Earlier quoted context omitted.
It's too early to play guess the acronym for me. What is the MAUL part of your FAANGMAUL acronym.
Microsoft, Airbnb, Uber, Lyft. When will we stop adding companies' acronyms?
Nothing's iMessage app was a security catastrophe, taken down in 24 hours
91–100 of 147 posts
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#92Earlier quoted context omitted.
I hope this is facetious. Security is everyone’s job, and unencrypted customer data, outside of a locked-down DB, should give one pause.
Everyone here is to blame. Not just the PM, not just the engineers. I'd also blame the hiring manager.
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#93Earlier quoted context omitted.
> Apple is almost certainly aware of this at the C-Suite level What makes you think this?
iMessage is one of the primary moats keeping a lot of people on iPhone. I'm not necessarily as sure as the parent comment that the c-suite was briefed or anything, but I do think that iMessage exclusivity is pretty important to Apple
The issue is Sunbird's shoddy implementation in particular compromising the security of a bunch of their users' accounts, with a real Android OEM vouching for their service and shipping it on their new phone, giving Sunbird a big publicity boost in the process.
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#94Earlier quoted context omitted.
Are engineers really setting up sentry without it being on the roadmap? PMs direct the engineers.
Yes... Why would a PM put Sentry on the roadmap, unless that PM has some reasonable level of technical understanding, but at that point the same PM should have been aware of many of the security implications of the overall project. A not unreasonable guess would be that Sunbird doesn't have a great number of senior engineers on staff, either do to cost, or because very few wanted to take on such a project. So it cobb…
I think there is a perception issue. Ars is not a person. I don’t know who was hyped when the phone was released, but Ron Amadeo sounds like someone who would indeed have been skeptical about Nothing’s pitch.
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#95Earlier quoted context omitted.
True, but at the same time, it’s a very small attack vector. I’d say the vast majority of users could really care less that an iMessage is decrypted for a brief period in-memory on some Mac VM in a data center. You place your trust in 3rd party cloud servers for so many things. Email, as an example, is far more confidential / important, but most people never have it encrypted. It’s still a fair criticism, but I still…
> I’d say the vast majority of users could really care less that an iMessage is decrypted for a brief period in-memory on some Mac VM in a data center. And yet, that's precisely where I would go if I were law enforcement or a secret service. Tell them they're being used by terrorists/drug kingpins/CSAM peddlers, slap a gag order on 'em, and scoop up everything. And unlike Apple, Whatsapp or Telegram whoever hosts suc…
Use Signal if you want end-to-end encryption and don't feel bad about using Beeper for people stuck on iMessage.
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#96Earlier quoted context omitted.
> Apple is almost certainly aware of this at the C-Suite level What makes you think this?
iMessage is one of the primary moats keeping a lot of people on iPhone. I'm not necessarily as sure as the parent comment that the c-suite was briefed or anything, but I do think that iMessage exclusivity is pretty important to Apple
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#97Earlier quoted context omitted.
Microsoft, Airbnb, Uber, Lyft. When will we stop adding companies' acronyms?
I'll stick with the ~1T market cap software/service ones: Facebook, Apple, Amazon, Microsoft, Google/Alphabet: FAAMG; But in discussions I'll include any company that has similar tech/business requirements or behavior.
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#98Earlier quoted context omitted.
It's too early to play guess the acronym for me. What is the MAUL part of your FAANGMAUL acronym.
Microsoft, Airbnb, Uber, Lyft. When will we stop adding companies' acronyms?
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#99Apple is almost certainly aware of this at the C-Suite level; I wouldn’t even be surprised if Tim Cook were briefed. Had Apple pulled Sunbird’s access to iMessage before information about their shoddy security coming out via third-party, they would have run the risk of playing into Google’s narrative about Apple being petty about their closed standard. Here’s what I think (and hope) will happen: * Apple will revoke S…
> Apple will revoke Sunbird’s access How do your expect that they will do this? IIUC they are basically logging in to real Apple hardware with the users credentials. There is nothing concrete that can be used to identify these sessions. (Obviously things like shared IPs, reused machines and other patterns can be used, but these aren't 100% accurate). That being said it surprises me that this can be profitable. If the…
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#100>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…
> Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early access reviewer raised these exact security concerns in public? Why are we blaming PMs, here? Plenty of engineers out there make really stupid decisions every day. (To be clear: I'm an engineer, not a PM.)