Obviously that outcome is something he wants, but I still think its interesting.
[0]: https://www.theverge.com/2023/12/5/23987817/beeper-mini-imes...
Obviously that outcome is something he wants, but I still think its interesting.
[0]: https://www.theverge.com/2023/12/5/23987817/beeper-mini-imes...
There's probably a cliff in complexity. Once Apple starts requesting signed attestations from the secure enclave on the devices that have one, it's game over.
They probably don't just yet, since still too many people use iMessage on first-party clients that don't have one, e.g. Intel laptops without a T1 or T2.
Note that iPhones already receive SMS spam and fraud just like every other phone.
However, you are correct that the blue bubble is no longer a guarantee that the bad actor is using an iPhone.
Like the legal action that is currently protecting us from robocalls?
I don’t know if iMessage registration requires bidirectional SMS verification, though. If it does, that would be significantly harder to spoof than just caller IDs.
Whether the number uses iMessage or not is totally irrelevant.
There were also differences in the platforms with how/when your phone number can leak to spammers and data aggregators, although I'm no longer deep enough into mobile OS or related CVEs to know current details.
Spam protection should be on the recipient, rather than the sender.
I'm willing to bet the latter is much, much higher. It certainly is for me.
That's not to say that requiring remote attestation or blocking third party clients entirely is proportional, but Apple should (and does) play a role in spam prevention.
(perhaps different sets of data can be used, but it must be something that Apple already has, and the user has already provided (i.e. the iMessage email or the iMessage phone number, from the iPhone's enabled Settings)
I spent a number of days with them where they were trying to work out if they were fake. The serial number was real but they were fairly sure the number had been taken from a real product and reused, but were unable to say for sure.
I ended up just returning them (because of the ebay return window) but found it interesting that Apple couldn't easily check this, and was very aware of the issue.
If it ever becomes popular, there will be a lot of duplicate serial numbers. That's easy to detect and ban.
> Apple can break Beeper without relying on the secure enclave: If Apple devices just send their serial number
You have come full circle with the comment 4 posts up.
I would think that’s the biggest issue right now. If spammers can register “real” iMessage accounts at scale without Apple hardware, Messages becomes less pleasant, very quickly.
No matter the method it would be a scorched earth approach. I suspect the number of people actually using Beeper will be far below a rounding error for Apple.
That and reading the books is actually about the only thing it can do right now.
But mainly it's because base Android (AOSP) can be arbitrarily modified by the OEM; and Google doesn't want to have to trust installations of Google Play Services that have been arbitrarily modified by OEMs.
(Especially because those versions would likely all act differently-enough from one-another that they would be forced to loosen their server-side, network-traffic-fingerprint-based "authentic Android device" detection that allows them to ignore/block bots pretending to be Android devices.)
By shipping Google Play Services through the store, they can ensure that, on devices that run it, it's exactly the same code for every device that runs it, with no OEM alterations. (And they can also include various checks to reject devices that would try to alter that code at load time. This is the real reason why e.g. Huawei devices are blocked from using Google Play Services — they try to patch unspecified parts of the Play Services code while loading it, "breaking the integrity of the platform" from Google's perspective.)
And as part of Security Updates they have patched vulnerabilities just in the relevant apps.
So there is nothing technical stopping them. It's just been customary to treat iOS as a product where all features ship together.
Actual updates require the app binary/bundle to be mutable.
Right now they can probably just ban known-spam-originating devices, which is much more effective than banning iCloud accounts since there is a much higher cost to the spammers.
No they haven't. On my Mac it's just an app and a reusable framework.
There is nothing stopping them releasing it on the App Store similar to Mail.
It's not deeply integrated into the iOS by any normal definition. It's just shipped together.
Btw, maybe related, on iOS I have "app privacy report" enabled, to show me a list of apps and the recent entitlements they used. Every Apple app, even those that don't need access to them, is shown as having recently accessed my Contacts. I find this weird. Anyone know why they do that? e.g. I've never even used the Health app and yet it's accessing my Contacts for some reason.
In the sense that the app is just a wrapper around a system framework, sure. But changing that framework would be an OS release.
They would need to accept and verify a flag from messages that the copycats can't reproduce. At the very least that would require a client update from anyone using official iMessage clients, which covers many millions of devices.
Unless they're able to hook into already existing flags/keys on the devices since they already verify application signatures and a whole other host of things.
Apple can probably do it, but much like jailbreaking how fast can they release breaking changes?
edit, because i used the wrong turn of phrase
Apple could block any device without attestation then offer a discount for those on old products to upgrade. Now bad news is good news.