8 ms·
>Apple on Wednesday appeared to have blocked what Beeper described as "~5% of Beeper Mini users" from accessing iMessages >Apple previously issued a (somewhat
by NettleBurr 3y ago
>Apple on Wednesday appeared to have blocked what Beeper described as "~5% of Beeper Mini users" from accessing iMessages
>Apple previously issued a (somewhat uncommon) statement about Beeper's iMessage access, stating that it "took steps to protect our users by blocking techniques that exploit fake credentials in order to gain access to iMessage." Citing privacy, security, and spam concerns, Apple stated it would "continue to make updates in the future" to protect users. Migicovsky previously denied to Ars that Beeper used "fake credentials" or in any way made iMessages less secure.
Not commenting about the ethics of all this, just wondering why technically Apple can only block ~5% of Beeper Mini users instead of all of them? Could this potentially be tied to the use of an email id as the iMessage handle?
- user_7832 3y ago> Not commenting about the ethics of all this, just wondering why technically Apple can only block ~5% of Beeper Mini users instead of all of them? Could this potentially be tied to the use of an email id as the iMessage handle? I wonder if it might also have anything to do with govt action. I believe a US elected rep recently tweeted in favour of Beeper. Apple cares much more about PR than they'll admit, and server costs for them are negligible.
- nozzlegear 3y agoThe rep was Senator Elizabeth Warren, who was once pretty popular during the Obama years when she helped create the CFPB. She sadly doesn’t hold much sway (e: in the senate) anymore.
- I_Am_Nous 3y agoSeems like a chess move. Apple blocks a small percentage of users instead of all of them, which casts uncertainty on using Beeper Mini at all. It also allows them to A/B test various methods of blocking or honeypotting Beeper Mini logins without giving away any big secrets. From Beeper's perspective, they now have to figure out why only those logins were blocked and if they need to patch something or not. Apple could be wasting their time and blocked random users out of spite. Time will tell.
- MuffinFlavored 3y agoMy bigger question is how are any Beeper Mini users getting through (aka how is Beeper Mini's backend getting around the fact that... I thought you needed a valid serial # to an Apple device specific to you to log in + use iMessage)
- dylan604 3y agoat some point Serial Box will have a list of valid/invalid hardware serial numbers. or, someone will crack the code to generate valid codes. oh wait. i drifted off back to the 90s software cracking days.
- MuffinFlavored 3y agoif apple checks an online database for "you authenticated and paired this hardware ID to this apple ID", is that a "Beeper Mini" killer?
- rezonant 3y agoWhat about when the hardware is legitimately sold and reset and a new Apple ID starts using it?
- chongli 3y agoYou have to de-register the device with Apple when you sell it. Otherwise you retain the ability to remote wipe and brick the device and the buyer has no recourse. After you de-register it the buyer can register it with Apple under their Apple ID.
- dylan604 3y agoisn't that essentially what they are doing? that's one of the reasons a stolen iDevice is pretty much worthless.
- Wingy 3y ago
- turquoisevar 3y ago> Not commenting about the ethics of all this, just wondering why technically Apple can only block ~5% of Beeper Mini users instead of all of them? Could this potentially be tied to the use of an email id as the iMessage handle? Apple could block 100% of the people using Beeper and throw Hackintosh users into that as a bonus as well. The reason they’re not doing that is because it could have unintended consequences as some are using someone else’s actual device serial number and those people would be inconvenienced. It’s nothing that can’t be easily solved, the moment they reach out to support either in person or via phone/chat Apple can immediately verify if they’re using a legitimate Apple device, but even if it boils down to a small percentage of users you still need to prepare for the influx of support requests. To do this, Apple uses a scoring model to determine if they can access iMessage and historically they’ve been pretty generous by allowing clearly spoofed serials if the Apple ID involved is in good standing and has a positive history, think of it as a credit score. They can tweak the threshold score and probably are testing this out as we speak to find a sweet spot they’re content with. Apple could also push out an update tomorrow that would end this once and for all by utilizing device attestation and leveraging Secure Enclave, but this would potentially lock out older devices, something they were willing to do when they upgraded the FaceTime protocol a couple of years ago, but they might not want to do that this time around.
- tremon 3y ago[flagged]
- beeboobaa 3y ago> Apple could also push out an update tomorrow that would end this once and for all by utilizing device attestation and leveraging Secure Enclave More proof that Remote Attestation is evil and does not exist to serve the user.
- deleted 3y ago[deleted]
- mngdtt 3y agoAs a user, I am very well served by remote attestation when it is used to stop cheaters in videogames or spammers in messaging platforms.
- jimmyk2 3y agoMight be intentional. Unreliable service is probably worse as a user. Never know if the system is down or if it’s just you. Plus probably harder for beeper to work out how/why they are getting blocked.
- MuffinFlavored 3y ago> Migicovsky previously denied to Ars that Beeper used "fake credentials" As far as I know (I could be wrong), in order to log in + auth to Apple's various protocols that are involved to make iMessage work, you need a valid Apple ID and some sort of valid hardware ID. If you don't have either of those, how would you be talking to Apple's services? If their POST /login requires email + password + valid registered serial # of device sold that isn't flagged stolen and not shared across 100 accounts... how does Beeper Mini expect to work?
- saintfire 3y agoAFAIK, and I could be wrong, beeper mini registers a new HWID with apple for each phone. Which is why they thought it was unpatchable, at first, as they would need to determine which phone is in fact an iPhone.
- nneonneo 3y agoThere's much more to the validation protocol than just HWID/serial. See https://github.com/JJTech0130/pypush/blob/main/emulated/data.plist https://github.com/JJTech0130/pypush/blob/main/emulated/data... for a list of the data that is pulled from the platform and used for validation. I would assume that Beeper registrations either use data from a pool of real devices, or made-up data that Apple might "permit" (because hackintoshes) but can definitely detect and block at any time.
- MuffinFlavored 3y ago> use data from a pool of real devices This feels super against terms of services. Taking a paying Apple user's hardware ID and using it for a non-paying user? Also, I thought you had to tie/pair hardware ID to Apple ID.
- hackernewds 3y agoblock 5% for experimentation data to observe whether it's net viable for their metrics to allow cross-pollinating the users finally