Live data from Hacker News

Apple restricts Pebble from being awesome with iPhones

ericmigi.com

231–240 of 1001 posts

Re: Apple restricts Pebble from being awesome with iPhones

#232

Some 6 years ago I bought new bluetooth headphones. Every time I'd put them on, my macbook would open apple music (I didn't even know it was installed). Every time. No way to disable it, I really tried. Stopped shy of doing some kernel stuff. Sold that laptop, and have never touched anything apple since. Probably never will. The hardware's good, everything else is an embarrassing mess. Sent from my Ubuntu.

It's because your headphones were sending a Bluetooth "Play" command on connect (my Honda Odyssey does this as well). For anyone else with this problem, you can override this silly default in macOS using Privacy & Security > Bluetooth, adding Music, then turning off Bluetooth access for Music.

Just did this, pressing play on my headphones still launches Apple Music.

Re: Apple restricts Pebble from being awesome with iPhones

#233
post #184
post #81

I think, we fundamentally lack a mechanism to enforce secure / privacy aware APIs without resorting to trusted inner-circle type of things. I am already not comfortable with Apple picking winners (such as giving Zoom special entitlement but not the VOIP apps you want to distribute by your own). Apple trusting their own apps more than other apps is another symptom of this and it is not helping their anti-trust situati…

Quicktime Player.app gets an entitlement called `com.apple.private.tcc.allow`, giving it unprompted access to the Camera, Microphone, and Screen Capture. An MDM administrator, managing a computer or device owned by an organization, cannot grant those permissions to anything without user consent. For good reason! So why the *fuck* does Apple think they're entitled to?

Remember when people realized that Apple apps were bypassing application-level firewalls like LittleSnitch?

First it was denied, then it was a bug, then it was a "temporary workaround" while ... something ... was updated.

And that was just ... accepted as an answer. I could never fathom why TextEdit might need a kernel extension in the first place, let alone unfettered/unmonitored network access. I don't even think it was necessarily nefarious, just "we know best, shut up and buy".

Re: Apple restricts Pebble from being awesome with iPhones

#234

The best decision I made was to switch to Linux Mint and Samsung Z Fold 6. I can't believe I was ever a fan of apple products. Hobbled walled garden products. If you're in tech you should not use apple products. Unless you're building an iphone app.

I got on the apple train on Mojave. Before that I was enticed by iOS 6. It was a good platform. But now it just have too much restrictions and other weirdness like not being able to delete apple’s apps, writing files on network shares, not able to adjust system fonts (like the menu bar).

While I still keep the Mac for professional purpose, I move over to fedora.

Re: Apple restricts Pebble from being awesome with iPhones

#235

I guess I’ll take the contra here on messages integration — moving a message over BLE to untrusted hardware and worse accepting them back into iMessage is a massive, massive change in the security boundary and therefore security architecture and therefore security promises that apple makes on iMessage. I do not believe average smartwatch users understand what they’d be doing if they got this. I do not believe vendors…

This is cap. I worked on heads up glasses, and one of our issues was the lack of integration with Apple's iMessage ecosystem. Device makers are willing to go through several security measures, like deploying the MFi chips and certification. However, at best this gives you access to the notification system, not iMessage itself. You are able to respond to messages via the notification framework, but not integrate direc…

*This is false.

Re: Apple restricts Pebble from being awesome with iPhones

#236
post #216

Earlier quoted context omitted.

This is cap. I worked on heads up glasses, and one of our issues was the lack of integration with Apple's iMessage ecosystem. Device makers are willing to go through several security measures, like deploying the MFi chips and certification. However, at best this gives you access to the notification system, not iMessage itself. You are able to respond to messages via the notification framework, but not integrate direc…

Every device you let in is another attack surface, and no certification process can eliminate it. Allowing devices to view and respond to messages is inherently lower risk than allowing them to freely communicate with anyone.

You could say the same about software and app stores. If safety were the top priority, then the safest option is to say no apps, but that isn't competitive or lucrative. Apple's approach is to create safe frameworks and a review process that allows the App Store to exist.

Re: Apple restricts Pebble from being awesome with iPhones

#237

Earlier quoted context omitted.

Yes? Imagine a bug where iMessages are leaked over Bluetooth when a user has installed an application that integrates with some watch brand. Bring this to an airport and you can steal hundreds/thousands of messages from a wide range of people. That’s widely different attack vector than targeting macOS. That said, I don’t see why Apple can’t provide toolkit/certification that will make it safe to communicate over Blue…

Bluetooth is encrypted.

Should be, but BT stacks are super crap and it's hard to truly guarantee that. Pretty sure they do not currently require the highest (actually proper) security level from everyone.

Re: Apple restricts Pebble from being awesome with iPhones

#238
post #229
post #184

Earlier quoted context omitted.

Quicktime Player.app gets an entitlement called `com.apple.private.tcc.allow`, giving it unprompted access to the Camera, Microphone, and Screen Capture. An MDM administrator, managing a computer or device owned by an organization, cannot grant those permissions to anything without user consent. For good reason! So why the *fuck* does Apple think they're entitled to?

I mean the reason is because Apple, the people who made the security boundary, and Apple the people who made Quicktime are the same people. I'm not saying it's not anti-competitive but it's fine from a security context. Apple knows exactly how Quicktime behaves, that it doesn't act maliciously, and can't be updated to do so.

> Apple knows exactly how Quicktime behaves, that it doesn't act maliciously, and can't be updated to do so.

Yes, it's physically impossible for an Apple developer to accidentally or maliciously introduce an exploit into QT and for it to elude security or code review...

I've never heard a security posture that is "well, we know what your tool does, so it doesn't need any security controls".

Re: Apple restricts Pebble from being awesome with iPhones

#239
post #198

Earlier quoted context omitted.

That's not good enough. If you're Apple, and you're worth 3 trillion dollars, you can both do security and behave in a way that isn't anti-competitive. They could interoperate securely. Is it easier to just lock out your competition and use proprietary everything? Yes, duh. It's also blatantly anti-competitive, which is a thing that societally and (arguably) morally is not acceptable. I hope to read this blog post in…

It isn't anti-competitive to not open up your hardware and software security stack to any other OEMs who wander by. You can simply just buy a competitor's product, for less money even.

Whether or not something is anti-competitive has nothing to do with how convenient it is for the incumbent. It may indeed by quite onerous for the incumbent. The bar for anti-competitive behavior is:

- Is this stifling competition?

- Is that harming consumers?

Per the contents of the blog post, yes this is absolutely stifling competition given that Pebble won't be able to provide the same features/experience as the Apple watch. This directly hurts Pebble which prevents them from competing.

As for how much that hurts consumers, the answer is not a clear "yes". The iOS market share is ~60% in the US and I don't think the majority of those folks wear or are interested in wearing any kind of watch, smart or not.

However, if Apple keeps this up they're absolutely going to go the way of Ma Bell https://en.wikipedia.org/wiki/United_States_v._AT%26T_(1982) and the eventual Telecommunication Act of 1996 which forced incumbent providers to interconnect with folks who would ostensibly be their competition.

Re: Apple restricts Pebble from being awesome with iPhones

#240
post #179
post #77

Earlier quoted context omitted.

I guess you could call it lazy, I value my time and have zero desire to tinker with the daily products I use. I am sure some enjoy it but I do not.

And GP is saying that that’s totally okay.

I am saying folks who use Linux do not know how to utilize their time well. It’s tongue in cheek at the commentary to the GP but hope that makes more sense to you.
Post reply on HN