Live data from Hacker News

Beeper Mini is back

blog.beeper.com

521–530 of 1001 posts

Re: Beeper Mini is back

#521

As far as I understand, in order to talk to Apple iMessage services/backend (and all auth pieces) you need a "legit" Apple ID and legit Apple hardware model #s / serial #s If you don't have that, how are they able to get auth tokens / send messages around without basically "exploiting a hidden hack that might get patched"?

The hackintosh community has tools to generate those #s. e.g. https://dortania.github.io/OpenCore-Post-Install/universal/i...

Re: Beeper Mini is back

#522

As far as I understand, in order to talk to Apple iMessage services/backend (and all auth pieces) you need a "legit" Apple ID and legit Apple hardware model #s / serial #s If you don't have that, how are they able to get auth tokens / send messages around without basically "exploiting a hidden hack that might get patched"?

AFAIK they are using a reverse-engineered Apple binary that does the real iMessage - and since Apple doesn't update apps outside of iOS updates, Apple can't, in theory, patch it without also breaking iMessage on older iPhones.

Re: Beeper Mini is back

#523

As far as I understand, in order to talk to Apple iMessage services/backend (and all auth pieces) you need a "legit" Apple ID and legit Apple hardware model #s / serial #s If you don't have that, how are they able to get auth tokens / send messages around without basically "exploiting a hidden hack that might get patched"?

Maybe they generate legit-looking fake device serial numbers, that just happen to match real devices most of the time?

Re: Beeper Mini is back

#524
post #367
post #148

Earlier quoted context omitted.

The best case outcome is to get publicity leading to US and EU antitrust regulators to file a lawsuit against Apple, both of which Apple loses. The conclusion of this lawsuit is that not only must Apple allow access to iMessage, they also must allow changing the default for every component of iOS - messaging app, browser, app store, let you replace Siri with other voice assistants - and to lower the 30% app store fee…

Let's say that Apple is forced to allow third parties to use iMessage. Can't Apple just make the cost prohibitively high?

The “forcing” would likely come with conditions and some oversight. See how big phone companies in some countries are “forced” to allow competitors (eg. MVNOs) to connect to their networks at wholesale prices - do you think they chose that price point themselves?

Re: Beeper Mini is back

#525
post #471

> Messages will be sent and received via your email address rather than phone number. [...] Even worse, when iPhone customers added an Android phone number to an existing iMessage secure encrypted group chat, the Messages app would by default switch the entire group chat to using unencrypted, unsecure SMS. These two Messages features combine to create a terrible UX. When someone starts a group chat in Messages and in…

I almost forgot that you could MMS to email addresses. Crazy times of old.

Re: Beeper Mini is back

#526

As far as I understand, in order to talk to Apple iMessage services/backend (and all auth pieces) you need a "legit" Apple ID and legit Apple hardware model #s / serial #s If you don't have that, how are they able to get auth tokens / send messages around without basically "exploiting a hidden hack that might get patched"?

AFAIK they are using a reverse-engineered Apple binary that does the real iMessage - and since Apple doesn't update apps outside of iOS updates, Apple can't, in theory, patch it without also breaking iMessage on older iPhones.

I'd have assumed there'd be something more going on in iMessage, like each device has a private key that needs to sign the messages, and Apple can ban any private keys that leak -- but in theory couldn't they even be prevented from leaking by secure enclave?

I'm just speculating on what would have made sense, but I'm guessing that's not how it's working since Beeper Mini exists. It begs the question: why isn't that the way they do it?

Re: Beeper Mini is back

#527

Apple/Google/Microsoft/Amazon do a lot of extremely petty things that should disgust us and give us a glimpse at how this pettiness and adversarial conduct might escalate in a GAI world: - Amazon does not carry Google branded products. ([edit] they do now once again, whew!) - Search in GMail is nearly completely broken when you have too many messages, yet Google (ostensibly a search company) can't deliver good email…

How can this be taken seriously when basic facts are wrong. Go on Amazon and check for Google products. Apple has no way of telling you what an advertisement or promotion is, and it’s inherently subjective.

> Push Notifications should not be used for promotions or direct marketing purposes unless customers have explicitly opted in to receive them via consent language displayed in your app’s UI, and you provide a method in your app for a user to opt out from receiving such messages.

From (section 4.5.4 of) the App Store Review Guidelines. GP is incorrect on many points.

Re: Beeper Mini is back

#528
Maybe this came up in the earlier threads (announcement, outage) so I apologize if it's been discussed ...

This project is fantastic. The hacker spirit is in full force, and I love a good David and Goliath story. However, all the comments about demanding interoperability and protocols keep confusing me -- I don't consider APNS a protocol (like TCP anyways), it's also not incidental, extra header space to stuff data into in an existing message being transported (ala early SMS), and it's not an open relay for everybody to use. It's Apple's private message delivery system!

Why does everybody feel entitled to use it if they're not using Apple products?

I'm not licking boots over here, just genuinely curious. I wouldn't want to set up a mail server and then foot the bill and assume liability for whatever the hell goes through it from random people on the internet.

And trust me, I'm all for civil disobedience and sticking it to the man with clever technical solutions, but given the (probable) massive costs of operating APNS, Apple's got every right in the world to close any gaps in their system and keep kicking Beeper out.. and Beeper can keep trying to get back in.. but I just can't wrap my head around making the assumption that APNS access is somehow a fundamental right that we're all being denied.

Re: Beeper Mini is back

#529

Maybe this came up in the earlier threads (announcement, outage) so I apologize if it's been discussed ... This project is fantastic. The hacker spirit is in full force, and I love a good David and Goliath story. However, all the comments about demanding interoperability and protocols keep confusing me -- I don't consider APNS a protocol (like TCP anyways), it's also not incidental, extra header space to stuff data i…

> Why does everybody feel entitled to use it if they're not using Apple products?

Network effects.

Re: Beeper Mini is back

#530

I’m really curious how this is possible. Why wouldn’t every iMessage sent be tied to an Apple ID? If Beeper can do this, wouldn’t that mean anyone else with the same technique could basically spam iMessage users across the world?

A friend of mine got her Apple ID compromised years ago and cloud sync brought back the spam that the attacker was sending. iMessage spam is not new - whether it will increase remains to be seen.

It just seems like an insane way to set things up. I must be missing something because Apple is not usually a crazy company.
Post reply on HN