[1] https://blog.nektra.com/2020/01/12/reflecting-on-16-years-of...
Anecdote: we reverse engineered several Microsoft products and before Microsoft Windows 7 launch we were contacted by Microsoft QA and they offered us support to check if our software was compatible with it! BTW, our software was installed in millions of computers around the globe. For example, Trend Micro used our software for supporting their antivirus in Outlook Express and Windows Mail.
Our Deviare Hooking Engine [1] was eclipsed when Microsoft Detours [2] turned to an MIT license and free. Even when our was superior in several ways. This is why I wrote that you should continuously fight for "adversarial interoperability".
[1] https://github.com/nektra/Deviare2
[2] https://www.microsoft.com/en-us/research/project/detours/
If you know anybody that can help please let me know because I want to get back to maintaining the project.
https://gist.github.com/smashah/667d4d5cf31670ee87547450861a...
They sent us C&Ds based on ToS.
Meta has done this before to insta and android devs.
Some never came back to their projects. It causes insane amount of stress and depression amongst the devs I've spoken with who went through the same thing.
If the use of this software is against their rights in some way, the end users running it would be the ones in violation. Publishing original software is protected expression.
So it's even worse than the risk of being taken down. Way worse.
https://www.eff.org/deeplinks/2017/10/drms-dead-canary-how-w...
Assuming that DMCA does not cover API authentication (i.e. preventing unauthorized third-party clients from being able to access a server-side API – and I really don't know if it does or doesn't!), I wonder what the implications are if the same mechanism is used for both DMCA-covered DRM mechanisms, but also non-covered other purposes.
My intuition would be that it can't be good to "multi-purpose" a DRM tool from a DMCA enforcement point of view, but maybe that was never Apple's plan, and they just used the most secure attestation technology they had available on each platform, which for Intel Macs might just have been software-only FairPlay.
Yeah, and when exactly should everyone expect to stop seeing DMCA take down notices that didn't abuse the system, willingful harm creators, and an appeals process that is an unfunny joke?
Until then, it doesn't matter what the law says. They will abuse it, because PROFITS.
An open source client for an API need not include any non-original works.
The situation seems very similar to the AACS key leak back in the day: https://en.wikipedia.org/wiki/AACS_encryption_key_controvers...
It targets games, so manages to be useful without having to emulate or re-implement the majority of the OS.
That means Jack Shit in a world where a lawsuit can ruin a person's life regardless of its legal merit, with zero consequences for the corporation that filed it even if it gets tossed out by a judge eventually.
LPT: Live as if human/constitutional rights didn't exist. Because if push ever comes to shove, you will quite possibly find that they indeed don't exist in practice.
There's no story in the world that will get people to stop using services like Whatsapp or Instagram.
The only thing stopping these big companies is potentially setting a legal precedent that interop projects are legal.
They can potentially win such a case as it stands because the targets for their threats are few and far between.
If we as digital humans want to solidify this digital right then we need to have a unified front against threats like this. That means we need to have an OSS union behind which companies and individuals can unify if a precedent setting case ever does come up
At the time it seemed like a serious threat.
Obviously that outcome is something he wants, but I still think its interesting.
[0]: https://www.theverge.com/2023/12/5/23987817/beeper-mini-imes...
There's probably a cliff in complexity. Once Apple starts requesting signed attestations from the secure enclave on the devices that have one, it's game over.
They probably don't just yet, since still too many people use iMessage on first-party clients that don't have one, e.g. Intel laptops without a T1 or T2.
Note that iPhones already receive SMS spam and fraud just like every other phone.
However, you are correct that the blue bubble is no longer a guarantee that the bad actor is using an iPhone.
Like the legal action that is currently protecting us from robocalls?
I don’t know if iMessage registration requires bidirectional SMS verification, though. If it does, that would be significantly harder to spoof than just caller IDs.
Whether the number uses iMessage or not is totally irrelevant.
There were also differences in the platforms with how/when your phone number can leak to spammers and data aggregators, although I'm no longer deep enough into mobile OS or related CVEs to know current details.
Spam protection should be on the recipient, rather than the sender.
I'm willing to bet the latter is much, much higher. It certainly is for me.
That's not to say that requiring remote attestation or blocking third party clients entirely is proportional, but Apple should (and does) play a role in spam prevention.
I would think that’s the biggest issue right now. If spammers can register “real” iMessage accounts at scale without Apple hardware, Messages becomes less pleasant, very quickly.
> Apple can break Beeper without relying on the secure enclave: If Apple devices just send their serial number
You have come full circle with the comment 4 posts up.
If it ever becomes popular, there will be a lot of duplicate serial numbers. That's easy to detect and ban.
(perhaps different sets of data can be used, but it must be something that Apple already has, and the user has already provided (i.e. the iMessage email or the iMessage phone number, from the iPhone's enabled Settings)
I spent a number of days with them where they were trying to work out if they were fake. The serial number was real but they were fairly sure the number had been taken from a real product and reused, but were unable to say for sure.
I ended up just returning them (because of the ebay return window) but found it interesting that Apple couldn't easily check this, and was very aware of the issue.
No matter the method it would be a scorched earth approach. I suspect the number of people actually using Beeper will be far below a rounding error for Apple.
Right now they can probably just ban known-spam-originating devices, which is much more effective than banning iCloud accounts since there is a much higher cost to the spammers.
That and reading the books is actually about the only thing it can do right now.
And as part of Security Updates they have patched vulnerabilities just in the relevant apps.
So there is nothing technical stopping them. It's just been customary to treat iOS as a product where all features ship together.
Actual updates require the app binary/bundle to be mutable.
But mainly it's because base Android (AOSP) can be arbitrarily modified by the OEM; and Google doesn't want to have to trust installations of Google Play Services that have been arbitrarily modified by OEMs.
(Especially because those versions would likely all act differently-enough from one-another that they would be forced to loosen their server-side, network-traffic-fingerprint-based "authentic Android device" detection that allows them to ignore/block bots pretending to be Android devices.)
By shipping Google Play Services through the store, they can ensure that, on devices that run it, it's exactly the same code for every device that runs it, with no OEM alterations. (And they can also include various checks to reject devices that would try to alter that code at load time. This is the real reason why e.g. Huawei devices are blocked from using Google Play Services — they try to patch unspecified parts of the Play Services code while loading it, "breaking the integrity of the platform" from Google's perspective.)
No they haven't. On my Mac it's just an app and a reusable framework.
There is nothing stopping them releasing it on the App Store similar to Mail.
In the sense that the app is just a wrapper around a system framework, sure. But changing that framework would be an OS release.
It's not deeply integrated into the iOS by any normal definition. It's just shipped together.
Btw, maybe related, on iOS I have "app privacy report" enabled, to show me a list of apps and the recent entitlements they used. Every Apple app, even those that don't need access to them, is shown as having recently accessed my Contacts. I find this weird. Anyone know why they do that? e.g. I've never even used the Health app and yet it's accessing my Contacts for some reason.
They would need to accept and verify a flag from messages that the copycats can't reproduce. At the very least that would require a client update from anyone using official iMessage clients, which covers many millions of devices.
Unless they're able to hook into already existing flags/keys on the devices since they already verify application signatures and a whole other host of things.
Apple can probably do it, but much like jailbreaking how fast can they release breaking changes?
edit, because i used the wrong turn of phrase
Apple could block any device without attestation then offer a discount for those on old products to upgrade. Now bad news is good news.
If Apple is able to update the protocol in such a way that it requires some kind of signed attestation from the secure enclave (basically a DRM) they’ll get legal protection.
Also. Nobody uses iMessage in the EU. It’s all WhatsApp here. Blue bubbles are an American obsession.
This might be news, but the DMCA laws don't allow you to restrict software which is compatible with your own, especially if the competitor never used your code.
No it’s not, it’s an obsession by a small number of users, not widespread at all.
Even if short lived they could onboard a lot of Android users and then use RCS once it’s supported.
It would be, however would not bet my chatting account history on a phone number. Phone number does get lost over time. Email is more reliable, but may be a private key for authentication instead. Also a modern day chat app, one would expect to have chatting over bluetooth as well Internet such as Briar, and chatting over Tor such as Quite would be much more needed.
That to me is not universal chat, that's just welding 10 chat apps into one, somewhat poorly.
That being said XMPP was well on the way to becoming something universally supported, and though the protocol itself was way more complicated and crufty than I'd like, it's a shame that Google particularly abandoned it for really no reason.
> Google particularly abandoned it for really no reason
What most annoying is seeing Big Tech now trying to write a new standard to comply with the EU instead of using the existing standard they abandoned that already has all the mileage & scaling looked at. Instead all the same hurdles will have to be overcome yet again, just like the current growing pains of Matrix meanwhile XMPP is still quietly holding strong for massive chat/presence systems.
Some others:
- Find my device features including Bluetooth ping networking (airtags, Tile, Android's upcoming network)
- Airdrop/Nearby Share
- Bluetooth LE proximity pairing (at least I doubt this works when pairing cross ecosystem)
- Carplay/Android Auto
- Airplay/Google Cast
Another Apple ecosystem that can be used by non-Apple devices. OpenHaystack [0] has been working well for quite a while.
You can buy tags from AliExpress for $5 that implement it. I've been using a few for a couple of months, and no issues so far.
You are referring to being able to track devices via the Find My portal on Apple.com or your Apple devices, but I am referring to being able to merge the networks so that Apple devices will forward pings onto Android's Find My network and vice versa.
The last commit and release is from october.
Are there any headunits that only support one or the other? The cheap Chinese unit I got last year supports wireless for both. It would be nice to have an open protocol though, so third parties could develop alternative UIs.
the EU is fundamentally interested in these changes regardless of consumer welfare. this is sour grapes because they fail at tech by every conceivable metric and by degrading everything to a common feature set and commoditizing certain standards, they hope to give domestic companies a prayer. that it prevents innovation and improvements is merely a secondary concern for the hard-headed anti-Americans in brussels.
Another way to read this: Apple has a superior product because they perform anti-competitive practices and don't allow other companies to out-product them. And when they do, they buy them/shut them down before anyone is the wiser.
https://www.theverge.com/2021/4/27/22406303/imessage-android...
In short, Eddy Cue proposed in 2013 that Apple owning the best-in-class messaging app would be a win, and even mentioned the cost being low. Phil Schiller shut him down, arguing it would remove a barrier preventing iPhone parents from buying their kids Android phones.
That reads like anti-competitive motivation to me. In particular, it looks like tying, where two unrelated products are connected artificially. The wikipedia article on anticompetitive behaviors has a section on tying, and mentions another case involving Apple that bears some resemblance involving iPods being artificially restricted to only playing tracks either from iTunes or direct CD rips.
So I think the anti-competitive angle has some real merit.
The innovation claim, though, I have a harder time with. I don't see how releasing Messages for Android implies design-by-committee. They could just release it, like Beeper Mini just did, but without the reverse engineering part.
As much as I think Beeper's work on iMessage is important, apps like that do not and have never solved this problem. Because then you have different contact identifiers to contend with, the inability to make groups amongst those users, differing features, and the list goes on.
If you look closely at what I'm saying here, it's easy to compare it to what iMessage users say about why Android users create problems for them, and that's true. That's why messaging interoperability is important.
I cannot remember the last time I've received a non-spam SMS. The whole iMessage thing feels so alien to me. My girlfriend is an Apple fan-girl and has never used iMessage in her life. I kinda wanted to see what was special about it and when I asked her about it, she had no idea what I was talking about.
You can definitely make the argument about innovation in the messaging space, but RCS is very extensible. RCS Encryption definitely needs to be standardized, but I recommend you check out how Google layered it on top of RCS [1] including handling fallbacks for corner cases like switching your RCS client away from Google Messages before the system realizes it.
This is to say that RCS is pretty flexible, the key is handling the fallback paths in the extension design and working with other vendors to standardize promptly, so we don't end up with the same kind of broken mess that the carriers made.
[1] https://www.gstatic.com/messages/papers/messages_e2ee.pdf
Honestly, this reads more like marketing spin to cover anti-competitive behaviour than a forum post.
Certainly not every iOS app has a custom Airdrop integration either.
Every time I've nearby shared it's worked just fine. What phone do you have?
The same is also true, say about AirDrop, if apple makes it "Open" and they have to make a breaking change for security or whatever reason, they can't feasibly even make an update available for non-apple devices let alone enforce it.
Now "Apple" has broken your non-apple device and along with it their reputation.
Open is good, but the cost is non-zero.
This argument is silly. You could use this line of reasoning to justify why all computers should use the same OS from the same vendor. Of course then you'd have a monoculture where implementation bugs that cause vulnerabilities are universally exploitable, instead of only exploitable on machines running that vendor's software.
Far from it, actually.
If a part of your user base uses another service, you’ll inevitably have to add workarounds specifically to cater to users for that service. It’s just a fact of life when multiple groups have to implement a spec. If you aren’t willing to add workarounds, users will think your software is broken when they should be blaming someone else.
For example, Firefox maintains a few workarounds for websites that ship in the browser. They aren’t the web developers responsible for the sites but someone has to make it work.
Interoperability is not free.
You mean like WhatsApp, Signal, Telegram and dozens of different chat apps available for both Android and iOS?
Universal in this context is referring to the ability to use a single app across protocols rather than the ability to use a single app across platforms.
It's what EU mandated and from March '24 all major chat apps have to be able to communicate with each other.