Live data from Hacker News

Apple restricts Pebble from being awesome with iPhones

ericmigi.com

271–280 of 1001 posts

Re: Apple restricts Pebble from being awesome with iPhones

#271
I wonder what people mean here by "security promises" made by Apple. There is no such thing.

iMessage has been targeted for years with zero click exploits, most notably by the NSO group.

Apple’s restrictions aren’t meant to protect consumers, their purpose is to protect Apple’s profits.

Re: Apple restricts Pebble from being awesome with iPhones

#272

I guess I don't see why Pebble, or any smart watch, should need a phone at all. The watch should be able to connect to wifi and/or cellular by itself. We should be able to run full apps on the watch itself.

Battery life. Radios are energy-intensive, and the processing required to run "full apps" is also often pretty steep. In the meantime, while battery chemistries are getting better space is very much at a premium on one's wrist.

From the other recently-posted article, the new Pebble watches are targeting 30-day battery lives between charges. That would be unthinkable for a watch that manages its own wifi/cellular connections.

Re: Apple restricts Pebble from being awesome with iPhones

#273

I guess I’ll take the contra here on messages integration — moving a message over BLE to untrusted hardware and worse accepting them back into iMessage is a massive, massive change in the security boundary and therefore security architecture and therefore security promises that apple makes on iMessage. I do not believe average smartwatch users understand what they’d be doing if they got this. I do not believe vendors…

Step 1: Have the iPhone pop up saying "do you want to be able to send messages?" and let the user decide which devices can send their phone messages. Step 2: Have the iPhone pop up saying "do you want to be able to send messages?" and don't just assume "yes" Both steps would improve security, even if they harm Apple's profits.

How would step 1 improve security over not allowing third party devices to send messages at all?

Re: Apple restricts Pebble from being awesome with iPhones

#274

I guess I’ll take the contra here on messages integration — moving a message over BLE to untrusted hardware and worse accepting them back into iMessage is a massive, massive change in the security boundary and therefore security architecture and therefore security promises that apple makes on iMessage. I do not believe average smartwatch users understand what they’d be doing if they got this. I do not believe vendors…

This is cap. I worked on heads up glasses, and one of our issues was the lack of integration with Apple's iMessage ecosystem. Device makers are willing to go through several security measures, like deploying the MFi chips and certification. However, at best this gives you access to the notification system, not iMessage itself. You are able to respond to messages via the notification framework, but not integrate direc…

What are the limitations of integrating via notifications? That seems like the user-respecting method. For example, I don't use iMessage or SMS, but WhatsApp.

Re: Apple restricts Pebble from being awesome with iPhones

#275
post #210
post #13

iOS wearable integrations are bad, but somehow Meta Ray-Bans are very good. Voice assist to start a call, send a text, read a notification, etc. Did Meta get special access to do this?

For voice integration, you can just provide a bluetooth microphone on you device and have it access Siri. Garmin have tried the same strategy on some of their watches. What you can't do is reply to a text without using voice, which is what I'd like.

I wonder if you could synthesize a voice with TTS saying "hey siri, send a text to X saying Y", and send that over bluetooth as if it was mic input.

Re: Apple restricts Pebble from being awesome with iPhones

#276

I guess I don't see why Pebble, or any smart watch, should need a phone at all. The watch should be able to connect to wifi and/or cellular by itself. We should be able to run full apps on the watch itself.

Two reasons:

One, adding hardware to connect to WiFi and cellular increases size and power requirements. Notably, the new Pebble 's battery is projected to last 30 days.

Two, people use phones. They want their watch to work with their phone instead of around it.

Re: Apple restricts Pebble from being awesome with iPhones

#277

I guess I’ll take the contra here on messages integration — moving a message over BLE to untrusted hardware and worse accepting them back into iMessage is a massive, massive change in the security boundary and therefore security architecture and therefore security promises that apple makes on iMessage. I do not believe average smartwatch users understand what they’d be doing if they got this. I do not believe vendors…

Bluetooth devices can already read Messages from your iPhone with no degradation to E2EE: https://developer.apple.com/library/archive/documentation/Co...

This is just about sending.

Re: Apple restricts Pebble from being awesome with iPhones

#278

Earlier quoted context omitted.

> moving a message over BLE to untrusted hardware and worse accepting them back into iMessage is a massive, massive change in the security boundary Anyone can already screenshot iMessages and move them out of the "security boundary"... which btw doesn't exist much, as if you have any Mac connected to your iCloud account then those messages are being synced to an SQLite DB any process running under your user can acces…

I don’t think you understand what the security boundary of iMessage is. People’s phones got compromised by NSO sending images to them via whatsapp that used an exploit in one of the image libraries to run a malware payload. The security boundary isn’t about whether you can see your own messages, it’s whether bad people can root your phone by getting untrusted code to run. That’s a very different proposition if iMessa…

> People’s phones got compromised by NSO sending images to them via whatsapp

Has this happened on iOS via WhatsApp?

I know Apple's had a view problems with this happening with iMessage, but always been unsure whether third party app sandbox does a good job of containing this?

Re: Apple restricts Pebble from being awesome with iPhones

#279
post #131

Earlier quoted context omitted.

I am aware that apple blocks certain functionality to maintain a cohesive and secure experience. It is THE reason I buy their products, I want the curation. Otherwise I'd buy an android device.

That's all well and good. Opting into that knowingly is a reasonable decision. Hopefully knowing you've opted into that you aren't then cursing Google when they don't support some functionality blocked by Apple, or when RCS is poorly supported, but instead recognizing this as a trade-off you made opting into the Apple closed garden.

RCS is supported per the standard. Google's implementation uses proprietary extensions. It's not the ivory tower you seem to think it is.

Re: Apple restricts Pebble from being awesome with iPhones

#280

Earlier quoted context omitted.

Bluetooth is encrypted.

Should be, but BT stacks are super crap and it's hard to truly guarantee that. Pretty sure they do not currently require the highest (actually proper) security level from everyone.

[flagged]
Post reply on HN