Earlier quoted context omitted.
I don’t think you understand what the security boundary of iMessage is. People’s phones got compromised by NSO sending images to them via whatsapp that used an exploit in one of the image libraries to run a malware payload. The security boundary isn’t about whether you can see your own messages, it’s whether bad people can root your phone by getting untrusted code to run. That’s a very different proposition if iMessa…
> People’s phones got compromised by NSO sending images to them via whatsapp Has this happened on iOS via WhatsApp ? I know Apple's had a view problems with this happening with iMessage, but always been unsure whether third party app sandbox does a good job of containing this?
Apple restricts Pebble from being awesome with iPhones
871–880 of 1001 posts
Re: Apple restricts Pebble from being awesome with iPhones
#872Earlier quoted context omitted.
> moving a message over BLE to untrusted hardware and worse accepting them back into iMessage is a massive, massive change in the security boundary Anyone can already screenshot iMessages and move them out of the "security boundary"... which btw doesn't exist much, as if you have any Mac connected to your iCloud account then those messages are being synced to an SQLite DB any process running under your user can acces…
I don’t think you understand what the security boundary of iMessage is. People’s phones got compromised by NSO sending images to them via whatsapp that used an exploit in one of the image libraries to run a malware payload. The security boundary isn’t about whether you can see your own messages, it’s whether bad people can root your phone by getting untrusted code to run. That’s a very different proposition if iMessa…
Re: Apple restricts Pebble from being awesome with iPhones
#873Re: Apple restricts Pebble from being awesome with iPhones
#874Earlier quoted context omitted.
I think trillion dollar companies should not exist. They are inherently destructive to humanity.
This seems arbitrary. What is the limiting principle here? Should there be no 100 billion dollar company? How about after 50 years of inflation?
Re: Apple restricts Pebble from being awesome with iPhones
#875Earlier quoted context omitted.
Given that Apple controls the entire hardware and software stack, can't they guarantee messages are encrypted and refuse to send them if they aren't? It seems like they're refusing unconditionally and claiming security instead of actually requiring security.
Well they could require a security level for starters and require only secure pairing (the fact that we even have something besides secure pairing should make a few bells ring), but that still leaves a bunch of avenues for an external vendor to fuck up their side of the implementation. It's a whole another system outside of Apple's control and some mutually agreed upon Bluetooth LE elliptic key does nothing to protec…
Really Apple allows HTTPS connections but the same implementation concerns apply there. The web server could publish it's private and session keys to a "status" page and leak enough to make decryption trivial
I think it'd be more honest if they say "we don't want to give users options" (for better or worse) instead of claiming it's security
Re: Apple restricts Pebble from being awesome with iPhones
#876Earlier quoted context omitted.
Couldn't you make that argument for literally any anticompetitive practice? Like in the 1990s: "Microsoft isn't making an OS for people that want to try different browsers"
Not any anticompetitive practice, just the ones that allow in competitors who have different security models for human/computer interaction. Imagine if you could swap out Siri for Alexa. The privacy guarantees are nothing alike. People buy iPhones because they prohibit unsafe choices.
Re: Apple restricts Pebble from being awesome with iPhones
#877I guess I’ll take the contra here on messages integration — moving a message over BLE to untrusted hardware and worse accepting them back into iMessage is a massive, massive change in the security boundary and therefore security architecture and therefore security promises that apple makes on iMessage. I do not believe average smartwatch users understand what they’d be doing if they got this. I do not believe vendors…
Counterpoint: SMS is not a spam cesspit in Romania. My phone number is public (company information is public). And I get 1 completely unsolicited messages per month and 1 per week from companies that I bought something from. That's not even enough to get me to try to get rid of those messages.
Re: Apple restricts Pebble from being awesome with iPhones
#878Earlier quoted context omitted.
Conveniently, Apple's App Store Review Guidelines also include several rules that restrict apps from duplicating features that the OS already provides. So if they detect a trend early enough, they implement it as first-party feature, dry out the existing competitors while restricting new competitors to enter based on the App Store Review...
The guideline says: "Apps that copy basic iPhone or iPad functionality (including but not limited to its UI, gestures, core features) will be rejected unless the app provides a clearly different purpose or adds unique functionality." Note the "basic" line. And there are plenty of Photos, Notes, Streaming etc apps so not seeing where this is being used to exclude competitors.
Re: Apple restricts Pebble from being awesome with iPhones
#879The best decision I made was to switch to Linux Mint and Samsung Z Fold 6. I can't believe I was ever a fan of apple products. Hobbled walled garden products. If you're in tech you should not use apple products. Unless you're building an iphone app.
Re: Apple restricts Pebble from being awesome with iPhones
#880Earlier quoted context omitted.
> having a smartphone is becoming a necessity for being a functional part of the society This is correct, as in some countries, you use your phone to authenticate access to banking applications and payments (e.g., https://en.wikipedia.org/wiki/Smart-ID ). However, I find it a bit of a stretch to claim that having iMessage access on a smartwatch is essential for being a functional member of society. Corporations will…
What I had in mind wasn’t iMessage, but the fact that banking and digital ID systems such as Danish MitID are increasingly being built with the assumption that everyone owns a smartphone. https://www.mitid.dk/en-gb/
What I originally meant was that I don’t see Apple’s reluctance to open up the iMessage ecosystem as an indication that they wouldn’t support a banking or government authentication system. I just don't understand the concern here.