Live data from Hacker News

Nothing's iMessage app was a security catastrophe, taken down in 24 hours

arstechnica.com

81–90 of 147 posts

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#81
post #50

Earlier quoted context omitted.

I work for a company like this right now. About the same number of employees, same mistakes and same time to market on innovative stuff. Here's my two cents on how this can happen: > Which product manager in his/her right mind There is no product manager. There is a project manager. They steer on deadlines and functionality, nothing more. > How do these managers get jobs in these big name companies? Because they talk…

>As a project manager, that's the last thing you want. First, it'll show what you didn't manage well. Secondly, it costs money. Finally, negative findings will delay delivery and means you failed to deliver on time, which is your only priority. And yet FAANGMAULs and other tech-first companies like Mozilla, seem to be doing quite well on security with relatively very few oversights, caused by dev gross negligence. So…

Those companies spend a bananas amount of money on security and pay a huge price in delivery times. They can afford to.

New enterprises can’t. And if you go back to those companies growth phases you’ll see security decisions that seem bananas now.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#82
post #58

Apple is almost certainly aware of this at the C-Suite level; I wouldn’t even be surprised if Tim Cook were briefed. Had Apple pulled Sunbird’s access to iMessage before information about their shoddy security coming out via third-party, they would have run the risk of playing into Google’s narrative about Apple being petty about their closed standard. Here’s what I think (and hope) will happen: * Apple will revoke S…

> Apple will revoke Sunbird’s access

How do your expect that they will do this? IIUC they are basically logging in to real Apple hardware with the users credentials. There is nothing concrete that can be used to identify these sessions. (Obviously things like shared IPs, reused machines and other patterns can be used, but these aren't 100% accurate).

That being said it surprises me that this can be profitable. If they run multiple users on the same hardware they risk being banned pretty quickly. In theory they can reuse hardware after user churn but that can probably be done a limited number of times. Is old used Apple hardware just so cheap that they can buy them then resell for a reasonable cost?

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#83

The other story people are missing here is that even if this wasn't a security issue, iMessage is adopting RCS next year, so the whole blue/green bubble thing will become much less relevant.

I'm on Android and don't SMS with hardly anyone these days. I just use telegram channels or signal messenger.

Right? Even if RCS is adopted by every major manufacturer, it's far too late to grab any market share. Everyone uses iMessage/WhatsApp now. Text messaging is dead, even if you can send gifs/stickers/group chats/video/etc.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#84

Earlier quoted context omitted.

> How do these managers get jobs in these big name companies? Nothing is very far from what I would consider a "big name company" They are actually a really small joint venture between Carl Pei and Teenage Engineering. This whole iMessage fiasco is exactly why I have such a hard time taking Carl seriously in anything he does. He seems more concerned with creating hype through smoke and mirrors than in releasing anyth…

It is a big name company though. Not a lot of companies have access to a supply chain and logistics to design and ship products like they do worldwide.

LOL you can find lots of small companies in China you have never heard of that make (better) phones and ships to dozens of countries. Nothing isn't any better than those companies other than marketing.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#85

Earlier quoted context omitted.

> Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early access reviewer raised these exact security concerns in public? Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. (To be clear: I'm an engineer, not a PM.)

Are engineers really setting up sentry without it being on the roadmap? PMs direct the engineers.

Yes... Why would a PM put Sentry on the roadmap, unless that PM has some reasonable level of technical understanding, but at that point the same PM should have been aware of many of the security implications of the overall project.

A not unreasonable guess would be that Sunbird doesn't have a great number of senior engineers on staff, either do to cost, or because very few wanted to take on such a project. So it cobbled together by inexperienced engineering that know enough to understand the Sentry is useful, but not experienced enough avoid logging credentials.

Basically all the errors listed in the article just reads like what happens when you set a bunch of inexperience developers and SREs to build a platform that doesn't want to exist. Which leads me to: How the does this even work? I'd assume a massive number of virtualized macOS installation, anything more advanced would sort of negate the incompetence on the security front.

Sort of a side note: I questioned the point of the Nothing Phone and Nothing Phone 2 when they where both released, they are nothing more than Android phones with a few gimmick but everyone was loosing their minds over those things and now ArsTechnica writes: "Nothing has always seemed like an Android manufacturer that was more hype than substance" (and apparently also did for back when the Nothing Phone release. I'm getting so very tied of the hype and how easily any criticism can be reject as me being old and "not getting it".

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#86
post #35

Earlier quoted context omitted.

> How do these managers get jobs in these big name companies? Nothing is very far from what I would consider a "big name company" They are actually a really small joint venture between Carl Pei and Teenage Engineering. This whole iMessage fiasco is exactly why I have such a hard time taking Carl seriously in anything he does. He seems more concerned with creating hype through smoke and mirrors than in releasing anyth…

Is Teenage Engineering actually a part of a joint venture or are they just design consultants used to pump brand appeal?

Up until now I had no idea TE had anything to do with Nothing phones.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#87
post #75

Earlier quoted context omitted.

It's too early to play guess the acronym for me. What is the MAUL part of your FAANGMAUL acronym.

Microsoft, Uber, Lyft, and AirBnB is what I eventually found. FAANGMULA in the above case.

Why are Uber, Lyft, and AirBnB being added only now, after their infinite-VC-money heyday is drying up, and when the general public is starting to hate them and are returning to taxis and hotels?

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#88

>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…

what damn engineer thought it was good idea to have sentry on in release on an app that uses firestore? I am extremely careful of when I turn on release app mode reporting to 3rd parties and about sandboxing said things so that passwords and ug messages do not get sent to 3rd party.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#89
post #7

Earlier quoted context omitted.

I don't think Beeper can promise end to end encryption for 3rd party services either. Fundamentally if you're interfacing with a service like iMessage or Whatsapp - even if they offer end to end encryption - the message has to be decrypted and then sent to the 3rd party app. Unless that gateway is running on your phone, the messages have to be decrypted in the cloud somewhere. At that point, you are placing all your…

True, but at the same time, it’s a very small attack vector. I’d say the vast majority of users could really care less that an iMessage is decrypted for a brief period in-memory on some Mac VM in a data center. You place your trust in 3rd party cloud servers for so many things. Email, as an example, is far more confidential / important, but most people never have it encrypted. It’s still a fair criticism, but I still…

> I’d say the vast majority of users could really care less that an iMessage is decrypted for a brief period in-memory on some Mac VM in a data center.

And yet, that's precisely where I would go if I were law enforcement or a secret service. Tell them they're being used by terrorists/drug kingpins/CSAM peddlers, slap a gag order on 'em, and scoop up everything. And unlike Apple, Whatsapp or Telegram whoever hosts such a service can't even refuse such an order on grounds of technical impossibility because the messages are in plaintext in memory.

Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours

#90

Earlier quoted context omitted.

>Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. EXACTLY! Because it's a known fact all devs make mistakes, and as such, as a product manager/owner you're responsible for the bigger picture of the product and ensuring the right requirements, checks and bound are put in palce and validated for a successful product release. It's not the job of the lowly SW engineers w…

I hope this is facetious. Security is everyone’s job, and unencrypted customer data, outside of a locked-down DB, should give one pause.

Well, managers are happy to take responsibility for their project/product when everything goes well. It’s actually the argument for their salaries and bonuses compared to lowly engineers. So why should they not take responsibility when it goes sideways? Particularly when failure affects the whole product like the Sunbird app.

You cannot say that the project works because of you, and then turn around and pretend you have nothing to do with its failures.

Post reply on HN