Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

881–890 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#881

Where is the hacker spirit here? The number of Apple apologists that have crawled out to say "see? I told you so!!" is saddening. It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist. Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have t…

[deleted]

Re: Apple cuts off Beeper Mini's access

#882
post #768
post #437

Earlier quoted context omitted.

It’s also at severe risk of ruining the fun for numerous other hacker-spirit communities like hackintosh or opencore. Apple can come down on this in ways that potentially make it much more difficult for hackintosh to operate, or for people to update their legitimate apple systems after the end of official support. Which was pointed out in those threads too. See also geohot taking some other PS3 exploits that were alr…

All these activities live in a grey area: "We are breaking some rules, but in such a small-time way that the big guys don't bother enforcing the them". Fly below radars, and you will have your small joys for indefinitely long. This raises the question: is that a space worth inhabiting? Are hackintosh or homebrew PlayStation games worth it, compared to more open platforms where you are not breaking ToS? Answers, of co…

At least regarding homebrew PlayStation games, for me that was a very valuable grey area space on the PSP and then PSVita, since back then there weren't many other kid-friendly options for similar portable computers (this being relevant because as an adult I am not dependent on convincing someone else to buy me things).

Nowadays smartphones are so much more capable and so much more accessible to kids, plus you can even get literal handheld PCs like the Steam Deck, so homebrew is a lot less worthwhile in my opinion (except for just the sake of hacking, since consoles at least tended to have very interesting security/DRM arrangements).

Re: Apple cuts off Beeper Mini's access

#883

Earlier quoted context omitted.

This would be the case if it were a protocol designed to be opened up for use by 3rd party clients. As it stands, this was a clever hack which would undermine the integrity of the system if left in place. Within a few weeks we’d see 100 3rd party iMessage clients, and it would be luck of the draw if the one someone downloads is secure or not.

How is using another client undermining the security of the whole system?

The system wasn't designed with those 3rd party clients, and security around them, in mind. Beeper Mini is spoofing/reusing device IDs, pretending to be some random person's Mac, for example. True support for 3rd party clients wouldn't not require this kind of thing.

From what I understand Beeper Mini is interfacing with iMessage on-device, what's to stop another clients from using a server and intercepting messages? While I don't have time to look it up again, I think there was also something on how Beeper Mini is handling the push notifications when the app isn't open. While that may not leak a lot of information, and there is also the news of Apple/Google sharing push info with some governments, that's something that can at least raise some eyebrows when it comes to how private it is.

Re: Apple cuts off Beeper Mini's access

#884
post #862

Earlier quoted context omitted.

Not even that - Because Apple controls the key exchange, Apple could also just silenty register another recipient (their own mitm) and siphon off all your messages if they wanted to. You must trust that Apple (or Whatsapp or whatever) does not do that.

This isn’t true because you will get notified that another device was added to your account.

Do you think the Apple that would surreptitiously add another 'device' into your iMessage recipients would not be able to suppress that notification?

Or, how could you verify that you've been notified about every device added?

Re: Apple cuts off Beeper Mini's access

#885

Earlier quoted context omitted.

> Are these iMessage group chat really a thing? For some, but everyone knows and has the capacity to download WhatsApp. The root issue is there is a lot of judgment about Android users, hence wanting to restrict chats to iMessage. It’s a signal that you are part of the in group vs out group. Although, it is objectively convenient to have a group of all iMessage users at events, because any pics/video get shared at hi…

Walled garden development practices sold under the guise of privacy and security. It's a very tired and old playbook that has real societal damage. So. Tired. Of. It.

There’s a reason why robocalls and spam emails and spam paper mail are a nearly universal thing and iMessage spam is not.

Re: Apple cuts off Beeper Mini's access

#886
post #210

Earlier quoted context omitted.

>It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. I don't follow this logic at all. Shouldn't supporting thirdparty clients be desirable if security is a primary feature in the interest of transparency? Especially if the reference client is proprietary and undocumented.

This would be the case if it were a protocol designed to be opened up for use by 3rd party clients. As it stands, this was a clever hack which would undermine the integrity of the system if left in place. Within a few weeks we’d see 100 3rd party iMessage clients, and it would be luck of the draw if the one someone downloads is secure or not.

If the existence of a working unsanctioned client undermines the integrity of a system as prominent and security- and privacy-focused as iMessage proclaims to be, then that system has big problems.

Certainly this is not the first time some entity in the world has reverse-engineered iMessage; it's just the first time that it was publicized.

Re: Apple cuts off Beeper Mini's access

#888
post #65

As usual, Gruber was right on the money. Via Threads yesterday: "My prediction is that Apple will make changes—fixing bugs and/or closing loopholes—that break Beeper Mini. It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. It’s a very nice app, remarkably clever, and for now works like a charm, but if Apple wanted an iMessage client…

> Seems irresponsible for Beeper to charge a subscription for an unsupported service.

Completely wrong. It's a job-seeking ad. “Look, I'm ruthless enough to fuck over users who buy this bogus subscription.” Which SV startup wouldn't pay millions for a crook of that caliber?

Re: Apple cuts off Beeper Mini's access

#889

Earlier quoted context omitted.

This would be the case if it were a protocol designed to be opened up for use by 3rd party clients. As it stands, this was a clever hack which would undermine the integrity of the system if left in place. Within a few weeks we’d see 100 3rd party iMessage clients, and it would be luck of the draw if the one someone downloads is secure or not.

If the existence of a working unsanctioned client undermines the integrity of a system as prominent and security- and privacy-focused as iMessage proclaims to be, then that system has big problems. Certainly this is not the first time some entity in the world has reverse-engineered iMessage; it's just the first time that it was publicized.

Every system has holes that get discovered in time. Leaving those holes open is a different thing.

Re: Apple cuts off Beeper Mini's access

#890

To my understanding, Beeper uses some random Mac's serial number to complete device attestation. Would this be salvageable if I could provide my own legitimately purchased iPhone or Mac serial number?

Beeper fixed their other iMessage bridge service last night by rotating device serial numbers on their server farm, so I would guess this would work? To my knowledge the pypush library itself isn't broken.
Post reply on HN