Live data from Hacker News

Nothing's iMessage app was a security catastrophe, taken down in 24 hours

arstechnica.com

131–140 of 147 posts

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#131

Earlier quoted context omitted.

>Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. EXACTLY! Because it's a known fact all devs make mistakes, and as such, as a product manager/owner you're responsible for the bigger picture of the product and ensuring the right requirements, checks and bound are put in palce and validated for a successful product release. It's not the job of the lowly SW engineers w…

I hope this is facetious. Security is everyone’s job, and unencrypted customer data, outside of a locked-down DB, should give one pause.

One of the counterintuitive things I've learned is that "security is everyone's job" is one of the worst possible scenarios.

First, the vast majority of people are not equipped to find or address major security issues well. Unless you have specialists integrated in the right places this means everyone's likely to be bad at the security part of their job and ill-equipped to notice.

Second, this means conflicts of interest everywhere. When you have a dedicated security org, you have people whose job it is to catch issues, hold things up, and generally make sure things get fixed. Without that, you have a bunch of people who have to choose between the possibility of a security event they don't understand and the certainty of blowing a deadline.

Third, security being everyone's job almost certainly means accountability is broken. Consequences will likely fall on some junior employee who might be directly accountable for an issue, but the huge org around them that did not enable them to succeed go unaffected.

You need specialists, an org to enable them, and an enterprise-wide apparatus to support a strong security process.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#132
post #86

Earlier quoted context omitted.

Up until now I had no idea TE had anything to do with Nothing phones.

I like their mini synths. Never knew that they are involved with phones or anything beyond small synths tbh.

They have an extremely expensive field table to put your extremely expensive TE devices on.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#133
post #108

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

This has the overall feeling of something developed by a team where leadership sincerely believes that security is everyone's job. Because it's everyone's job and they hire good people, they don't need specialists. When there are deadlines to hit, average quality non-specialist management will generally prioritize keeping promises to leadership over meeting security requirements. It takes a rare manager with a strong…

Replace 'Security' with 'Safety' and your comment still rings eerily true! One exception (? probably not an exception) is that sometimes organizations will still hire safety/security specialists (because the externally viewed perception of not having them is damaging), but these specialists are then (perhaps unintentionally) knee-capped to various extents in order to prioritize promises to leadership or other org. goals that must be hit. The net result is that good and capable folks who care deeply about the company's mission may watch in consternation as the org. slowly train wrecks itself if the roll of the dice doesn't land right. See, for example, the story of several autonomous driving organizations.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#134
post #77

Reading Sunbird's site makes it all feel like a scam. Their FAQs and Privacy and Security page are just chock full of what appear to be egregious lies. Both repeatedly state that messages are never stored, and end-to-end encrypted. It is not possible they didn't know this was a lie, because it is fundamentally built in a way that can't have E2E encryption (leaving aside the other horrendous security aspects). https:/…

> In my opinion, Sunbird Messaging are fraudsters, and Nothing was their mark. 100% agree with this. `nothing` since its inception has been nothing but a marketing gimmick.

"Get hyped for the phone that will change the world!"

>Unveils phone with blinking LED for notifications and Nothing else interesting

Cool...not sure how this changes the world or is considered an innovation of any kind. Have their phones done anything worth talking about since launch?

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#135
post #120
post #76

Earlier quoted context omitted.

iMessage is one of the primary moats keeping a lot of people on iPhone. I'm not necessarily as sure as the parent comment that the c-suite was briefed or anything, but I do think that iMessage exclusivity is pretty important to Apple

iMessage is a relic, most people in Europe use WhatsApp and alternatives in other continents. The whole blue/green thing is just Apple-driven hype to remember folks that iMessage even exists.

This is not the case. WhatsApp is only prevalent outside the United States and doesn't compare to iMessage in terms of features, privacy, security, long-term storage of messages and media, etc.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#136

Earlier quoted context omitted.

Because it's the PM's job to oversee the whole project end to end.

Does your PM know the difference between HTTP and HTTPS? Mine doesn't. They manage tickets and expenses, not technical details.

Usually they would buy they have the tech audit teams to check these things anyway.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#137
post #50

Earlier quoted context omitted.

I work for a company like this right now. About the same number of employees, same mistakes and same time to market on innovative stuff. Here's my two cents on how this can happen: > Which product manager in his/her right mind There is no product manager. There is a project manager. They steer on deadlines and functionality, nothing more. > How do these managers get jobs in these big name companies? Because they talk…

>As a project manager, that's the last thing you want. First, it'll show what you didn't manage well. Secondly, it costs money. Finally, negative findings will delay delivery and means you failed to deliver on time, which is your only priority. And yet FAANGMAULs and other tech-first companies like Mozilla, seem to be doing quite well on security with relatively very few oversights, caused by dev gross negligence. So…

At some point their engineers are just better. I've been part of teams where every one was highly skilled, maybe a few juniors. And teams where everyone was junior and because they were very skilled on one specific thing, they assumed they were senior. The difference in those teams are that skilled engineers:

- Code review holistically bc they understand that part of the codebase, and other parts it interacts with, and they ask thoughtful questions. So things like logging sensitive info in plain text are not even a question.

- They understand how multiple components of a system work, like the tcp/ip stack, http, and other parts. Specifically not just how they eg. send messages, but how connections are setup/managed/torn down. Often that's where the security issues are (like which parts of a connection are insecure and when/how the upgrade happens).

- They have this deep understanding because they put effort and time to diagnose issues that happen do them and enjoy sharing. Unskilled devs just say "it's not working, someone else fix it please". I had a mobile dev once lose his mind because he was unable to upload a file to the api. Turned out his app was using a library that was messing up the multipart upload boundaries and content length headers (tracked it to a bug with multiple gh issues). He was unable to use this info to proceed.

- Participate in the hiring process, for they're a good filter for the company

- They abstract away a lot of the implementation details from product managers and eat a lot of the complexity to the point that the product manager only sees 60% or less of the actual work in Jira.

- A security autidor would need to really be worth his pay to find vulnerabilities, scanning for OWASP top 10 is not enough.

Note, these engineers do not need to be 10x, they just need to...be engineers.

Companies like Sunbird would not know how to tell one from the other, and product managers don't know what a secure app looks like. They could actually add that as a requirement and not know how to verify it. Often it's the developers that tell QA how to verify something. If your engineers are crap, you end up with apps like Nothing Chat. They aren't to blame, the company had no standards to begin with.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#138

Earlier quoted context omitted.

It is a big name company though. Not a lot of companies have access to a supply chain and logistics to design and ship products like they do worldwide.

Worldwide? Nothing Phone 1 wasn't even available for purchase in the U.S and I've yet to see any of their other products being sold throughout latam. They operate like the infamous street fashion brand Supreme with limited "drops" in carefully chosen markets to generate hype through manufactured scarcity.

[deleted]

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#139

I still can't fathom why people would care in the slightest what their message bubble color was (I mean as a European I don't get iMessage at all, I use Signal and WhatsApp for the less tech-literate family of mine), it sounds like the most insanely petty thing to grab onto to care about.

The colors functionally denote the features available in the chat. In group chats, having a single non-iMessage user devolves the features available to the group chat to the SMS level. You also lose E2E and high res pictures and video. The different colors of bubbles are a consequence of iMessage's origin as a protocol that supplanted SMS/MMS messaging while allowing the older protocols as seamless fallbacks; WhatsAp…

> Signal never had a requirement like that

See TextSecure

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#140

Earlier quoted context omitted.

Well, managers are happy to take responsibility for their project/product when everything goes well. It’s actually the argument for their salaries and bonuses compared to lowly engineers. So why should they not take responsibility when it goes sideways? Particularly when failure affects the whole product like the Sunbird app. You cannot say that the project works because of you, and then turn around and pretend you h…

>You cannot say that the project works because of you, and then turn around and pretend you have nothing to do with its failures. You'd be surprised. I've been in at least 2 companies where that was the case and had to be the scapegoat for projects going sideways due to poor management. Humans are shit and would much rather push the blame on someone if the company culture is not blameless.

Fair enough! I should have written “you cannot in good faith”.
Post reply on HN