Live data from Hacker News

Apple restricts Pebble from being awesome with iPhones

ericmigi.com

871–880 of 1001 posts

Re: Apple restricts Pebble from being awesome with iPhones

#871

Earlier quoted context omitted.

I don’t think you understand what the security boundary of iMessage is. People’s phones got compromised by NSO sending images to them via whatsapp that used an exploit in one of the image libraries to run a malware payload. The security boundary isn’t about whether you can see your own messages, it’s whether bad people can root your phone by getting untrusted code to run. That’s a very different proposition if iMessa…

> People’s phones got compromised by NSO sending images to them via whatsapp Has this happened on iOS via WhatsApp ? I know Apple's had a view problems with this happening with iMessage, but always been unsure whether third party app sandbox does a good job of containing this?

I believe this was used to install Pegasus yes

Re: Apple restricts Pebble from being awesome with iPhones

#872

Earlier quoted context omitted.

> moving a message over BLE to untrusted hardware and worse accepting them back into iMessage is a massive, massive change in the security boundary Anyone can already screenshot iMessages and move them out of the "security boundary"... which btw doesn't exist much, as if you have any Mac connected to your iCloud account then those messages are being synced to an SQLite DB any process running under your user can acces…

I don’t think you understand what the security boundary of iMessage is. People’s phones got compromised by NSO sending images to them via whatsapp that used an exploit in one of the image libraries to run a malware payload. The security boundary isn’t about whether you can see your own messages, it’s whether bad people can root your phone by getting untrusted code to run. That’s a very different proposition if iMessa…

No, that’s not true. NSO Group already has the means to send people spicy JPEGs all they want. Adding this would not significantly change their capabilities.

Re: Apple restricts Pebble from being awesome with iPhones

#873
post #559
post #284

Earlier quoted context omitted.

I know. However, apple devices have been just more reliable for me and retain better resale.

Why do you think they are more reliable and have better resale value?

Surely because they can’t be paired with a Pebble

Re: Apple restricts Pebble from being awesome with iPhones

#874
post #740

Earlier quoted context omitted.

I think trillion dollar companies should not exist. They are inherently destructive to humanity.

This seems arbitrary. What is the limiting principle here? Should there be no 100 billion dollar company? How about after 50 years of inflation?

You’re more than welcome to adjust for inflation on that number.

Re: Apple restricts Pebble from being awesome with iPhones

#875
post #463

Earlier quoted context omitted.

Given that Apple controls the entire hardware and software stack, can't they guarantee messages are encrypted and refuse to send them if they aren't? It seems like they're refusing unconditionally and claiming security instead of actually requiring security.

Well they could require a security level for starters and require only secure pairing (the fact that we even have something besides secure pairing should make a few bells ring), but that still leaves a bunch of avenues for an external vendor to fuck up their side of the implementation. It's a whole another system outside of Apple's control and some mutually agreed upon Bluetooth LE elliptic key does nothing to protec…

You have to trust 3rd parties at some point. Apple can make it reasonably secure and let the user decide if 3rd party accessories are worth the potential risk but that option is never exposed.

Really Apple allows HTTPS connections but the same implementation concerns apply there. The web server could publish it's private and session keys to a "status" page and leak enough to make decryption trivial

I think it'd be more honest if they say "we don't want to give users options" (for better or worse) instead of claiming it's security

Re: Apple restricts Pebble from being awesome with iPhones

#876
post #329
post #293

Earlier quoted context omitted.

Couldn't you make that argument for literally any anticompetitive practice? Like in the 1990s: "Microsoft isn't making an OS for people that want to try different browsers"

Not any anticompetitive practice, just the ones that allow in competitors who have different security models for human/computer interaction. Imagine if you could swap out Siri for Alexa. The privacy guarantees are nothing alike. People buy iPhones because they prohibit unsafe choices.

I mean the security model for both is pretty similar, you have a provider which gets your audio and then decides what they want to do with it.

Re: Apple restricts Pebble from being awesome with iPhones

#877
post #828

I guess I’ll take the contra here on messages integration — moving a message over BLE to untrusted hardware and worse accepting them back into iMessage is a massive, massive change in the security boundary and therefore security architecture and therefore security promises that apple makes on iMessage. I do not believe average smartwatch users understand what they’d be doing if they got this. I do not believe vendors…

Counterpoint: SMS is not a spam cesspit in Romania. My phone number is public (company information is public). And I get 1 completely unsolicited messages per month and 1 per week from companies that I bought something from. That's not even enough to get me to try to get rid of those messages.

Just don't make the mistake and give your phone number to any American companies. I did so when starting my current job since I didn't yet have a company phone number, and I suddenly started receiving multiple spam messages daily, which has been going on for years now.

Re: Apple restricts Pebble from being awesome with iPhones

#878

Earlier quoted context omitted.

Conveniently, Apple's App Store Review Guidelines also include several rules that restrict apps from duplicating features that the OS already provides. So if they detect a trend early enough, they implement it as first-party feature, dry out the existing competitors while restricting new competitors to enter based on the App Store Review...

The guideline says: "Apps that copy basic iPhone or iPad functionality (including but not limited to its UI, gestures, core features) will be rejected unless the app provides a clearly different purpose or adds unique functionality." Note the "basic" line. And there are plenty of Photos, Notes, Streaming etc apps so not seeing where this is being used to exclude competitors.

Do you think Apple will describe how they’re using this to prevent competition in their guidelines? You’ll need to read third party developers’ accounts for that.

Re: Apple restricts Pebble from being awesome with iPhones

#879

The best decision I made was to switch to Linux Mint and Samsung Z Fold 6. I can't believe I was ever a fan of apple products. Hobbled walled garden products. If you're in tech you should not use apple products. Unless you're building an iphone app.

I've had iPhones since the 3GS and not once have I seen a convincing argument for why I should switch. I need my phone to make calls, send text messages, and to be a 2FA device. The secure "hobbled walled garden" you're talking about is a selling point.

Re: Apple restricts Pebble from being awesome with iPhones

#880
post #579

Earlier quoted context omitted.

> having a smartphone is becoming a necessity for being a functional part of the society This is correct, as in some countries, you use your phone to authenticate access to banking applications and payments (e.g., https://en.wikipedia.org/wiki/Smart-ID ). However, I find it a bit of a stretch to claim that having iMessage access on a smartwatch is essential for being a functional member of society. Corporations will…

What I had in mind wasn’t iMessage, but the fact that banking and digital ID systems such as Danish MitID are increasingly being built with the assumption that everyone owns a smartphone. https://www.mitid.dk/en-gb/

There is also a code reader version available: https://www.mitid.dk/en-gb/get-started-with-mitid/mitid-auth.... In Lithuania, similar systems for banking have existed for a long time—especially code generators—as a method of authentication. In recent years, they have been widely adopted across various platforms, particularly government services, as a login method. Essentially, it functions as a digital ID.

What I originally meant was that I don’t see Apple’s reluctance to open up the iMessage ecosystem as an indication that they wouldn’t support a banking or government authentication system. I just don't understand the concern here.

Post reply on HN