11 ms·
> "if Apple truly cares about the privacy and security of their own iPhone users, why would they stop a service that enables their own users to now send encrypt
by Grustaf 3y ago
> "if Apple truly cares about the privacy and security of their own iPhone users, why would they stop a service that enables their own users to now send encrypted messages to Android users, rather than using unsecure SMS?" - Eric Migicovsky
1. If Apple sees this as a gap, it is very obvious that they would address that themselves, rather than by allowing a hack to exploit loopholes in their architecture
2. Since Apple has no control over the Beeper mini client, they would not consider it safe, it could easily be spying on users without their knowledge.
- CivBase 3y ago> 2. Since Apple has no control over the Beeper mini client, they would not consider it safe, it could easily be spying on users without their knowledge. Since I have no control over iMessage, I would not consider it safe. It could easily be spying on me without my knowledge.
- diligiant 3y agoThe basic assumption here is trusting Apple, provided that numerous security researchers have access to the platform. If you don't trust Apple, don't buy their products.
- 0cf8612b2e1e 3y agoIt’s a two party marketplace. Even if I don’t like Apple, the alternative is not great either.
- judge2020 3y ago"they would not consider it safe" is from Apple's perspective, which is the only thing that matters when Apple is the steward of legally and technically enforcing who can use their APIs.
- CivBase 3y agoSure. They have every right to do what they're doing. I'm just mocking Apple because I think their implication that they're the only trustworthy entity is ridiculous. We have no reason to trust them any more than we do Beeper or any other company. If Apple actually cared about security they'd implement an open protocol that is provably secure. Imagine if they supported something like Matrix. But that's clearly not their primary concern here. It's just a convenient excuse to maintain their walled garden.
- addandsubtract 3y agoWhich is why most people (should) opt to use a cross platform messenger, such as Signal.
- SahAssar 3y agoIf signal would officially allow third party clients, non-phone-number-bound users and maybe federation that'd be great. It does not.
- anigbrowl 3y agoSignal does allow third party clients, Beeper is one. I agree about other things, and would expand on the list.
- SahAssar 3y agoThey do not officially and discourage it. Moxie and the rest of the company has been extremely clear that all third party clients are not considered supported or allowed, regardless if they can and do interact with signal services.
- anigbrowl 3y agoUseful (though somewhat dispiriting) to know. I would feel a lot more forgiving toward Signal's UI shortcomings if I had a choice of alternative front-ends.
- kccqzy 3y agoDoes iMessage allow third party clients? No? Then why the double standard?
- SahAssar 3y agoI'm saying that if we hold something to a higher standard lets actually hold them to a higher standard. Is signal better than iMessage? Probably. Should we ask for them to be better than they are? Yes.
- Grustaf 3y agoAs pointed out below, "they" is Apple, but I would also assume that at least 99.9% (really) of users would trust Apple more than Beeper, i they had to choose.
- cqqxo4zV46cp 3y agoLet’s add a few more 9s to that, just to make it even more realistic.
- willseth 3y agoIf you don’t trust Apple, then obviously you don’t use it. If you do, then it shouldn't be possible for a 3rd party client to break that trust. Users only see iMessage vs no-iMessage and have no other way to identify the client to decide for themselves whether to trust it.
- johnbellone 3y agoNot what he said. He said he doesn’t trust them (safe). The question you should be asking is why do you?
- cqqxo4zV46cp 3y ago[flagged]
- vGPU 3y agoBecause they’ve proven to be the most trustworthy and if you can’t trust the manufacturer of the device and OS you also can’t trust any app running on said hardware.
- thomastjeffery 3y ago> If you do, then it shouldn't be possible for a 3rd party client to break that trust. A correctly implemented end-to-end encrypted protocol would be safe for all participating clients. The only way to break that security is by copying messages outside the protocol in the app itself. Neither of us knows whether iMessage or Beeper Mini does this. To bring up the possibility is to criticize both apps equally.
- willseth 3y ago> A correctly implemented end-to-end encrypted protocol would be safe for all participating clients. As long as the clients are closed source, this is a circular argument. The client itself is a vector. Not just for a good E2E implementation but for the 3rd party company to not outright steal everyone’s messages, create a backdoor, etc. You have to be willing to trust every client used in the thread.
- verandaguy 3y ago> Since I have no control over iMessage, I would not consider it safe. Generally fair assumption. There's been some research (both positive and negative) around their E2EE claims, though AFAIK much of what's known about iMessage's E2EE guts has been learned through unofficial means. I think that for the vast majority of users, iMessage is probably safe enough. As a user, you have the agency to choose a messenger app that better suits your privacy/convenience balance, though in fairness, I think even among users who care about privacy, many don't know how to judge privacy features and implementation details well. Like others in this thread, I personally recommend Signal. It's widely available, easily usable, has been audited and researched a fair bit, and though it doesn't have a self-hosted option, it does have white papers out about its protocol which IMO are worth a read.
- Grustaf 3y ago> Since I have no control over iMessage, I would not consider it safe. I would trust iMessage about 95% less if I had written, or even implemented, the protocols myself, and I consider myself a pretty good developer.
- CivBase 3y agoIf I'm expected to believe a messaging app is secure, the first thing I want is an open protocol. An open source client would be nice too, but honestly I'm fine with just the protocol. I do not need to have had a hand in developing any of this. It's not my expertise and, like you, I'd feel more comfortable having it developed by the experts.
- LordDragonfang 3y ago(1) is exactly what that quote is pointing out. If Apple actually cared about its users' security, they would see this as a gap, and would have addressed it already. The fact that they haven't means that, despite all their posturing about being a security-first platform, they care more about lock-in and marketing than they do about user security.
- robertoandred 3y agoAn intentional gap? Or a bug that they've now fixed?
- Dylan16807 3y agoFixing this bug leaves the gap intact.
- Grustaf 3y agoIt's a pretty indirect gap, since it has nothing to do with Apple's infrastructure, it's about users choosing to interact with users of non-Apple platforms using insecure means. There are dozens of secure cross-platform messenger apps that they could be using, and SMS is a legacy technology.
- georgespencer 3y agoPutting aside that I count at least two glaring examples from this list[^1] in your reply, I suspect Apple would argue that it is in fact _solely_ preoccupied with its users' security: that's why iMessage is end to end encrypted and Apple does not offer 2FA / OTPs via SMS. Apple does not generally try to mitigate security issues which are beyond its control (e.g. non-Apple devices, protocols). [^1]: https://en.wikipedia.org/wiki/List_of_fallacies https://en.wikipedia.org/wiki/List_of_fallacies
- jeroenhd 3y ago> and Apple does not offer 2FA / OTPs via SMS Last time I checked, Apple still used security questions any hacker can get answers to on Facebook. I'm not all that confident about Apple's approach to account security. Apple has the ability to control security issues on Android: they can release an Android app, like every other E2EE messenger out there. Apple chooses not to, and it's their choice, of course. It doesn't care about the privacy of it's non-users, and it doesn't care about the privacy of its users when they communicate with non-users. From what I can tell, it only cares if you stay within the Apple bubble.
- maxlin 3y agoSince apple has no control over your fire extinguisher, they sent a man to securely take it from your house and dispose of it. It could have been a bomb for all you know.
- vosper 3y agoExcept that the iMessage system belongs to Apple, not to you > The app doesn’t connect to any servers at Beeper itself, only to Apple servers, the way a “real” iMessage text would. https://techcrunch.com/2023/12/05/beeper-reversed-engineered-imessage-to-bring-blue-bubble-texts-to-android-users/ https://techcrunch.com/2023/12/05/beeper-reversed-engineered...
- georgespencer 3y agoDo you really consider Apple's control over a proprietary protocol which they invented and maintain to be comparable to a scenario in which Apple "sends a man" to take "your fire extinguisher […] from your house"? I've re-written this comment five or six times in an attempt to find the most charitable interpretation, but I just cannot comprehend how it made it through your filter and out onto the internet.
- iAMkenough 3y agoThere's an open standard they're refusing to adopt that would be more secure than forcing users back to SMS.
- Hamuko 3y agoAre you referring to the one that they're adopting?
- georgespencer 3y agoApple is adopting RCS, but as far as I can tell your reply has nothing whatsoever to do with my comment.
- kamilner 3y ago
- CharlesW 3y agoKeep in mind that this is spin — Erik's statement is ridiculous, and he knows it. To think that Apple would somehow not treat Beeper like any other bad actor hacking iMessage protocols is delulu.
- Grustaf 3y agoSure, that's fair. But if he knows that, why spend the time to build this app in the first place? Is it a marketing play? It did buy them a whole lot of attention.
- lisper 3y ago> It did buy them a whole lot of attention. Ding ding ding! We have a winner!
- deleted 3y ago[deleted]
- cqqxo4zV46cp 3y ago[flagged]
- pjz 3y agoBesides the obvious attention play, he might be going for an acquisition play... "Why bother writing our own iMessage for Android when we can just buy this little company that's already done it?" There's obvious issues with that plan, but that doesn't keep delusional founders from being delusional.
- paulryanrogers 3y agoApple chose not to support Android on purpose. They know iMessage exclusivity drives hardware sales. The emails have come out proving as much. It's the same reason they dragged their feet supporting RCS, until regulatory pressure started mounting.
- 3y ago
- foobiekr 3y agoSpam. Spam is the reason and the Beeper guys know it.