Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…
Apple cuts off Beeper Mini's access
881–890 of 1001 posts
Re: Apple cuts off Beeper Mini's access
#882Earlier quoted context omitted.
It’s also at severe risk of ruining the fun for numerous other hacker-spirit communities like hackintosh or opencore. Apple can come down on this in ways that potentially make it much more difficult for hackintosh to operate, or for people to update their legitimate apple systems after the end of official support. Which was pointed out in those threads too. See also geohot taking some other PS3 exploits that were alr…
All these activities live in a grey area: "We are breaking some rules, but in such a small-time way that the big guys don't bother enforcing the them". Fly below radars, and you will have your small joys for indefinitely long. This raises the question: is that a space worth inhabiting? Are hackintosh or homebrew PlayStation games worth it, compared to more open platforms where you are not breaking ToS? Answers, of co…
Nowadays smartphones are so much more capable and so much more accessible to kids, plus you can even get literal handheld PCs like the Steam Deck, so homebrew is a lot less worthwhile in my opinion (except for just the sake of hacking, since consoles at least tended to have very interesting security/DRM arrangements).
Re: Apple cuts off Beeper Mini's access
#883Earlier quoted context omitted.
This would be the case if it were a protocol designed to be opened up for use by 3rd party clients. As it stands, this was a clever hack which would undermine the integrity of the system if left in place. Within a few weeks we’d see 100 3rd party iMessage clients, and it would be luck of the draw if the one someone downloads is secure or not.
How is using another client undermining the security of the whole system?
From what I understand Beeper Mini is interfacing with iMessage on-device, what's to stop another clients from using a server and intercepting messages? While I don't have time to look it up again, I think there was also something on how Beeper Mini is handling the push notifications when the app isn't open. While that may not leak a lot of information, and there is also the news of Apple/Google sharing push info with some governments, that's something that can at least raise some eyebrows when it comes to how private it is.
Re: Apple cuts off Beeper Mini's access
#884Earlier quoted context omitted.
Not even that - Because Apple controls the key exchange, Apple could also just silenty register another recipient (their own mitm) and siphon off all your messages if they wanted to. You must trust that Apple (or Whatsapp or whatever) does not do that.
This isn’t true because you will get notified that another device was added to your account.
Or, how could you verify that you've been notified about every device added?
Re: Apple cuts off Beeper Mini's access
#885Earlier quoted context omitted.
> Are these iMessage group chat really a thing? For some, but everyone knows and has the capacity to download WhatsApp. The root issue is there is a lot of judgment about Android users, hence wanting to restrict chats to iMessage. It’s a signal that you are part of the in group vs out group. Although, it is objectively convenient to have a group of all iMessage users at events, because any pics/video get shared at hi…
Walled garden development practices sold under the guise of privacy and security. It's a very tired and old playbook that has real societal damage. So. Tired. Of. It.
Re: Apple cuts off Beeper Mini's access
#886Earlier quoted context omitted.
>It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. I don't follow this logic at all. Shouldn't supporting thirdparty clients be desirable if security is a primary feature in the interest of transparency? Especially if the reference client is proprietary and undocumented.
This would be the case if it were a protocol designed to be opened up for use by 3rd party clients. As it stands, this was a clever hack which would undermine the integrity of the system if left in place. Within a few weeks we’d see 100 3rd party iMessage clients, and it would be luck of the draw if the one someone downloads is secure or not.
Certainly this is not the first time some entity in the world has reverse-engineered iMessage; it's just the first time that it was publicized.
Re: Apple cuts off Beeper Mini's access
#887Re: Apple cuts off Beeper Mini's access
#888As usual, Gruber was right on the money. Via Threads yesterday: "My prediction is that Apple will make changes—fixing bugs and/or closing loopholes—that break Beeper Mini. It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. It’s a very nice app, remarkably clever, and for now works like a charm, but if Apple wanted an iMessage client…
Completely wrong. It's a job-seeking ad. “Look, I'm ruthless enough to fuck over users who buy this bogus subscription.” Which SV startup wouldn't pay millions for a crook of that caliber?
Re: Apple cuts off Beeper Mini's access
#889Earlier quoted context omitted.
This would be the case if it were a protocol designed to be opened up for use by 3rd party clients. As it stands, this was a clever hack which would undermine the integrity of the system if left in place. Within a few weeks we’d see 100 3rd party iMessage clients, and it would be luck of the draw if the one someone downloads is secure or not.
If the existence of a working unsanctioned client undermines the integrity of a system as prominent and security- and privacy-focused as iMessage proclaims to be, then that system has big problems. Certainly this is not the first time some entity in the world has reverse-engineered iMessage; it's just the first time that it was publicized.
Re: Apple cuts off Beeper Mini's access
#890To my understanding, Beeper uses some random Mac's serial number to complete device attestation. Would this be salvageable if I could provide my own legitimately purchased iPhone or Mac serial number?