this post was submitted on 08 Dec 2023
107 points (95.7% liked)

Technology

58150 readers
4303 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
all 26 comments
sorted by: hot top controversial new old
[–] LWD@lemm.ee 71 points 9 months ago* (last edited 9 months ago) (2 children)
[–] deegeese@sopuli.xyz 32 points 9 months ago (2 children)

To be fair, I would totally believe Apple changed something small for the sole purpose of breaking iMessage interoperability with Android.

[–] roofuskit@lemmy.world 21 points 9 months ago (1 children)

I would be surprised if they didn't have it ready to go and flipped the switch once they felt it would hurt the apps reputation the most.

[–] LWD@lemm.ee 9 points 9 months ago* (last edited 9 months ago)
[–] LWD@lemm.ee 4 points 9 months ago* (last edited 9 months ago)
[–] habanhero@lemmy.ca 11 points 9 months ago (1 children)

The tech is pretty interesting but the business is sus...It's kind of like selling fake admissions to a club and calling that a startup.

[–] LWD@lemm.ee 7 points 9 months ago* (last edited 9 months ago) (2 children)
[–] habanhero@lemmy.ca 7 points 9 months ago

The product Beeper is selling is essentially access to "blue bubbles" and iMessage without having to pay the price of admission (i.e., owning an iDevice and working with Apple). That's the part that's shady and sus. What they are paying or saving on infrastructure cost is irrelevant - they are basically still running a counterfeit operation, doesn't matter what their costs are.

[–] BearOfaTime@lemm.ee 2 points 9 months ago (1 children)

The push servers are required for beeper Mini, because it acts as a gateway between GCM and ANP.

Beeper Cloud uses Mac Minis, and Beeper posted the software on github so you can self host it.

The two apps work very differently.

[–] LWD@lemm.ee 1 points 9 months ago* (last edited 9 months ago)
[–] almar_quigley@lemmy.world 18 points 9 months ago (2 children)

Why is this a thing? I like iMessage but is there a reason people are trying to force their way into the protocol or whatever? Just to show blue or is there something unique to iMessage that no one else has?

[–] misk@sopuli.xyz 18 points 9 months ago (1 children)

iMessage chats are supposedly horribly broken for people participating over SMS. It got so bad in the US that teenagers treat it as a status symbol too.

[–] Joelk111@lemmy.world 20 points 9 months ago* (last edited 9 months ago)

As an android user, I treat it as an early red flag, if someone treats it as a status symbol.

[–] BearOfaTime@lemm.ee 17 points 9 months ago (1 children)

We need a sticky for this.

When a group chat on iPhone includes an SMS-only participant, it downgrades the conversation for everyone to SMS. So everyone gets crappy images, and certain iMessage group features don't work.

[–] yokonzo@lemmy.world 16 points 9 months ago (1 children)

Well it’s the first few days, let’s give it some more time before screaming sinking ship

[–] habanhero@lemmy.ca 29 points 9 months ago (2 children)

...Beeper CEO Eric Migicovsky responded to TechCrunch’s inquiry about Beeper Mini’s status by pointing us to the X post acknowledging the outage, and providing more detail. Asked if possibly Apple found a way to cut off Beeper Mini’s ability to function, he replied, “Yes, all data indicates that.”

Emphasis mine. Source: Techcrunch.

[–] alquicksilver@lemmy.world 14 points 9 months ago

I am shocked. Shocked, I tell you.

[–] peregrine_falcon@lemmy.world 9 points 9 months ago

Full points for transparency, I guess?

[–] WhiteOakBayou@lemmy.world 2 points 9 months ago (3 children)

I've been using it for a few days and was going to put it on my wife's phone tonight. Maybe the next one won't be so well publicized.

[–] Imgonnatrythis@sh.itjust.works 8 points 9 months ago (1 children)

Whoa. That is way too short of a trial for migrating something new to the wifephone.

Don't forget to cancel your subscription!

[–] WhiteOakBayou@lemmy.world 1 points 9 months ago

Yeah, she's grown used to, but not fond of, me installing buggy alpha or beta software on her phone. The promise of non potato quality pictures from her family was going to be the selling point :/

[–] BearOfaTime@lemm.ee 4 points 9 months ago* (last edited 9 months ago)

I tried it yesterday, it still has some growing pains (had some trouble getting it to connect).

Going to keep watching though, for a new app it looks pretty good, fluid, well designed from a UI standpoint.

Given the dev was able to reverse-engineer Apple's ANP (equivalent to Google's GCM), build an app, backend, etc, it should be fun to watch.

It's also generating a conversation around the misperception of iMessage being perfectly secure, and how SMS downgrades iMessage to not secure at all.

Hacker News story about the lack of Forward Secrecy and other concerns: https://news.ycombinator.com/item?id=38537444

A summary of what I think is the primary issue with iMessage security that most people can easily understand (I've quoted this from another commenter, this is in the article):

  1. iMessage uses RSA instead of Diffie-Hellman. This means there is no forward secrecy. If the endpoint is compromised at any point, it allows the adversary who has

a) been collecting messages in transit from the backbone,

or

b) in cases where clients talk to server over forward secret connection, who has been collecting messages from the IM server

to retroactively decrypt all messages encrypted with the corresponding RSA private key. With iMessage the RSA key lasts practically forever, so one key can decrypt years worth of communication.

I've often heard people say "you're wrong, iMessage uses unique per-message key and AES which is unbreakable!" Both of these are true, but the unique AES-key is delivered right next to the message, encrypted with the public RSA-key. It's like transport of safe where the key to that safe sits in a glass box that's strapped against the safe.

**BearOfATime Comment: **This lack of Forward Secrecy alone is enough to say iMessage is nowhere as secure as we've been lead to believe. The delivery of the AES key with the AES-encrypted message but the package encrypted with RSA that virtually never changes is so blindingly flawed. This setup makes the AES encryption pointless, if you're going to package the key with it. Because once the RSA is broken/acquired, they have the AES key for the message (and ALL messages)!

The concern over the RSA key length is a bit premature, I'd say it's more of a future concern that Apple is probably working on.

The other issues (unchanging identifiers, for example) are a valid concern. Something I've seen other apps take into consideration (Signal, Briar, SimpleX Chat).

[–] kaitco@lemmy.world 2 points 9 months ago (2 children)

If they don’t publicize, they won’t make any money.

[–] BearOfaTime@lemm.ee 2 points 9 months ago

The dev has always been pretty open. The published a self-hostable version of Beeper Cloud on github, and the dev published some docs on how iMessage works, how their implementation of ANP works, etc. Like detailed docs that are frankly above my pay grade.

[–] WhiteOakBayou@lemmy.world 1 points 9 months ago

The iptv guys seem to do alright and they stay out of the limelight.