Live data from Hacker News

Beeper Mini is back

blog.beeper.com

351–360 of 1001 posts

Re: Beeper Mini is back

#351

Relying on the assumption of an “authorized client” is fundamentally not a reliable security or anti-spam mechanism, as this Beeper saga demonstrates. A curious 16 year old casually figured out how to make a client be “authorized”, and a motivated party just demonstrated basic interference from Apple can’t stop it from continuing to practice guerrilla interoperability. Apple might be able to sue Beeper out of existen…

Do we know that beeper wasn’t cut off by e.g. an automated spam algorithm? I saw lots of technical discussion in previous threads that stated that they were using the same faked hardware ID for all messages… that would seem an obvious red flag.

I'm dying to know the technical details, but I wouldn't advise Beeper to disclose because it will just make it easier for Apple to block them.

Re: Beeper Mini is back

#352

Earlier quoted context omitted.

> Isn't this one of them? I don’t believe so. Beeper Mini uses Apple’s protocols the same way the native iMessage uses it; they didn’t exploit a security hole (unless you classify the device faking part as a security hole—I don’t). They maintain the E2EE flow.

The protocol's implementation is intended to verify you're connecting a device Apple built, with stuff like secure enclave and end-to-end encryption as known quantities. With Beeper, you have to give your Apple ID to a third-party app , which they then proxy through a server of some kind ( https://techcrunch.com/2023/12/11/beeper-mini-is-back-in-ope... ; "signing in with our Apple ID generated an Apple prompt that no…

> With Beeper, you have to give your Apple ID to a third-party app, which they then proxy through a server of some kind (https://techcrunch.com/2023/12/11/beeper-mini-is-back-in-ope... "signing in with our Apple ID generated an Apple prompt that noted our ID was being used to sign in with a device “near Los Angeles, CA” (where we are not located.)")

I think they have another primary product of the same name that operates this way, but Beeper Mini never sends your credentials off anywhere other than Apple’s servers [0][1].

[0]: https://blog.beeper.com/p/how-beeper-mini-works

[1]: https://github.com/JJTech0130/pypush

Re: Beeper Mini is back

#353

Apple/Google/Microsoft/Amazon do a lot of extremely petty things that should disgust us and give us a glimpse at how this pettiness and adversarial conduct might escalate in a GAI world: - Amazon does not carry Google branded products. ([edit] they do now once again, whew!) - Search in GMail is nearly completely broken when you have too many messages, yet Google (ostensibly a search company) can't deliver good email…

How can this be taken seriously when basic facts are wrong. Go on Amazon and check for Google products. Apple has no way of telling you what an advertisement or promotion is, and it’s inherently subjective.

As noted in the comment, Google products are once again available on Amazon. They were removed for several years not long ago.

Ads are subjective? Apple has many criteria for rejecting app store submissions, why not add "misleading push message content not labeled as advertising"

Re: Beeper Mini is back

#354

Earlier quoted context omitted.

I think they ignored a rarely talked about but important aspect. iMessage is free for Apple users because it comes bundled with all Apple products. The cost to run iMessage and deliver millions of messages daily must be a significant number. With beeper, they are enabling the functionality for android. That is every android user signed up with beeper will end up costing Apple some money to send messages to iphone (or…

It’s actually really surprising to me (from a technical perspective) that this wasn’t already the case. Based on what I’ve read they’re basically spoofing the fact that they’re an iDevice which seems like it should be much more difficult than Beeper has made it look.

It was open sourced by a 16 year old apparently.

https://github.com/JJTech0130/pypush

They used this and added their own changes. From their communication about what they are doing, it's remarkably similar, and i would be very surprised if they did not see this before.

Re: Beeper Mini is back

#355

Earlier quoted context omitted.

How is this an actionable anti-trust issue? iMessage doesn't even register as a messaging platform in the minds of most users globally. In the US is it dwarfed by at least three other platforms. Globally, do any of the other top ten (Apple is nowhere near the top ten) messaging apps allow third parties to spoof their service? The purpose of anti-trust is to increase competition and prevent unlawful monopolies. Apple…

> In the US is it dwarfed by at least three other platforms Maybe because it comes preinstalled?

This makes no sense.

“Because it comes preinstalled it is dwarfed by at least three other platforms”??

Re: Beeper Mini is back

#356
post #148

Earlier quoted context omitted.

The best case outcome is to get publicity leading to US and EU antitrust regulators to file a lawsuit against Apple, both of which Apple loses. The conclusion of this lawsuit is that not only must Apple allow access to iMessage, they also must allow changing the default for every component of iOS - messaging app, browser, app store, let you replace Siri with other voice assistants - and to lower the 30% app store fee…

How is this an actionable anti-trust issue? iMessage doesn't even register as a messaging platform in the minds of most users globally. In the US is it dwarfed by at least three other platforms. Globally, do any of the other top ten (Apple is nowhere near the top ten) messaging apps allow third parties to spoof their service? The purpose of anti-trust is to increase competition and prevent unlawful monopolies. Apple…

So "monopoly" as a single entity controlling a single market is a simplistic view of the issue at hand. Anti-trust is far broader than that, where any anticompetitive action can be subject to anti-trust lawsuits/regulatory action.

So the legal argument would be that, because Apple allows for a single messaging app, and interacting with that app requires an iphone, they're effectively preventing messaging app competition.

Apple has a very, very talented legal team though, so, for this to even see argument in court someone's going to have to realllly have to want it, and be able to fund it.

Re: Beeper Mini is back

#357
post #29

I’m curious what their best-case outcome is here. It’s fully transparent at this point that Apple has no appetite for a third party iMessage client on any platform and will take whatever technical steps needed to prevent this from happening. I’d wager heavily that even if Beeper plays cat-and-mouse to the point where they’ve exhausted Apple’s budget for blocking them and somehow managed to avoid Apple’s legal team pu…

I'm just glad to see Apple's proprietary gatekeeping being challenged and this app has helped bring "green bubble bullying" to the fore. A lot of Apple fans seems to applaud Apple for acting ethically (at least relative to other big tech) and I hope they now view this marketing tactic by Apple as unethical and demand it be stopped.

Re: Beeper Mini is back

#358
post #61

Earlier quoted context omitted.

If the only thing Beeper does is continue to make Apple look anti-competitive, they've succeeded as far as I'm concerned. I'm deep into the Apple ecosystem and don't see myself getting out anytime soon. But I think their stance on iMessage sucks, even while understanding the strategic reasons they're doing it. I don't see this as "leeching off an undocumented API" as much as demonstrating that iMessage is already in…

That's a strange argument... It sounds like you're making the claim that every single chat application should be mandatory legally required to have completely open APIs for any clone that wants to pop up and get access to their network. What chat apps using a centralized server owned by a single company have open APIs that let anyone use them?

I don’t believe every chat application should be required to have completely open APIs. Key factors in my mind:

- iMessage isn’t a chat app. It’s the default experience for sending the equivalent of text messages from the Apple ecosystem. They’ve blended the experiences such that it’s not fair to compare it to a traditional chat app

- 3rd party chat apps are cross platform. The only reason Beeper exists is because there is no first party option to interact with iMessage chats outside of the ecosystem. This is not the case for actual “chat apps”, and the non-existence of APIs takes on lesser relevance

Re: Beeper Mini is back

#359
post #165

Earlier quoted context omitted.

Only question is what’s the endgame? It’s not like they’re going to gain meaningful followers from this. This happens every 3-5 years with something Apple does and all that happens is Apple hardens even more, the little guy gets some press for a month and then disappears into the ethers

The context is a little different, with the EU looking into whether iMessage is anticompetitive and should be opened up: https://arstechnica.com/gadgets/2023/11/google-argues-imessa... I imagine Beeper is providing exhibits A and B for any such court case, should it happen. And they get some good brand publicity along the way.

The EU has already decided the iMessage is not a gatekeeper.

Re: Beeper Mini is back

#360
post #104

Yeah, I am not expecting this to be a protracted game of cat and mouse. Apple will just sue them in the end; that'll put a REAL quick stop to this. I wish things had more interoperability, but Apple is under no obligation to implement it or be okay with it. And honestly, I believe them when they say that this is a security/privacy risk; even if it does serve their anticompetitive tendencies.

[deleted]
Post reply on HN