43 ms·
Show HN: Beeper Mini – iMessage client for Android
Hi HN! I’m proud to share that we have built a real 3rd party iMessage client for Android. We did it by reverse engineering the iMessage protocol and encryption system. It's available to download today (no waitlist): https://play.google.com/store/apps/details?id=com.beeper.ima https://play.google.com/store/apps/details?id=com.beeper.ima and there's a technical writeup here: https://blog.beeper.com/p/how-beeper-mini-works https://blog.beeper.com/p/how-beeper-mini-works.
Unlike every other attempt to build an iMessage app for Android (including our first gen app), Beeper Mini does not use a Mac server relay in the cloud. The app connects directly to Apple servers to send and receive end-to-end encrypted messages. Encryption keys never leave your device. No Apple ID is required. Beeper does not have access to your Apple account.
With Beeper Mini, your Android phone number is registered on iMessage. You show up as a ‘blue bubble’ when iPhone friends text you, and can join real iMessage group chats. All chat features like typing status, read receipts, full resolution images/video, emoji reactions, voice notes, editing/unsending, stickers etc are supported.
This is all unprecedented, so I imagine you may have a lot of questions. We’ve written a detailed technical blog post about how Beeper Mini works: https://blog.beeper.com/p/how-beeper-mini-works https://blog.beeper.com/p/how-beeper-mini-works. A team member has published an open source Python iMessage protocol PoC on Github: https://github.com/JJTech0130/pypush https://github.com/JJTech0130/pypush. You can try it yourself on any Mac/Windows/Linux computer and see how iMessage works. My cofounder and I are also here to answer questions in the comments.
Our long term vision is to build a universal chat app (https://blog.beeper.com/p/were-building-the-best-chat-app-on https://blog.beeper.com/p/were-building-the-best-chat-app-on). Over the next few months, we will be adding support for SMS/RCS, WhatsApp, Signal and 12 other chat networks into Beeper Mini. At that point, we’ll drop the `Mini` postfix. We’re also rebuilding our Beeper Desktop and iOS apps to support our new ‘client-side bridge’ architecture that preserves full end-to-end encryption. We’re also renaming our first gen apps to ‘Beeper Cloud’ to more clearly differentiate them from Beeper Mini.
Side note: many people always ask ‘what do you think Apple is going to do about this?’ To be honest, I am shocked that everyone is so shocked by the sheer existence of a 3rd party iMessage client. The internet has always had 3rd party clients! It’s almost like people have forgotten that iChat (the app that iMessage grew out of) was itself a multi-protocol chat app! It supported AIM, Jabber and Google talk. Here’s a blast from the past: https://i.imgur.com/k6rmOgq.png https://i.imgur.com/k6rmOgq.png.
- ddxv 3y agoFirst they require email and personal info. Then they tell you it's a monthly subscription. Felt like a terrible onboarding experience and a bit of a dark pattern.
- mianos 3y agoIf you scratch around enough they do say it's a paid product. Pretty cool yes,"show hacker news"? Dunno.
- wills_forward 3y agoIs this part of the reason Apple decided to support RCS? They knew the iMessage system would get opened up eventually anyway...
- skygazer 3y agoDoes this mean it’s trivial to spoof iMessage from arbitrary phone numbers not already registered with iMessage, or hijack any non-iPhone users SMS messages by tricking the iPhones they communicate with to send replies via iMessage to the spoofer rather than SMS? If this is true, (edit: probably not true,) and I’m just speculating without specific knowledge, it seems Apple would shut this down for legitimate security reasons, and perhaps re-engineer things to prevent this.
- brenns10 3y agoI just tried out the app - an SMS challenge was sent to my phone number, and the app sends a response via SMS. By challenge, I mean there's several fields with encoded data (not just a 6-digit OTP). I have no idea how it's implemented by Apple but I'd hope there's some sort of expiry time. I'm sure they've thought of SIM-swapping as a way to take over people's accounts.
- skygazer 3y agoDoes that challenge seem to come from Apple or Beeper? I hope Apple. That would largely allay my concern. I guess I should have given Apple more credit, because this “vulnerability” would likely have come to light much earlier otherwise, as they’ve always needed reliable means to establish ownership of a number — it’s just been automatic and invisible on the iPhone.