4 ms·
> how do they solve it? Release iMessage on Android. If there is a concern that it wouldn't be secure with Google controlling it, then they could put it out on
by hornban 3y ago
> how do they solve it?
Release iMessage on Android. If there is a concern that it wouldn't be secure with Google controlling it, then they could put it out on F-Droid, which would simultaneously prove that they're serious and also undermine Google's own efforts at controlling the culture war.
- mthoms 3y agoBut then they wouldn’t be able to claim that alternative app stores are bad for consumers.
- antiframe 3y agoThe presupposition was "let's assume it was an engineering problem, how would they solve it". Obviously we can revert it back to a business choice rather than engineering problem rather trivially.
- stouset 3y agoPart of the iMessage security model is that devices are attested. Without this, the service as-is becomes widely open to spam and other forms of abuse. Yes, there are other solutions to the spam problem. They are nowhere near as effective as what I’ve witnessed as an iMessage user so far. I regularly get spam chats on WhatsApp and Signal.
- viraptor 3y agoAs we know, the devices are not attested, because beeper works. They're also not attested on old iPhone versions which are valid iMessage parties. Some new devices being bound to the hardware key doesn't change that. Spam doesn't matter here - same app is used for SMS, which gets spam, so there's nothing new here. But if Apple wanted to, they'd just sort out a deal that allows hardware signing of iMessage accounts on Android. That's not an unfixable problem.
- klausa 3y ago>As we know, the devices are not attested, because beeper works. This argument doesn't make any sense. They managed to figure out a way to create valid attestation data via old Apple binaries. Just because a security (well. "security") measure was circumvented, doesn't mean it doesn't exist at all.
- CuriousCosmic 3y agoSoftware attestation of hardware is just pointless anti-competitive behavior. Hardware Attestation however can have an actual security benefit. If beeper was able to attest without hardware, Apple isn't doing hardware attestation and it's therefore just anti-competitive.
- deleted 3y ago[deleted]
- judge2020 3y agoFrom the way I see it described here, it's more in-depth hardware attestation on newer models. So they're doing the good security thing here, but also not making millions of users' lives worse by outright blocking old phones that don't have the necessary hardware features to perform this attestation. x (5? 15?) years in the future they'll block super old stuff that doesn't meet these security requirements.
- viraptor 3y agoThat's not how it works. Beeper uses the old binaries, because those come from older iPhones where the hardware signing was not possible yet. It's not circumventing anything as far as I understand, just connecting the way an older iPhone would connect.
- klausa 3y agoI mean, we're splitting hairs on terminology here I feel like? Apple does not want you to connect to iMessage with non-Apple hardware and Beeper uses old Apple binaries to let you do just that. That, to me, does fall under the umbrella term of "circumventing" some measures that Apple put in place to stop you from doing that; but I guess I can see the point where you'd object to use of that word?
- bmicraft 3y agoI've not received a single spam message on Whatsapp or Signal for as long as I can remember.
- skibbityboop 3y agoSame, in years and years of use, never a single spam message.
- j16sdiz 3y agoI got lots spam on WhatsApp, None on signal. Guess it's local issue?
- ycombinatrix 3y agoi've gotten spam on signal
- aspenmayer 3y agoWas it from a number with the same area code as your Signal number? What was the spam for? Care to share the message if you still have it? I research around spam as a hobby. Email is in my bio if needed. Thanks in advance.
- stouset 3y agoI always delete it, but 100% of it is cryptocurrency scams. I have not participated in any cryptocurrency-related groups, so I have always assumed it’s just random.
- scrubs 3y agoDitto. Add signal. Never
- marcus_holmes 3y agoSame. Travelled all round the world for years using WhatsApp for local comms and Signal for long-term relationships, and never had spam on either.
- deleted 3y ago[deleted]
- cozzyd 3y agoDoes f-droid allow non-open source apps?
- nani8ot 3y agoNo, F-Droid builds almost all apps from source. Even some open source apps don't make it to F-Droid if the F-Droid maintainer doesn't manage to build it themselves on their build server. Additionally, F-Droid signs every app themselves. [1] https://f-droid.org/docs/Building_Applications/ https://f-droid.org/docs/Building_Applications/
- j16sdiz 3y agoThis make them a nice target for malware injection. edit: When the signing is in single entity like f-droid, we have single point of failure. When everybody sign their own app, we have trust scalability issues -- "trust" just can't scale to everybody.
- wkat4242 3y agoThe reason F-Droid does this is reproducible builds. Which is a big advantage because the code you see on GitHub is the binary you get in your device. It also means it's quite obvious when code is being added because you can reproduce it. Of course the build platform being compromised is possible but that can happen even with binary distribution.
- extraduder_ire 3y agoI thought they only allow you to guild/sign your own apps if it is a reproducible build, and they verify that the version they build is identical to the one you supply.
- extraduder_ire 3y agoYou can add a repository containing whatever apps you want.