Live data from Hacker News

Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

arstechnica.com

431–440 of 665 posts

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#431

I think this is kinda technically a win for Beeper. I would've expected another 100% lockout to be Apple's priority. They were instead only able to block 5%, which sounds like a heuristic being applied, and possibly not even an intentional block of Beeper (in the sense that some anti-spam service may be identifying some Beeper users). They can certainly escalate with protocol changes, but they still have to contend w…

My father has an iPhone 8 which did not receive the latest iOS update. I can iMessage him just fine.

There are millions of people out there running old iPhones like that. If Apple just decided to cut them all off iMessage they would do far more damage to their brand than Beeper could possibly manage.

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#432
post #279

Earlier quoted context omitted.

> Apple could also push out an update tomorrow that would end this once and for all by utilizing device attestation and leveraging Secure Enclave More proof that Remote Attestation is evil and does not exist to serve the user.

As a user, I am very well served by remote attestation when it is used to stop cheaters in videogames or spammers in messaging platforms.

I know of no messaging platform using remote attestation for antispam - and, as far as those platforms continue to support web registration, they can't use remote attestation[0]. Even if they could, it wouldn't help. Remote attestation verifies that your client code is running without modification. What you care about with spam is keeping the spammers from registering large numbers of unrelated accounts, which doesn't require modifying the client at all.

I will give you that remote attestation does help anticheat. However, the current state of anticheat in games is so invasive now that you have to install special kernel drivers, and that kernel has to be on bare metal (no hypervisors allowed). This only happened because a specific genre of fast-twitch first person shooter has a lot of closet cheating going on. But it also gets blindly applied to things like rhythm games that absolutely do not need kernel-level anticheat[1]. So every game gets more invasive because of one hyper-competitive game genre triggering an anticheat arms race.

[0] Or at least, for as long as Web Environment Integrity stays dead

[1] Altering the client isn't even the most common way of cheating rhythm game records. For example, a good chunk of the rules for, say, Pump It Up's online leaderboards is "don't have other players play on your A.M.Pass" and "don't hook up a hand controller onto an online cab". Neither of which would be stopped by an anticheat system (and yes, PIU being an arcade rhythm game, there's shitton of encryption on it).

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#433
post #110

Earlier quoted context omitted.

The better analogy is using a fake ID to get the locksmith to give you a copy of the house key. The house is Apple’s servers The fake ID is spoofed device serials and UUIDs The copy of the house key is the authentication blob Nobody would blink twice if a prosecutor threw the book at someone like that. Still, somehow, I’m sure many here would complain if the DOJ would prosecute Beeper for violating the CFAA by commit…

Pretty sure they're buying actual Mac minis and using those device IDs. If you have evidence to the contrary I would be very interested in seeing it.

Pretty sure you’re mixing up Beeper Cloud with Beeper Mini.

Beeper Mini is based on pypush, which they’ve bought, and is clearly using spoofed data in the data.plist[0].

I’ve searched, but I’ve found no mention of them purchasing Mac Minis en masse to support the $2/mo Beeper Mini customer’s texting habits.

Besides, it wouldn’t make sense anyway because they used to tout you didn’t need an Apple ID and instead could use your phone number, and non-iPhone IDs don’t allow for iMessage activation on phone numbers, only email addresses.

0: https://github.com/JJTech0130/pypush/blob/main/emulated/data...

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#434
post #178

Earlier quoted context omitted.

They don’t, it “just works” (to the degree MMS can work at all) — which means iMessage is perfectly positioned.

Ah so do "free texts" in the USA include MMS? That might explain the continued usage. In the UK MMS often aren't included, if anything they're charged stupidly high, so you'd never send a pic via text message.

On most plans in the US, unlimited texting is the only option, and there is no differentiation between SMS and MMS. It's all free with your plan.

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#435
post #127

Earlier quoted context omitted.

Huh. How does that work with multimedia? Do US carriers not differentiate between SMS and MMS?

Carriers typically charge the actual media portion of MMS (e.g. the photo or video) as data.

I'm not sure how universal that is, but it doesn't really matter when data plans are almost always unlimited. After all, iMessage also goes through cellular data.

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#436

Earlier quoted context omitted.

Your advice was "There are plenty of cross-platform things out there. Signal, Telegram, WhatsApp", but you don't seem happy to take it and move away from iMessage either. This tension is at the center of the it all, and why Beeper Mini exists in the first place.

What? I pay for iMessage. You’re just arguing for the right to use products for free, and in Beeper’s case to create monetized products that use others’ products for free.

I'm arguing that the crux of the issue is a lot more than just "why don't they use something else ?" The same way you see value in iMessage, other users also see value in iMessage. You may want them to go away, but to my eyes that's the same weight as other users wanting to be there. I'll be standing in the corner with the popcorn to see how it turns out.

On what is paid and what is free, Beeper mini is free, iMessage is free (as we've learned from the whole saga, you don't even need an icloud account). Using someone else's public facing API without consent is rude, but hey, our whole industry started with kits to plug into the AT&T network with unauthorized material, and as of now no money is changing hands.

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#437

Earlier quoted context omitted.

Doesn't bother me at all. I'm ok with losing a text or two to help bring regulatory pressure against Apple to un-wall the garden so I can use it again.

> I'm ok with losing a text or two That’s the whole point. You’re using it for non-critical things.

Yes, but I'm happy to help provide critical mass.

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#438

Earlier quoted context omitted.

at some point Serial Box will have a list of valid/invalid hardware serial numbers. or, someone will crack the code to generate valid codes. oh wait. i drifted off back to the 90s software cracking days.

if apple checks an online database for "you authenticated and paired this hardware ID to this apple ID", is that a "Beeper Mini" killer?

isn't that essentially what they are doing? that's one of the reasons a stolen iDevice is pretty much worthless.

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#439

Earlier quoted context omitted.

> It seems a bit entitled behaviour for someone to feel like Apple should be forced to bring iMessage to Android for any reason besides Apple's own choice, and that they know better than Apple on how to run Apple's business. It is simultaneously possible for it to appear entitled, while also recognizing how extremely restrictive, anti consumer and anti competition Apple is. And in this fight of a trillion dollar comp…

It can be agreeable to an extend that Apple seem like an extremely restrictive, anti consumer and anti competition. But, the other side (Android), which has been positioned open, pro-consumer and pro-competition doesn't seem to be true to its roots or any better anyways. Android is mostly dominated by Samsung and Samsung is heavily pushing their own ecosystem of apps, just like every other company, and most brands wa…

You can push your own ecosystem of apps and still allow your customers to replace them. I'm not aware of a Samsung app or service that cannot be swapped out. And I struggle even more to find a Samsung component that is designed to create network effect lock in like iMessage is. And Apple Messages can't be swapped out, it is the only texting app on iOS. You can install Signal or Whatsapp or whatever, but you can only talk to other people who have those apps installed. You cannot use them to talk to any phone number like a texting app can.

Re: Apple partly halts Beeper's iMessage app again, suggesting a long fight ahead

#440

Earlier quoted context omitted.

if apple checks an online database for "you authenticated and paired this hardware ID to this apple ID", is that a "Beeper Mini" killer?

What about when the hardware is legitimately sold and reset and a new Apple ID starts using it?

You have to de-register the device with Apple when you sell it. Otherwise you retain the ability to remote wipe and brick the device and the buyer has no recourse.

After you de-register it the buyer can register it with Apple under their Apple ID.

Post reply on HN