Live data from Hacker News

Beeper Mini is back

blog.beeper.com

331–340 of 1001 posts

Re: Beeper Mini is back

#331

Earlier quoted context omitted.

> it seemed Apple was actually doing the a lot of the right things when it came to privacy and security Isn't this one of them? A security hole existed that permitted Beeper to pretend to be your Apple device. In this case, it was being used for non-nefarious purposes, but that doesn't mean everyone would. Apple's fixing that hole seems in-line with your desired "privacy and security".

> Isn't this one of them? I don’t believe so. Beeper Mini uses Apple’s protocols the same way the native iMessage uses it; they didn’t exploit a security hole (unless you classify the device faking part as a security hole—I don’t). They maintain the E2EE flow.

This is incorrect. They're using a legacy, less secure protocol - not in the sense of encryption, but in the sense of the need to generate auth tokens per user.

Re: Beeper Mini is back

#332

Earlier quoted context omitted.

> iPhone customers desperately want to be able to chat together is also laughably false lol. iPhone users just want android users to get an iphone.

...in the US. The rest of the world uses Telegram, WhatsApp and Signal. This blue/green bubble SMS but not SMS -thing is a 100% an American issue.

Ye you are probably right that I am american-centric in my perspective. Only one that really matters in tech tho.

Percentage share of iphones are rising in korea and japan tho for similar reasons though.

Re: Beeper Mini is back

#333

Earlier quoted context omitted.

> it seemed Apple was actually doing the a lot of the right things when it came to privacy and security Isn't this one of them? A security hole existed that permitted Beeper to pretend to be your Apple device. In this case, it was being used for non-nefarious purposes, but that doesn't mean everyone would. Apple's fixing that hole seems in-line with your desired "privacy and security".

> Isn't this one of them? I don’t believe so. Beeper Mini uses Apple’s protocols the same way the native iMessage uses it; they didn’t exploit a security hole (unless you classify the device faking part as a security hole—I don’t). They maintain the E2EE flow.

The protocol's implementation is intended to verify you're connecting a device Apple built, with stuff like secure enclave and end-to-end encryption as known quantities. With Beeper, you have to give your Apple ID to a third-party app, which they then proxy through a server of some kind (https://techcrunch.com/2023/12/11/beeper-mini-is-back-in-ope...; "signing in with our Apple ID generated an Apple prompt that noted our ID was being used to sign in with a device “near Los Angeles, CA” (where we are not located.)")

I don't see how you could describe that as anything other than a security hole.

Re: Beeper Mini is back

#334

I’m a former Android fanatic turned iPhone user. I still own Android devices, but my primary device is an iPhone. I haven’t had something excite me as much as this Beeper Mini situation in years—I love that they’re doing this. One of the things that got me to switch to the iPhone a few years ago was the fact that it seemed Apple was actually doing a lot of the right things when it came to privacy and security. Obviou…

If you want privacy a de-googled android phone is far better than apple.

Re: Beeper Mini is back

#335

Relying on the assumption of an “authorized client” is fundamentally not a reliable security or anti-spam mechanism, as this Beeper saga demonstrates. A curious 16 year old casually figured out how to make a client be “authorized”, and a motivated party just demonstrated basic interference from Apple can’t stop it from continuing to practice guerrilla interoperability. Apple might be able to sue Beeper out of existen…

Do we know that beeper wasn’t cut off by e.g. an automated spam algorithm?

I saw lots of technical discussion in previous threads that stated that they were using the same faked hardware ID for all messages… that would seem an obvious red flag.

Re: Beeper Mini is back

#336
post #2

I have a feeling they're not going to stop being a thorn in Apple's side for quite a while...

They're either going to keep getting their access cut, or sued into bankruptcy. You can't really piggyback off another companies service in violation of their TOS without things working out poorly for you IMO.

There’s no piggybacking. Beeper’s messages never hit Apple servers.

Re: Beeper Mini is back

#337

Earlier quoted context omitted.

How is this an actionable anti-trust issue? iMessage doesn't even register as a messaging platform in the minds of most users globally. In the US is it dwarfed by at least three other platforms. Globally, do any of the other top ten (Apple is nowhere near the top ten) messaging apps allow third parties to spoof their service? The purpose of anti-trust is to increase competition and prevent unlawful monopolies. Apple…

> In the US is it dwarfed by at least three other platforms Maybe because it comes preinstalled?

[deleted]

Re: Beeper Mini is back

#338
post #148

Earlier quoted context omitted.

The best case outcome is to get publicity leading to US and EU antitrust regulators to file a lawsuit against Apple, both of which Apple loses. The conclusion of this lawsuit is that not only must Apple allow access to iMessage, they also must allow changing the default for every component of iOS - messaging app, browser, app store, let you replace Siri with other voice assistants - and to lower the 30% app store fee…

How is this an actionable anti-trust issue? iMessage doesn't even register as a messaging platform in the minds of most users globally. In the US is it dwarfed by at least three other platforms. Globally, do any of the other top ten (Apple is nowhere near the top ten) messaging apps allow third parties to spoof their service? The purpose of anti-trust is to increase competition and prevent unlawful monopolies. Apple…

Aren't 70% of American teenagers on iPhone because of the iMessage network effects? The whole "green bubble" shaming issue.

Re: Beeper Mini is back

#339

I’m a former Android fanatic turned iPhone user. I still own Android devices, but my primary device is an iPhone. I haven’t had something excite me as much as this Beeper Mini situation in years—I love that they’re doing this. One of the things that got me to switch to the iPhone a few years ago was the fact that it seemed Apple was actually doing a lot of the right things when it came to privacy and security. Obviou…

> The way Apple tries to lock you in though while stifling competition is extremely disappointing. They’re on the wrong side of history. Fascinating that you say this when you literally switched to iPhone yourself.

How is it fascinating? Apple exerts pressure on customers to buy their products, and then further pressures to keep them integrated with Apple's ecosystem. Here, a customer gave in to the first pressure and is disappointed by the artificial friction Apple uses to upsell their customers.

So... are we shocked that iPhone customers don't de-facto agree with everything Apple does? Or the fact that OP would be willing to criticize something they paid for and supposedly identify with?

It's really not fascinating at all. It reads like a perfectly level-headed and candid criticism of an ecosystem by someone who isn't invested in the success of one particular company. It's almost too lucid for HN.

Re: Beeper Mini is back

#340
post #202

Earlier quoted context omitted.

If we’re talking best case outcomes, then why settle for 10%? 0%! Free distribution for everyone.

Yes! We don't need any moderation or policy enforcement, viruses for everyone!

You have a garbage sandbox if you can get viruses that easily. People expect much better from modern operating systems.
Post reply on HN