account, and 10 minutes later, it had alerted someone I hadn't talked to in years that I had an account, simply because they had my phone number at some point in the past, and they messaged me.

For a nominally privacy focused app, for them to literally alert people to my new Signal account I'd gotten to securely message someone violated all trust I had in them. What's to stop someone from just adding a Contact for every single valid phone number on their phone and then getting an alert for any time anyone makes a Signal account? I may as well just use Facebook then.

Re: Apple cuts off Beeper Mini's access

#672
post #437

Earlier quoted context omitted.

> Where is the hacker spirit here? The hacker spirit is the fun of reverse engineering. The hacker spirit is about personal use. It's not expecting to be able to turn it into a business , or a popular app, that wouldn't quickly be shut down. That's just common sense. > Myself for example owns a Macbook, but an Android phone. Am I not allowed to use iMessage? I paid the toll. Of course you can. It's sitting there on y…

It’s also at severe risk of ruining the fun for numerous other hacker-spirit communities like hackintosh or opencore. Apple can come down on this in ways that potentially make it much more difficult for hackintosh to operate, or for people to update their legitimate apple systems after the end of official support. Which was pointed out in those threads too. See also geohot taking some other PS3 exploits that were alr…

[deleted]

Re: Apple cuts off Beeper Mini's access

#673

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

> Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? Actually it is documented by Apple themselves that they receive the encrypted messages and the key to decrypt them when iCloud backup is used (unless you and the person you are messaging have specifically enabled their "advanced data protection" feature). They have decrypted messages in respo…

You left off the point that that only true if you had iCloud backup of iMessages enabled. If you didn't have iCloud backup enabled then they've always been E2EE.

Re: Apple cuts off Beeper Mini's access

#674

I'm pretty sure this quote from the founder is wrong on multiple levels: > “That means that anytime you text your Android friends, anyone can read the message. Apple can read the message. Your phone carrier can read the message. Google… literally, it’s just like a postcard. Anyone can read it. So Beeper Mini actually increases the security of iPhones,” he [the founder of Beeper] had told TechCrunch. The phone carrier…

Push notifications

SMS doesn't go through APNS, that's not how cellphones work.

Re: Apple cuts off Beeper Mini's access

#675

Earlier quoted context omitted.

> how publishing a private key makes the slightest bit of sense. From what I gather, the private key was private until it was leaked to / stolen by the team who published it for this use case. I don't have enough context to say, because I have to admit that once published, the keypair corresponding to the private key is likely to be revoked/discarded.

> the keypair corresponding to the private key is likely to be revoked/discarded. That's precisely it! Publishing a private key -- anyone's -- invalidates the security of the private-public key pair, making it worthless as security. There's going to be some consequence to this, such as the third party "changing the locks" and locking out you, or your users. Similarly, it might allow hackers to intercept the comms, br…

I think I'm on board with your POV here.

I guess it would have been more difficult for Apple to find the key/device ID used in this scheme had these not been available on the first few pages linked by a lot of articles claiming iMessage is broken.

Had this not been publicly posted, someone would've been forced to at least open a log file.

Re: Apple cuts off Beeper Mini's access

#676
post #437

Earlier quoted context omitted.

> Where is the hacker spirit here? The hacker spirit is the fun of reverse engineering. The hacker spirit is about personal use. It's not expecting to be able to turn it into a business , or a popular app, that wouldn't quickly be shut down. That's just common sense. > Myself for example owns a Macbook, but an Android phone. Am I not allowed to use iMessage? I paid the toll. Of course you can. It's sitting there on y…

It’s also at severe risk of ruining the fun for numerous other hacker-spirit communities like hackintosh or opencore. Apple can come down on this in ways that potentially make it much more difficult for hackintosh to operate, or for people to update their legitimate apple systems after the end of official support. Which was pointed out in those threads too. See also geohot taking some other PS3 exploits that were alr…

[flagged]

Re: Apple cuts off Beeper Mini's access

#677
post #418
post #403

Earlier quoted context omitted.

I don't get why Americans cling so dearly to SMS.

As a European living in the US, it's been baffling to me. Everywhere else in the world people use WhatsApp, Telegram, Signal, etc. This iMessage green/blue bubble nonsense just isn't a thing outside the US.

I mean, isn't this just trading one bad monopoly for another? It's weird to me that everyone's like "oh, the backwards US where they gave in to the Apple monopoly. We enlightened rest of the world use Facebook's Whatsapp like real free people".

Re: Apple cuts off Beeper Mini's access

#678
post #665

Earlier quoted context omitted.

Yes. I believe people are just saying that they assume unknown-contact SMS is spam and that sort of sounds like Apple's SMS spam filtering isn't very good.

For iPhone there are two tiers - the carrier provided SMS spam filtering, and apps written to provide such filtering[1]. 1: https://developer.apple.com/documentation/sms_and_call_repor...

Oh, so there's no builtin message filtering at all??

This explains some things. Why wouldn't they just add a spam filter. Is there still iCloud email addresses? Do they have spam filtering?

Re: Apple cuts off Beeper Mini's access

#679

Earlier quoted context omitted.

How would third-party clients _increase_ security (other than indirectly, by people using SMS less)? On the contrary, third-party clients is a gigantic security hole, since Apple can't even know if a client app is spying on users.

> On the contrary, third-party clients is a gigantic security hole, since Apple can't even know if a client app is spying on users. Security isn't about Apple knowing if an app is spying on users, but about THE USERS knowing that nobody is spying on them. At best a third party iMessage client can only be as secure as iMessage itself because the back end is still closed and has no transparency, so it's the weakest lin…

> They can increase security by breaking a single target into multiple targets, by increasing competition around security and privacy issues, by having more people use and work with the protocols and able to spot potential problems, by encouraging more transparency around issues when they arise, and by having alternatives readily available if one of the clients is found to be compromised or insecure.

I believe you are speaking to transparency, not third party clients.

Beeper Mini actually bundled binaries that they didn't understand to bootstrap registration. They could only attempt to be compatible with messages that they have received, and verify messages they send show up correctly - they cannot know they covered all available options.

I speak to this as someone who reverse engineered MSN Messenger back in the early 2000s for an XMPP gateway - you'd occasionally find an entirely new type of message (requiring an entirely new parsing code path for their undocumented/bespoke messaging protocol) because someone registered for a stock ticker or the like.

There was no fuzzing the official servers or clients to see if they were robust or secure - the goal was to have a salable product. In fact, we saw other messaging systems where we had significant concerns based on our understanding of the protocols through reverse engineering, and we saw one vendor exploit a security vulnerability in their own shipping product in order to verify authenticity and block third party clients (which worked for a period of time)

From what I saw of the iMessage system, third party support is not going to be feasible even with a documented protocol without partnership, because there is an assumption of attestation of real, unique hardware as part of registration to prevent mass abuse.

Re: Apple cuts off Beeper Mini's access

#680

This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…

Yes, totally understandable that this would be blocked within our legal system... but its a proof of concept that it would not be burdensome for apple to enable interoperability. We should be demanding support for open standards for messaging from mono/duopolists like Apple/Google.

The EU will soon require interoperability between messaging apps! Real Freedom!

(for the users, not for the companies)

Post reply on HN