Live data from Hacker News

Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'

theverge.com

71–80 of 105 posts

Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'

#71
post #70

Earlier quoted context omitted.

> Messages.app, not iMessage is the default. This is semantics and you know it. > iMessage exists for Apple-to-Apple messaging There we go. iMessage is the default for Apple phones contacting other phones. Given that iPhones are a majority in the US, iMessage is the default for most phones in the US. > What? That is certainly a take. I don't see how. I think it's perfectly rational. I'm surprsied you disagree so stro…

> This is semantics and you know it. Nope, it's a distiction . And an important one. > There we go. iMessage is the default for Apple phones contacting other Apple phones. TFTFY. To contact other phones, use SMS, MMS. Even better, talk to your iPhone friends and agree to use another service. What is wrong with that? Literally the rest of the world managed it. > I don't see how. I think it's perfectly rational. I'm su…

> Nope, it's a distiction. And an important one

It really isn't. I find you making this point funny though after accusing me of being here in bad faith.

> TFTFY.

Not really.

> Literally the rest of the world managed it.

Well, Americans are weird. It's why the blue/green bubble divide even exists in the first place. And if Apple users don't get on board it's just the same situation that already exists right now.

> I disagree because every point you have made has be immature or wrong.

Well that's just plain not true. Although the same could easily be said about your arguments. And again this is funny after you claimed I'm here in bad faith, but you're the one throwing out insults and being dismissive.

> blue/green doesn't exist anywhere in the world,

lol what? It's a problem in the US and not in other countries. If you deny that you have to be pretty out of touch. There's a ton of articles written about it.

> You bringing it up leads me to believe that your likely in your early twenties.

Lol you're desperate to try and dismiss my argument any way you can and it's sad to see. You're about 20 years off.

> You said it, silly, and nor really big bad Apple's fault.

Ahh I get it. You're hooked on the Apple Kool-aid. That explains a lot of your responses to be honest.

And yeah, of course it's Apples fault. They're controlling the way it's implemented.

> They cannot solve for childish responses from people that should know better.

This coming from you is quite ironic.

> It really does, if they want said manufacturer to adope their standard.

Again, it makes no difference if the biggest manufacturer won't support it or chooses to bypass it for most of their users.

Please make sure you read the above line before replying.

> And it was going nowhere then. It's still not widley used.

And if Apple had contributed to the standard instead of offering their proprietary service instead, everyone would be better off.

> So Google restricting access to their proprietary implementation of their RCS service is Apples fault for not contributing to a standard that they were unable at the time to contribute to because they were not members of the standard body drafting the standard behind closed doors. That takes some mental hoop jumping. Are you smelling toast?

Good lord the fallacies here lol.

Google restricting access to their proprietary implementation has nothing to do with Apple not being interested in collaborating and working on a common standard.

> If that is genuinely the case, why isn't a problem for the rest of the world?

Why are many of the problems unique to or prevalent in the USA not problems in the rest of the world? Generally there's not a simple answer.

> Reminder to future me. Don't respond. It's a waste of time.

I honestly hope you won't respond against to this message although you seem like someone that's going to need to. Honestly it's discussions like this that make me wish HN had a block function. You've been rude and dismissive from the start.

Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'

#72

I've asked this 3 times across the various threads on this, and have yet to get a 100% confirmed "you are right" answer because I don't know the specifics and I haven't come into anybody who has taken the time to research the answer: When you log in to iMessage and the various underlying protocols/services, you do it with an Apple ID. Is that Apple ID tied in a one-to-many (but you need at least one) fashion of regis…

It is.

Apple essentially uses a scoring model. The legitimacy of your device is only one part of the score; your Apple ID and its history and standing is another. Those and other factors are calculated into a score, and if you meet the threshold, you can use iMessage. Think of it as a credit score.

Before the Beeper saga, I haven’t looked into it since Hackintosh users have found that Apple will allow you to use iMessage with clearly spoofed device attributes as long as your Apple ID is in good standing and not brand new.

Why they did is anyone’s guess.

The leading theory has always been that, based on your Apple ID activity, they considered you a valuable customer. They didn’t think it was worth the hassle and potential backlash to block you despite using spoofed device attributes.

But it’s just that, a theory. And nothing is stopping Apple from tweaking its score threshold.

Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'

#73
post #64

Earlier quoted context omitted.

Seems easier to just break Beeper's implementation a few times. No one wants to use a messaging service that works sometimes.

I wonder how long they can keep that up for though.

Beeper or Apple?

Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'

#74

I've asked this 3 times across the various threads on this, and have yet to get a 100% confirmed "you are right" answer because I don't know the specifics and I haven't come into anybody who has taken the time to research the answer: When you log in to iMessage and the various underlying protocols/services, you do it with an Apple ID. Is that Apple ID tied in a one-to-many (but you need at least one) fashion of regis…

Spoofs masquerade using confirmed serial numbers. In the case of Hackintoshes you manually repeat activation until you get a valid serial number; I don't know what Beeper's implementation does. So Apple can maintain this database but they still have the problem of proving that a serial number attestation, sending all the right information, is from that actual hardware and not a spoof of the hardware. Without intensel…

> Spoofs masquerade using confirmed serial numbers.

Most Hackintosh users use a plausible, but non-legitimate serial number. The community has found it immoral to potentially cause issues to random people by using their device’s serial number and that is why they stay away from it and tutorials typically instruct against it.

Doesn’t mean it doesn’t actually happen, but I’ve seen only a handful of people who openly admit to it.

> So Apple can maintain this database but they still have the problem of proving that a serial number attestation, sending all the right information, is from that actual hardware and not a spoof of the hardware.

It’s actually quite easy for them to infer due to the simple premise that a physical device can’t be in two places at once, coupled with other behaviors and it’s pretty easy to nail down which device attributes are being exploited for this purpose.

The only hard part would be to determine which is the actual device and which is the fake one, if there’s no activity that predates the spoofing.

All in all it’s a safe assumption that a very low number of devices have their attributes abused for spoofing (easily single digit percentage) and at a certain point Apple might find it more desirable to inconvenience the owners of these “donor devices” by locking things down and having them contact support, than to let the spoofing go on.

I think that point might be nearer than we think. Already Apple seems to have no qualms to ban Apple IDs of legitimate customers who entirely legitimately have bought gift cards and loaded them up on their account, on the simple premise that their algorithm flags accounts that top up more than $1k as suspicious.

Both Apple Store geniuses and Apple Care support personnel can easily establish in a minute or so if you have possession of the actual physical device and take actions accordingly.

> Without intensely protected cryptography like the T1/T2 enclaves, there is nothing legitimate hardware can send that can't be mimicked once the protocol is reversed.

True, without a Secure Enclave, device attestation will never be airtight. But it might be that Apple might drop iMessage support for older devices, or more likely, between older and newer devices, in due time like they did with FaceTime.

iPhone 5s and newer had them so there aren’t many iPhone left behind if they upgrade the protocol. Same for iPad Air and Apple Watch Series 1.

2016 was the first time MacBooks were introduced with T1, in a few years that’ll be a decade ago. I could see them upgrade the protocol by then and leave older devices behind.

Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'

#77
post #37
post #13

This isn't a technical problem. Nobody really uses iMessage enough in the EU, but in the USA where people seem to shun use of third-party messaging apps like WhatsApp, the solution would be to deem Apple a "gatekeeper" under legislation equivalent to the Digital Markets Act and force interoperability via regulation given Apple's market dominance. The regulatory process has worked with side-loading, and EU citizens wi…

It’s not that it’s active shunning, things just evolved here into two systems (RCS and iMessage) and a lowest common denominator (SMS) they both fall back to automatically. So there is VERY little friction. You can message anyone easily without downloading anything, though the experience varies. So the idea of downloading an additional app for certain people is kind of odd. If you live somewhere everyone uses WeChat,…

[dead]

Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'

#78
post #45

Earlier quoted context omitted.

I think you're right -- You piqued my curiosity with your example, though. 10-100s of people logging into the same Mac with their Apple ID? Is that possible? I thought there was a 1:1 mapping of, say, Apple ID signed into ID : *NIX account. Does OS X have something more ephemeral these days? That would be fantastic for shared computing.

Having hundreds or even tens of thousands of Unix accounts on a single system is not a problem in corporate or institutional environments since macOS integrates with LDAP and Active Directory via Open Directory. I was able to log in to any of the Macs in the computer rooms on campus at my university using my regular Unix username and password. UIDs go as high as 2 billion on macOS as well (they're signed 32 bit integ…

OK, but those aren't AppleIDs?

Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'

#79
post #45

Earlier quoted context omitted.

Having hundreds or even tens of thousands of Unix accounts on a single system is not a problem in corporate or institutional environments since macOS integrates with LDAP and Active Directory via Open Directory. I was able to log in to any of the Macs in the computer rooms on campus at my university using my regular Unix username and password. UIDs go as high as 2 billion on macOS as well (they're signed 32 bit integ…

OK, but those aren't AppleIDs?

They’re not Apple IDs but each user can login with an Apple ID. Presumably you do that once and it sticks because it’s part of your user profile.

Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'

#80

I've asked this 3 times across the various threads on this, and have yet to get a 100% confirmed "you are right" answer because I don't know the specifics and I haven't come into anybody who has taken the time to research the answer: When you log in to iMessage and the various underlying protocols/services, you do it with an Apple ID. Is that Apple ID tied in a one-to-many (but you need at least one) fashion of regis…

> If it isn't, why doesn't Apple do this Not sure if there would be any real benefit in that. Consider the over-abused Macs at university campuses as an example, used by 10s-100s of persons/day, each potentially logging in with their own user ID. Suddenly their ID is tied to a legit HW, if it wasn't the case already. Of course, technically, Apple could ban the IDs or these computers... but why would they?

Thankfully I never sat down at a public comouter at my college and found it was a Mac.
Post reply on HN