2 ms·
Hm, the breach contained metadata, but not message contents. RCS does not attempt to defend against metadata surveillance. Is the author's point, simplified, "
by aesh2Xa1 2y ago
Hm, the breach contained metadata, but not message contents. RCS does not attempt to defend against metadata surveillance.
Is the author's point, simplified, "any centralized collection of communications data, unencrypted, is vulnerable?" They mention E2EE, but even some of those still present centralized, unencrypted metadata.
- FireBeyond 2y agoMaybe. But really, to me, the author's real point is "Why are you people forcing Apple to support RCS? Leave them alone" and he'll draw longer and longer bows to justify it. Gruber has had several moments where he's stridently defended Apple and denied issues only for it later to be revealed that there absolutely was an issue. The last straw for me was the LassPass App Store issue a few months ago (where a scam app was approved and took the top spot in the store, over the official app). Gruber, on this: > > Instead, the scam LassPass app tries to steer you to creating a “pro” account subscription for $2/month, $10/year, or a $50 lifetime purchase. Those are actually low prices for a scam app — a lot of scammy apps try to charge like $10/week. Emphasis mine, but are you kidding me? He actually tries to downplay the issue by saying "Well, at least you wouldn't be scammed out of that much money". And then doubles down, by claiming, with absolutely no knowledge whatsoever: > It doesn't look like the app was intended to steal credentials. Why do you think that is plausible reasoning? To me, the credentials are what you're intending to steal with the scam app. You might make some money from the IAPs, but that's a cherry on the top (and likely the actual reason why the amounts were low, so it didn't raise more red flags). I've seen yoga practitioners who can't contort themselves as much as Gruber can when trying to defend/promote Apple and their interests.
- isleyaardvark 2y ago> He actually tries to downplay the issue by saying "Well, at least you wouldn't be scammed out of that much money". That’s a ridiculously uncharitable take on a simple statement of fact that you yourself even seem to accept later in your comment.
- FireBeyond 2y agoThe thing is Gruber tried to imply/claim that there was no reason to believe that there was an intent to steal credentials, i.e. the only part of the scam was the financial aspect. So no, I stand by it. If by his belief, not mine, that the app was purely a financial scam, he literally downplayed it, effectively, as "even if you're being scammed, you could have been scammed more elsewhere", and most of the rest of his writing was implying people are being overly critical of Apple. As for an uncharitable take? Were it Gruber's first forays into defending Apple in the face of evidence, maybe. After screen staining, batterygate, butterflygate, logic board issues, and several more (hell, he even defended "You're holding it wrong"), all of which Gruber insisted these were all user issues, non-issues or random events, several of which ended up resulting in warranty extensions and/or recalls, I'm less inclined to be ... 'charitable'.