Nothing Chats, an iMessage app for Android, is a privacy nightmare
9to5google.com
9to5google.com
> Some of the messaging community believes that software that is open source is more secure. It is our view that it is not. The more visibility there is into the infrastructure and code, the easier it is to penetrate it. By design, open source software is distributed in nature. There is no central authority to ensure quality and maintenance and by putting that responsibility on Sunbird, development would not be feasible. Open source vulnerabilities typically stem from poorly written code that leave gaps, which attackers can use to carryout malicious activities.
Wow. I can understand not making app open source due to business model but that explanation is something else, mother of all red flags.
Then they are assuming their whole app infrastructure is written poorly and insecure, then instead of fixing their app they will take the lazy route and make the app closed source.
I’ve heard this reason many times over the years and, universally, it’s made by someone who is completely clueless. Many times by a stupid business person, but sometimes by an even stupider engineer.
Even worse is that it shows a stupidity of philosophy over a stupidity of knowledge.
Let’s say I use this service…how confident can I be that Apple doesn’t pull the plug on Nothing?
I think Apple could easily figure out where their traffic is coming from and block it.
Technically not at all, practically they would be making arguments for EU why sideloading is needed.
The promise was, implicitly, that Nothing (terrible name) had reimplemented enough of the iMessage encryption architecture to replicate it on an Android phone. If that had been the case, there's no reason they couldn't have made it end-to-end encryption, just like Apple's implementation of iMessage is.
The reality is that they lied. It's not clear that there was any encryption involved beyond standard TLS and (possibly?) at-rest encryption in Firebase. None of this adds up to E2EE.
Tangentially related: My thinking is Apple’s reverse course on RCS will help them justify keeping iMessage itself closer to Apple platforms, particularly when governments/society demand that they justify their closed access.
AFAIK you could get imessage to work on a hackintosh, which technically isn't an apple device.
[1] https://en.wikipedia.org/wiki/Trusted_Computing#Endorsement_...
https://dortania.github.io/OpenCore-Post-Install/universal/i...
> Using native chat apps independently may be more secure than connecting to other encrypted chat networks with Beeper.