8 ms·
Sweet, they open sourced their iMessage connector. I was shocked to see that Apple is using Hashcash in their oauth header! (I see now hashcash.js when I login
by FriedPickles 3y ago
Sweet, they open sourced their iMessage connector. I was shocked to see that Apple is using Hashcash in their oauth header! (I see now hashcash.js when I login on the website too). I assume this is to make password testing more expensive, and probably explains why I've never had to bother with a captcha when logging into an Apple ID.
https://github.com/beeper/imessage/blob/2c45fc5619cbc33f2441cb07fedb3ca18604ee89/imessage/appleid/hashcash.go https://github.com/beeper/imessage/blob/2c45fc5619cbc33f2441...
- gorkish 3y agoThanks for pointing out the use of Hashcache. Since there are many projects apparently using this name, for anybody else like me wanting to search it up, it's the proof of work one: https://en.wikipedia.org/wiki/Hashcash https://en.wikipedia.org/wiki/Hashcash
- manmal 3y agoFor anyone interested, mCaptcha is a drop in solution: https://mcaptcha.org/ https://mcaptcha.org/
- khaki54 3y agoIt looks like beeper published most of the code at this point. Would be funny if Samsung or Google built it into the native messaging app. They have the resources to continually torture apple. The problem is Samsung and Google have deep enough pockets to try to sue.
- rootusrootus 3y ago> They have the resources to continually torture apple Why is this something we should want? And what gives Samsung and/or Google any sort of high ground position against Apple?
- ljm 3y agoIt's fascinating that this boils down to the US market using the iPhone's default message app and social status being assigned to the colour of your bubble. Everywhere else you'll have people on Whatsapp, Signal, Telegram and FB Messenger. I don't have a single friend in the UK or Europe that uses SMS or iPhone messages. The default message app is basically just a spam bucket for automated texts and 2FA codes.
- bloppe 3y agoYa, it's mainly a US problem. And it should be the domain of antitrust regulation. But, American regulators probably won't get around to it in the foreseeable future, so a little needling is good.
- abracadaniel 3y agoIs it even an actual status symbol, or is that just meme? FWIW, personally I've never met anyone who cared one way or another. Just heard people online say that others do. Similarly I can’t find anyone claiming they themselves see it as a status symbol.
- SeanAnderson 3y agohttps://www.wsj.com/articles/why-apples-imessage-is-winning-teens-dread-the-green-text-bubble-11641618009 https://www.wsj.com/articles/why-apples-imessage-is-winning-...
- talldatethrow 3y agoI'm 38 but date girls in their 20s. I would say that every single girl I've talked to has at one point mentioned/joked that I use an android. You can make of that what you will based on your world view. In my opinion, it is absolutely a slight negative to overcome. Tall +10 points. Fun cool car +5 points. Android -3 points.
- ljm 3y agoYou might consider that you're touching upon your 40s and you've chosen to date people almost 20 years younger than you, so you're just talking about the kids these days and not the attitudes of the people closer in maturity. Only it's the kids these days you're sleeping with.
- __MatrixMan__ 3y agoTorturing Apple is best for the common good so long as the torture stops if they open up their protocol: incentives towards good behavior.
- paulmd 3y agoThankfully this is the kind of thing where apples tolerance and forebearance will cease and the lawyers will come out. There really is clear cause for CFAA charges already, but the optics of doing this are not good against a small indie developer. This is not the case with google or Samsung getting onboard. Playtime is over, beeper was always gonna get squashed and apple played it incredibly well without turning it into more of a legal fight than they needed to. There are zero (0) services that are going to tolerate a third-party commercial service spoofing device credentials to get into a service that is very obviously not offered in the form they are offering. Discord will ban you for using Revanced too, even more aggressively than apple. Just imagine being some YC startup and some other service thinks they can use your email servers for spam and sues when you close an accidentally open relay lmao. It’s a facially absurd case when you remove it from the “apple bad” fervor surrounding every single apple article. Nobody is going to tolerate commercial third party operators using their infra for revenue operations. “Well they should have to too and —“ let me stop you there - no. Do you want open spam relays? That’s how you get open spam relays. Even with beeper it’s always been about the wave of spam that is going to be unleashed for the other legitimate users of the service. Spam as a service on other people’s infra is bad actually. It is, again, exactly that simple. It would be an absurd case if it were anyone besides apple but the unthinking hatred of android users is just that intense. All you can see is the carrot, and you really don’t care about the consequences or the precedent, this is an absurdly bad idea/argument. But that’s how android users react on every apple topic. It gets old. Open spam relays are not a good thing even if it means you stick it to apple. Imagine saying google has to run an open smtp relay just because they’re a gatekeeper. If somehow you managed to spoof googles server into thinking you were a google relay and started selling access to this as a commercial product they’d ban your ass too, in a literal heartbeat, but because of the constant unthinking bleating of the android fanboys it’s somehow an issue that needs to be discussed. No, you can’t do that and it it wouldn’t be a good thing if you could. Why is that even a question? Literally I am asking, why is that a legitimate thing anyone would ever argue other than blinding levels of fanboydom? It’s so noxious, it’s every damn apple thread. The value of green bubbles as a social filter has become very apparent to me after a number of these apple threads. I didn’t think that way before but I do now, there is another reason y’all ain’t getting invited to those chats. (Oops, naughty naughty, only green bubbles get to make sly little digs about the other sort.)
- ParetoOptimal 3y agoThe goal is breaking down the walled garden and moving towards open standards. Companies generally are against this, but if a company picked up beeper code to profit off of "imessage support on android"... The yardstick would be closer to open standards.
- bzzzt 3y agoiMessage is not an open standard, even if third parties have access. And in most parts of the world (outside of the US) iMessage is not really a relevant player. If you're against walled gardens you also have to be against all the obstacles Google and Samsung have planted. Why shouldn't Apple users make free use of Google maps without paying Google (in privacy)? Why can't every person access the advertising data collected by these companies? If the answer is "companies invest a lot of money to make these products possible" why is iMessage different?
- AnthonyMouse 3y ago> If you're against walled gardens you also have to be against all the obstacles Google and Samsung have planted. Okay, let's be against those too.
- bzzzt 3y agoIf you're serious about opening up literally everything and probably destroying all the leverage for possible business models how do you expect companies to keep providing the services you enjoy at the moment?
- AnthonyMouse 3y agoGmail seems to do fine with an interoperable network.
- voakbasda 3y agoHow about through business models that do not smell like rent-seeking extortion?
- throwaway2037 3y agoHat tip! Thank you to share about Hashcash. Do you know why email has not introduced something similar? For example, SMTP servers would reject email without a valid Hashcash token.
- ankit219 3y agoThe entire model was initially opensourced by a 16 year old. https://github.com/JJTech0130/pypush https://github.com/JJTech0130/pypush They modified it with their own touch.
- xyzzy_plugh 3y agoThat repository is not open source.
- popcorncowboy 3y agoAh you mean Open Source^tm. If the source is on Github that's what open source de facto means _these days_. not to the priesthood of course
- xyzzy_plugh 3y agoI ain't no OSI shill. No, rather I mean it's "your employer probably doesn't want you to even look at this" source-available. Many people here work on SaaS products. If you work on a SaaS you likely want to avoid AGPL/OSL/SSPL without consulting your legal team. As a corollary, the Unreal engine source is on GitHub, but that doesn't make it open source. It's strictly disingenuous to call SSPL open source (I personally believe it's disingenuous to call AGPL open source but I digress)