Earlier quoted context omitted.
> Of course you can. It's sitting there on your Mac where you can use it as much as you like. For what? I own a Mac an iPhone and an iPad but iMessage and FaceTime are entirely useless to me because no one I communicate with on a regular basis uses Apple devices. Same thing with various iCloud sharing features. Not using the family sharing offers is entirely uneconomical as well. So what happens is that I gravitate t…
If you don't want to communicate with other Apple owners over iMessage, then there is no issue. What Beeper set out to do was to solve the opposite problem, people who don't have Apple devices, but want to use iMessage. And the poster above did have an Apple device, and wanted to use iMessage, but didn't seem to realise that iMessage works on Macs too.
Apple cuts off Beeper Mini's access
851–860 of 1001 posts
Re: Apple cuts off Beeper Mini's access
#852Earlier quoted context omitted.
> Of course you can. It's sitting there on your Mac where you can use it as much as you like. For what? I own a Mac an iPhone and an iPad but iMessage and FaceTime are entirely useless to me because no one I communicate with on a regular basis uses Apple devices. Same thing with various iCloud sharing features. Not using the family sharing offers is entirely uneconomical as well. So what happens is that I gravitate t…
> So what happens is that I gravitate to other ecosystems. I use a Mac but an Android phone. Android because I require the ability to install apps from arbitrary sources, including piracy. Mac because modern Windows is so contemptuous towards its users, and desktop Linux falls apart unless you know the intricacies of its internals. Anyway, transferring files between the two was a pain in the butt that eventually grew…
Re: Apple cuts off Beeper Mini's access
#853Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…
HN's obsession with Apple feels like some twisted mix of Stockholm syndrome, american nationalism and sunk cost falacy. Truly bizare to the point I wouldn't be surprised if we find out Apple is actively astroturfing this and many other topics. No other tech focused forum does this.
Re: Apple cuts off Beeper Mini's access
#854Re: Apple cuts off Beeper Mini's access
#855Earlier quoted context omitted.
(1) is exactly what that quote is pointing out. If Apple actually cared about its users' security, they would see this as a gap, and would have addressed it already. The fact that they haven't means that, despite all their posturing about being a security-first platform, they care more about lock-in and marketing than they do about user security.
A third party client in iMessage allows for spam attacks, and (worse) malicious payload attacks. It’s very much in the interests of security that Apple fence them out.
Of course, this is a hard problem. I'm not saying Apple is bad at security, many good messaging platforms run into these kinds of problems. But the way you fix these problems (and the way Apple in fact did fix the bugs above) was through patching their own software, not by trying to control what attackers can send.
If security researches can send a malicious payload attack that compromises iMessage, the solution is not to make sure they can't send that payload (which would be impossible to guarantee anyway), the solution is to patch iMessage to no longer be vulnerable to that payload attack.
One hopes that the only thing preventing your iMessage client from being compromised is not whether or not the attacker has a spare $1,000 lying around.
Re: Apple cuts off Beeper Mini's access
#856Earlier quoted context omitted.
A third party client in iMessage allows for spam attacks, and (worse) malicious payload attacks. It’s very much in the interests of security that Apple fence them out.
I don't think it's at all clear that the approach you describe is working: https://www.wired.com/story/imessage-interactionless-hacks-g... (2019), https://www.forbes.com/sites/daveywinder/2023/06/02/warning-... (2023) Of course, this is a hard problem. I'm not saying Apple is bad at security, many good messaging platforms run into these kinds of problems. But the way you fix these problems (and the way Apple in fact…
Re: Apple cuts off Beeper Mini's access
#857Earlier quoted context omitted.
I don't think it's at all clear that the approach you describe is working: https://www.wired.com/story/imessage-interactionless-hacks-g... (2019), https://www.forbes.com/sites/daveywinder/2023/06/02/warning-... (2023) Of course, this is a hard problem. I'm not saying Apple is bad at security, many good messaging platforms run into these kinds of problems. But the way you fix these problems (and the way Apple in fact…
The longer term solution is to stop using memory unsafe languages.
The actual solution is to make the client/server not be vulnerable to malicious payloads that would cause a buffer overflow. Whether you do that by patching bugs individually or switching to a memory safe language, or whatever strategy is used -- "don't send our messaging platform bad data" isn't a security fix.
Re: Apple cuts off Beeper Mini's access
#858Earlier quoted context omitted.
This is actually a great point I didn’t originally consider. People could easily infiltrate the iMessage fort with spam and other stuff which at the moment requires a genuine Apple device.
Still need a valid phone number with a SIM that can do the special SMS needed for this, so it's hardly going to produce a big spam farm too fast.
Re: Apple cuts off Beeper Mini's access
#859Earlier quoted context omitted.
Good? RCS isn't universal. Am I gonna be sending and receiving Google, Verizon, TMobile, or Samsung messages? It's not universally encrypted either. No way am I turning it on.
RCS Universal Profile. Vendors are going to have to actually work on improving the standard (and Apple has committed to working within GSMA on an appropriate multi-vendor E2EE mechanism) In the absence of interoperable standards through GSMA, there will likely still be quite a bit of broken behavior, e.g. when it's not a Google RCS Server and all Google clients.
There is zero benefit for apple to make it good and no commercial reason for these vendors to make it good for multi vendors.
Re: Apple cuts off Beeper Mini's access
#860Earlier quoted context omitted.
> Of course you can. It's sitting there on your Mac where you can use it as much as you like. For what? I own a Mac an iPhone and an iPad but iMessage and FaceTime are entirely useless to me because no one I communicate with on a regular basis uses Apple devices. Same thing with various iCloud sharing features. Not using the family sharing offers is entirely uneconomical as well. So what happens is that I gravitate t…
> So what happens is that I gravitate to other ecosystems. I use a Mac but an Android phone. Android because I require the ability to install apps from arbitrary sources, including piracy. Mac because modern Windows is so contemptuous towards its users, and desktop Linux falls apart unless you know the intricacies of its internals. Anyway, transferring files between the two was a pain in the butt that eventually grew…
No one "requires" access to theft.