Live data from Hacker News

Apple cuts off Beeper Mini's access

techcrunch.com

321–330 of 1001 posts

Re: Apple cuts off Beeper Mini's access

#321
post #210
post #65

As usual, Gruber was right on the money. Via Threads yesterday: "My prediction is that Apple will make changes—fixing bugs and/or closing loopholes—that break Beeper Mini. It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. It’s a very nice app, remarkably clever, and for now works like a charm, but if Apple wanted an iMessage client…

>It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. I don't follow this logic at all. Shouldn't supporting thirdparty clients be desirable if security is a primary feature in the interest of transparency? Especially if the reference client is proprietary and undocumented.

No. This is an entirely self-centred view. The only people that equate this sort of transparency with genuine security are computer nerds. These tend to be the sorts of people that don’t sit very highly on my internal list of “people who stand to benefit the most from increased privacy measures”. For…literally every other member of society, this sort of implementation detail doesn’t mean anything^. They hear some (from their perspective) very abstract words like ‘open’, and all that means is that they’re trusting some league of computer nerds to tell them that something is ‘secure’. This is somehow meant to be more convincing than Apple, who, to most people, is at the very least another mob of computer nerds, but in reality also happen to have a pretty good track record of making phones that seem to work alright for people.

Beyond optics, let’s just look at attack surface. The implication that the sort of security holes that “openness” would fix are anywhere near the top of the list is…where’s that xkcd about cryptography and crowbars? It’s very clearly in the realm of nerdy cosplay. You know what is* a much more realistic threat? Some stupid third-party client on the Play store that exfiltrates all messages sent and received. Apple has absolutely no control over that. No protocol security accounts for that.

Re: Apple cuts off Beeper Mini's access

#322

Earlier quoted context omitted.

Keep in mind that this is spin — Erik's statement is ridiculous, and he knows it. To think that Apple would somehow not treat Beeper like any other bad actor hacking iMessage protocols is delulu.

Sure, that's fair. But if he knows that, why spend the time to build this app in the first place? Is it a marketing play? It did buy them a whole lot of attention.

[deleted]

Re: Apple cuts off Beeper Mini's access

#323

Earlier quoted context omitted.

When did Google react to the SEO heist? I can't seem to find a source for it.

https://x.com/rosshudgens/status/1729889490947518868

The follow up tweet says he typo'd the company name in the screenshot: https://twitter.com/RossHudgens/status/1729927440112189820

And the tweet fundamentally misunderstands how ahref works. If google killed the site in question, ahref would have no idea given they have their own crawl.

Re: Apple cuts off Beeper Mini's access

#324

Earlier quoted context omitted.

Putting aside that I count at least two glaring examples from this list[^1] in your reply, I suspect Apple would argue that it is in fact _solely_ preoccupied with its users' security: that's why iMessage is end to end encrypted and Apple does not offer 2FA / OTPs via SMS. Apple does not generally try to mitigate security issues which are beyond its control (e.g. non-Apple devices, protocols). [^1]: https://en.wikipe…

> and Apple does not offer 2FA / OTPs via SMS Last time I checked, Apple still used security questions any hacker can get answers to on Facebook. I'm not all that confident about Apple's approach to account security. Apple has the ability to control security issues on Android: they can release an Android app, like every other E2EE messenger out there. Apple chooses not to, and it's their choice, of course. It doesn't…

My points are narrowly related to the parent's assertion that Apple preventing Beeper Mini interoperability / allowing SMS is evidence of their convictions relating to privacy being hokum, but since you're not one of those 3 month old accounts I see making specious arguments…

> Last time I checked, Apple still used security questions any hacker can get answers to on Facebook.

Apple's default for a number of years has been to use trusted devices IIRC. Their kb article on resetting a forgotten Apple ID password even suggests that it's better to wait until you're back with a trusted device than to immediately try to reset without one, suggesting that the process is somewhat intensive and perhaps subject to human review? I just kicked it off online and the first question _is_ to confirm an obfuscated cell phone number, but I can't imagine that after that it's mother's maiden name dreck?

> Apple has the ability to control security issues on Android: they can release an Android app, like every other E2EE messenger out there.

Which would thus expose them to security weaknesses of a device and OS they do not control, and potentially expose iPhone and iOS customers to increased risk should an Android iMessage user's phone have malware, or screen scraping, or keylogging, etc.

> Apple chooses not to, and it's their choice, of course. It doesn't care about the privacy of it's non-users, and it doesn't care about the privacy of its users when they communicate with non-users. From what I can tell, it only cares if you stay within the Apple bubble.

Nail on the head, but I do think that folks overstate the simplicity with which Apple could provide a comparably secure iMessage experience on Android.

Re: Apple cuts off Beeper Mini's access

#325

Earlier quoted context omitted.

It's time that we as an industry push back against Apple and Google. The smartphone is the single most important device for modern life and society. It's news, photos, communications with loved ones, work, entertainment, food, paying for practically everything... And it's just two companies. Two companies with an iron grip over such a wide and diverse set of functionalities that, taken together, should be as inaliena…

The alternative phones outside the duopoly exist. Sent from my Librem 5.

Have Purism solved the problem where it will randomly burn through an entire battery charge in an hour?

That basically makes it a non-option for the overwhelming majority of people, and it was still an issue 6 months ago.

I really want to like the Librem but it's hard to justify the price tag when you're going to have to carry another phone around with you anyway.

Re: Apple cuts off Beeper Mini's access

#326

The EU should, like they did years ago with PC operating systems, mandate a default browser selection screen. And a default messenger selection screen. And a default app store selection screen. Not that we'd get it in the US but it would help reduce Apple/Google market capture efforts.

'Nobody' in the EU uses iMessage, even on iPhones. Everyone here already uses Whatsapp. This demonstrates a lack of a monopoly and how competition can flourish. Honestly - and EU-regulation that Apple faces over iMessage would just be collateral damage from EU targeting Whatsapp.

Your view is clearly not representative for the whole of EU.

Most of my family, friends and colleagues are on iMessage. I often need to explain why facetime will not work.

Whatsapp is also common, but different as it does not as easily replace SMS.

Re: Apple cuts off Beeper Mini's access

#327
post #211

Earlier quoted context omitted.

So instead of being possibly unencrypted RCS when sending outside iMessage, you'd rather guarantee it be unencrypted?

The only texts I get are unwanted spam or some confirmation codes and no it is not worth it to use RCS with the amount of unsent messages it keeps having problems with, maybe for some "possible encryption". It is trash all the way around.

[deleted]

Re: Apple cuts off Beeper Mini's access

#328

This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…

This is actually a great point I didn’t originally consider. People could easily infiltrate the iMessage fort with spam and other stuff which at the moment requires a genuine Apple device.

I'm pretty sure some of the spam I am getting was using this vector. Hopefully it kills it now.

Re: Apple cuts off Beeper Mini's access

#329

Earlier quoted context omitted.

'Nobody' in the EU uses iMessage, even on iPhones. Everyone here already uses Whatsapp. This demonstrates a lack of a monopoly and how competition can flourish. Honestly - and EU-regulation that Apple faces over iMessage would just be collateral damage from EU targeting Whatsapp.

Every person I interact with in the EU uses iMessage. Let’s avoid making sweeping generalizations.

That's a pretty sweeping generalisation on it's own. You personally interacting via iMessage with people in the EU has absolutely no bearing on this. When people say that 'no-one' uses iMessage, they are really saying saying that it's a very small percentage. It's like saying 'no-one uses Yahoo! mail' - relative to GMail and Outlook.com, it's use is vanisingly small these days, but I guaruntee that there is a not-insignificant number of mail originating from Yahoo domains.

Re: Apple cuts off Beeper Mini's access

#330

Earlier quoted context omitted.

Keep in mind that this is spin — Erik's statement is ridiculous, and he knows it. To think that Apple would somehow not treat Beeper like any other bad actor hacking iMessage protocols is delulu.

but the real problem some of use have with Apple's behavior is the real underlying reasons they're doing this I am reasonably sure that their main driver is profit which really means exploitation of people; I consider their public arguments lies made up to cover up the fact that what they account for as profit comes from what are in the end some really ugly historical and traditional imperialistic (colonial, neocolon…

> I am reasonably sure that their main driver is profit which really means exploitation of people

Just wondering if you've forgotten what site you're on.

This is YC which exists to build companies whose main driver will always be profit.

Post reply on HN