Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

921–930 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#922
post #273

Earlier quoted context omitted.

We've really done one over on ourselves by adopting the mental model that only a vertically integrated corp can deliver privacy and security to users. This rigid tendency towards homogeneity is bound to suffer a tragic systemic failure before too long. It would be healthier to assume multi-polarity and lean into it.

> We've really done one over on ourselves by adopting the mental model that only a vertically integrated corp can deliver privacy and security to users. This rigid tendency towards homogeneity is bound to suffer a tragic systemic failure before too long. Look no further than the other news that came out this week re: government spying via push notifications. ( https://www.reuters.com/technology/cybersecurity/governme…

I suspect there's more where that came from. The only reason we learned of this, is because the cat was let out of the bag, and Apple was able to talk about it (gag order).

People might want to think about how AirTags and Find My Phone work...

Re: Apple cuts off Beeper Mini's access

#923
post #210
post #65

As usual, Gruber was right on the money. Via Threads yesterday: "My prediction is that Apple will make changes—fixing bugs and/or closing loopholes—that break Beeper Mini. It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. It’s a very nice app, remarkably clever, and for now works like a charm, but if Apple wanted an iMessage client…

>It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. I don't follow this logic at all. Shouldn't supporting thirdparty clients be desirable if security is a primary feature in the interest of transparency? Especially if the reference client is proprietary and undocumented.

Yeah but then that one Israeli company that spies on everybody will just pump these apps out.

Re: Apple cuts off Beeper Mini's access

#924

This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…

Can you say more about how Beeper is doing device attestation using ripped Apple device identifiers, or where you discovered that? Device attestation can be extremely user hostile, and if this is a true workaround it will be useful in other applications.

Re: Apple cuts off Beeper Mini's access

#926
post #783
post #520

Earlier quoted context omitted.

Hacking? Hacking means whining when what you are hacking fights back? I mean go for it, hack away! I hope apple keeps android far far away from me though lol

> I hope apple keeps android far far away from me though What a bizarre thing to say.

Well, I try.

Re: Apple cuts off Beeper Mini's access

#927
post #520

Earlier quoted context omitted.

Hacking? Hacking means whining when what you are hacking fights back? I mean go for it, hack away! I hope apple keeps android far far away from me though lol

Personally for me it's people who buy Frigidaire appliances. They are the worst!

Appliances don't talk to other people's appliances. Beeper users on imessage would be unpleasant. I used android for like a decade, my takeaway is that you all can't stand other people not enduring the chaos with you.

Re: Apple cuts off Beeper Mini's access

#928

This was why I never shared my iMessage for Windows: https://neosmart.net/blog/imessage-for-windows/ They’d block an account out of spite without a second thought.

Your article was the first I thought of when Beeper Mini was released. I knew it had already been done by you and never saw the light of day for a reason!

Re: Apple cuts off Beeper Mini's access

#929
Techcrunch is an absolute abomination of a website. For those using uBlock and/or uMatrix, have a look at the list of third-party domains the site uses.

No less than 18(!) of them:

* ads-twitter.com

* bizzabo.com

* dscg1.akamai.net

* facebook.net

* google-analytics.com

* googlesyndication.com

* googletagmanager.com

* mrf.io

* oath.com

* sail-horizon.com

* twitter.com

* twitter.map.fastly.net

* typekit.net

* vidible.tv

* wp.com

* yahoo.com

* yahoodns.net

* yimg.com

There's also two (!) layers of cookie consent redirects and the page simply will not load without JavaScript.

Even with first-party scripts enabled the main article doesn't load and at this point I don't give enough of a shit to work out why.

@dang should consider banning Techcrunch URLs from Hacker News IMHO.

Re: Apple cuts off Beeper Mini's access

#930

Earlier quoted context omitted.

> We've really done one over on ourselves by adopting the mental model that only a vertically integrated corp can deliver privacy and security to users. This rigid tendency towards homogeneity is bound to suffer a tragic systemic failure before too long. Look no further than the other news that came out this week re: government spying via push notifications. ( https://www.reuters.com/technology/cybersecurity/governme…

I suspect there's more where that came from. The only reason we learned of this, is because the cat was let out of the bag, and Apple was able to talk about it (gag order). People might want to think about how AirTags and Find My Phone work...

> People might want to think about how AirTags and Find My Phone work...

rotating BTLE identifiers controlled by a pseudorandom sequence derived from a key, and tunneled over end to end encryption?

Post reply on HN