Earlier quoted context omitted.
I get iMessage spam all the time, Apple even has a report spam feature so it’s clearly an issue. I guess you’re just lucky but it definitely exists. I got four just in the last day even.
Wonder what the cause is? I don’t think I’ve literally ever received a spam on iMessage
Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'
91–100 of 105 posts
Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'
#92Earlier quoted context omitted.
It’s not that it’s active shunning, things just evolved here into two systems (RCS and iMessage) and a lowest common denominator (SMS) they both fall back to automatically. So there is VERY little friction. You can message anyone easily without downloading anything, though the experience varies. So the idea of downloading an additional app for certain people is kind of odd. If you live somewhere everyone uses WeChat,…
It's bizarre though; despite the apparent lack of friction I don't know anyone who uses RCS or SMS (and frankly I'm unimpressed by its design - why involve carriers at all? Your mobile network should be dumb and provide you with a simple, neutral, fast and unmetered TCP/IP connection. RCS also launched without E2E encryption. Frankly the whole protocol seems like garbage to me and nobody in the UK cares about it, the…
I assume the path was like iMessage. People used the default messaging app which used SMS. One day it got an upgrade and just started using RCS if the other person was providing a better experience.
It wasn’t an active choice to switch to it, just the power of defaults. I guarantee you that no normal person knows what RCS is by name. At most they would know that sending messages to iPhones is somehow “different“ and it doesn’t work as well (SMS fallback).
Also sort of makes me wonder if the “open iMessage” stuff will all be sort of a tempest in a teapot within a year or so. Once iPhones get RCS I wonder if people will care that much outside of ideological reasons.
Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'
#93I've asked this 3 times across the various threads on this, and have yet to get a 100% confirmed "you are right" answer because I don't know the specifics and I haven't come into anybody who has taken the time to research the answer: When you log in to iMessage and the various underlying protocols/services, you do it with an Apple ID. Is that Apple ID tied in a one-to-many (but you need at least one) fashion of regis…
Spoofs masquerade using confirmed serial numbers. In the case of Hackintoshes you manually repeat activation until you get a valid serial number; I don't know what Beeper's implementation does. So Apple can maintain this database but they still have the problem of proving that a serial number attestation, sending all the right information, is from that actual hardware and not a spoof of the hardware. Without intensel…
Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'
#94Earlier quoted context omitted.
> Spoofs masquerade using confirmed serial numbers. Most Hackintosh users use a plausible, but non-legitimate serial number. The community has found it immoral to potentially cause issues to random people by using their device’s serial number and that is why they stay away from it and tutorials typically instruct against it. Doesn’t mean it doesn’t actually happen, but I’ve seen only a handful of people who openly ad…
> Already Apple seems to have no qualms to ban Apple IDs of legitimate customers who entirely legitimately have bought gift cards and loaded them up on their account, on the simple premise that their algorithm flags accounts that top up more than $1k as suspicious I wonder if that’s an AML thing? Buying apps from a small (15%) developer account using gift cards (paid with cash) could be an efficient way to clean mone…
In almost all described cases they claim that they used legitimate gift cards bought or gifted to them in an effort to purchase an Apple device.
I have my doubts about the veracity of some of those stories, but assuming everything is aboveboard and truthfully conveyed, I think $1k might be a bit too sensitive for a company that sells a lot of hardware that’s priced above that.
It might also be more prevalent nowadays because App Store funds and Apple Store funds used to be separate, they merged the balances not too long ago.
Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'
#95Earlier quoted context omitted.
I’ve had this same question. I use beeper because I’m an Apple user and want access to what I pay for. I’m confused by the pathway where paying apple can be skipped.
> want access to what I pay for You do not pay for this. You would like to, I’m sure.
edit: I mean hell, i certainly don't pay Apple for hardware. You might argue i do, but i don't actually have access to the hardware - right? It's not like a PC where each component has value to me, that it's documented and hackable, etc. Nono, you buy the suite - everything, when you buy an iPhone. If not for iOS, iPhone is a nearly useless undocumented brick.
Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'
#96Earlier quoted context omitted.
The question is not why Apple should give access to their messaging system to third parties- they have the full right of doing whatever they want. The question is why the customers don't give Apple and its pathetic excuses the middle finger- and instead praise the wisdom of the company and whine about Android users not buying iPhones. This in the face of a perfectly clear example of Apple making the life of its own c…
Personally I like Apple not allowing other companies who hacked into their infrastructure to using it without permission. That seems incredibly reasonable to me. Beeper’s statements seem almost like parody to me. “I know I broke into your house, but someone else figured out the key. Now I’m here I should be able to rent out your couch! The renters deserve it, you’re discriminating. I’ll give you a cut!” People want i…
>> “I know I broke into your house, but someone else figured out the key. Now I’m here I should be able to rent out your couch! The renters deserve it, you’re discriminating. I’ll give you a cut!”
Beeper's arguments are about the benefit of encryption to phone users, not about who reverse-engineered the iMessage service. The main benefit is giving agency to Android users to send and receive encrypted messages from iMessage users, and the secondary benefit is letting iMessage users send and receive encrypted messages from those Android users. (Why don't both parties use a cross-platform E2EE messaging app? Beeper Mini requires only the Android user to alter their own messaging setup.) Beeper Mini tricks Apple into giving the Android user a private key on the Android user's behalf. In order to achieve this setup, Beeper Mini needs to stand in for the Android user and pretend to have an Apple device (requires a fake serial number - fake credentials - if MuffinFlavored is correct). That's the only fake part.
There are two overarching security issues at play.
1. Apple doesn't reliably distinguish between real and fake devices. That's an important problem but has no impact on iMessage encryption. Apple may have a right to shut out Beeper Mini, but Beeper Mini isn't in the wrong solely for utilizing a bug Apple missed. Otherwise, the acts and applications of reverse-engineering in general would be wrong, and that seems to be the opposite of the hacker spirit to me.
2. Beeper Mini supposedly doesn't give Beeper access to the private key for decrypting iMessage messages. Supposedly. The code isn't free software, so an Android user has to choose between trusting Beeper Mini's code or not using Beeper Mini. If you don't trust Beeper to give only you the encryption key then Beeper is a bad idea. (In that case, you can inspect the source-available iMessage implementation proof of concept called pypush by JJTech0130, or you could install a Signal/Matrix app instead.)
Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'
#97I've asked this 3 times across the various threads on this, and have yet to get a 100% confirmed "you are right" answer because I don't know the specifics and I haven't come into anybody who has taken the time to research the answer: When you log in to iMessage and the various underlying protocols/services, you do it with an Apple ID. Is that Apple ID tied in a one-to-many (but you need at least one) fashion of regis…
> Don't they have a database of every device they've sold? A database isn't enough. They'd also need a way for that device to attest its identity to Apple, and serial numbers can be relatively easily copied (or sometimes even brute-forced). This should be possible for newer devices using Apple's own chips, but I believe that at least non-T1/T2 Intel Macs lack any such capability. > Why don't they check "is this devic…
You are correct about pre-T1 Intel Macs though. Apple will have a blind spot by design, until support is dropped for old machines.
Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'
#98Earlier quoted context omitted.
Arguably, messaging life is somewhat miserable due to the existence of various closed systems that force people to install and use multiple messengers concurrently (outside of the US) or fall back to SMS (US). I, as a mostly happy Apple customer, would lose absolutely nothing and in fact gain quite a lot of convenience if Apple were to allow an Android iMessage client. Sure, running servers isn't free, nor is spam mo…
> " This really is exclusively about Apple's bottom line. " I'm unconvinced. Like I said further up the thread, the evidence to the contrary of the 'misery' of using other apps is abundant, especially given the standing of iMessage on the global scale.
https://www.thurrott.com/apple/248931/apple-didnt-bring-imes...
Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'
#99I've asked this 3 times across the various threads on this, and have yet to get a 100% confirmed "you are right" answer because I don't know the specifics and I haven't come into anybody who has taken the time to research the answer: When you log in to iMessage and the various underlying protocols/services, you do it with an Apple ID. Is that Apple ID tied in a one-to-many (but you need at least one) fashion of regis…
It is. Apple essentially uses a scoring model. The legitimacy of your device is only one part of the score; your Apple ID and its history and standing is another. Those and other factors are calculated into a score, and if you meet the threshold, you can use iMessage. Think of it as a credit score. Before the Beeper saga, I haven’t looked into it since Hackintosh users have found that Apple will allow you to use iMes…
Re: Apple responds to the Beeper iMessage saga: 'We took steps to protect our users'
#100In other words, Apple wants to control who enters their garden. Not surprised and not sure I disagree. Why is it that Beeper, or anyone else that isn’t Apple gets to decide who uses iMessage?
They pretty much announced in public that they were going to follow this model of breaking the ToS for every major IM service because they managed to get it working with iMessage.
I pointed it out on the HN post about Beeper's blog post on the topic that this will only be harmful in the end, specially for those that self-host Matrix bridges.