Apple cuts off Beeper Mini's access
921–930 of 1001 posts
Re: Apple cuts off Beeper Mini's access
#922Earlier quoted context omitted.
We've really done one over on ourselves by adopting the mental model that only a vertically integrated corp can deliver privacy and security to users. This rigid tendency towards homogeneity is bound to suffer a tragic systemic failure before too long. It would be healthier to assume multi-polarity and lean into it.
> We've really done one over on ourselves by adopting the mental model that only a vertically integrated corp can deliver privacy and security to users. This rigid tendency towards homogeneity is bound to suffer a tragic systemic failure before too long. Look no further than the other news that came out this week re: government spying via push notifications. ( https://www.reuters.com/technology/cybersecurity/governme…
People might want to think about how AirTags and Find My Phone work...
Re: Apple cuts off Beeper Mini's access
#923As usual, Gruber was right on the money. Via Threads yesterday: "My prediction is that Apple will make changes—fixing bugs and/or closing loopholes—that break Beeper Mini. It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. It’s a very nice app, remarkably clever, and for now works like a charm, but if Apple wanted an iMessage client…
>It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. I don't follow this logic at all. Shouldn't supporting thirdparty clients be desirable if security is a primary feature in the interest of transparency? Especially if the reference client is proprietary and undocumented.
Re: Apple cuts off Beeper Mini's access
#924This was the obvious outcome. People were being willfully blind about how this "hack" works. Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate A…
Re: Apple cuts off Beeper Mini's access
#925Re: Apple cuts off Beeper Mini's access
#926Earlier quoted context omitted.
Hacking? Hacking means whining when what you are hacking fights back? I mean go for it, hack away! I hope apple keeps android far far away from me though lol
> I hope apple keeps android far far away from me though What a bizarre thing to say.
Re: Apple cuts off Beeper Mini's access
#927Earlier quoted context omitted.
Hacking? Hacking means whining when what you are hacking fights back? I mean go for it, hack away! I hope apple keeps android far far away from me though lol
Personally for me it's people who buy Frigidaire appliances. They are the worst!
Re: Apple cuts off Beeper Mini's access
#928This was why I never shared my iMessage for Windows: https://neosmart.net/blog/imessage-for-windows/ They’d block an account out of spite without a second thought.
Re: Apple cuts off Beeper Mini's access
#929No less than 18(!) of them:
* ads-twitter.com
* bizzabo.com
* dscg1.akamai.net
* facebook.net
* google-analytics.com
* googlesyndication.com
* googletagmanager.com
* mrf.io
* oath.com
* sail-horizon.com
* twitter.com
* twitter.map.fastly.net
* typekit.net
* vidible.tv
* wp.com
* yahoo.com
* yahoodns.net
* yimg.com
There's also two (!) layers of cookie consent redirects and the page simply will not load without JavaScript.
Even with first-party scripts enabled the main article doesn't load and at this point I don't give enough of a shit to work out why.
@dang should consider banning Techcrunch URLs from Hacker News IMHO.
Re: Apple cuts off Beeper Mini's access
#930Earlier quoted context omitted.
> We've really done one over on ourselves by adopting the mental model that only a vertically integrated corp can deliver privacy and security to users. This rigid tendency towards homogeneity is bound to suffer a tragic systemic failure before too long. Look no further than the other news that came out this week re: government spying via push notifications. ( https://www.reuters.com/technology/cybersecurity/governme…
I suspect there's more where that came from. The only reason we learned of this, is because the cat was let out of the bag, and Apple was able to talk about it (gag order). People might want to think about how AirTags and Find My Phone work...
rotating BTLE identifiers controlled by a pseudorandom sequence derived from a key, and tunneled over end to end encryption?