Nothing's iMessage app was a security catastrophe, taken down in 24 hours
1–10 of 147 posts
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#2Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#3Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early access reviewer raised these exact security concerns in public?
It's the one thing you had to make sure was air-tight, especially considering the raised eyebrows and extra scrutiny you'll get from security researchers when they see something as juicy as "iMessage on Android". Any security issue on launch day/week will get you nailed to the cross and bury your credibility for good.
How do these managers get jobs in these big name companies? You could have at least hired a third party for a pen-test/security audit before the big launch. It's the best way to uncover shoddy dev and security practices that creep in when you're crunching to get something out the door by launch day.
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#4Wow! How do such fundamental errors make it into these apps? Did _nobody_ who was working on it have an previous experience? Or is this another case of upper management ignoring the experts and pushing terrible ideas regardless?
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#5>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#6>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…
It really does beggar belief. I’d love to do interviews with the team, I’ll bet somebody knows why this happened, even if they’re not eager to talk about it.
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#7Beeper seems a lot better then. Based on Matrix, so at least you know there is a foundation of security there.
Obviously they can still make better decisions than these guys - don't write confidential data to your logs! Don't unencrypted HTTP APIs! But unless the gateways to the 3rd party services run locally, you will never have end to end security.
Edit: Beeper has published their bridges as open source, so you could self-host it. That would at least give you full control of the stack. https://github.com/beeper/self-host
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#8>"Sunbird actually logged and stored messages in plain text on both the error reporting software Sentry and in a Firebase store. Authentication tokens were sent over unencrypted HTTP so this token could be intercepted and used to read your messages" Which product manager in his/her right mind, thought this was passable when you're building and marketing your product as an iMessage alternative and every single early a…
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#9Beeper seems a lot better then. Based on Matrix, so at least you know there is a foundation of security there.
I don't think Beeper can promise end to end encryption for 3rd party services either. Fundamentally if you're interfacing with a service like iMessage or Whatsapp - even if they offer end to end encryption - the message has to be decrypted and then sent to the 3rd party app. Unless that gateway is running on your phone, the messages have to be decrypted in the cloud somewhere. At that point, you are placing all your…
EDIT: forgot to add that there are several beeper specific MSC's that other clients don't render, thus if you want the full experience you either use their service or just stick with a normal matrix instance.
Re: Nothing's iMessage app was a security catastrophe, taken down in 24 hours
#10> Authentication tokens were sent over unencrypted HTTP Wow! How do such fundamental errors make it into these apps? Did _nobody_ who was working on it have an previous experience? Or is this another case of upper management ignoring the experts and pushing terrible ideas regardless?