4 ms·
People complain about the green/blue bubble thing that Apple does, but I like to be able to see if the other user is using iOS, because SMS has no encryption wh
by amusingimpala75 3y ago
People complain about the green/blue bubble thing that Apple does, but I like to be able to see if the other user is using iOS, because SMS has no encryption whatsoever, and this iMessage shim that Beeper is using effectively opens the possibly of MITM the iMessage traffic without one’s knowledge. From this security perspective, I don’t have a problem with Apple cracking down on this misuse of iMessage.
- neodymiumphish 3y agoBut you can run the bridge locally, so the "MitM" is the user themselves, and not actually a threat.
- stemlord 3y agoSeems like Apple is well capable of enabling secure messaging to and from outside the Apple-ecosystem and are using security as a red herring, in that case.
- zamadatix 3y agoIf that was really Apples only concern too then they'd separate the bubbles color from having both security and non-security indications (and probably publish a library, or at least not take down any reverse engineering attempt, so the e2e can be maintained fully instead of relayed). They don't because security is just a convenient pitch for why things have to be this way when the bubble is overloaded and nobody else can connect to the servers without getting banned.
- danaris 3y agoBut there are only two ways to have a message appear in Apple's Messages app: 1) If it's an SMS, which has no encryption possible 2) If it's going through the iMessage service, in which case it has all the protections and features that Apple puts there. (At some point in the future, there will be a third way: if it's an RCS message. We don't fully know what features that will support on Messages, or what bubble color it will have.) What you're suggesting would only make sense if there were some kind of "Messages API" that various companies could use to get their chat apps to interoperate with it. Maybe there should be, but there isn't, and suggesting, in isolation, that Apple separate out the security indicator from the platform indicator of the bubbles is like suggesting that supermarkets be required to put clear notifications on their apple pies that contain salmon.
- zamadatix 3y agoI'm suggesting Apple will continue to do anything that aligns opening up iMessage in any way with the maximum amount of security implications. They will continue to require any conversation about opening up iMessage to become focused on arguments of the security implications instead of just letting it be secure in general. I'm not suggesting they've left any way around that today or that it behaves differently today, just that it's a weapon they use today. That the conversation has turned into comparison to "contains salmon" labels on pies is a great example the strategy is wonderful at complicating any discussion around whether it should be opened up.
- zamadatix 3y agoI was reminded that live bridges are also still allowed, e.g. how "Microsoft Phone Link for iPhone" works. So keep in mind even with banning relays there are officially supported ways an app can MITM iMessage traffic, regardless of bubble color you see on your end.