8 ms·
I saw an article on the topic where the reporter spoke with Beeper's CEO, Eric Migicovsky. He seems to believe that blocking Beeper might cause problems for leg
by chipgap98 3y ago
I saw an article on the topic where the reporter spoke with Beeper's CEO, Eric Migicovsky. He seems to believe that blocking Beeper might cause problems for legitimate Apple user's.
Obviously that outcome is something he wants, but I still think its interesting.
[0]: https://www.theverge.com/2023/12/5/23987817/beeper-mini-imessage-android-reverse-engineer https://www.theverge.com/2023/12/5/23987817/beeper-mini-imes...
- BowBun 3y agoIt's not too hard to think through - They would need to accept and verify a flag from messages that the copycats can't reproduce. At the very least that would require a client update from anyone using official iMessage clients, which covers many millions of devices. Unless they're able to hook into already existing flags/keys on the devices since they already verify application signatures and a whole other host of things. Apple can probably do it, but much like jailbreaking how fast can they release breaking changes?
- IshKebab 3y agoThey could probably require a new check but whitelist already registered numbers.
- afavour 3y agoThat would make sense: because Apple have deeply coupled iMessage to the OS they can’t simply roll out a new version of the app with protocol changes that would block Beeper, they’d have to release entire OS updates. No matter the method it would be a scorched earth approach. I suspect the number of people actually using Beeper will be far below a rounding error for Apple.
- crystaldecanter 3y agowill iMessage Contact Key Verification coming in iOS 17.2 break Beeper — or just make it super annoying like the “not a genuine Apple part” warning when replacing a screen or battery
- nebula8804 3y agoUptake for OS updates is very high on iOS though right? I heard a while back that it is like 90+% in 6 months. (could be totally wrong on that can someone confirm?)
- afavour 3y agoThere’s a ton of devices out there unable to upgrade to the latest iOS. Obviously you can release point upgrades for old versions but I do wonder what the uptake of those is like. I’d wager there are a ton of very old iOS devices out there. At the very least many more than there are potential users of Beeper.
- dylan604 3y agoanecdote of 1, but i have a 6S+ that is kept up with any updates it receives which is 15.8. there maybe some devs that have older devices that they intentionally keep at even older versions, but if someone is using an old iDevice as a daily driver, they're probably still more likely to run the updates. at least, that's my reaches up and grabs for an opinion
- pashky 3y agoUptake of updates is, uptake of devices isn’t. Here I have 1st gen retina iPad from 2012 which is on the latest iOS available for it - 9.3.5 (from 2016, current version is 17.1.2). As of today FaceTime and iMessage still work perfectly fine. That and reading the books is actually about the only thing it can do right now.
- jotux 3y agoI'm not that familiar with ios apps, can they not push out updates to individual apps?
- matthew-wegner 3y agoNot the OS-included ones, afaik. Some Apple apps are through the AppStore normally, which can be updated independently (i.e. TestFlight, despite its deep hooks).
- philsnow 3y agoWhy did google break out Google Play Services as a separate app, was that when they started integrating more with third-party android phone suppliers, and they didn't want to have to wait for OS upgrade cycles from slower-moving companies?
- derefr 3y agoProbably they originally did it because Android has high-assurance embedded use-cases (compare/contrast: Windows IoT Core) where you want to strip out everything possible from the attack surface. But mainly it's because base Android (AOSP) can be arbitrarily modified by the OEM; and Google doesn't want to have to trust installations of Google Play Services that have been arbitrarily modified by OEMs. (Especially because those versions would likely all act differently-enough from one-another that they would be forced to loosen their server-side, network-traffic-fingerprint-based "authentic Android device" detection that allows them to ignore/block bots pretending to be Android devices.) By shipping Google Play Services through the store, they can ensure that, on devices that run it, it's exactly the same code for every device that runs it, with no OEM alterations. (And they can also include various checks to reject devices that would try to alter that code at load time. This is the real reason why e.g. Huawei devices are blocked from using Google Play Services — they try to patch unspecified parts of the Play Services code while loading it, "breaking the integrity of the platform" from Google's perspective.)
- 3y ago
- lxgr 3y agoNon-Apple legitimate users aren't the only concern for Apple: Once third-party clients are readily available, this makes spam much harder to filter. Right now they can probably just ban known-spam-originating devices, which is much more effective than banning iCloud accounts since there is a much higher cost to the spammers.
- threeseed 3y ago> because Apple have deeply coupled iMessage to the OS No they haven't. On my Mac it's just an app and a reusable framework. There is nothing stopping them releasing it on the App Store similar to Mail.
- afavour 3y agoI’m talking about the iPhone.
- threeseed 3y agoMessages is the same on OSX and iOS. It's not deeply integrated into the iOS by any normal definition. It's just shipped together.
- andygeorge 3y agofwiw it hasn't been called "OSX" for awhile now
- lotsofpulp 3y agoThe Messages app in macOS is less capable than the Messages app in iOS. It cannot even edit sent messages.
- a_carbon_rod 3y agoIt can, by right clicking the desired message to edit. This is in macOS Sonoma, and I believe was a part of Ventura as well.
- lotsofpulp 3y agoOh interesting, I have a 2015 MacBook Air. Wonder if the feature is not available on whatever macOS version I have.
- 3y ago
- dylan604 3y agoYou say this like Apple doesn't release OS updates. Why are you putting that as some arbitrary limiter to what Apple could do to protect its walled garden?
- 1231232131231 3y agoThey don't usually remove features as important as iMessage from older iOS versions. I don't believe they push updates to the iPhone 7 and older anymore, so they'd be unable to use iMessage.
- dylan604 3y agoI have a 6sPlus, and messages work just fine, and it may not be iOS 17, but I recently-ish ran an update for its OS that Apple deliberately updated (which you just know must have been an important update). You can stop making stuff up now
- deleted 3y ago[deleted]
- mattgreenrocks 3y agoWhat's brilliant is they get press either way this goes down.
- dylan604 3y agoi understand no such thing as bad news/publicity, but if the 800lb gorilla squashes the little guy, then that's some pretty bad news. with the recent Twitt...er,X and reddit debacle with 3rd party apps, that 800lbs is pretty powerful when it wants to be edit, because i used the wrong turn of phrase
- tekknik 3y agois it powerful? In both cases X and reddit, nothing meaningful happened. Apple could block any device without attestation then offer a discount for those on old products to upgrade. Now bad news is good news.
- hedgehog 3y agoApple maintains iMessage compatibility with devices that are long out of support, if Beeper Mini is sufficiently similar to the client in for example iOS 12 then it makes an Apple decision to break Beeper fairly expensive. Even if they do the work to publish iMessage updates for the old iOS versions it just buys a little time before the new version gets reverse engineered, and that at the cost of poor user experience for the people with those devices in a form they will directly blame on Apple. Given all that I suspect he's right.
- hedgehog 3y agoLooks like Apple figured out a way to identify Beeper clients: https://techcrunch.com/2023/12/08/apple-cuts-off-beeper-minis-access-after-launch-of-service-that-brought-imessage-to-android/ https://techcrunch.com/2023/12/08/apple-cuts-off-beeper-mini...
- lxgr 3y ago> Even if they do the work to publish iMessage updates for the old iOS versions it just buys a little time before the new version gets reverse engineered There's probably a cliff in complexity. Once Apple starts requesting signed attestations from the secure enclave on the devices that have one, it's game over. They probably don't just yet, since still too many people use iMessage on first-party clients that don't have one, e.g. Intel laptops without a T1 or T2.
- ttul 3y agoIf Apple does start enforcing signed attestations, they will say that it's to reduce abuse. I have no doubt (being in the anti-abuse world) that spammers and phishing gangs will immediately begin using Beeper to spam iMessage users because this allows them to avoid buying an iOS device. With end-to-end encryption, Apple may also decide to roll out privacy-protecting client-side spam and phishing detection, which would IMHO be a really great thing.
- solardev 3y agoMaybe Apple needs an even blue-r bubble to set apart the super attested users from the mere blue bubble peasants