iMessage has been targeted for years with zero click exploits, most notably by the NSO group.
Apple’s restrictions aren’t meant to protect consumers, their purpose is to protect Apple’s profits.
271–280 of 1001 posts
iMessage has been targeted for years with zero click exploits, most notably by the NSO group.
Apple’s restrictions aren’t meant to protect consumers, their purpose is to protect Apple’s profits.
I guess I don't see why Pebble, or any smart watch, should need a phone at all. The watch should be able to connect to wifi and/or cellular by itself. We should be able to run full apps on the watch itself.
From the other recently-posted article, the new Pebble watches are targeting 30-day battery lives between charges. That would be unthinkable for a watch that manages its own wifi/cellular connections.
I guess I’ll take the contra here on messages integration — moving a message over BLE to untrusted hardware and worse accepting them back into iMessage is a massive, massive change in the security boundary and therefore security architecture and therefore security promises that apple makes on iMessage. I do not believe average smartwatch users understand what they’d be doing if they got this. I do not believe vendors…
Step 1: Have the iPhone pop up saying "do you want to be able to send messages?" and let the user decide which devices can send their phone messages. Step 2: Have the iPhone pop up saying "do you want to be able to send messages?" and don't just assume "yes" Both steps would improve security, even if they harm Apple's profits.
I guess I’ll take the contra here on messages integration — moving a message over BLE to untrusted hardware and worse accepting them back into iMessage is a massive, massive change in the security boundary and therefore security architecture and therefore security promises that apple makes on iMessage. I do not believe average smartwatch users understand what they’d be doing if they got this. I do not believe vendors…
This is cap. I worked on heads up glasses, and one of our issues was the lack of integration with Apple's iMessage ecosystem. Device makers are willing to go through several security measures, like deploying the MFi chips and certification. However, at best this gives you access to the notification system, not iMessage itself. You are able to respond to messages via the notification framework, but not integrate direc…
iOS wearable integrations are bad, but somehow Meta Ray-Bans are very good. Voice assist to start a call, send a text, read a notification, etc. Did Meta get special access to do this?
For voice integration, you can just provide a bluetooth microphone on you device and have it access Siri. Garmin have tried the same strategy on some of their watches. What you can't do is reply to a text without using voice, which is what I'd like.
I guess I don't see why Pebble, or any smart watch, should need a phone at all. The watch should be able to connect to wifi and/or cellular by itself. We should be able to run full apps on the watch itself.
One, adding hardware to connect to WiFi and cellular increases size and power requirements. Notably, the new Pebble 's battery is projected to last 30 days.
Two, people use phones. They want their watch to work with their phone instead of around it.
I guess I’ll take the contra here on messages integration — moving a message over BLE to untrusted hardware and worse accepting them back into iMessage is a massive, massive change in the security boundary and therefore security architecture and therefore security promises that apple makes on iMessage. I do not believe average smartwatch users understand what they’d be doing if they got this. I do not believe vendors…
This is just about sending.
Earlier quoted context omitted.
> moving a message over BLE to untrusted hardware and worse accepting them back into iMessage is a massive, massive change in the security boundary Anyone can already screenshot iMessages and move them out of the "security boundary"... which btw doesn't exist much, as if you have any Mac connected to your iCloud account then those messages are being synced to an SQLite DB any process running under your user can acces…
I don’t think you understand what the security boundary of iMessage is. People’s phones got compromised by NSO sending images to them via whatsapp that used an exploit in one of the image libraries to run a malware payload. The security boundary isn’t about whether you can see your own messages, it’s whether bad people can root your phone by getting untrusted code to run. That’s a very different proposition if iMessa…
Has this happened on iOS via WhatsApp?
I know Apple's had a view problems with this happening with iMessage, but always been unsure whether third party app sandbox does a good job of containing this?
Earlier quoted context omitted.
I am aware that apple blocks certain functionality to maintain a cohesive and secure experience. It is THE reason I buy their products, I want the curation. Otherwise I'd buy an android device.
That's all well and good. Opting into that knowingly is a reasonable decision. Hopefully knowing you've opted into that you aren't then cursing Google when they don't support some functionality blocked by Apple, or when RCS is poorly supported, but instead recognizing this as a trade-off you made opting into the Apple closed garden.