Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

851–860 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#851

Earlier quoted context omitted.

> Of course you can. It's sitting there on your Mac where you can use it as much as you like. For what? I own a Mac an iPhone and an iPad but iMessage and FaceTime are entirely useless to me because no one I communicate with on a regular basis uses Apple devices. Same thing with various iCloud sharing features. Not using the family sharing offers is entirely uneconomical as well. So what happens is that I gravitate t…

If you don't want to communicate with other Apple owners over iMessage, then there is no issue. What Beeper set out to do was to solve the opposite problem, people who don't have Apple devices, but want to use iMessage. And the poster above did have an Apple device, and wanted to use iMessage, but didn't seem to realise that iMessage works on Macs too.

The poster does - he was claiming that since he bought one Mac device capable of iMessage that he should then he allowed to use it also in his android device (where it would be far more useful) since he already paid the apple "tax" or what have you for iMessage access.

Re: Apple cuts off Beeper Mini's access

#852

Earlier quoted context omitted.

> Of course you can. It's sitting there on your Mac where you can use it as much as you like. For what? I own a Mac an iPhone and an iPad but iMessage and FaceTime are entirely useless to me because no one I communicate with on a regular basis uses Apple devices. Same thing with various iCloud sharing features. Not using the family sharing offers is entirely uneconomical as well. So what happens is that I gravitate t…

> So what happens is that I gravitate to other ecosystems. I use a Mac but an Android phone. Android because I require the ability to install apps from arbitrary sources, including piracy. Mac because modern Windows is so contemptuous towards its users, and desktop Linux falls apart unless you know the intricacies of its internals. Anyway, transferring files between the two was a pain in the butt that eventually grew…

Actually it is more like knowing the intricacies of its distribution specific internals.

Re: Apple cuts off Beeper Mini's access

#853

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

HN's obsession with Apple feels like some twisted mix of Stockholm syndrome, american nationalism and sunk cost falacy. Truly bizare to the point I wouldn't be surprised if we find out Apple is actively astroturfing this and many other topics. No other tech focused forum does this.

No astroturfing needed. It's called the Apple Cult for a reason.

Re: Apple cuts off Beeper Mini's access

#855
post #248

Earlier quoted context omitted.

(1) is exactly what that quote is pointing out. If Apple actually cared about its users' security, they would see this as a gap, and would have addressed it already. The fact that they haven't means that, despite all their posturing about being a security-first platform, they care more about lock-in and marketing than they do about user security.

A third party client in iMessage allows for spam attacks, and (worse) malicious payload attacks. It’s very much in the interests of security that Apple fence them out.

I don't think it's at all clear that the approach you describe is working: https://www.wired.com/story/imessage-interactionless-hacks-g... (2019), https://www.forbes.com/sites/daveywinder/2023/06/02/warning-... (2023)

Of course, this is a hard problem. I'm not saying Apple is bad at security, many good messaging platforms run into these kinds of problems. But the way you fix these problems (and the way Apple in fact did fix the bugs above) was through patching their own software, not by trying to control what attackers can send.

If security researches can send a malicious payload attack that compromises iMessage, the solution is not to make sure they can't send that payload (which would be impossible to guarantee anyway), the solution is to patch iMessage to no longer be vulnerable to that payload attack.

One hopes that the only thing preventing your iMessage client from being compromised is not whether or not the attacker has a spare $1,000 lying around.

Re: Apple cuts off Beeper Mini's access

#856
post #248

Earlier quoted context omitted.

A third party client in iMessage allows for spam attacks, and (worse) malicious payload attacks. It’s very much in the interests of security that Apple fence them out.

I don't think it's at all clear that the approach you describe is working: https://www.wired.com/story/imessage-interactionless-hacks-g... (2019), https://www.forbes.com/sites/daveywinder/2023/06/02/warning-... (2023) Of course, this is a hard problem. I'm not saying Apple is bad at security, many good messaging platforms run into these kinds of problems. But the way you fix these problems (and the way Apple in fact…

The longer term solution is to stop using memory unsafe languages.

Re: Apple cuts off Beeper Mini's access

#857
post #856

Earlier quoted context omitted.

I don't think it's at all clear that the approach you describe is working: https://www.wired.com/story/imessage-interactionless-hacks-g... (2019), https://www.forbes.com/sites/daveywinder/2023/06/02/warning-... (2023) Of course, this is a hard problem. I'm not saying Apple is bad at security, many good messaging platforms run into these kinds of problems. But the way you fix these problems (and the way Apple in fact…

The longer term solution is to stop using memory unsafe languages.

Regardless, when a buffer overflow happens, it's not reasonable to say, "well, we'll just make sure nobody sends us badly formatted or maliciously formatted data. As long as only iPhone users can send us data then we can trust it."

The actual solution is to make the client/server not be vulnerable to malicious payloads that would cause a buffer overflow. Whether you do that by patching bugs individually or switching to a memory safe language, or whatever strategy is used -- "don't send our messaging platform bad data" isn't a security fix.

Re: Apple cuts off Beeper Mini's access

#858

Earlier quoted context omitted.

This is actually a great point I didn’t originally consider. People could easily infiltrate the iMessage fort with spam and other stuff which at the moment requires a genuine Apple device.

Still need a valid phone number with a SIM that can do the special SMS needed for this, so it's hardly going to produce a big spam farm too fast.

It’s completely trivial to get a real number for sms these days thanks to scum like twilio. You can use your legitimate Apple device identifiers to run something like a hackintosh and then use iMessage that way, or use the script linked last week.

Re: Apple cuts off Beeper Mini's access

#859
post #723
post #166

Earlier quoted context omitted.

Good? RCS isn't universal. Am I gonna be sending and receiving Google, Verizon, TMobile, or Samsung messages? It's not universally encrypted either. No way am I turning it on.

RCS Universal Profile. Vendors are going to have to actually work on improving the standard (and Apple has committed to working within GSMA on an appropriate multi-vendor E2EE mechanism) In the absence of interoperable standards through GSMA, there will likely still be quite a bit of broken behavior, e.g. when it's not a Google RCS Server and all Google clients.

They don't have to, as they haven't for over a decade. It will suck and I doubt anyone will use it unless they're forced to (for 2fa). This is too little too late, if not iMessage, they'd use Snapchat, Facebook messenger, or IG before switching over to texting.

There is zero benefit for apple to make it good and no commercial reason for these vendors to make it good for multi vendors.

Re: Apple cuts off Beeper Mini's access

#860

Earlier quoted context omitted.

> Of course you can. It's sitting there on your Mac where you can use it as much as you like. For what? I own a Mac an iPhone and an iPad but iMessage and FaceTime are entirely useless to me because no one I communicate with on a regular basis uses Apple devices. Same thing with various iCloud sharing features. Not using the family sharing offers is entirely uneconomical as well. So what happens is that I gravitate t…

> So what happens is that I gravitate to other ecosystems. I use a Mac but an Android phone. Android because I require the ability to install apps from arbitrary sources, including piracy. Mac because modern Windows is so contemptuous towards its users, and desktop Linux falls apart unless you know the intricacies of its internals. Anyway, transferring files between the two was a pain in the butt that eventually grew…

> I require the ability to install apps from arbitrary sources, including piracy.

No one "requires" access to theft.

Post reply on HN