Live data from Hacker News

Apple restricts Pebble from being awesome with iPhones

ericmigi.com

531–540 of 1001 posts

Re: Apple restricts Pebble from being awesome with iPhones

#531
post #184
post #81

I think, we fundamentally lack a mechanism to enforce secure / privacy aware APIs without resorting to trusted inner-circle type of things. I am already not comfortable with Apple picking winners (such as giving Zoom special entitlement but not the VOIP apps you want to distribute by your own). Apple trusting their own apps more than other apps is another symptom of this and it is not helping their anti-trust situati…

Quicktime Player.app gets an entitlement called `com.apple.private.tcc.allow`, giving it unprompted access to the Camera, Microphone, and Screen Capture. An MDM administrator, managing a computer or device owned by an organization, cannot grant those permissions to anything without user consent. For good reason! So why the *fuck* does Apple think they're entitled to?

> So why the *fuck* does Apple think they're entitled to?

Because they manufactured the device, and you bought it?

And honestly, I support them. Because starting QuickTime is a user action, and it only records when I want it to. QuickTime is an app I trust.

I don't trust an organization admin not to record me without my consent. As we've heard the horror stories of schools spying on students with school laptops while they're in their own homes, their own bedrooms.

I trust Apple a whole lot more than I trust an org admin.

Re: Apple restricts Pebble from being awesome with iPhones

#532
post #430

Earlier quoted context omitted.

This is cap. I worked on heads up glasses, and one of our issues was the lack of integration with Apple's iMessage ecosystem. Device makers are willing to go through several security measures, like deploying the MFi chips and certification. However, at best this gives you access to the notification system, not iMessage itself. You are able to respond to messages via the notification framework, but not integrate direc…

As a user, I am totally fine with Apple restricting access to iMessage. In fact, now that I read this, I want them to do this, thanks Apple.

I’m with you on this one. I’d be fine with Apple opening up their ecosystem in a safe and careful way to other companies but only if the security stays, at least, at the same level - and if I’m able to turn off these options in the settings.

Re: Apple restricts Pebble from being awesome with iPhones

#533

Earlier quoted context omitted.

Plenty of choice... so long as that choice has been approved by Apple. It's a very convenient position for a company with a competing product.

Apple doesn't approve of me not having an Apple Watch.

What point are you making here? That Apple should be able to leverage their market position to crush their competition for a particular device just because it doesn't affect you in particular? You don't care for smart watches so the smart watch market should be exempt from regulation?

Re: Apple restricts Pebble from being awesome with iPhones

#534
post #229

Earlier quoted context omitted.

I mean the reason is because Apple, the people who made the security boundary, and Apple the people who made Quicktime are the same people. I'm not saying it's not anti-competitive but it's fine from a security context. Apple knows exactly how Quicktime behaves, that it doesn't act maliciously, and can't be updated to do so.

> Apple knows exactly how Quicktime behaves, that it doesn't act maliciously, and can't be updated to do so. Yes, it's physically impossible for an Apple developer to accidentally or maliciously introduce an exploit into QT and for it to elude security or code review... I've never heard a security posture that is "well, we know what your tool does, so it doesn't need any security controls".

I'm sure that could happen, but it's not really any different than exploiting some other part of the system. You make a fine case that the nature of this code means it will likely be under less security scrutiny than such an entitlement warrants but that's Apple's problem now.

> well, we know what your tool does, so it doesn't need any security controls

This really isn't that weird. The camera app doesn't need to ask for permission to use the camera/mic. And the why is because the thing you're worried about is some random 3rd party app capturing audio/video without the user's knowledge or intent. You know the built-in camera app doesn't do that because you wrote it, so it's fine to give it an entitlement to bypass the usual prompts. It can also access your photos without prompts because the threat model is malicious exfiltration and again, you know it doesn't do that.

Re: Apple restricts Pebble from being awesome with iPhones

#535

Earlier quoted context omitted.

I honestly don't care about Microsoft bundling a browser. The real problem was that they intentionally broke web standards to push websites to "work best on Internet Explorer," so even those who chose not to use Windows were caught up in it. Whereas, Android users aren't affected by what Apple does here. They still bundle Edge, and keep setting it to default. But idc, it's just one of 1000 reasons I don't use Windows…

Isn't the WebKit the only allowed browser engine on iOS?

Yes. Essentially Safari is the only iOS browser. Ironically, this is the only thing stopping a Chrome web monopoly.

Re: Apple restricts Pebble from being awesome with iPhones

#536

Earlier quoted context omitted.

Apple doesn't approve of me not having an Apple Watch.

What point are you making here? That Apple should be able to leverage their market position to crush their competition for a particular device just because it doesn't affect you in particular? You don't care for smart watches so the smart watch market should be exempt from regulation?

Exactly. They're just toys. I also don't care that my Nintendo GameCube can't use an Xbox controller.

Re: Apple restricts Pebble from being awesome with iPhones

#537

I guess I’ll take the contra here on messages integration — moving a message over BLE to untrusted hardware and worse accepting them back into iMessage is a massive, massive change in the security boundary and therefore security architecture and therefore security promises that apple makes on iMessage. I do not believe average smartwatch users understand what they’d be doing if they got this. I do not believe vendors…

Only letting Apple Watch have this functionality is what is wrong. It's clearly anti-competitive, in my opinion their hand-waving about security is just that.

They could implement something that works for other smartwatch vendors, they haven't because they don't want to.

Re: Apple restricts Pebble from being awesome with iPhones

#538

There's nothing new here. From AirDrop to AirPods, Apple's MO is to lock you into their ecosystem and be as belligerent as possible toward any non-Apple gizmo. Couple that with social and network effects, and you have a perfect formula for monopolizing a market without continuously improving the tech.

> and you have a perfect formula for monopolizing a market without continuously improving the tech.

...but the Apple ecosystem has the best tech. M chips, AirPods Pro, Apple Watch, iPad, Pencil, I mean the tech is great.

Apple isn't monopolizing anything. They're competing like hell and winning because their tech is best. The real question is why the Android and Microsoft ecosystems don't do better at improving their tech. Where's the Windows equivalent of an M4 MacBook Air in terms of performance and battery life?

Re: Apple restricts Pebble from being awesome with iPhones

#539

There's nothing new here. From AirDrop to AirPods, Apple's MO is to lock you into their ecosystem and be as belligerent as possible toward any non-Apple gizmo. Couple that with social and network effects, and you have a perfect formula for monopolizing a market without continuously improving the tech.

I like the ecosystem. If you don’t, choose another ecosystem.

[deleted]

Re: Apple restricts Pebble from being awesome with iPhones

#540

in the 90s there were no APIs you would just debug resident memory and network buffers to reverse engineer the API & IPC Am I old or do people have higher expectations now?

The author of this article was also the CEO of Beeper. They did just that and released an iMessage client for Android in December 2023. Apple proceeded to ban users of that client, launched a smear campaign against the company and implemented countermeasures until Beeper gave up on the whole endeavour.

Apple has lots of options at their disposal to frustrate any attempts to reverse engineer their APIs, and have shown they're willing to go above and beyond in defending their walled garden. If all else fails, every Apple device newer than 2018 has a secure enclave and verified boot, so they could just enforce an encrypted channel between the enclave - which will be able to attest that the device is running latest iOS or macOS with all DRM measures enabled - and iMessage servers. The only reason they don't do that already is the number of users on older devices, but that number gets lower and lower each year.

Post reply on HN