Live data from Hacker News

Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

arstechnica.com

401–410 of 665 posts

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#401

Earlier quoted context omitted.

iMessage is routed through apple's servers over TCP. So this is like saying: sometimes I go to google.com but it randomly loads bing.com... must be related to my group carrier plan What data made you make that association? Seems unlikely. If that happens, then apple would have to be routing messages incorrectly, but that would be a massive bug/security issue... especially considering how E2EE works.

Yeah sounds more like the aunt and uncle once shared an Apple ID and then moved to seperate ones later.

This is by far the most plausible explanation. iMessage’s biggest surface area for problems is multiple/migrated associated emails.

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#402

Earlier quoted context omitted.

My understanding is that the serials represent information, including model and date/location of manufacture. It’s therefore possible to create correctly formed but impossible serials, for example one that represents a pre-touchbar 2015 MBP manufactured in Ireland in 2018. Apple should easily be able to tell when someone has done this.

They indeed used to have data like that encoded in it. Not too long ago, however, they moved to a completely randomized serial format, perhaps partly because of iMessages shenanigans.

iMessage seems to use quite a lot of information from the hardware aside from the serial number. See https://github.com/JJTech0130/pypush/blob/main/emulated/data... for the data that is used to calculate the "validation blob" to activate iMessage. Several of the keys (not values!) are random-looking gibberish like "kbjfrfpoJU" and "oycqAZloTNDm", while others are normal things like "product-name" and "IOPlatformUUID".

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#403

Earlier quoted context omitted.

Macs are an Apple product and have the very nearly the same hardware protections.

How so? You can easily automate sending messages on a Mac, and you can easily change the IDs on Intel based Macs. Ultimately, the only solid line of defence is banning your phone number and Apple ID.

[deleted]

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#404

Earlier quoted context omitted.

> Migicovsky previously denied to Ars that Beeper used "fake credentials" As far as I know (I could be wrong), in order to log in + auth to Apple's various protocols that are involved to make iMessage work, you need a valid Apple ID and some sort of valid hardware ID. If you don't have either of those, how would you be talking to Apple's services? If their POST /login requires email + password + valid registered seri…

AFAIK, and I could be wrong, beeper mini registers a new HWID with apple for each phone. Which is why they thought it was unpatchable, at first, as they would need to determine which phone is in fact an iPhone.

There's much more to the validation protocol than just HWID/serial. See https://github.com/JJTech0130/pypush/blob/main/emulated/data... for a list of the data that is pulled from the platform and used for validation. I would assume that Beeper registrations either use data from a pool of real devices, or made-up data that Apple might "permit" (because hackintoshes) but can definitely detect and block at any time.

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#405

Earlier quoted context omitted.

Your advice was "There are plenty of cross-platform things out there. Signal, Telegram, WhatsApp", but you don't seem happy to take it and move away from iMessage either. This tension is at the center of the it all, and why Beeper Mini exists in the first place.

What? I pay for iMessage. You’re just arguing for the right to use products for free, and in Beeper’s case to create monetized products that use others’ products for free.

[deleted]

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#406
Completely uninformed question, doesn't this fight just push people to WhatsApp?

I never use SMS, and no one in Mexico does either. My friends in Europe seem to largely use WhatsApp as well. So it really seems like Americans are outliers in their choice for iMessage / SMS.

So, wouldn't this push Americans to WhatsApp?

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#407

Earlier quoted context omitted.

> I'm sure if Ford dictated how and where you drove your car you'd be outraged, but we should kowtow to the likes of Apple? I just wouldn't buy a Ford.

What if Ford made it so that their vehicles drive worse when non-Ford vehicles were on the road, and then when confronted about it told all of their customers that they should convince their neighbors to buy a Ford to solve the problem?

> What if Ford made it so that their vehicles drive worse

Then you really wouldn't buy a Ford. Problem solved?

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#408

Earlier quoted context omitted.

Your advice was "There are plenty of cross-platform things out there. Signal, Telegram, WhatsApp", but you don't seem happy to take it and move away from iMessage either. This tension is at the center of the it all, and why Beeper Mini exists in the first place.

What? I pay for iMessage. You’re just arguing for the right to use products for free, and in Beeper’s case to create monetized products that use others’ products for free.

> What? I pay for iMessage.

I doubt that. iMessage is a free service if you have almost any Apple OS product (iOS, iPadOS, macOS). You aren't making ongoing payments for the iMessage service.

You could say you paid for iMessage in that you bought a device that worked with it. But you do not pay for iMessage.

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#409

Earlier quoted context omitted.

> It seems a bit entitled behaviour for someone to feel like Apple should be forced to bring iMessage to Android for any reason besides Apple's own choice, and that they know better than Apple on how to run Apple's business. It is simultaneously possible for it to appear entitled, while also recognizing how extremely restrictive, anti consumer and anti competition Apple is. And in this fight of a trillion dollar comp…

It can be agreeable to an extend that Apple seem like an extremely restrictive, anti consumer and anti competition. But, the other side (Android), which has been positioned open, pro-consumer and pro-competition doesn't seem to be true to its roots or any better anyways. Android is mostly dominated by Samsung and Samsung is heavily pushing their own ecosystem of apps, just like every other company, and most brands wa…

[deleted]

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#410
post #381

Earlier quoted context omitted.

Did you get this before? All your messages have been recorded by the government, since the government has been collecting all push notifications on iPhones, and iMessage runs over push notifications

Actually no, the end to end encryption on iMessage is envelopes inside the push notifications. The message content is not readable, even if you intercept APNs messages.

And it wasn't a blanket capture of push notifications anyway, right? Nobody has confirmed so far this is a Room 641a situation
Post reply on HN