Live data from Hacker News

Apple restricts Pebble from being awesome with iPhones

ericmigi.com

861–870 of 1001 posts

Re: Apple restricts Pebble from being awesome with iPhones

#861
post #840
post #366

Earlier quoted context omitted.

While I agree with you (I daily a rooted Android phone), anyone who cleaned up a few Windows machines for non-technical people 20 years ago probably at least understands where Apple is coming from. The average person is really bad at system administration, and it doesn't take many bad actors creating malware and scams to have a big impact.

It's not really about system administration. The average person is a low effort moron who will do whatever he pleases without thinking about the consequences. The difference with computing is that since it's "new" and sometimes it has bugs, they will blame the hardware/OS any chance they get.

Just like your comment was not really about providing anything new, but insulting people who use technology?

Re: Apple restricts Pebble from being awesome with iPhones

#862
post #777
post #364

Earlier quoted context omitted.

You do realize this is a very infantilizing attitude? Why can't the end user choose its own level of security vs usability? Letting a corporation decide this for all users is just creating a nanny state in different clothing.

Because the end user aren't computer scientists. End users should have NO capability in determining their own security, since they could LITERALLY BE infants playing with the iPad. It is the responsibility of the systems designer to make sure the system is secure, not the end user. And if you require instructions on how to secure your system, then you have already failed. A properly designed system is secure with zer…

You do understand that “make it work by default” and “customization” are not exclusive, right? you can definitively pick defaults and allow customization for those who want it.

Re: Apple restricts Pebble from being awesome with iPhones

#863

Earlier quoted context omitted.

This is cap. I worked on heads up glasses, and one of our issues was the lack of integration with Apple's iMessage ecosystem. Device makers are willing to go through several security measures, like deploying the MFi chips and certification. However, at best this gives you access to the notification system, not iMessage itself. You are able to respond to messages via the notification framework, but not integrate direc…

The attack vector is a 3pt app being compromised - maliciously or otherwise - that logs/collects the messages - i.e, the apps themselves can be a threat vector. To be blunt and honest, I’m not sure I disagree. The notification framework seems like an okay compromise to me. I have used it with my Garmin bike computer and I’m more than happy with the level of integration.

The framework that lets you collect messages and ship them god-knows-where but not send them?

Re: Apple restricts Pebble from being awesome with iPhones

#864

Earlier quoted context omitted.

This is cap. I worked on heads up glasses, and one of our issues was the lack of integration with Apple's iMessage ecosystem. Device makers are willing to go through several security measures, like deploying the MFi chips and certification. However, at best this gives you access to the notification system, not iMessage itself. You are able to respond to messages via the notification framework, but not integrate direc…

Might be a little bit of both but nothing you said there contradicts the original point--opening up iMessage integration to arbitrary bluetooth connections is a bad idea. It blows open access to all your messages...who knows, maybe even the e2ee keys. Law enforcement would have a brand new frictionless way into all your messages

I don’t think Apple would ever expose the encryption keys to your messages. Nobody would want it anyway: why reimplement the protocol when you actually just want to send and receive messages? And I fail to see why it would be frictionless for law enforcement, as they’d need to have access to your device.

Re: Apple restricts Pebble from being awesome with iPhones

#865

Earlier quoted context omitted.

This is cap. I worked on heads up glasses, and one of our issues was the lack of integration with Apple's iMessage ecosystem. Device makers are willing to go through several security measures, like deploying the MFi chips and certification. However, at best this gives you access to the notification system, not iMessage itself. You are able to respond to messages via the notification framework, but not integrate direc…

As someone who has found a lot of holes both in design and implementation, which have been reviewed and vetted by excellent people and companies, which have all the appropriate certifications - no thank you. I understand the benefit of an open ecosystem. Use your web browser, or a third-party app. The tech adopted by the masses needs guard rails and secure defaults. I hated Apple’s ecosystem growing up, now I think i…

> Use your web browser, or a third-party app. The tech adopted by the masses needs guard rails and secure defaults.

Do you think “the masses” should not use web browsers or third party apps?

Re: Apple restricts Pebble from being awesome with iPhones

#866

Earlier quoted context omitted.

This is cap. I worked on heads up glasses, and one of our issues was the lack of integration with Apple's iMessage ecosystem. Device makers are willing to go through several security measures, like deploying the MFi chips and certification. However, at best this gives you access to the notification system, not iMessage itself. You are able to respond to messages via the notification framework, but not integrate direc…

> This is crap I appreciate you sharing your experience, I just wish you could have done it without this bit.

[flagged]

Re: Apple restricts Pebble from being awesome with iPhones

#867
post #5

You'll one day hear Apple's lawyers argue in court that "security" never meant cybersecurity, only share price security.

or job security

If only

https://www.hrgrapevine.com/us/content/article/2024-08-29-te...

Re: Apple restricts Pebble from being awesome with iPhones

#868

Earlier quoted context omitted.

This is cap. I worked on heads up glasses, and one of our issues was the lack of integration with Apple's iMessage ecosystem. Device makers are willing to go through several security measures, like deploying the MFi chips and certification. However, at best this gives you access to the notification system, not iMessage itself. You are able to respond to messages via the notification framework, but not integrate direc…

May I suggest using proper English? I believe part of the reason you are getting downvoted is due to the hat language you are using. Several people, understandably, will not comprehend.

Nothing makes their English any less proper than yours.

Re: Apple restricts Pebble from being awesome with iPhones

#869

Earlier quoted context omitted.

> moving a message over BLE to untrusted hardware and worse accepting them back into iMessage is a massive, massive change in the security boundary Is it? My iPhone replicates messages to my mac from where a process can extract that data, it can capture the screen etc. I can use a mac today to set up a relay that would then send those messages to a smart watch if one would do that.

Your phone and Mac have strong trust at the OS, hardware, and manufacturing level.

Ok but that strong trust lets them do exactly what was mentioned above.

Re: Apple restricts Pebble from being awesome with iPhones

#870
post #843

Can anybody explain to me in simple terms the argument about opening the floodgates for spam on iMessage if Apple would lower their restrictions? I just don't get it. If true, wouldn't this mean that every other messenger app with fewer restrictions or even alternative clients would have a massive spam problem? Anecdotally, I can't really confirm that.

Start with the conclusion that Apple's actions are necessary and morally good, find a reasonable-sounding but ultimately weak technical explanation and confidently present it as the only solution, then fearmonger less technical users into accepting the preconceived solution with all of its drawbacks using anecdotes and hyperbole.

Lastly, ignore or dismiss any evidence that invalidates your preconceived conclusions, like the fact that these "floodgates" have always been open [1] and yet people credit non-existent floodgates for solving the spam problem.

Anecdotally, the amount of spam I receive across Signal and Telegram is zero, and SMS is very close to 0, maybe one SMS every few weeks.

[1] https://documenter.getpostman.com/view/765844/UV5RnfwM#0d8e0...

Post reply on HN