Live data from Hacker News

Show HN: Beeper Mini – iMessage client for Android

beeper.com

891–900 of 902 posts

Re: Show HN: Beeper Mini – iMessage client for Android

#891
post #47
post #38

OK, took a while to figure out what it is, as I barely know anyone using iphone. Though it's not for me, BUT if they deliver this: > Over time, we will be adding all networks that Beeper supports into Beeper Mini, including SMS/RCS, WhatsApp, Messenger, Signal, Telegram, Instagram, Twitter, Slack, Discord, Google Chat and Linkedin. We'll also bring Beeper Mini to desktop and iOS. I'm interested, even if it's paid. I'…

Is this some sort of new mobile Adium?

Miranda-NG.

Re: Show HN: Beeper Mini – iMessage client for Android

#892

Earlier quoted context omitted.

That seems like a problem. Emulating the protocol is okayish-to-gray but having the binary there will just be a straight DMCA. Wonder what the actual app is doing since this is just the PoC.

There’s no need for Apple to react to this project at all. Eventually, someone will send spam using this app, at which point automated systems at Apple will “console ban” the hardware identifier shared by all of the app’s customers. The project presumably has a library of valid hardware identifiers collected and ready to go, and eventually that’ll be drained by spammers faster than revenue versus device purchasing al…

Followup: One day after widespread press, Beeper has apparently triggered Apple’s protections and is temporarily offline until they rotate identifiers and perhaps IPs. Apple has neither acknowledged that Beeper exists, nor stated whether Beeper was blocked by automated or a manual process. This happens every year with third-party iMessage clients, but we’ll see how it goes for them. Perhaps it’ll be different this time.

Re: Show HN: Beeper Mini – iMessage client for Android

#893
post #435

Earlier quoted context omitted.

That seems like a problem. Emulating the protocol is okayish-to-gray but having the binary there will just be a straight DMCA. Wonder what the actual app is doing since this is just the PoC.

The app is not redistributing it, it just requests a server to get validation data (since anyway the actual library loading involves patching every system function, making the function independent from the host device, see [0] if you want to see how it's stubbed to run on Linux using a data.plist file), and thus there is no need to emulate it on device. [0]: https://github.com/Dadoum/imd-apple-services

My (very limited) understanding is that this "validation data" is related to the certificate generation (see [0]). So if the app isn't emulating this on device, and instead calling out to a Beeper server that is hosting the Apple binary, is this a potential security risk? Is it possible to use the data that gets sent off device to derive the client encryption key? If so, that would be a huge security hole in this implementation, completely negating their claim of maintaining secure E2E encryption.

[0]: https://www.reddit.com/r/beeper/comments/18duom1/is_beeper_m...

Re: Show HN: Beeper Mini – iMessage client for Android

#894
post #435

Earlier quoted context omitted.

The app is not redistributing it, it just requests a server to get validation data (since anyway the actual library loading involves patching every system function, making the function independent from the host device, see [0] if you want to see how it's stubbed to run on Linux using a data.plist file), and thus there is no need to emulate it on device. [0]: https://github.com/Dadoum/imd-apple-services

My (very limited) understanding is that this "validation data" is related to the certificate generation (see [0]). So if the app isn't emulating this on device, and instead calling out to a Beeper server that is hosting the Apple binary, is this a potential security risk? Is it possible to use the data that gets sent off device to derive the client encryption key? If so, that would be a huge security hole in this imp…

I didn't implement all the IDS stuff, but I am pretty sure the certificate is not used at all to derive keys for anything related to iMessage. I think it is used to attest that the device running it is running Apple software, and it may generate keys to make that an identifier to Apple (probably also because the user may not have any Apple account, so they have to generate another identifier for that purpose).

Re: Show HN: Beeper Mini – iMessage client for Android

#895

Earlier quoted context omitted.

Since those services all died off my memory is a bit foggy, but I recall stacking contacts in one with Adium & being able to prioritize in that meta contact which service they provided. But I really only ever used it for two-person conversations so I had no experience with the group situation. Even still, a multi-chat app was a vastly better user experience than running several independent applications (with the cost…

I agree that it's better than using multiple applications, but today I just use one (for personal conversations at least, Slack for business and Discord for communities is a bit different), which is texting.

My texting is scattered. I’d prefer it to be all XMPP, but I engage with Signal, & Mattermost, IRC, & Matrix on a regular basis… & largely this is a result of me just quitting the other chat platforms that most are using here (LINE, Facebook Messenger) which has made communications more difficult for others. I could run gateway to puppet all those accounts which is a lot closer than Pidgin was at unifying it all, but I’ve been a bit lazy to set it all up (& if the common gateway tool wasn’t Python I’d be more thrilled to touch it).

Re: Show HN: Beeper Mini – iMessage client for Android

#896

Earlier quoted context omitted.

I saw an article on the topic where the reporter spoke with Beeper's CEO, Eric Migicovsky. He seems to believe that blocking Beeper might cause problems for legitimate Apple user's. Obviously that outcome is something he wants, but I still think its interesting. [0]: https://www.theverge.com/2023/12/5/23987817/beeper-mini-imes...

Apple maintains iMessage compatibility with devices that are long out of support, if Beeper Mini is sufficiently similar to the client in for example iOS 12 then it makes an Apple decision to break Beeper fairly expensive. Even if they do the work to publish iMessage updates for the old iOS versions it just buys a little time before the new version gets reverse engineered, and that at the cost of poor user experience…

Looks like Apple figured out a way to identify Beeper clients: https://techcrunch.com/2023/12/08/apple-cuts-off-beeper-mini...

Re: Show HN: Beeper Mini – iMessage client for Android

#897
I got into a debate with someone over this. It didn’t last. Apple killed it. Copyright Infringement is serious. They reversed engineered iMessage. In Apple TOU it specifically says that they are not allowed to do this. I would be expecting a response from Apple in the form of a lawsuit. Unjust enrichment by this company. They know better.

Re: Show HN: Beeper Mini – iMessage client for Android

#898
post #420

Earlier quoted context omitted.

Probably they originally did it because Android has high-assurance embedded use-cases (compare/contrast: Windows IoT Core) where you want to strip out everything possible from the attack surface. But mainly it's because base Android (AOSP) can be arbitrarily modified by the OEM; and Google doesn't want to have to trust installations of Google Play Services that have been arbitrarily modified by OEMs. (Especially beca…

Man, that's contrived. Really its simple: Google seperates out Play Services so they can harvest user data from virtually all Andoid devices. It lets them market Android as OSS while still reaping the benefits of closed source data scraping.

Google can harvest data from "virtually all Android devices" just by offering Chrome, Google Search, and Gmail as apps. Almost every Android user has at least one of those apps installed. They don't need Play Services itself to spy on you on top of that.

Re: Show HN: Beeper Mini – iMessage client for Android

#899

I've had a lot of trouble getting dates, women see the Android-colored bubbles when I message them, then they typically blow me off. I'm sure it's the Android-colored bubbles.

Come to Germany, everybody uses Whatsapp, nobody cares about the color of your bubbles or what phone you have.

They were being sarcastic.

Re: Show HN: Beeper Mini – iMessage client for Android

#900
post #159

Earlier quoted context omitted.

Sounds like phone-only registration didn't work. This may happen if you don't have a SIM card that can text outbound. If you are outside of US, Apple's SMS registration number is in the UK (+42)

+42 is Czechoslovakia +44 is UK

Czechoslovakia isn't a thing anymore.
Post reply on HN