Apple cuts off Beeper Mini's access
techcrunch.com
techcrunch.com
Show HN: Beeper Mini – iMessage client for Android - https://news.ycombinator.com/item?id=38531759 - Dec 2023 (863 comments)
iMessage, explained - https://news.ycombinator.com/item?id=38532167 - Dec 2023 (143 comments)
"My prediction is that Apple will make changes—fixing bugs and/or closing loopholes—that break Beeper Mini. It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature.
It’s a very nice app, remarkably clever, and for now works like a charm, but if Apple wanted an iMessage client for Android they’d release an iMessage client for Android. Seems irresponsible for Beeper to charge a subscription for an unsupported service."
- From the National Association of Criminal Defense Lawyers
Other way around. If anything, it sounds to me like Beeper Mini was acting illegally by accessing Apple’s servers in a way they didn’t give permission for.
The CFAA is ripe for abuse. I’m not saying applying it here would be just or not, only that Apple likely wasn’t the one acting illegally.
So I would summarize it as the corporate entity connecting to an Apple API and using it in undocumented ways that they reverse engineered, intercepting messages meant only for Apple software, doing so without prior permission, for purpose to selling access to services which would normally be covered by an Apple EULA.
It is not quite like a smaller word processor wanting to be able to import Word documents - without tying into Apple's service, Beeper Mini has zero value.
They may very well have violated the law as it is actually written.
Beeper is lucky they weren't sued under the DMCA anti-circumvention clause, as they clearly were bypassing the technological measures Apple uses to prevent genuine devices from connecting to iMessage & Apple services.
I think you’re likely right though. If they had such a claim I think their lawyers would have been on it instantly.
That’s why I mentioned the CFAA. Accessing servers without someone’s permission is the exact kind of thing people have gotten very stiff punishments for under the CFAA in the past. It’s basically the main reason I know the law exists, stories about peoples ridiculous punishments for relatively benign things.
Sure it’s useful for real things. I bet you can prosecute ransom under it. Or hacking to break into a rival company.
But it’s also great for when someone embarrasses a politician with stuff that they published on their own website and “something has to be done”.
At the same time, I miss the era of rich third party client ecosystems for things like AIM or MSN messenger. Blocking interoperability is a bummer for innovation.
Android vs iPhone is definitely a thing people in their 20s and 30s even use to judge others. I have polled quite a few family/friends, and it is near unanimous that it is a dealbreaker in dating, mostly because they assume there is a higher likelihood they will not mesh with the type of person the non iPhone user is.
>but that seems like a poor basis for anti-trust action.
Correct.
Whether that argument holds is for governments and courts to decide, ultimately.
I was sharing that theory as a conjecture, since I have no reason to believe such a provision exists.
1. An enforceable contract existed (check!)
2. Beeper knew about the contract (check!)
3. Beeper's actions intentionally caused a breach of that contract (check!)
4. An actual breach of Apple's Terms & Conditions occurred
5. Apple had damages
None of those elements have much to do with profit.
That doesn't mean it's a sure winner, just that it's a live question until more info is known. I imagine Apple would say they need to tighten up any parts of their system that could allow for spoofing or other security issues, and that was their 'legitimate' reason to make these changes.
Beeper made several design decisions that made the app super easy to use (i.e. using a single certificate that wasn't supplied by a user's phone), but if you extract the necessary source material from an old jailbroken iDevice, you could create an iMessage clone that Apple can't ban without either legal action or breaking compatibility with all easily jailbroken iOS devices.
Back in the days of AIM and MSN, even large companies used reverse engineering to get chat interoperability, and it was so successful that AIM left open an RCE vulnerability to push shellcode so that Microsoft couldn't chat through their service.
I don't follow this logic at all. Shouldn't supporting thirdparty clients be desirable if security is a primary feature in the interest of transparency? Especially if the reference client is proprietary and undocumented.
Security isn't about Apple knowing if an app is spying on users, but about THE USERS knowing that nobody is spying on them.
At best a third party iMessage client can only be as secure as iMessage itself because the back end is still closed and has no transparency, so it's the weakest link. If Apple (or a third party) is spying on the back end then no client can be safe.
> How would third-party clients _increase_ security (other than indirectly, by people using SMS less)?
They can increase security by breaking a single target into multiple targets, by increasing competition around security and privacy issues, by having more people use and work with the protocols and able to spot potential problems, by encouraging more transparency around issues when they arise, and by having alternatives readily available if one of the clients is found to be compromised or insecure.
And of course open source clients can be verified and validated by other developers and security professionals.
I believe you are speaking to transparency, not third party clients.
Beeper Mini actually bundled binaries that they didn't understand to bootstrap registration. They could only attempt to be compatible with messages that they have received, and verify messages they send show up correctly - they cannot know they covered all available options.
I speak to this as someone who reverse engineered MSN Messenger back in the early 2000s for an XMPP gateway - you'd occasionally find an entirely new type of message (requiring an entirely new parsing code path for their undocumented/bespoke messaging protocol) because someone registered for a stock ticker or the like.
There was no fuzzing the official servers or clients to see if they were robust or secure - the goal was to have a salable product. In fact, we saw other messaging systems where we had significant concerns based on our understanding of the protocols through reverse engineering, and we saw one vendor exploit a security vulnerability in their own shipping product in order to verify authenticity and block third party clients (which worked for a period of time)
From what I saw of the iMessage system, third party support is not going to be feasible even with a documented protocol without partnership, because there is an assumption of attestation of real, unique hardware as part of registration to prevent mass abuse.
So iMessage is not going to be willing to hand out private keys or negotiate them for a third party application, and Beeper will not be trusted to register a private key itself.
Android iMessage support would be weird because there is no iMessage application - there is an application which lets you send SMS and to upgrade to MMS or iMessage when available. So, if there ever was an official Messages app for Android, I would somewhat expect it to also offer to take over being the default application for SMS/MMS.
True, but Apple caters specifically to a consumer base that can't know this and does not want to think about this. Whether this is health or sustainable in the future is another matter.
Clearly, what matters to Apple is what _they_ believe is secure, and they of course trust themselves more than they trust Beeper.
> At best a third party iMessage client can only be as secure as iMessage itself
Exactly, they can never be safer, and given that Apple, or we as users, know very little about the company behind the client, third-party clients are much less secure.
It would be healthier to assume multi-polarity and lean into it.
Look no further than the other news that came out this week re: government spying via push notifications. (https://www.reuters.com/technology/cybersecurity/governments...) Consumers rationally trust the few big companies which are incentive-aligned to protect their data and government then goes after those few big companies. I thought this was particularly galling:
> In a statement, Apple said that Wyden's letter gave them the opening they needed to share more details with the public about how governments monitored push notifications.
> "In this case, the federal government prohibited us from sharing any information," the company said in a statement. "Now that this method has become public we are updating our transparency reporting to detail these kinds of requests."
People might want to think about how AirTags and Find My Phone work...
rotating BTLE identifiers controlled by a pseudorandom sequence derived from a key, and tunneled over end to end encryption?
Who is saying that? Certainly nobody anywhere in this HN thread. It is, however, fair to say that the only guarantor of privacy and security is a network of trust. There are plenty of examples where trust is partially decentralised, the most notable being the system of certificates used for establishing trust in HTTP over TLS.
There is a quote in the top level comment of this thread that says that.
> It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature.
All they're saying is that the existence of third party software compromises Apple's ability to make blanket statements about the security and privacy of this one specific platform. An unofficial third party client breaks an established network of trust — which is an objective fact. If you doubt this, then you really should use this Chromium fork I just developed. Use it to log into your internet banking. Don't be scared. There's nothing to worry about. See, there's a lock symbol in the address bar and everything.
Can a bad actor slap a green lock on an insecure browser clone and harm users? Certainly. And yet, in a survey of the systemic threats to security and privacy on the open web, such attacks are relegated to the margins.
Apple encourages a popular narrative that centralization and control beget trust, and from there may enable privacy and security. Look no further than the comments on this HN post to see the narrative echoed!
It's fair to point out that it's not literally what Gruber wrote, but readers will fill in the negative space around his uncritically apologetic commentary. To state the implied message: trust in Apple's way, and remember that third parties (who are not accountable to Apple) will ultimately deprive you of privacy and security!
The web browser ecosystem has its own (different) problems, but iMessage lacks requisite variety to back up its particular claims to privacy and security (see that Reuters article for a preview).
I skipped past that because that wasn't what I had expressed disagreement about. Though now you elucidate further I'll say I fundamentally disagree with your "actual point" as expressed. While I agree that systems of distributed trust are fundamentally healthier, they are an order of magnitude harder, and rely upon educating users. And some percentage of users will always be impervious to education — see the continued prevalence of phishing scams for example.
A system which relies upon trusting fewer entities is inherently less fragile and less vulnerable to exploitation. It's true that systems can be designed which rely on users trusting a large number of entities, and can sometimes result in a more educated user base, but they're much harder to implement and much, much, much, much rarer in the real world.
But if we have centralization on the scale of a society, then anyone interested in any of the groups using that centralized source of secure data storage/transfer will be drawn to look for the flaws in that source. And there are always flaws, either technical, legal (as with the government spying mentioned elsewhere in the comments), or otherwise. And once any group manages to infiltrate that one source, they get access to everything dependent on it.
Sure, decentralized security is harder to get together, meaning we have an initially-high violation rate that decreases over time (though this can be supplemented by security-conscious users taking their own steps to protect their data). But centralized security at sufficiently large scales essentially guarantees a breach impacting everyone within its domain; and the kind of trust that would be required to sustain such centralization also anti-correlates with users independently adding additional layers of security to their systems.
This seems like a much greater risk than just accepting that users who are "impervious to education" will be vulnerable to certain social-side exploits, while everyone else will be reasonably safe.
That it’s not currently a problem is due to 25 years of strongly pushing for privacy & security.
We’re still not there (see Google & adblockers in chrome)
We’ve also got examples of Apple making misleading statements about the security and privacy of their platform, as a result of government gag orders.
That recent disclosure makes me suspect that every vector that they do not disclose explicitly as being private, is very much not private. To that end, the platform is clearly neither private nor secure if you value privacy from the government.
…so I’m not particularly concerned about third party software being a cause for concern anymore.
I think this is key. The problem is the security of iMessage as a protocol is dependent on trust between client (implementations). Which is actually not that great from a security perspective.
I don’t mean that there are necessarily vulnerabilities in the protocol (there very well may be), but that the protocol is not something that Apple is willing to depend upon to uphold their desired security guarantees.
From what I understand Beeper Mini is interfacing with iMessage on-device, what's to stop another clients from using a server and intercepting messages? While I don't have time to look it up again, I think there was also something on how Beeper Mini is handling the push notifications when the app isn't open. While that may not leak a lot of information, and there is also the news of Apple/Google sharing push info with some governments, that's something that can at least raise some eyebrows when it comes to how private it is.
It sure as heck better have been designed with that in mind, because it sends SMS messages to uncontrolled 3rd party clients that could be stealing your information or spying on push notifications every single time you message an Android user.
I genuinely don't understand this argument. Do people think that SMS messages don't generate push notifications? Does Apple have a 1st-party SMS messenger available on Android that I'm not aware of? You're already communicating with 3rd-party clients that could be spying on you, and you're already receiving messages from those clients in the iMessage app. The biggest difference is that your messages with those clients today are fully unencrypted, so spying on them doesn't even require compromising an app.
It's weird for people to be so concerned about push notifications as if that's a decrease in security when the alternative system they're proposing is for iOS messages to be sent to Android devices fully unencrypted. Apple/Google can share all of that information with the government as well; if they're not being asked to it's only because the government can get it even more easily directly from the telcos.
It also changes nothing about my comment, because you can call SMS a different system all you want, but your conversations with Android users are still being sent unencrypted and any malicious payloads you get from SMS phones are still being loaded into the same Messages app. If you're worried that a 3rd-party client on Android is going to let a company spy on conversations you're having with Android users, then I still have real bad news for you about how Apple sends messages to Android users.
Draw the lines however you want between Messages and iMessages, but the security implications of Apple's setup are exactly the same. When you write a message to an Android contact, Apple sends that message unencrypted to a 3rd-party client that could by spying on you, leaking your data, or sending malicious payloads to your iOS Messages app. It still makes no sense whatsoever to be this concerned about the security of the push notifications for your messages to Android users when the alternative being proposed is to throw security entirely out of the window for those conversations. It is still a clear security improvement for conversations between Apple and Android users to be E2EE rather than to be sent over SMS, because the risks being raised about 3rd-party messaging clients are already present within those conversations today.
Certainly this is not the first time some entity in the world has reverse-engineered iMessage; it's just the first time that it was publicized.
Apple did leave the hole open; they left it open until it threatened their customer lock-in. Only at that point did they decide that it was a security risk.
Beyond optics, let’s just look at attack surface. The implication that the sort of security holes that “openness” would fix are anywhere near the top of the list is…where’s that xkcd about cryptography and crowbars? It’s very clearly in the realm of nerdy cosplay. You know what is* a much more realistic threat? Some stupid third-party client on the Play store that exfiltrates all messages sent and received. Apple has absolutely no control over that. No protocol security accounts for that.
One way to avoid that outcome would be to have a first-party client on the Play store.
Instead, Apple drops all message security entirely from cross-platform communications for iOS users, allowing anyone to read those messages whether or not they have a crowbar. This is security 101: users do dangerous crap when the secure options don't have affordances for their use-cases. Users are lazy. If an official 1st-party secure client exists that meets their needs, they won't install a 3rd-party client. Users resort to dangerous and unsupported options when the safe, obvious options either don't work or aren't available.
And thankfully, we now know that it would be entirely possible for Apple to fix that problem and to move its own users off of SMS for communication with Android contacts, and we know that because a 16 year-old high-schooler was able to build that support with zero documentation. Presumably Apple is capable of doing the work of a 16 year-old. We now know that it would in fact be entirely possible for Apple using a 1st-party controlled, proprietary client with a proprietary protocol, to encrypt virtually every message that Apple users send to every one of their contacts, rather than what Apple does today where it encrypts... some of them.
None of this requires Apple to Open Source anything or to document or make available any of their protocols. The only reason Apple is in this position right now of needing to deal with 3rd-party clients is because of a lack of support from their 1st-party client.
I think that's my biggest gripe with the situation. Or my second-biggest. My biggest gripe is that the only notification that your messages are now not end-to-end encrypted is the green bubble. They don't tell you anywhere that the green bubble (also) means that.
The first half definitely made me think sarcasm, then the second half... I mean I know some people actually believe this... Then I noticed you said "encryption" instead of "protocol". Breaking an encryption standard is obviously very hard, breaking a protocol is obviously not nearly so hard.
On the other hand, taking this stance would be insane given the post we're talking about. A company that actively circumvented apples security measures. So you must be being sarcastic. You just have to be.
Remember, on the internet it's kinda hard to tell. Make sure to throw in a /s unless you really REALLY sell it.
It's just that in addition to sending your messages to 3rd party clients that could be stealing the data, Apple goes the extra step to make it even more insecure and also sends your messages completely unencrypted, so that everybody along the path from your device to the 3rd-party client can join in and also read your messages and can also use them for ad targeting or worse.
I'll make the argument that this is strictly worse for security than tolerating an encrypted 3rd-party client (or better, releasing their own 1st-party client rather than relying on SMS).
yeah can’t imagine why apple doesn’t use it
But Apple doesn't have to use it. They could release a messaging app for Android that used their own encryption, and they could encourage Android users to switch. But they don't do that, because distinguishing between Android and iOS users is ultimately more important to Apple than securing the conversations that Apple users have.
If RCS is garbage (and it is) then it is extremely weird that Apple has committed to supporting RCS for cross-platform messages instead of encouraging adoption of what would be a superior form of encryption for those conversations.
What you have to ask is, if you are an Apple user, why isn't Apple trying to encrypt every message that you send? Why are they asking you to use a garbage protocol when you send messages to Android users?
> yeah can’t imagine why apple doesn’t use it
Really, this statement should be reversed, it's difficult to imagine why Apple is planning to use RCS. Why is Apple more willing to implement a garbage protocol than they are willing to release a messaging app for Android?
Everything you said is correct.
Imagine there is a theme park that has normal ticket booths and some requirements there to get in. Then there comes a Beeper that finds a hole in the fence on the perimeter and sets up their ticket booths there. It's in theme park's best interest to close that hole and cut off the revenue stream of somebody pigging back on their theme park.
Okay, I've stretched the metaphor out enough.
A Lamborghini Urus costs $230k so I guess it's morally acceptable to break into a dealership and steal it.
If the richest company in the world wanted their chat app to run on Android, it would by now.
It's strange Apple doesn't sell an iMessage Android app, but I'm sure they've had somebody do the math and found out that it's more money for Apple in the long run if they don't.
years and years of "apple sheeple" variants tend to take their toll, you're just the latest in an endless parade of microaggressions even if you don't think your particular case was notable.
why is it so important for you to push on the idea apple users being thoughtless trend-followers? just don't do that, be better. you can do it. the next time you feel like posting that, simply take a deep breath and don't post it.
there is just no reason to go around posting that "[device that 50% of people own] users are all doing it for [trite/dismissive reason]" in the first place, let alone on a tech forum where everyone has very specific reasons for their tech purchases. and it's so completely normalized, android users do it so routinely and don't even think that what they are saying is offensive. it's literally the classic microaggression problem.
Thats a very funny statement. From my experience tech people in general are the ones falling for vanity, fashion, dogmas etc. most often while claiming some "practical" reasons
Android doesn't suffer from that kind of complaint because it's often perceived as the opposite: a socioeconomic indicator for low status. It's socially acceptable to mock people for choosing high socioeconomic indicators, but not low socioeconomic indicators.
"You only bought that because you're rich" has a very different ring than "you only bought that because you're poor".
That perception of low vs high indicators is somewhat wrong (high-end Android phones cost more than the latest iPhone, used iPhones are pretty affordable) but it is the perception.
Or put another way: If the privacy and security of imessage is compromised by someone building another client, I'd argue that you never had either to begin with.
I can't think of an any with independent implementations.
For instance, have a few third party Signal clients, which work by using the official libSignal . These are not third party clients, but third party GUIs. Use of libSignal on the official Signal network is also not supported or recommended.
Likewise, all the third-party Telegram clients I know of are forks using Telegram source.
This makes sense, because neither of these are stable systems. A third party has to stay up-to-date with features and changes made to the official servers and clients.
Do you know of a security and privacy focused messaging platform which is both:
1. documented
2. has multiple independent implementations of the networking and security protocols?
Security wise, there is interesting work adopting MLS (and I believe key transparency) under Matrix, see https://arewemlsyet.com for example.
That's like saying the internet protocol is neither private and secure because people willingly use random public Wi-Fi
Another theme here is BBM (Bloomberg Messaging). People/Companies pay BB five figures per year just to get BBM. Why would they ever release a messaging app outside of the terminal. They will die before this happens.
Apple doesn’t sell apps they sell hardware and services. There’s no incentive for them to provide a free iMessage app for android, and I doubt many people would pay for one.
Enough people paid for one. Enough to make Apple scared and use engineer time to ban/block people anyway.
> We took steps to protect our users by blocking techniques that exploit fake credentials in order to gain access to iMessage.
> We will continue to make updates in the future to protect our users.
[0]: https://techcrunch.com/2023/12/08/apple-cuts-off-beeper-mini...
Completely wrong. It's a job-seeking ad. “Look, I'm ruthless enough to fuck over users who buy this bogus subscription.” Which SV startup wouldn't pay millions for a crook of that caliber?
What a stupid take on the situation. At most it's untenable to Apples short term financial interests. A well designed protocol and implementation would be even better at protecting user privacy and security especially from a privileged attacker like the service provider and anyone able to put covert pressure on them.
The only way in which vendor lock-in helps the the existing users is that spammers and scammers have to invest additional money to acquire Apple devices to create new accounts instead of just phone numbers and a labor to create accounts.
yes, you can indeed build a secure system on the basis of increasing the economic cost of attack beyond reasonable levels and by forcing attackers to repeatedly slash their stake to perform an attack
Apple is, however, nothing for "privacy and security" beyond what they need to do to be marginally better, and that's a stretch these days. If Gruber really believes what he wrote he's full-on living in Apple's orchard behind the walled garden that Tim Cook splendidly gatekeeps. But because Apple puts marketing dollars behind ads that say "privacy" and "security" it must be so!
This is why it's always funny to me when the trope of the hour is the mass privacy failures of Signal through use of phone numbers. And then the author turns around and types out an iMessage to a blue-bubble friend. I really hope we can move beyond the Apple reality distortion machine and move to truly user focused platforms that aren't designed to steal user data or make the board richer.
Apple has become rotten.
1. If Apple sees this as a gap, it is very obvious that they would address that themselves, rather than by allowing a hack to exploit loopholes in their architecture
2. Since Apple has no control over the Beeper mini client, they would not consider it safe, it could easily be spying on users without their knowledge.
Since I have no control over iMessage, I would not consider it safe. It could easily be spying on me without my knowledge.
If Apple actually cared about security they'd implement an open protocol that is provably secure. Imagine if they supported something like Matrix. But that's clearly not their primary concern here. It's just a convenient excuse to maintain their walled garden.
It does not.
Is signal better than iMessage? Probably. Should we ask for them to be better than they are? Yes.
If there is some recent revelation that makes phone numbers all of a sudden a secure, portable and censorship-resistant identifier please link me that.
Until then I'd prefer to not have my private communication determined by telephone companies that often have not cared for either security, censorship or privacy. Regardless of signals e2e encryption having my access to the network determined by a telephone company is not the right way to go.
For a nominally privacy focused app, for them to literally alert people to my new Signal account I'd gotten to securely message someone violated all trust I had in them. What's to stop someone from just adding a Contact for every single valid phone number on their phone and then getting an alert for any time anyone makes a Signal account? I may as well just use Facebook then.
A correctly implemented end-to-end encrypted protocol would be safe for all participating clients.
The only way to break that security is by copying messages outside the protocol in the app itself.
Neither of us knows whether iMessage or Beeper Mini does this. To bring up the possibility is to criticize both apps equally.
As long as the clients are closed source, this is a circular argument. The client itself is a vector. Not just for a good E2E implementation but for the 3rd party company to not outright steal everyone’s messages, create a backdoor, etc. You have to be willing to trust every client used in the thread.
If we must be willing to distrust one closed source client, then we ought to distrust both.
That said, I don't personally trust either of them. When it comes to matters of security, I prefer open protocols which can be proven to be secure over pinky swears from companies.
The level of trust I currently give in Beeper is that identity verification happened such that someone could potentially be prosecuted for abuses after-the-fact.
They have not built up a reputation, and in the face of potential scams or privacy abuses their reputation may not be as valuable as the user information they can gain access to.
Small incidents can cause significant reputation harm to Apple, and those equate to billions of dollars lost in corporate value.
Even the recent notification monitoring announcement harms their reputation, where the government itself mandated non-transparency. (For this reason, I somewhat expect they are trying to design an oblivious notification system, where role separation prevents a single intermediary from knowing both where a notification is from and where it is going to.)
You just brought up a better word: "liability". I'll go one step further: "attack surface".
When it comes to security in software, we don't need to work with many unknowns. The unknowns we do work with are the attack surface. By presenting a greater domain of unknown behavior, closed source software effectively presents me (the user) a larger attack surface. Sure, I could trust that the extra attack surface is actually covered; but I can't know. With open source, I don't have to trust, because I can know instead.
If I am to choose between open and closed source software, then I am choosing between knowledge and trust. That is a completely different position than choosing between closed and closed: trust vs. trust. So long as any securely-designed open-source messaging app exists, iMessage is at a disadvantage in end-user security. Even if Apple can know for certain that iMessage's attack surface is not larger than an open-source alternative, we the users can't. Closed source software will always present a higher demand for trust.
Generally fair assumption. There's been some research (both positive and negative) around their E2EE claims, though AFAIK much of what's known about iMessage's E2EE guts has been learned through unofficial means. I think that for the vast majority of users, iMessage is probably safe enough.
As a user, you have the agency to choose a messenger app that better suits your privacy/convenience balance, though in fairness, I think even among users who care about privacy, many don't know how to judge privacy features and implementation details well.
Like others in this thread, I personally recommend Signal. It's widely available, easily usable, has been audited and researched a fair bit, and though it doesn't have a self-hosted option, it does have white papers out about its protocol which IMO are worth a read.
I would trust iMessage about 95% less if I had written, or even implemented, the protocols myself, and I consider myself a pretty good developer.
I do not need to have had a hand in developing any of this. It's not my expertise and, like you, I'd feel more comfortable having it developed by the experts.
Last time I checked, Apple still used security questions any hacker can get answers to on Facebook. I'm not all that confident about Apple's approach to account security.
Apple has the ability to control security issues on Android: they can release an Android app, like every other E2EE messenger out there.
Apple chooses not to, and it's their choice, of course. It doesn't care about the privacy of it's non-users, and it doesn't care about the privacy of its users when they communicate with non-users. From what I can tell, it only cares if you stay within the Apple bubble.
Apple is doing it optionally because they're trying to balance two opposing forces here: helping its users access a locked account, and giving users tightly locked accounts.
> Last time I checked, Apple still used security questions any hacker can get answers to on Facebook.
Apple's default for a number of years has been to use trusted devices IIRC. Their kb article on resetting a forgotten Apple ID password even suggests that it's better to wait until you're back with a trusted device than to immediately try to reset without one, suggesting that the process is somewhat intensive and perhaps subject to human review? I just kicked it off online and the first question _is_ to confirm an obfuscated cell phone number, but I can't imagine that after that it's mother's maiden name dreck?
> Apple has the ability to control security issues on Android: they can release an Android app, like every other E2EE messenger out there.
Which would thus expose them to security weaknesses of a device and OS they do not control, and potentially expose iPhone and iOS customers to increased risk should an Android iMessage user's phone have malware, or screen scraping, or keylogging, etc.
> Apple chooses not to, and it's their choice, of course. It doesn't care about the privacy of it's non-users, and it doesn't care about the privacy of its users when they communicate with non-users. From what I can tell, it only cares if you stay within the Apple bubble.
Nail on the head, but I do think that folks overstate the simplicity with which Apple could provide a comparably secure iMessage experience on Android.
Check again.
I recently reset a forgotten iTunes password. This required:
- An email verification
- An SMS verification
- A verification code sent to another device on the account
- A ten-day wait
- Another second device verification
That's 5FA authentication just to reset a password.The days of answering personal trivia questions to reset passwords are long gone.
I'm surprised I haven't seen this mentioned more. They could even make a green (or whatever colour they wish) iMessage bubble to denote that it is not from an Apple device. Seems like it solves all the problems people present with E2EE/iMessage with Android interop. On the issue of spam, which I feel is just grasping at straws, You could allow blocking unknown non-Apple iMessages by default. Unless I am mistaken, this really only leaves the walled-garden as the thing that stops Apple from implementing something like this.
In fact, you could even only allow Android iMessage conversations that include at least one genuine Apple device. This combats the argument that they shouldn't have to give resources away to Android users for free. This would be added-value to their own customers by providing more streamlined messaging with their Android contacts. Such as situations where group chats are forced to swap to MMS for a single Android user, sending pictures/video to a friend, etc.
Because they don't own an Apple device or have iMessage, which is the entire point of this discussion?
Sure, if this car is super safe it may be better if both you and the other driver both had it. But it is clearly better to have airbags, even if the other car is less safe than it could be if it was from the first-party brand.
It is one thing to not try to mitigate security issues outside their control and another thing to remove possible security because you don't control it entirely.
Of course, this is a hard problem. I'm not saying Apple is bad at security, many good messaging platforms run into these kinds of problems. But the way you fix these problems (and the way Apple in fact did fix the bugs above) was through patching their own software, not by trying to control what attackers can send.
If security researches can send a malicious payload attack that compromises iMessage, the solution is not to make sure they can't send that payload (which would be impossible to guarantee anyway), the solution is to patch iMessage to no longer be vulnerable to that payload attack.
One hopes that the only thing preventing your iMessage client from being compromised is not whether or not the attacker has a spare $1,000 lying around.
The actual solution is to make the client/server not be vulnerable to malicious payloads that would cause a buffer overflow. Whether you do that by patching bugs individually or switching to a memory safe language, or whatever strategy is used -- "don't send our messaging platform bad data" isn't a security fix.
> The app doesn’t connect to any servers at Beeper itself, only to Apple servers, the way a “real” iMessage text would.
https://techcrunch.com/2023/12/05/beeper-reversed-engineered...
I've re-written this comment five or six times in an attempt to find the most charitable interpretation, but I just cannot comprehend how it made it through your filter and out onto the internet.
SMS is insecure and no one should use it. RCS isn't that much better and history is a lesson that it returns to a partner that isn't trustworthy.
SMS can be read but it is still at least somewhat decentralized. It isn't being funneled to a single party whose business model is profiling users.
Stuff like this happens all the time and the internet has always been like this. I'm sure older users will remember even older examples
On a more serious note though, in the end Apple absolutely has the power of increasing everyone's capability and security by doing something like setting up a playbook of how iMessage could just use Signal protocol and how other actors could join in, or really anything else but doing this.
Right now I can presume a basic level of device security across all iMessage threads I have. Beeper deranges that: E2EE is still there, but Beeper exposes my correspondence to device security weaknesses from other OEMs, malware, keyloggers, screen scrapers, etc. as a result of lax app marketplace security & privacy.
It seems to me to be entirely disingenuous to suggest that Beeper increases security: in fact, the opposite is true.
> in the end Apple absolutely has the power of increasing everyone's capability and security by doing something like setting up a playbook of how iMessage could just use Signal protocol and how other actors could join in, or really anything else but doing this.
I don't see why any company should be denigrated for not helping the users of another competing platform, particularly when doing so likely comes at the cost of increasing the risk to its own users.
Hmmming and hawing over "OEMs... and ...lax app marketplace security" seems like quite a high bar to hold, a bar so high it ceases to be useful. Remember, iPhone users can disable passwords on their iPhone entirely; if that's not something you ever worry about, then worrying about a minority of OEM's seems like mere pretext to keep your comfy walled garden all to yourself.
Subjective, speculative.
> when in reality
I think you mean "when in my opinion".
> they are making a decision on improving their profit
Speculative, and "improving their profit" is clumsy enough vocabulary that it's a red flag on continuing to discuss this with you.
> regardless if it decreases security of its customers and other people
The plurality of countervailing perspectives in this thread – which you have failed to address or refute, as far as I can tell – ought to indicate to you that it is arguable that Apple's decision in this case increases security of its customers.
> It is undeniable and silly to argue against.
I'll let others judge who seems silly here.
My point stays exactly the same. You haven't said anything real against it.
Is that really true though? Jailbroken phones, iMessage may still work. Any device security gets thrown out the window.
You also can't expect everyone to have an Apple device for security, which we've seen time and time again SS7 being weak - So is the requirement to remove SS7, for everyone to jump on the Apple train?
I see Beeper as doing Apple a service, not so much a competing platform, but a gateway to the iMessage ecosystem - 'Hey, this would be pretty cool to use without this app and have it native' vs the 'Only Apple devices can use this.'
Apple closes exploits which allow jailbreaking, precludes it in the EULA. What more would you have them do?
Preventing jailbreaking is not a good thing, in part since that's what allows us to check on what Apple is doing on the device, in regards to privacy, security and e2e encryption. If nobody can check, do you suppose we just accept their statements about the device as fact?
iMessage using SMS to communicate with Android devices increases the risk to iOS users. Apple customers are still Apple customers when they communicate with Android users.
Every risk you describe is still present in the current implementation of iMessage when communicating with Android users, except the risks are much greater because SMS is much easier to exploit and intercept than an E2EE protocol would be.
A message platform that forces Apple users to use an insecure protocol when communicating with Android users decreases the security and privacy of Apple users.
So even an imperfect implementation of real E2EE between Apple and Android users, even with all the risks you describe above, is still an improvement in security over what we have right now: a situation where Apple forces iMessage users to use to what is quite possibly the least secure communication method possible when communicating with their friends and family in different ecosystems.
It's not necessarily about helping the users of another competing platform, Apple users who are using normal iPhones are sending unencrypted and unsecured messages to their friends and family members because Apple is more interested in vendor lock-in than it is interested in making sure that its customers are able to communicate securely with their contacts.
The idea that Apple users would suddenly stop caring about security or that they wouldn't want their conversations encrypted just because they're talking to someone else who's on an Android device is very strange to me -- it suggests that Apple is willing to sacrifice security for paying iOS users just to keep Android users from seeing any of the benefits of those security improvements.
Yes, there may exist reasons to distinguish between locked down vendor-controlled devices where users do not have the autonomy to change device settings that could damage encryption, and devices where users do have that autonomy. I understand that concern, even if I think it's usually disengenous. But there is really no reason and no excuse (especially now that we know how easy it would be for Apple to take its encryption multiple-platform) for going beyond distinguishing between those devices, and going so far as to actively drop all security measures and all encryption from those conversations. It's like saying that because a window can be broken we might as well take the door off of its hinges and put up a "burglars welcome" sign -- and, incredibly, it's claiming that anyone who tries to replace the door without permission is somehow decreasing security. Apple doesn't just distinguish between controlled and uncontrolled environments, it removes the door entirely by dropping its users into a messaging format with no end-to-end encryption at all. It's a bad policy that hurts Apple users and decreases their safety.
it's going to become illegal not to have one in california! so you better invest NOW!!!
go to double U double U double U blah blah blah dot yadda yadda yadda
*full disclaimer, this technology is patent pending**
**doubly full disclaimer, "patent pending" in the sense that the invention is still to be invented, the panel of experts said 20 (more) years!
The smartphone is the single most important device for modern life and society. It's news, photos, communications with loved ones, work, entertainment, food, paying for practically everything...
And it's just two companies. Two companies with an iron grip over such a wide and diverse set of functionalities that, taken together, should be as inalienable as free speech.
- They control what you can put on the devices (or in the cases where they're open, they scare you or make it exceedingly difficult).
- They tax all innovation happening on the platform. Because web is second class. If you build an app, you have to pay for ads against your own brand. You can't have a customer relationship (yet Google and Apple get that). You have to keep up with their release cycles on their timeline. They can deny you or ban you at any point. They take 30% of your margin. You're forced to use their billing. In many cases, they actively develop software that competes with you.
- They're extremely user hostile. The devices aren't easily repairable, the batteries force upgrade cycles, and they do stupid things that make your kids want to buy the most expensive model for clout. Green and blue bubbles, etc.
- On top of this, they're gradually eating away at every related industry. The music industry. The credit cards and payments and finance industry. The film industry. It's all getting absorbed into the blob that is the locked down smartphone.
- They turn their devices into "CSAM detection dragnets" (read: five eyes, US, China, and every other entity that wants to surveil).
This is fucking absurd and it needs to stop.
We need more than two device and platform manufactures.
Apps should be at least one of: (1) portable, (2) freely installable from the web without scare tactics, (3) web should be first class / native
The device provider shouldn't be able to use their platform play to maintain dominance. The cost of switching should be zero until there are enough new peer-level competitors.
I could keep going... the status quo is a tax on the public, a tax on innovation, and a really overall unfortunate situation.
Sent from my Librem 5.
That basically makes it a non-option for the overwhelming majority of people, and it was still an issue 6 months ago.
I really want to like the Librem but it's hard to justify the price tag when you're going to have to carry another phone around with you anyway.
The battery thing is not an issue for me in practice. I carry a spare battery (they're swappable), but I never actually need it because there's USB-C chargers everywhere I go, and I made it a habit to plug it in whenever I can.
A phone should adapt to your lifestyle. You should not have to adapt your lifestyle to your phone.
Edit: Actually it did happen when I opened a Firefox tab with a heavy js and left it open with deactivated suspend, which you shouldn't do on any phone (and even then it's more than a couple of hours).
that would be nicer than the current situation where they take away 30% of your revenue
There's also the mountain of 'mobile first' (aka mobile-only) garbage out there, and stuff that is nerfed on mobile unless you download the app (so they can squeeze telemetry out of you).
Don't get me wrong, I'm not defending Apple or Google - far from it - but I'm saying there's a lot of real crap going on in tech right now.
To be fair, I am a curious person and use both android and iOS. I use onedrive and (sigh) icloud for storing photos. On my android phone, I can actually have it sync pictures to onedrive and nowhere else (and it'll free up the storage, even! I think...). On iOS it either fills your phone up and then nags you constantly to manually delete pictures, or you use iCloud. There's no other choice.
Ding ding ding! We have a winner!
It's the same reason they dragged their feet supporting RCS, until regulatory pressure started mounting.
I find this incredibly hard to believe. And just because the Apple marketing department believes something is true, doesn't make it so.
Maybe I run in a weird crowd, but I've never met anyone who cares whether "text messages" are delivered over SMS or iMessage. In general most messaging I do happens over Signal, WhatsApp, Discord, or (in a few unfortunate cases) Instagram messenger.
https://www.thurrott.com/apple/248931/apple-didnt-bring-imes...
On a more serious note regarding the Hardware sales- Apple inc does not make that much profit based on "what" they sell, its "who" they are selling to.
It’s possible that the GP is unfamiliar with iMessage because they don’t live in NA. I have neither sent nor received an iMessage for several years. I use the Messages app for receiving SMS OTP codes only and pretty much nothing else.
It was an acquihire involving a 16 year old who was doing it for fun.
I am reasonably sure that their main driver is profit which really means exploitation of people;
I consider their public arguments lies made up to cover up the fact that what they account for as profit comes from what are in the end some really ugly historical and traditional imperialistic (colonial, neocolonial, and occulted) practices
Just wondering if you've forgotten what site you're on.
This is YC which exists to build companies whose main driver will always be profit.
that's the generalized pattern
What phone do you use that does not have the same issue?
As opposed to Beeper?
The GitHub developer I guess. Still his project got noticed because of all of this so it still sort of fits.
Doesn’t mean it wouldn’t be an awesome project to do. I don’t blame them one bit. It’s an awesome achievement.
What technical investment? They bought an open-source project from a high-school student.
Beeper Mini is an app they would have built anyway. They simply implemented the bare minimum of iMessage functionality there. Which is a couple of days worth of work, maximum. Maybe a week. And some for testing.
I’m somewhat certain it cost them less than 5 figures. And if it did, what a great marketing campaign. I had no idea what Beeper even was before this whole fiasco.
As is all I know about is the chat app whose primary sales pitch is the now-broken iMessage interop.
Using an exfiltrated binary they used its blackbox functions to perform a sort of device attestation using ripped Apple device identifiers. Clearly Apple simply needs to blacklist any device attestation that this service uses, which is obviously trivial. These aren't just RNGs they're fabricating, they're sets of legitimate Apple device data that isn't plainly evident to any random user-mode app.
Why would they block it? Every service has some sort of gate on who can message or it will be overrun by bad actors and spammers. Signal, Telegram and others make you validate your cell phone number -- there's a finite number of those, and they can blacklist them as necessary. Online services make you validate an email, do bot checks, etc. Beeper, and more importantly the technique they used, offers none of those gates. It was a plainly problematic free for all that was guaranteed to be closed.
but I don't think it's their main reason, if anything I see that argument as convenient posturing which aids in covering the uglier underlying reasons
1: https://developer.apple.com/documentation/sms_and_call_repor...
This explains some things. Why wouldn't they just add a spam filter. Is there still iCloud email addresses? Do they have spam filtering?
This could have been blocked in minutes. The delay was likely to get approval from Legal.
Hmm, wouldn't blocking IPs be overly broad and risked affecting regular users? Considering that IPs are scarce and constantly recycled by ISPs etc. Blocking device identifiers sounds more targeted and, for that reason, realistic.
So your point is Apple can presumably distinguish between an actual iOS connection and Beeper's connection by looking at "how many connections per IP"? Still seems prone to false positives to me, unless there is something else I missed.
(Upon re-reading the post, I realized that the phone number registration is actually done by Apple. Wonder if this might provide another basis to block Beeper, i.e. all this SMS infrastructure is not cheap to maintain and Beeper's integration is arguably using it in an "unauthorized" way.)
They don't need to break it completely. If Beeper is unreliable, nobody is going to pay for it.
The amount of legitimate users it would affect would be trivial and can be taken care of by customer support.
The benefit of that is that I can then, at that point, verify if we’re dealing with a legitimate device or not. Geniuses at Apple Stores can obviously do this physically, and remote support has the option to run remote diagnostics and even share screens.
Otherwise the IP Apple sees is those of the individual handsets on whatever network they are on.
It's pretty likely that they blocked Mini based on the IDS (Identity Service) which requires the device to pass it's hardware model, serial number, and disk UUID as described elsewhere.
https://github.com/JJTech0130/pypush/blob/main/albert.py#L16
What will really happen is that there will be some subpar common denominator. An existing "walled garden" (WeChat?) would add support for this as well.
But this would wind up being rather insecure, because messaging services tend to use email addresses they don't control or phone numbers they don't control as identifiers. We'd have to wait for carriers and email providers to be regulated with the burden of solving this mess (for markets they aren't in).
Letting (actual) Android users use iMessage probably wouldn’t affect that, but the open source hack/reversing of it opened the door to iMessage spam that Apple, for the sake of reputation, and customer satisfaction, is obliged to close.
Anyway, I guess my point is that there are some “burdens” that are less obvious than others.
The word "monopolist" in 2023 seems to mean "a company whose corporate values are different than my personal ones and/or whose pricing and packaging don't match my consumption function and/or who has a lot of money and of whom I am jealous".
You can say iMessage isn't a texting app because iMessage functionally (as in, the technical details) works like a non-texting app, but it is the only texting app on those phones and is the way normal texting is done. Perhaps it would be different if iMessage was just installable from the app store.
I understand that the distinction might seem slight, but in the eyes of most US consumers, texting is distinct from a chat app that you download from an app store even if it uses your phone number.
The absolute one way that everyone with a phone has to send a textual message to another person is to text them with their phone number.
In the US, where adoption of Signal, Whatsapp, Discord, or insert hundreds of other apps is very small, the percentage of your real world contacts using a particular app is also extremely small. Convincing all of them to use Signal would certainly be great, but in reality you will be using all of those apps if you are trying to escape the interoperability nightmare that is currently texting.
Given that everyone has a phone and they are all texting already, it would be awfully nice if we could just use texting without these interoperability problems without having to manage all of the apps, and without having to remember who prefers which one.
Group texting is also hugely popular in the US. If no single third party messaging app covers the set of friends you want to group text, what do you do? You text them. Because everyone has it. Let's say when you started your group everyone was on Whatsapp. Phenomenal! Start the group on Whatsapp. Then you meet Joe, and Joe is very cool and you definitely want him in the group chat. Joe doesn't trust Meta products and doesn't want to use Whatsapp. Should Joe capitulate, install another chat app used only for a single group chat, and grant access to their device to a Meta app? Should a negotiation occur amongst the rest of the group where they select a new common app to run the group on and split the conversation history, while also adding an app that they only use for that group chat?
Let's say they choose to switch to Signal, but Josh keeps forgetting (dammit Josh) and keeps messaging the group on Whatsapp. And instead of yell at Josh that the group is on Signal now, folks reply! Because Josh's joke was super funny. Conversation also continues on Signal. Someone on Signal now does a reference to Josh's joke on Whatsapp. Joe is confused, but everyone else gets the joke. Someone realizes what happens and sends a screenshot of the joke and ensuing replies from within Whatsapp so Joe can catch up, but the messages around the joke are longer than one phone screen so there's a lot more context that he misses. Joe is annoyed but he gets over it.
A few months pass and Sandra seems to have a bug where Signal is chewing through her battery life. Since only one of her group conversations is on Signal (she uses Whatsapp mostly) and she is fine not getting the work related banter that is often the topic of the group chat. But then she finds an article that's super interesting and she wants to share it with the group. She remembers that the group moved to Signal, but who cares, that Whatsapp group still exists and there's only, like, one person that isn't in it. She sends the link in the WhatsApp group instead. This leads organically to the group wanting to get together for a holiday. They plan out that July 12th would be a perfect weekend, and since they want to do a potluck, they all choose what part of the meal they'll bring.
A few days before the potluck, someone mentions on the Signal chat that they are excited to see everyone at the potluck. Joe is very confused and asks what they mean. They realize that this was in the WhatsApp group chat and explain what everyone is bringing. Unfortunately Joe is working that weekend, and can't come.
Should the group chat reschedule?
Personally, I don't use default texting, like, at all. Except for those notification/2FA SMSes and couple of contacts, I don't ever open it. For me, mentally, chatting with people (with 2 exceptions) is done through different apps, not the built-in one. And this forms a view that default app is just "one rarely used messenger, of many".
But then, even though I'm in the US, most of my chats are international.
Nitpick, but I can text from my Mac laptop using the messages app. I haven't looked into exactly how exactly it works but I think it's somehow proxying/mirroring the messages through my iPhone. It's very smooth and "just works" though.
> interoperability nightmare that is currently texting.
How about calling it an open competitive market? Centralizing everything on a single format would be a bad thing for the industry and for consumers. Having separate independent networks with drastically different feature sets is a good thing. Trying to find the intersection feature set of Discord, LINE and Signal would result in three applications drastically hampered in their features. LINE for example has an extensive independent industry of artists selling "stamps" that you can buy.
Yes, SMS from iMessage on your non-iPhone (Mac, iPad) proxy through your iPhone. iMessages do not require your phone to be on, since Apple can deliver it directly without using SMS.
However, without a phone you cannot send an SMS message, and most people use phone numbers as contacts in iMessage, which requires an SMS based registration done transparently by your phone.
But all of this is just the technicals of how it works, to the end users it is just texting. The only reason non-technical users are even aware of, or care about, the distinction is because of how iMessage breaks group texting as soon as there's a non-iMessage user involved.
> Nitpick, but I can text from my Mac laptop using the messages app. I haven't looked into exactly how exactly it works but I think it's somehow proxying/mirroring the messages through my iPhone. It's very smooth and "just works" though.
Correct. I think the GP’s remark meant to say “…as if it was a phone, without a phone as well”.
If you’re sending or receiving an SMS from your Mac through the messages app, it absolutely depends on your phone being powered up and online, to route the message through.
But do we know why that is? In Europe everyone's on WhatsApp, and while I'm not especially fan of it, the one feature that I like is that it can be used from any browser on any device, including desktops, including a work laptop where one doesn't have admin rights to install anything, etc.
I can leave my phone away in my pocket all day and still message anyone I please. I would hate it any other way. Why don't people in the US want that?
I have that already via Google Messages, and iMessage already has that as well.
In the case of Google Messages, it's just a web app, you don't need to install it. You visit messages.google.com and scan a QR code from your phone and the devices are linked.
Or FB messenger, or actually mainly use SMS/iMessage. Europe is not as homogeneous as some people here might be implying. WhatsApp is not even the most popular messaging app in quite a few countries (Messenger is).
Also in Scandinavia, Britain and Switzerland iOS is about as popular as in the US while in some other countries it’s closer to 10%.
Sure, but I don’t think personal preferences matter that much in this case, most people just end up using what everyone else is whether they like it or not, which makes perfect sense.
But yeah, I think in most of Europe (not all, they were free/almost free since the late 2000s where I am) this started because SMS messages very relatively very expensive back when smartphones were becoming widespread.
Now WhatsApp, Messenger, Telegram, Viber and whatever else there is are quite entrenched so even if Apple and Google get serious about properly supporting RCS it might get tricky to get users to switch back to the default client
Popular non open-source 3rd party messaging apps don’t really have much interest in supporting interoperability due to obvious reasons.
> ..modern texting app that could message literally anyone with a phone number? Without having them download a specific app?
Well on this thread it seems that WhatsApp might be exactly that from the perspective of some people (to the extent that they don’t even believe that anyone in Europe could be using anything else)
I do want to say I've seen some others in this HN story contradict that Europe is as homogenous as your representing here though.
Still though, I looked at Germany's Whatsapp numbers and it's like 68% of the population, ignoring the fact that 1 account is not necessarily 1 person.
That's super dominant compared to the US which is somewhere around 22% with the same account assumption.
True. But it’s hard to say to what extent. Many/most people probably have multiple apps installed and use them somewhat regularly in addition to texting/iMessages.
I’m not sure what messaging standard you propose gets adopted, because the flavour du jour of most non-iMessage users is RCS, which as an open standard, is unencrypted and insecure.
(Well, at some point a year or two ago there was some controversy around WhatsApp, and some groups tried to migrate to Signal, but that all died out within a month -- never quite started, actually).
Believe it or not, I had almost never heard about iMessage and its specific quirks before the Beeper story (and still don't understand why the colors of the messages in green or blue matter).
> and still don't understand why the colors of the messages in green or blue matter
Because it indicates a fallback to standard SMS/text messaging which means all the more advanced features (which everyone expect messaging apps to have these days) stop working if you get a text from an Android device.
Bob has a hardon for mastadon so then another subgroup is created. Joan finds out that her Google Fi service is incompatible with RCS so she decides to create an email list. Joe finds a bug with Beeper and then decides that really everyone needs to move to ICQ. Marley decides maybe everyone should just try MMS again except that nobody can fall back on that because everyone except Joan has opted into RCS.
Apple's not going to solve your social problems (nor will any other company).
Another protocol like RCS? RCS simply solves the problems of SMS/MMS. It doesn't add another protocol, it ultimately replaces two of them.
> Bob has a hardon for mastadon so then another subgroup is created.
Good for Bob. I don't think Mastodon supports group chatting and its DM support is super nascent, its weird choice but I wish him the best.
> Joan finds out that her Google Fi service is incompatible with RCS
Even though Google Fi is definitely compatible with RCS, we can assume it isn't supported for the scenario.
> so she decides to create an email list.
Joan doesn't know what RCS is and doesn't care. Joan makes a group of people on Messages. It works fine, as it falls back to MMS automatically.
> Joe finds a bug with Beeper and then decides that really everyone needs to move to ICQ.
Wait why is anyone using Beeper here. So the user used a unifying client and ran into a bug and blamed something about the underlying messaging system?
> Marley decides maybe everyone should just try MMS again except that nobody can fall back on that because everyone except Joan has opted into RCS.
Everyone on RCS can fall back to MMS just fine, just like iMessage can. The only difference is one of these is a standard that Apple can implement and the other is a proprietary protocol that Google cannot.
It doesn't add another protocol, it ultimately replaces two of them.
How does this work (assuming your carrier supports MMS, and not all do): Everyone on RCS can fall back to MMS just fine
As for this: Even though Google Fi is definitely compatible with RCS
https://old.reddit.com/r/GoogleFi/comments/l1czwh/google_fi_...More recently it looks like Google added some half assed support for RCS and broke other stuff in the process:
https://old.reddit.com/r/GoogleFi/comments/12b8k2p/reminder_...
My cell carrier provides SMS for free, both sending and receiving. My cell carrier charges for MMS, both sending and receiving, so I have MMS disabled. My cell carrier doesn’t support RCS, and would probably charge if it did.
Thankfully, nobody I know tries to send me pictures using SMS/MMS/RCS, and uses WhatsApp / Signal / iMessage instead.
> Another protocol like RCS? RCS simply solves the problems of SMS/MMS. It doesn't add another protocol, it ultimately replaces two of them.
Experience tells me this is false, and that nothing ever dies, nothing ever gets replaced, and augmentation always happens, in IT.
I don't see anyone on Android wanting to put their SMS messages in the Discord app.
> No one wants
Quite the assumption. I had Google Hangouts set as my default SMS app for a time.. this seems quite similar to your Discord example?
It hurts nobody to have the _choice_. If you don't want to change the default that's totally OK.
In everyday iPhone usage, you would either run an app directly, use sharing intents, or use a messaging service specific identifier (eg custom URI scheme) to converse with someone. The social graph is either in the messaging app itself or in individual contact entries. There's no expectation of a Trillian/Adium style app that consolidates all information and messaging options.
There’s no choice not to use iMessage or their iMessage app to send a text, except if the other person is registered to iMessage, it will use that instead.
It’s really annoying. They either need to disable iMessage or open it up as a separate app you get from the App Store.
(for the users, not for the companies)
Although to be fair, I have a hard time imagining a world where this ever happens. So large companies have to proactively share information on all their users with all the other large companies, and vice versa? Or do I become skygazer@iMessage and everyone on instagram has to know that? This just seems like an absurd thing to mandate.
For what it's worth Beeper Mini did support using Apple's iMessage registration system to use your phone number.
Wrong
What do you mean by above board? What they claimed is that there is no way of telling Beeper Mini clients from an old iPhone, therefore Apple wouldn't be able to block one without blocking the other.
Clearly Apple managed to find a way, and who knows if there will be some more cat and mouse happening here. In theory though, I don't see why it wouldn't be possible to have a service that's indistinguishable from an old iPhone.
Newer devices can use device attestation, but old iPhones don't have secure enclave.
https://www.telemessage.com/mobile-archiver/whatsapp-archive...
It’s literally a hacked WhatsApp binary (that logs all your messages) that they sell to corporate clients…
Snapchat as a service is no more. But there may be other options:
It's only a matter of time until that "black box" gets manually deobfuscated. Apple should waste less time on this and instead focus on algorithms that detect and stop spammers.
They’d block an account out of spite without a second thought.
Does it come down to The Law of Leaky Abstractions?
>> https://www.joelonsoftware.com/2002/11/11/the-law-of-leaky-a...
Which means that if Apple wants to change something eventually, then they will possibly break downstream abstractions and then people will complain and the downstream abstraction will say "Well Apple changed their API, it is their fault". Letting someone do it from square one would be enabling that future scenario, as it isn't "if" it changes, it is "when".
If it was an open source API that would be different, but Apple's is closed source, that is Apple's philosophy at the core. It is a closed API yah? Not even an open spec right?
Vendors are going to have to actually work on improving the standard (and Apple has committed to working within GSMA on an appropriate multi-vendor E2EE mechanism)
In the absence of interoperable standards through GSMA, there will likely still be quite a bit of broken behavior, e.g. when it's not a Google RCS Server and all Google clients.
There is zero benefit for apple to make it good and no commercial reason for these vendors to make it good for multi vendors.
It really isn’t clear to me why so many people are so angry they cannot use iMessage on Android.
I think one of the key reasons, other than apple sending push notifications that it's going to automatically install overnight, is they bundle candy/goodies to entice users to update asap - Want the new emojis so your friends stop sending you scary black boxes with an x over it? Update now.
* Apple is really popular in the US
* Apple users tend to rely heavily on Apple's default applications
* Apple's messaging app is the default, and works fine with other Apple devices, but sends shitty SMS or MMS to non-Apple devices
SMS would disappear tomorrow if Apple adopts RCS.
And if they allowed iMessage clients on other platforms, they could corner the entire messaging market.
Once you automatically reject SMSes from those contacts, such that you don’t even know they're trying to contact you, the ball is entirely in their park to take action.
And it's not like there' some gigantic combinatorial explosion of apps you have to install. The vast majority of messaging around the world is about 5 apps. Facebook's Messager, Wechat, Instagram, Whatsapp, Discord. Between these, you'll reach the vast majority of the world's population somehow. And then you'll need one or two more locally-used ones like LINE or KakaoTalk depending who you're talking to.
It’s less about a specific feature set and more about inclusion and acceptance from/by peers.
This is especially prevalent among the younger crowd. Think high school group dynamics playing out with phones.
And then on top of that, photos/videos are terrible quality.
I mean just imagine they'd degrade sound to nearly noise if you'd call a non-iPhone.
The reason the video looks like ass is because MMS messages aren't meant to be very large. While (iirc) there isn't a hard limit, the recommended maximum message size is ~600KB. The only way to fit a video into that range is to compress the hell out of it.
Apple knows of such limitations and does nothing to improve the situation. In fact they ban those who try. FTA.
Why would they? It's not their problem, nor does it seem to be a big deal for their customers because they're not clamoring for a fix.
> In fact they ban those who try. FTA.
They don't, thiugh. The App Store has tons of photo and video sharing services, email, and other messaging services; I'm sure any number of them would let your iPhone-using friends and family easily send you a non-mangled videos. This is a solved, dozens of times over.
iMessage, on the other hand, is a service Apple provides for Apple customers. They get to set the terms under which it's used, and Beeper did not abide by those terms.
In my part of the world Whatsapp is the defacto standard for group chat and even for things like scheduling anpointment to a doctor/dentist/hairdresser.
And that is because it is available on android, apple devices and even those cheap kaios halfsmartphones.
For some, but everyone knows and has the capacity to download WhatsApp.
The root issue is there is a lot of judgment about Android users, hence wanting to restrict chats to iMessage. It’s a signal that you are part of the in group vs out group.
Although, it is objectively convenient to have a group of all iMessage users at events, because any pics/video get shared at high quality with no extra work.
For example, when RSVPing to a kid's birthday party, other parents' numbers are inevitably blue. When selling and buying items, the contacts for those sales have always been blue numbers, it's rare to encounter a number that doesn't "turn blue" when I enter it into the "to" field
I would say maybe 5% of the people I know and text use Android. For one of those people I use Signal, one other has asked me to use Facebook Messenger, one has asked me to use WhatsApp, and the remaining few use SMS. It's a pain to use three separate apps to message just these three people!
One of my cousins switched to an Android phone. This broke our long-standing group message in iMessage, so she was no longer able to be included in it. After two years of this her siblings simply ordered her a new iPhone and she is back in the group chat
Getting everyone to move their default messaging behaviour for one person is a huge ask. It was easier for one person to just relay the group chat info instead, but when this became annoying, it was even easier to buy her a new phone
It is very annoying and quite real.
Apple is arbitrarily and intentionally making it a worse experience than it needs to be.
The reason the iphone users don't like it is because Apple specifically and artificially makes the experience annoying and shitty in several different ways, for the iphone users not just for the Android users.
> Over time, the annoyance and frustration that built up between blue and green bubbles evolved into more than a tech problem. It created a deeper sociological divide between people who judged one another by their phones. The color of a bubble became a symbol that some believe reflects status and wealth, given a perception that only wealthy people buy iPhones.
...
> On dating apps, green-bubble users are often rejected by the blues. Adults with iPhones have been known to privately snicker to one another when a green bubble taints a group chat. In schools, a green bubble is an invitation for mockery and exclusion by children with iPhones, according to Common Sense Media, a nonprofit that focuses on technology’s impact on families.
> “This green-versus-blue issue is a form of cyberbullying,” said Jim Steyer, the chief executive of Common Sense, which works with thousands of schools that have shared stories about tensions among children using messaging apps.
* Android user in the US where this dynamic primarily exists, but I just don't care because I'm not 20 any more. I only very occasionally need to send a video or picture to anyone, and in those cases, I know enough to use email or a google photos link or something, which probably annoys the recipient a little and makes me weird to them, but I'm just ok with that since I know where the blame really lies. Similarly in the occasional times I txt with family members or friends, we're not in high school and so they don't care about my green bubble, and I just accept the annoying stupid extra txts I get that say "x smiled" or whatever. That ux don't bother me in the sense that I don't spend any time thinking and caring about it, but that doesn't make it not utterly stupid and ridiculous, and especially so when you know it's a deliberate act and not an honest technical limitation. Astonishingly it's possible to both recognize that something is not worth investing much care over, and recognize that it's wrong and that it's a deliberate wrong commited by someone and not just the weather. Amazing!
In a word, android would be considered just as uncool even if they had access to imessage.
I know multiple people who have switched to iPhone just for iMessage. And the kids these days won’t accept anything but the blue bubble. This is no longer a meme. Or if it is, it’s also real.
At least it sounds like that's what happens across the ocean.
Knowing someone has an iPhone tells you nothing about their wealth/power.
What people think it does tell them is where someone is on the cool / weird spectrum. See:
I have an ipad just to chat with people who refuse to use anything other than imessage.
I don't want anything to do with iMessage, but I have to.
Well, the time has come.
Most people don't talk to people they don't communicate as well with.
For those technically savvy enough to download an additional client like Meta's Whatsapp or Messenger... it's no problem, but for the less technically inclined (like my mother) they will just use the default client.
I'm in my early 30's and have been told to my face by friends I'm hanging out with that they excluded me from group chats because I have an Android phone. Sometimes there'll be two group chats where the second one is just the iPhone users subset. Some photos only get shared in that second group chat. Some messages get sent giving people a heads up about things and the sender sometimes forgets that a few people are being left out of the loop. There are real social segregation issues that happen.
> This doesn't appear to be some easy thing Apple can just turn off.
> It will require a complete redesign of their entire authentication and delivery strategy for not just iMessage but Apple ID account access as a whole.
It’ll be interesting if beeper mini ends up bypassing it.
They’re tech fans, not experts but act like they know the domain space enough to make strong authoritative claims since that’s what gives them an audience.
Honestly many people here, myself too probably at points, tend to just repeat what they’ve heard elsewhere as fact. You can see it if you try and notice phrasing patterns repeating.
My real lesson is less that the internet is a shit show (it is though), and more that people like to take a very strong opinion as fact, over a more nuanced opinion that requires understanding of a topic.
/s obviously!
literally yes, that is the correct course of action.
the issue is that you cannot publish videos and make money if you refrain from talking about stuff you don't really understand.
which is one of the problems with modern society, in general.
If the metadata includes the OS version, Apple probably blacklisted any new devices registered in the past few days with validation blobs generated from that binary.
(The binary was sourced from OS X 10.8 which is ~11 years old now)
Apple would've found some easy way to identify these users and Beeper will likely release a patch to fix it.
Maybe not though, who knows
I know this won't work for everyone (especially folks that don't have an Apple device). But this might be better than losing the app all together ¯\_(ツ)_/¯
(PS - I don't know much about how Beeper Mini's reverse engineering worked. Just going off what I believe I understood)
parent is asking if it’s possible to spoof the secure identifiers from the Mac in Beeper - extracting the secure IDs, inputting them into Beeper - at which point Beeper can communicate directly with Apple as if it is that Mac.
a clever workaround!
But I wonder if that’d even be possible. I hope someone from the Beeper team sees this!
As an iPhone user, I hate the idea that spammers can now use iMessage, and I'm glad the service was taken down.
Both things can be true at once.
I suspect there's some dark market for broken iPhones, and perhaps some rate limit for activations within a city block/building. The last time I had iMessage spam was years ago, so maybe it's not so practical.
(edit: typo)
I’ve never thought about it but that would be a huge black mark and could end up pushing a lot of people to WhatsApp/FaceBook Messenger/whatever.
This are not just spam but most are sms phishing with links. We have poor, inadequate cyber laws, so we are glad Apple is doing its part sealing this off.
Well no; spam yes, only spam no.
Signal is open source. It's a fair argument that they make it difficult to use servers other than theirs, and we can't be sure exactly what they run server-side, but their code is possible to fork and all that. Their licensing is clear. Even the choice of AGPL is significant here: they must provide the source for exactly what they run on their server.
Network access is orthogonal to source availability/openness. Closing source as a means to limit access is security through obscurity. Not to say that it wouldn't work, but we certainly wouldn't expect the Signal Foundation to take this approach.
The most significant measure Signal uses to manage access to their network has to do with the phone number requirement. That's an intentional choice on their part (arguably controversial, but I don't have an opinion about it).
I've never received a spam message from another Signal user... is this common for you (or anyone)? I think in all the years I've used Signal I've only received less than 5 spammy "message requests" that are quite obvious/easy to decline because I don't already have their phone number in my contacts. I've always had to first ask someone "hey, can we use Signal?" so I'm already expecting legitimate message requests when they arrive.
Now that Signal has usernames you can share, rather than phone numbers, I think the phone number decision is a lot less problematic.
Strangely enough, I did receive spam this week. Or at least I think I did, an account I didn't recognise with a profile picture of a woman I didn't recognise sent me "hi". This coincided with my first SMS spam of the year and spam on an email address I used for one specific company, so I guess they've been hacked and had their database dumped. Maybe I'm just lucky, but spam just isn't a problem for me.
Not that we'd get it in the US but it would help reduce Apple/Google market capture efforts.
What for? Everybody in the EU already uses whatsapp. That shows how unnecessary these selection screens are.
Going further: if we download different messengers, it stands to reason we can download different browsers, therefore if safari is the most used it's because it's the one we choose.
Honestly - and EU-regulation that Apple faces over iMessage would just be collateral damage from EU targeting Whatsapp.
Meanwhile, wait until Mr. Zuckerberg looks for new ideas to monetize their messaging ecosystem.
WhatsApp is the current leader because it's no-nonsense and works everywhere. The moment Facebook fucks that up even a little bit, people will have moved on to the next thing.
The last messages on a dying messenger are always instructions on how to move on to the next thing. In skype, my status and most recent messages are just informing people of my discord handle. I accept that I may not be the norm, because generally I don't reach out to people and don't initiate contact, meaning that the onus is on them to use the appropriate channel to reach me.
Maybe it's worse for people who voluntarily stay in contact with many others using different messengers, but I don't see the problem with just having multiple messaging apps, especially since modern phones just consolidate all messaging services's contacts into your contacts app (at least on Android). You don't even need to remember who is reachable where.
This is the problem I was expressing. If I want to contact Joe I have to use Signal, if I want to contact Sarah it is WhatsApp. Sam is SMS. Its hard to remember who is using which app.
> but I don't see the problem with just having multiple messaging apps, especially since modern phones just consolidate all messaging services's contacts into your contacts app (at least on Android). You don't even need to remember who is reachable where.
That is easy enough if you use the contacts app. I usually go straight to the app I want. Regardless, it doesn't solve the core problem because people use multiple apps. How am I supposed to remember which app they prefer? I could message them on their non-prefered app, but I don't like doing that if I can avoid it.
Thats the reason why until now they only added non intrusive monetizing ideas than company accounts and so on. And when you ask me, they found a way to make whatsapp better. I can now order sushi via whatsapp. Here in Germany I know no other messenger that makes this possile.
Facebook's business model is predicated on being able to sell access to me to third parties.
I can control the first one directly.
But messages falls back to sms and that I can notice.
Thats was the way to my blacklist. Droped Signal caused by unreliability.
Additionally, same as now iMessage, close out of other clients. Other asshole, same shit.
Wasn't that in 2014, so literally 9 years ago? Things are pretty different now.
There’s no other good group chat encrypted option for both iPhone and Android.
At scale yes, signal, telegram and whatsapp are perhaps more significant than the apple ecology and the ratio of android to apple outside the USA and canada probably shows why.
“Installs” are muddied by the fact that everyone with a Facebook account has a Messenger capability, and every Apple user has an iMessage app downloaded.
“Messages received” is distorted by group chat dynamics and commercial messages.
“Messages sent” is distorted by the unequal value of relationships.
For example, I generally communicate with FB marketplace sellers & acquaintances from high school on Messenger, but use WhatsApp for talking with overseas family members.
More generally, there are social dynamics which make messenger apps radically different from one another. Even when the feature sets of the applications are very similar.
But it gives normal users a choice if they want it. Maybe it would get some to think oh maybe I should try Signal. That's how some people found out about Firefox - unimaginable I know.
Most of my family, friends and colleagues are on iMessage. I often need to explain why facetime will not work.
Whatsapp is also common, but different as it does not as easily replace SMS.
Make X low enough, 250, and all of this would go away: no more corporatism, no more monopolies, no more special groups interests paying for government lobbying, no more abuse of power from a handful of companies...
Also there are a lot of things people could say “You know what you’re describing is never going to happen.” That did happen.
I’m not suggesting this one is. I don’t think so either, but it isn’t a very productive attitude.
Now I have a company that cannot compete at the scale some chinese company can. OK so we close the border to imports from companies that are larger than our rules. When has that ever worked out?
In fact, I didn't realize it's actually viable until now.
https://gs.statcounter.com/browser-market-share/desktop/worl...
Why does so many people have this attitude that Safari sucks and the only people who use it are idiots who don’t know better?
It’s so incredibly insulting.
Not that putting native Mac in quotes implies anything nice either.
It’s absolutely baffling that you could read my post as saying safari sucks or that people who use it are idiots.
Let me try to be more clear… there are two reasons someone uses Safari on macOS, in my experience:
1. They like it better. Usually, the reason they like it better is because it feels more “native Mac”. This term is in quotes because it’s not a technical term and my understanding of what it actually means is vague, but I by no means dispute that it’s real.
OR…
2. They don’t care, so they use the default.
The way this is written implies to me you think they should install something else, but obviously they just don’t care.
Whenever there are discussions about Safari on hacker news they tend to be a lot of people who seem to have the opinion it should die and that anyone with a brain uses chrome.
Between your word choice and that seemingly common sentiment here that’s what I thought you were saying. I’m sorry if I misunderstood.
I'm trying to understand the reason for the white knight HN commenters NPC reactions coming with their "stop insulting my favorite trillion dollar corporation".
There’s a very common sentiment on HN and other technical places that safari is a serious problem that needs to be removed from the web so that things can be “better”.
That’s why I’m insulted. Not because someone is insulting Apple, do that all you want if they deserve it. Because I’m tired of people implying that the browser I like is shit because it’s not chrome and its only used because people have no choice or can’t figure out how to switch.
People are entitles to their own opinion regarding products. If they think it's shit, it's their opinion same how you're entitled to your own different opinion, no need to be Apple's unpaid white knight and froth at the mouth at everyone calling their stuff shit.
Not every app needs to be compatible with every other app, though. There is a user base cutoff (and even then there is some room for interpretation) of 45 million users (10% of the EU population)/10k business users.
Negotiations aren't done yet, but it seems iMessage isn't popular enough to meet this cutoff. Alternatives like WhatsApp definitely are, though; I'm pretty sure that's exactly why Facebook is working on cross-platform messaging for WhatsApp: https://www.theverge.com/2023/9/10/23866912/whatsapp-cross-p...
This law doesn't just effect chat app developers: it also applies to app stores and other methods of digital gatekeeping.
That being said, Apple argues the app store for its iPads aren't popular enough to cross the threshold (they split up the iOS app store and the iPadOS app store in their statistics), so the impact of these requirements will depend on what specific iDevice you use.
When the EU forced that implementation, it was already behind the ball.
It all but ensured Chrome’s dominance by killing Firefox’s momentum and proved unsuccessful, which is why the browser selection screen got killed.
Basically a weapon to taint your competitors brands by redirecting their viewers away from their content to ad saturated AI garbage.
And the tweet fundamentally misunderstands how ahref works. If google killed the site in question, ahref would have no idea given they have their own crawl.
If anything, it makes iMessage look desirable, like a long line in front of a nightclub.
Literally everyone “saw that coming”. It’s also obvious that the client will be updated to make it work again, and the cycle will repeat.
I thought someone said something about that to block beeper mini, Apple would have to also block older iOS devices as that’s the method they were using that wasn’t as locked down.
Apple can try suing Beeper for publishing software, but ultimately software (that doesn’t infringe trademarks or copyrights) is protected expression.
One of the easiest ways is to block Beeper's encryption key from generating encryption tokens. Another way is to block the fake serial numbers and UDIDs Beeper uses. Yet another way is to block Beepers push notification servers.
A more long-term solution is to require device attestation. This functionality is already built into iOS, and on newer devices, it utilizes the Secure Enclave on the device.
This doesn’t require older iOS devices to be excluded from iMessage because the attestation can partially be done via Apple’s servers. For the most secure method, however, you’d want the device to have a Secure Enclave.
Breaking compatibility with older devices isn’t unheard of, however, when Apple upgraded the FaceTime protocol, older devices that didn’t support the newer iOS versions were left out and couldn’t make FaceTime calls with more recent devices on the more recent protocol.
All in all, many tech tubers were talking out of their behind because they didn’t understand the inner workings and were parroting what others told them.
> “That means that anytime you text your Android friends, anyone can read the message. Apple can read the message. Your phone carrier can read the message. Google… literally, it’s just like a postcard. Anyone can read it. So Beeper Mini actually increases the security of iPhones,” he [the founder of Beeper] had told TechCrunch.
The phone carrier can read the contents of the unencrypted SMS. But the contents of the message never traverse Apple or Google networks.
If an iPhone user's device attempts to send an iMessage, and it fails to send, then the device falls back to sending an SMS via the cellular network (actually, it's not even a fallback - the user needs to long-press the message and resend it as an SMS).
The content of the message never reaches Apple because the device never sends it to them. It doesn't even send the encrypted content because it wasn't able to exchange keys. I'm not even sure it sends the unencrypted phone number of the recipient to Apple...
And certainly, no part of the message is ever sent to Google's network... that doesn't even make sense.
Now, maybe he's arguing "Apple can see it because they control the operating system," but that's a ridiculous argument because you may as well say they can access every iMessage too...
I would assume that text message notifications are generated locally on the device when it receives an SMS message.
The iCloud Backup also includes the “Messages in iCloud” cross-device synchronization keys, so it is indeed true that Apple can read all of the iMessages. It’s not end to end encryption if the endpoint devices sync their endpoint keys to the middle transit service.
Apple’s own knowledge base article HT202303 is very clear on these points.
Note also that enabling e2ee for iCloud (currently opt in, and very buggy) does not protect you, as everyone else you iMessage with is escrowing their keys to Apple in their backups, so Apple can still read all of your iMessages from the other end of the conversations even if you enable e2ee on your backup.
I can't see any world where chat gets standardized that doesn't involve throwing out everything except the most basic sms-style semantics which is basically what RCS is.
Beeper the company also has Beeper (Cloud) which bridges a whole lot of chat apps via Matrix to their other client app, including iMessage via a Mac relay.
Been using it a while now, pretty good.
This was a proof of concept to expand that app, it's not the entire company
There's always a possibility of me being wrong! It does look like a bit of a pivot doesn't it.. Good point, well made.
I think I'll go double check I can still log in to my chat apps directly just in case haha
Even without iMessages, a fully local application like this would be a great product. The fact that it relied on their servers put me off of using Beeper cloud
> Our long term vision is to build a universal chat app (https://blog.beeper.com/p/were-building-the-best-chat-app-on). Over the next few months, we will be adding support for SMS/RCS, WhatsApp, Signal and 12 other chat networks into Beeper Mini. At that point, we’ll drop the `Mini` postfix. We’re also rebuilding our Beeper Desktop and iOS apps to support our new ‘client-side bridge’ architecture that preserves full end-to-end encryption. We’re also renaming our first gen apps to ‘Beeper Cloud’ to more clearly differentiate them from Beeper Mini.
“Apple and Google want you to use their app stores in this way.”
…they want you to use their app stores, their way, because they retain 100% control of what you can and cannot do.
It’s impossible to avoid relying on other people’s platforms. (Unless you want approximately zero customers, I guess) I wish these monopolistic corps didn’t have such an iron grip, but I’m not demanding creators single handedly remove every dependency on them. There is no ethical consumption (or production) in late stage capitalism.
I am shocked at this outcome, and shall write my senator.
Have you got a source on that? As far as I know, there's no workaround possible because the authentication blob is based on the UDID/serial. Put differently: without UDID/serial, there's no way of authenticating with the message servers.
Beeper keeps referring to pypush when it comes to details in their write-up[0], and pypush, in turn, clearly states[1] the need for information like serial and UDID when dealing with the albert server and IDS registration request.
As a “workaround,” they simply stuff fake serials, etc., and cross their fingers that it gets through Apple’s scoring mechanism.
0: https://blog.beeper.com/p/how-beeper-mini-works
1: https://jjtech.dev/reverse-engineering/imessage-explained/
But at the same time, you need to feed snobbery so that you get a safe mixture of 80% immaturity and 20% snobbery.
Let’s add two drops of self-deprecation, that boring feeling of “I don’t have blue bubbles, I’m worthless and a loser.”
And now you can take a large bag for money and leave it open - they will fill it themselves, tie it and send it to the address :)
Honestly, I have mixed feelings. I REALLY think that iMessage needs to be opened up, but this was not the way to do it. Really hoping the EU swoops in and saves the day here.
EU usage of iMessage is minimal compared to WhatsApp, Telegram, Signal and Facebook Messenger.
So there's little incentive for EU to get involved.
iMessage will reportedly dodge EU regulations, won’t have to open up https://arstechnica.com/apple/2023/12/imessage-will-reported...
If they really wanted to discourage 3rd-party clients they could just _subtly_ break them for users of Beeper Mini: Late messages. Truncated messages. A blue bubble that slowly turns brown. The wrong font. Zalgo text.
Apple’s MO clearly is breaking something and refusing to elaborate further.
Also humans.
### Beeper Mini - fix coming soon
Our fix for Beeper Mini is still in the works. It’s very close, and just a matter of a bit more time and effort.
In the meantime, we have deregistered your phone numbers from iMessage so your friends can still text you. Sorry, you’re temporarily a green bubble again. Annoyingly, the iPhone Messages app ‘remembers’ that you were a blue bubble for 6-24 hours before falling back to SMS, so it’s possible that some messages will not be delivered during this period.
Also, we are extending your 7 day trial by one additional week.
I just want to say thank you for bearing with us through this wild day (week!). I feel awful about important messages you may have missed today because our iMessage connection stopped working. My sincere apologies for this.
Tomorrow is a new day. Onwards!
### Beeper Cloud - iMessage works again!
I am very proud to say that iMessage is now working again on Beeper Cloud. After a Herculean effort from my amazing colleagues, our iMessage bridge is back in action. Unfortunately, messages received during the outage are not recoverable.
If you have a Mac or iPhone, you may see an alert that a new device has been added to your account. This due to the bridge update. The update is rolling out over the next hour.
And...it's not working for everyone yet. We're going to call it a night and get back to it tomorrow.
No less than 18(!) of them:
* ads-twitter.com
* bizzabo.com
* dscg1.akamai.net
* facebook.net
* google-analytics.com
* googlesyndication.com
* googletagmanager.com
* mrf.io
* oath.com
* sail-horizon.com
* twitter.com
* twitter.map.fastly.net
* typekit.net
* vidible.tv
* wp.com
* yahoo.com
* yahoodns.net
* yimg.com
There's also two (!) layers of cookie consent redirects and the page simply will not load without JavaScript.
Even with first-party scripts enabled the main article doesn't load and at this point I don't give enough of a shit to work out why.
@dang should consider banning Techcrunch URLs from Hacker News IMHO.
It became a game of whackamole where by Palm would update their OS (RIP WebOS) to reintroduce support for iTunes to their devices and Apple would bend over backwards to break it again.
Did Beeper not anticipate that this was inevitably coming and put fallbacks and rotational serial numbers in place if Apple start getting blocky?
Even if Apple would permit something like Beeper Mini for now, that would not only relieve demand for actual open standards efforts, but also put more people at the mercy of Apple.
(This is not a new idea. For example, every time I see another open source project push people to Discord for support/discussion/community, I make a big sad and disappointed face.)
It's not bad marketing strategy at all, I'm sure they gained a huge number of new users, and some percentage of them will stick around even without iMessage support (because there's not really someone else to switch to), but it seemed a bit too manipulative for my personal taste. They could have just said "try us out and see if you like us, we'll keep iMessage support going as long as we can" but instead they dodged the question entirely.
Building an application on someone else’s platform means they control your product
Doesn’t matter that “we all know that” this will continue to happen as long as closed platforms are the only thing people are incentivized to build/use.
> The sheer fucking hubris of these clowns to charge a subscription to forge device identifiers and transfer data through Apple's servers for users that have in no way actually paid Apple for that service and then say "there's no way they can shut us down!"
https://www.reddit.com/r/apple/comments/18dy7ip/apple_has_se...
Do you really think they're the worlds most valuable company because of "corporate interests" and not because people like their products?
Apple is a business, they have no users interests at heart. They may be very privacy focused, and maybe masterful at encryption but for sure they do not make products I love. Their instant change of UI, forceful updates and territoriality behaviour are some of the toxic behaviours that drive me mad.
As the same of Google. After Google banning my email for "non-inclusive" reasons wolfcub@gmail.com when I was 17, I will never return.
So within mobile, while only real alternative is Apple. Apart from my computer which is FreeBSD which will soon to be Haiku once it matures. I just couldn't get everything working with OpenIndiana and how I wanted it to be.
There's not much else I can say to the discussion but just wanted to reiterate my point that I'm not hating others for the reason but just disliking for the reasons. I've never been a laptop fan.
With awkward hands, handheld consoles, controllers, laptops have never jelled for me. Yet constantly disappointed for that they've have never been taken catered for. As VR with glasses, Netflix non-continuing content I enjoy; everything I seem to enjoy just vanishes. Sad, as after experiencing tech at such a young age with so much potential; for it to be regurgitated to how it is, singular devices makes it depressing.
I must be a niche but I just assume companies have to cater to the majority, for which I'm not one.
But anyway, this is only _my_ beloved product, and I certainly hadn't even considered a disability that would get in the way, and apologize for my ignorance. I hope you can find some setup that works well for you specifically that you end up loving :)
Truly sorry—certainly didn't mean to offend.
I'm not psychically disabled as I have no deformities, have fingers which work but it just seems that any portable device I use gives me hand cramps or just not enough room to flow.
It would just be nice for the factory default to just be usable. Thank you.
Hope you're having a great day :)
What, like this https://github.com/signalapp?
The only thing holding this back are end users. Not corporations or governments. A safe, vetable 'standard' exists, it just needs ratifying by a standards body. It is available cross platform and is free of charge and free-as-in-beer (mostly AGPL I believe).
Messages app exists to send SMS, MMS and soon RCS. Apple developed a convenience feature that allows users to send enhanced messages to other users of the platform. Since the platform is successful and has had compelling and useful features added, it has found popularity in territories that traditionally had free or cheap SMS bundles. The rest of the world didn't have this golden noose and settled on other platforms (WhatsApp, FB Messenger, Telegram, Line, WeChat, Signal, Viber, etc...) across all platforms.
Edited spelling/layout.
Oh right. No one cares. Apple’s iMessage is the only one a large number of people seem to care about.
I’ve never seen anyone call for opening the others. But Apple? Constantly.
If they're right and Apple doesn't have the user base, the EU gatekeeper laws won't have an effect on iMessage.
Why? iMessage simply does not have the market share enjoyed by WhatsApp, Facebook Messenger or Telegram EU-wide. iMessage was temporarily removed from the DMA in September and noises coming out of the commission favour Apple's stance that it is simply not big enough to warrant inclusion as a gatekeeper for messaging apps.
If the EU won't solve America's problems for us, who will?
"Why force iPhone users back to sending unencrypted SMS when they chat with friends on Android?," he asked."
Thought experiment: What if Apple trains an "AI" on peoples' text messages. What laws could stop them.
https://arstechnica.com/gadgets/2021/06/google-enables-end-t...
people forget that google has every interest in playing up the situation, and perversely this incentivizes them to refuse compromise or half-measures that might actually improve user experience. It's in google's interest for your apple<->google experience to be as poor as possible too, not just apple.
They absolutely can be. Apple could officially do what Beeper Mini did unofficially.
There's clearly a market of people on Android who would be willing to install an Apple messaging app in order to have secure messaging with their iOS contacts, and we know now that there's no technical barrier in front of an app like that existing.
Even if not every Android user installed that app, even if it was only a portion -- it would still represent a large security increase for a non-trivial number of messages sent from Apple devices. It would not require Google's permission for Apple to launch a messaging app on Android, nor would it require Apple to use Google's proprietary encryption extensions (or to even use RCS at all).
I agree that both Google and Apple have a vested interest in refusing interop, but it's not a stalemate -- both companies, individually, could take actions to improve security regardless of the other's position. It's not Apple's fault that Google has completely botched the entirety of RCS. It's not Apple's fault that Google is now disingenuously pushing a broken standard under the deceptive guise of interop. But it's also not Google's fault that Apple is forcing iOS users to use less secure communication methods for their Android contacts even in situations where Android users are demonstrating that they would be willing to install separate applications just to secure those communications.
Both companies have -- completely of their own free will -- chosen to leave the situation in its current state, and both companies could take steps to actually address these problems on their own if they wanted to. And neither Google nor Apple can blame the other for their failures to protect their own users.
Epic Games tried the same thing with Fortnite to force Apple's hand, it worked in the court but Apple only bends to laws of the land.
I don't see the big deal over iMessage - we use WhatsApp for chats in our family and it is cross platform.
Also, the whole use case is funny to me since everyone in my country (including iPhone users) use WhatsApp.
My mate and I had a bet on how long this would take (since the thread the other day), my guess of “3 weeks tops” was far too generous.
Just use literally any other messaging app
I don't want spam in my blue bubbles.
For Apple? Demonstrably so. Apple has stated as much in court filings against Epic. This is largely an American trend, third party messengers are much more popular outside of the US as the defacto standard, Apple sees clear value in the blue bubble.
Maybe it shouldn't be private or whatever, but it still seemed weird to me that they thought this would "just work".
Apple faces the heat of this competition - it frequently adds features to iMessage to make it equal or better than it's competition. Voice notes through iMessage was a direct reaction to popularity of that feature in other platforms.
Feel free to use the open standard but don't be iMessage.
I'm a long time beeper user. It's been nice to sign up with my email, and at least be in a few of the iPhone only chats.
When I saw Eric's post the other day, my first thought was 'what an arrogant dumbass.' My guess was that they though they have an anti trust case, and my guess is that apple may have thought the same, and so they enabled 'iMessage' access to RCS.
This was so predictable, especially after the RCS announcement, that I messaged my group threads and said they'd be borked by the end of the week, please switch back to signal.
So, I think I'll ride that train until RCS is a thing and be done with beeper. I honestly think they just shot themselves in the foot.
https://www.theverge.com/2023/11/16/23964171/apple-iphone-rc...
Not discouraging the endeavour but now they are on the hook for all of these customers who bought on this promise. Feels like it should have started as a free product to see how Apple would handle it.
A/S/L anyone? +5 Insightful
Some links for the befuddled
An overview: This made the front page https://www.nytimes.com/1999/07/24/business/in-cyberspace-ri... https://www.theguardian.com/media/2005/oct/13/yahoo.digitalm... A delightful internal MS assembly hacking rivals message apps interview. https://www.nplusonemag.com/issue-19/essays/chat-wars/
If Facebook does it, uhhh evil.
If Apple does it, right so!
https://arstechnica.com/apple/2023/12/imessage-will-reported...
It comes down to if, by having people send you messages, you are the one providing the data to the data controller, or not.
Currently I think it's ambiguous.
I don't have to let you into my house. I don't owe you a reason. It's my house.
The EU set up the rules of the game, and it turns out iMessage falls outside the rules (to the EU’s dismay).
Even if it would fall within the rules, EU regulations work on a policy level, not a technical one. In other words, they can force Apple to change their policy and facilitate interoperability, but there’s no legal mechanism to force Apple to allow unauthorized use of their service.
The best you can do, if you're so inclined, is hope that the EU will change the rules of the game, but that would be such a transparent attempt at targeting a specific company (a big no-no in the legal reality within the EU) that the European courts will strike it down before they finish their breakfast.
Surprised it only lasted this long though, I'm sure they weren't betting on that. I still wouldn't expect a refund for the 1,50$ of 3 weeks this payment cycle that you didn't use.
I would. They sold a service that they clearly cannot reliably provide.
Then why would anyone use BlueBubbles? If you already need the hardware, and presumably an Apple account, what advage would there be? Legitimately curious.
Edit: not a whole company, just a side project within a company I guess. Still, seems like a waste of time/effort to have even attempted.
apple owes nothing to anyone. they have created an ecosystem for their walled / gated devices that works extremely well. they don't have to let anyone else play in their pool.
this is really about blue bubbles vs green bubbles, it's the most asinine thing to waste thought on.
You can even use Beeper (Cloud) as a client if you don’t mind using a relay. They also had plans to extend Beeper Mini to support Signal and other e2e encrypted chat apps with no relay.
Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted? The level of trust we have to have for Apple is approximately the same for any other iMessage client. Obviously Mini was using the encryption properly else it wouldn't have worked to begin with. Of course, it's very unlikely Apple is doing that. Just putting the thought out there.
One other point raised that I saw was about how iMessage costs Apple money to run, and non-product owners should not have access since they haven't contributed. This falls apart if you own any Apple devices. Myself for example owns a Macbook, but an Android phone. Am I not allowed to use iMessage? I paid the toll.
I think HN exists at an intersection of individual hackerism and business. If a project is clearly by-hackers-for-hackers it gets a lot more leeway for unsustainable concepts / implementations. But this is building a business on adversarial interoperability, and many people who LOVE the concept and technical achievements will still post mostly critical things about the business model because it’s fairly clearly a very very challenging business model.
But also, it seems to me that compassion is an involuntary reaction.
Compassion is very much a quality that can be developed and nurtured.
I'd agree that both capacity and scope of triggers can be altered, but it seems to me that that's a process that takes some time and effort. Distinct from choosing in the moment "I am going to feel a certain way about this, right now".
Note: this is very different from "but I want to block all ads", that's not what I'm writing here and also not what others might be writing.
As for the audience, it varies, but this website is a VC thing, so it makes some sense that a bunch of visitors are from the VC ecosystem and as such might be very money-oriented.
No, this is preposterous and I will continue to refute this silly idea every time it shows up here. It is not stealing from radio stations to change the station when ads come on. It is not stealing from TV channels to go get a drink when ads come on. There is no moral compunction to watch ads, from anyone, anywhere. Stop trying to normalize advertising, which is to say, stop trying to normalize the enshittification of the human mind.
Meanwhile, a web browser is a user agent running on my machine. Youtube's content is a guest on my hardware. Once it's on my machine, I have the moral right to do whatever I please with it. If Google doesn't want to serve it to me, then it has the right to prevent me from accessing their server, such as in exchange for payment. But again, advertising is not payment, it's just corporate-sanctioned, socially-acceptable brainwashing.
Sure, but Google also has the moral right to do everything possible with their code to make it as hard as possible for you to skip ads on their videos. You both get to try as hard as you can, so good luck to you both.
There's no brainwashing here. It's just a business trying to make money, and trying to outsmart the users trying to outsmart it.
So, like use an entirely different part of the company like Chrome to push for WEI to make adblockers not run?
Or maybe use chrome to push for manifest v3?
Maybe the __moral right to do everything possible__ isn't actually moral when it's using its leverage in a separate market to protect another one of its assets. Maybe we should see this as something to anti-trust them?
Ads and adblockers are always going to be a cat and mouse game, so I don't see any reason to complain.
Antitrust doesn't really enter the picture. Chrome doesn't even come preinstalled on PCs or Macs anyways -- you've got to go out of your way to choose to install it. So just don't, if you don't like it.
I don't think this is true. Google Meet, Youtube, etc all perform worse on non-Chrome/Chromium based browsers.
I do think that the world's most popular browser, being owned by the same entity that owns Youtube, actively working to block adblockers (adblockers which, do *not* harm Chrome but do harm Youtube) is something for regulatory bodies to take into consideration.
Advertising is at least trying to make you think thoughts it feeds you. "Buy Brand X, you'll get women!" If the advertising is effective, you'll associate Brand X with something positive and want to buy it.
It's kind of blanket brainwashing with extra steps because it's more indirect. Similar technological brainwashing might be joining an algorithmic social media site and becoming convinced of something the algorithm felt was the most engaging thing that day and spread, regardless of truth. Choosing to believe what social media or advertising tells without healthy skepticism you is willingly accepting some brainwashing.
There are people who feel really strongly about ads, and I'm one of them. I hate them, they don't share my values, and they are only trying to extract value from me. I run ad blocker in my browser, but mute and skip any ads I can like a peasant on my TV or phone. So overall I end up watching more ads than not since I don't watch videos on my PC much.
When I do see ads its shocking. Car ads have little to do with cars, and everything to do with insecurity and Pavlovian hacks. Idiocracy drip by drip.
People expose themselves to crap influences day in and day out, then imagine this or that ad isn't impacting them. The stream has profoundly impacted them or they wouldn't tolerate any of it.
I am absolutely certain that the exponential increase in advertising is probably going to ultimately have been found to be at least partly responsible for so many of the mental and psychological problems that seem to be on the exponential increase in places like America. Humans are not designed to live our lives as donkeys chasing a carrot on a stick.
Precisely. Subjecting yourself to advertising (or allowing your children to be subjected to advertising) is simply bad mental hygiene.
That's because most car ads aren't actually trying to sell you the car. They are instead trying to sell you the idea of the car's status[0]. While people are most familiar with ads that are blatant attempts to get you to buy something, many are much more indirect. It's also why native advertising is so nefarious. A large portion of ads actually aren't the direct version, but most often people don't notice they're taking in an ad, and that's kinda the point.
[0] https://www.latimes.com/archives/la-xpm-1996-04-26-me-62995-...
BuT aDs DoN't AfFeCt Me!
I'm honestly frequently impressed how how often people don't understand what ads are or do. Especially considering they funds most of our paychecks. Everyone is affected by ads and convincing yourself that you aren't makes you more vulnerable to them.
I think the problem comes from people thinking ads exclusively are about selling things that have a monetary value. But ads sell ideas. Often that idea is that you should buy something, but sometimes it is a preference like a politician or a celebrity in their latest scandal or rise to fame. Ads can be good too, like public service announcements. But for sure we're over inundated with them and there's too many bad ones.
I am also particularly peeved about the ads that come from email addresses I can't exactly block. I really don't think anyone should be accountable for missing an important email if the sender also sends 90% junk from the same address. I'm looking at you every university ever[0]
> skip any ads I can like a peasant on my TV or phone.
Maybe check out reVanced. You can recompile the YouTube APK to be ad free.
[0] Here's the text from my uni's page when you click unsubscribe. What a joke. I don't need emails from the alumni association, publicity channels, or all that. And you have the audacity to try to convince me it isn't spam? What a joke. I'm glad I use a third party mail client that can filter this stuff but it is an absolute joke that we think this is acceptable. It shouldn't require special tools. There is a clear difference between police reports and the alumni association and they even come from different senders. In fact, not allowing for you to unsubscribe actually goes counter to the safety claim because it teaches people to ignore your emails.
> In order to share information quickly and efficiently with faculty, staff, GEs, and students, the university uses email as its official form of communication. All emails that end in an @<theuniversity>.edu address are required to receive email communications sent by the university. As such, there is no option for @<theuniversity>.edu email accounts to unsubscribe from official university communications emails and these emails are not considered spam under applicable laws.
Glad you can filter the crap, but I guess from a CYA perspective the school can say "we notified everyone through our official email channel" whether you were ever going to read that email or not.
Haha there's only a few places I get ads and I lock as much down as I can. There's a certain sense of joy when you get ads so misaligned from you that you know they are reaching.
Oh it's a constant battle to filter. But what worries me is actually that people honestly do not get it. These are clearly little metric hacking and I'm afraid we're just traveling deeper and deeper into Goodhart's Hell.
The person you're replying to acknowledges this, albeit indirectly.
But the point still stands: if Google sends me the bits, I am free (morally, and, at least for now, legally) to discard the bits that correspond to the ads if I can figure out how to do so without watching them. If Google can figure out ahead of time that's what I'm planning to do, and refuses to give me the bits, that's of course Google's right.
> There's no brainwashing here. It's just a business trying to make money
Advertising is psychological manipulation to coerce you to buy whatever product is on offer. The "best" advertising will convince you that you need a product that you'd never consider buying otherwise. "Brainwashing" might be a sensationalized way of putting it, but I don't think that's particularly inaccurate.
Huh, you can throw the guest out by not watching youtube. Ripping off guest seems strange moral right.
> Stop trying to normalize advertising, which is to say, stop trying to normalize the enshittification of the human mind.
Seems like you are deciding on everyone's behalf on what one should do with their mind.
If the content is rendered in my browser I can manipulate the JS and HTML as much as like. If you don’t like that -> feel free to put protections. But the same way a browser interprets the code I can put stuff on top of that interpretation.
So morally I’m okay to use a blocker if that’s what I want to do. It’s also immoral to track me but Google seems to be okay with it. If that is the relationship they want to establish so be it. I will act in the reciprocal manner.
The idea is not to decide on what someone else is going to do with their mind. Hence the idea that everyone is free to do what they want. Ads are not a natural part of the world so making the argument that not watching them is somehow wrong is what is actually a decision being pushed on others.
If companies didn’t try to normalize ads and tell you off for using adblockers then nobody would have a problem with it. But given that people say: You need to watch ads otherwise you are stealing is putting decisions in someone’s mind.
When you are an on-demand user where the transaction is media in exchange for something (advertisements or a paid subscription), and you weasel your way out of exchanging something you're not 'moral' or whatever measure you take.
It also doesn't matter what you think or feel with this transaction since the rules are known ahead of time, and you either agree to them or don't, and there is no third option that entitles you to free content. That includes your mental gymnastics about who is a server, who is a client and who did what. The technical details do not matter, they never did and they never will.
Is it a shit experience? Definitely. It doesn't mean that the rules you agreed to suddenly don't apply anymore.
yt-dlp's post on HN garnered a lot of overwhelmingly positive attention [0].
I learned about NewPipe from HN and am now an ardent fan. Also received an overwhelming amount of positive attention recently, with the top comment recommending a fork that blocks even more advertising [1].
Every release of uBlock Origin gets hundreds of upvotes (1.53 got 527 points [2]). Again, overwhelmingly positive attention.
There's a subset of HN that is obsessed with the fediverse, and another subset that is skeptical, but the skepticism is overwhelmingly technical in nature.
If you want to see corporate shills on HN, you'll probably be able to find some, but it's certainly not a majority (much less unanimous!) view.
[0] https://news.ycombinator.com/item?id=37474066
something something someone's salary and getting them to see something
I don't care about Google's profits but I figure we should try to support the content we enjoy in some way or else all we'll be left with is MrBeast, PewDiePie and content farm videos (ie the stuff that is so hyper scale that no amount of ad blocking can effectively hurt them)
In many ways it'd probably be far better for the world if making videos was not perceived as being profitable. The number of children who now want to be 'streamers' or 'youtubers' instead of astronauts, engineers, and scientists is not a good direction for society.
The platform itself may be replaced but the incredible result of the YouTube platform is that there are millions of excellent creators who are making a living by making their videos, and even making enough to keep raising the bar on their work.
It's not a given that growing such a swelling stream of creative work will ever again be possible if this one dies out. YouTube was in the right place at the right time with the right subsidization available while they made the systems work at scale, and scale them up to insane hyper scale levels. This happened because of the advertising bubble, which is showing heavy signs of stress especially in the last few years. Society is already pushing back against the data collection that makes advertising at these scales as lucrative as it is, and if the bubble finally pops it's possibly it'll never inflate this way again.
This is why it's important to support the small creators you enjoy in some way. Direct contribution is certainly the best of them all. Sure this might not be relevant for superstar YouTubers, but take for example Technology Connections. Alec is an amazing communicator who puts insane effort (full time) into producing super informative videos about electronics and engineering.
A lot of YouTubers I enjoy watching are very tech/science focused and use proceeds from their videos to purchase equipment that is used to create content. I don't think their channels would be nearly as interesting if they didn't make shiny-toy-money from it.
> The number of children who now want to be 'streamers' or 'youtubers' instead of astronauts, engineers, and scientists is not a good direction for society.
People desiring to be famous isn't an idea that started in the age of YouTube and TikTok. The medium changes with what's the dominant platform. If anything, YouTube and TikTok democratized the process.
(And yes, I'm going to assert that becoming an astronaut, engineer, scientist, etc. is immeasurably more useful than becoming an influencer or whatever. It's fine to disagree with me there, but that's my position.)
Having said that, I do get a lot of value and understanding and useful information from some YouTube channels (which I do my best to support through Patreon and my YT Premium subscription). But not all channels are created equal.
Only served via a different platform (or not really anymore for some like music videos).
People wanting to be streamers/youtubers is the same as them wanting to be any other celebrity.
To be able to show some valuable content, there has to be something valuable happening, and hopefully that still directs enough people to be astronauts, engineers and scientists (so eg NASA can live stream their flying to Moon or something).
All I am saying nothing has changed, really, other than the platform and accessibility.
This is pretty questionable. Quality takes time. If you need an income to pay your rent, 40 hours or more of your work week are taken up. That leaves a few hours before dinner and sleep to work on your videos (since in this hypothetical, it is "literally impossible" to make money on your videos).
Of course you could work on the weekend, and many do. But let's not forget that making videos is work, and it's important to do the things, you know, we invented weekends for. Like spending time with your family, reading a book, or playing a video game. How entitled this content creator must be to have a weekend. This is of course assuming that the creator's day job is a traditional one-- more than likely they work partial days 7 days a week at varying hours as is the norm for crappier jobs.
That 40 hours gives you enough income to pay your expenses, but unfortunately, for most people, doesn't give you the income you need to get a real camera, so you're just using the webcam that you already had on your computer.
The audio is terrible and the video looks like it came out of the early days of YouTube, but somehow that qualifies as "high production values".
Sometimes it's easy to lose sight of reality when working in a highly paid specialized field like engineering.
> In many ways it'd probably be far better for the world if making videos was not perceived as being profitable. The number of children who now want to be 'streamers' or 'youtubers' instead of astronauts, engineers, and scientists is not a good direction for society.
Well you are watching that content, presumably. Do you feel it provides value to you?
There are an awful lot of small science educators on YouTube. They are doing the work to inspire people to get into the sciences. Is that not valuable? Those people have an outsized dependency on the ad revenue and patreon income they receive so they can keep making videos that are accurate and engaging. For them, another hundred people blocking ads could mean the difference between doing what they love and releasing quality videos or having to go back to a day job that occupies all their time.
If there was no YouTube, how do our kids get inspired to become scientists-- by watching the latest MCU movie? By watching cable programming?
YouTube isn't all just MrBeast and dramatube videos but I get the impression that this is what you think of. It reminds me of the "algorithm slip" where users make broad assumptions about a platform because of what it serves to them, but really it says more about you than properly evaluating what content is on the platform.
When I sum up your take, it sounds like only those people with passive income should have the privilege to make videos, and that's actually not a world I want.
Same as everyone before YouTube. Role models and seeing/reading things.
Before YouTube and the Internet in general, only affluent people had these things, and we left behind a huge portion of the worlds population. Those people have the same potential as people of means or the luck to be born in an affluent country or an urban area.
I do get that you also include reading things on the Internet, but that's not always engaging enough to create a spark for people.
Since the advent of the internet the entire developed world has been getting literally dumber, so far as IQ can measure. [1] That's, to my knowledge, the latest study but a quick search for 'reversal of flynn effect' will turn up a zillion hits. In other words, what I'm saying is not controversial in the least. And one of the hypothesis for why this is happening (as per the linked paper) is, unsurprisingly, increased media exposure. YouTube is playing a significant role in literally making the world more stupid.
I love plenty of 'sciency' YouTubers - Veritassium, Cody's Lab, Smarter Every Day, and many more. But in reality, you're not like to learn much of anything from these sort of scientainment. It's just candy with a sciency coating, more likely to inspire people to want to make more candy, than to actually pursue science.
[1] - https://www.sciencedirect.com/science/article/pii/S016028962...
That's a pretty thorny question, come to think of it.
Perhaps it's like eating chocolate. It provides value to some part of me, but at the same time, a more reasonable part can judge that I as a whole would be better off if the chocolate wasn't there and I'd eat something healthier instead. So I can both consume it and desire an environment where I wouldn't consume it.
I'd assert that a lot of content on YouTube is not chocolate. There are high quality "healthy" options right there on the app. How about Technology Connections or the 4 hour long retrospectives on your favorite book, film, or video game? What about the years of technical and learning content? Those aren't chocolate, those are spinach.
They are also able to invest in their channels. Many bigger YouTubers have small production studios, very expensive camera equipment (think $70k Red Dragon/ARRI cameras, 5 figure lighting setups,etc), and full time staff. They can production quality that rivals a TV studio. None of that would be possible if video content couldn't be monetized.
I sort of agree about the obsession with being a "content creator". But at the same time, kids have always wanted to be rock stars, professional athletes, and movie stars. Content creator is just a new type of celebrity for kids to idolize.
I mean go for it, hack away! I hope apple keeps android far far away from me though lol
What a bizarre thing to say.
In what world is interoperability adversarial? What the actual?
OP didn't coin the term, it looks like it comes from Cory Doctorow [0].
[0] https://www.eff.org/deeplinks/2019/10/adversarial-interopera...
> Big Tech climbed the adversarial ladder and then pulled it up behind them.
Anyway the comment I was replying to was implying that Beeper is the adversary which is not a correct use of the term.
You can't have a single-party adversarial system. Each party is an adversary of the other: party A wants to interop against the wishes of party B, and party B wants to lock party A out. OP wasn't implying that Beeper is "the" adversary and Apple is in the clear, OP was just saying that trying to build a business around adversarial interoperability is extremely difficult and the outcome is unsurprising.
Noting that the results are unsurprising does not imply that we condone the system that makes such results nearly inevitable.
Forcing someone to interoperate with you doesn't immediately make it all collaborative any more than a stranger walking up to me at lunch and declaring they're my friend now makes me want to invite them home after.
Beeper is not someone who hacked your wifi. Beeper is sending legitimate packets to your router and Apple is saying “I don’t like those packets because they threaten my artificial hold on the market”.
> Just putting the thought out there.
Is making wild claims and then immediately trying to disavow them in the next sentences the hacker spirit?
How does it at all follow that Beeper Mini is using encryption properly (or else it wouldn't work) but it's unlikely Apple is? How would Beeper have been able to reverse engineer it if Apple's not using it? Who did they model their correct implementation of Apple's protocol off of?
> Apple claims iMessage is E2EE, do we have proof they aren't siphoning the messages from the client once it's been decrypted?
The answer here is no. Yes, making a wild claim afterwards is lazy, but the fact remains: there is no system in place to get anywhere close to "proof".
The best we have is researchers reporting trust violations when they find them, escalating those violations in the media, and sometimes forcing the company to change behavior. Relying on (ever more skilled!) unpaid volunteer work to verify the claims of the largest company in the world seems like an appeal to authority. It also doesn't scale as they make more claims and build more complex software.
Yes, breaking E2EE for everyone is so large that it would be impossible to do at scale without anyone noticing. Breaking it selectively to target individuals (the threat people are actually worried about!) is much harder to detect, no?
That's because it's a ridiculous premise. We don't have any evidence that Tim Cook isn't robbing banks in his spare time either. I'm not saying he does.. I'm just throwing it out there because he might be.
Not to mention the fact that you can't prove a negative anyway.
Apple added Contact Key Verification to eliminate one possible class of attack involving a lack of user transparency. Still trusting a whole lot of trust in the stack, but is an improvement.
What you think of as a ridiculous premise I think of as a goal to aspire to
Trust that a third-party application isn't stealing the decrypted messages requires the same type and amount of trust that Apple is not stealing the decrypted messages (or maybe less trust if the third-party solution is open source, etc.).
For a tiny company like Beeper, the incentives are different. The upside of being dishonest far outweighs the risks.
Not that I believe Beeper is nefarious. They probably aren’t. But their risk/reward for abusing trust is very different from Apple’s
What's good for the goose, etc.
It’s the market rate. Almost all retail stores online and offline charge 30%.
As for whether 3% is reasonable, again we can look to Epic for evidence. Epic's own Steam competitor takes a 12% cut — and they admitted in court that it was a money-losing venture. That should stop and make you think. The Epic Games Store isn't even a complex ecosystem, it's just a glorified Windows app downloader and even then they couldn't make a profit at 12%.
Apple argues that their 15% fee for most (30% for the ultra-successful) pays for a lot more than just payment services. It pays for absorbing the cost of fraud. It pays for dealing with refunds. It pays for developing the APIs. It pays for employing an enormous team to perform some imperfect-but-useful oversight over the 1,800,000 apps in their store. It pays for a lot of things.
If you think Apple makes too much money, fine. That's a perfectly fine argument to make. That's a very different one to claiming that they're not entitled to make money. Or that the government should dictate prices at them.
And saying apples cut pays for more services is just hilarious. we are forced to use those services and forced to pay for them. Stripe does refunds and fraud detection. There are other app development platforms for API's like kotlin and flutter.
And you and I both know that apple's margins on the app store is a joke. Thats why they dont report it seperatly in their financials. Whether epic couldnt make it is their problem.
You argue that a 5% cut is reasonable and a 15% cut is not reasonable. You are haggling over the price.
I’ve played with the same idea of making an Android client but I would never build a product on that because I know the limitations on my side.
As a company you are 100% allowed to break 3rd party client when they don’t have an agreement with you. It’s your product after all. Heck even with an agreement APIs don’t support old versions.
Why do you think they don't want you to run a jailbreak? It's to protect the walled garden. If you can install apps other than their store, that's lost revenue. They claim security blah blah, but it's removing mouths from the teet. So, it has everything to do with the walled garden. How does that not make sense to you?
It's similar to how OpenAI uses "safety" to make sure their LLMs don't get them in hot water, and PlayStation uses "safety" to make sure their consoles do not become associated with piracy and make publishers think twice.
This kind of "safety" is about business interests. :) Some companies can say it openly that they wish to protect their business, as fundamentally there is nothing wrong with that. Others can't as that will bode poorly for their monopoly status and they will suffer (overdue) legal repercussions. So it becomes "safety".
Notice how companies that argue against user freedom for "safety" are always in circumstances where bringing up business interests behind "safety" won't bode well.
The hacker spirit is the fun of reverse engineering. The hacker spirit is about personal use.
It's not expecting to be able to turn it into a business, or a popular app, that wouldn't quickly be shut down. That's just common sense.
> Myself for example owns a Macbook, but an Android phone. Am I not allowed to use iMessage? I paid the toll.
Of course you can. It's sitting there on your Mac where you can use it as much as you like.
See also geohot taking some other PS3 exploits that were already published and combining them into a piracy kit that caused Sony to come down on them and patch the exploits, ruining it for the rest of the homebrew community.
There’s a reason homebrew people try to keep it low-key, it doesn’t take many assholes to ruin it for everyone. Let alone turning it into an app on their own platform lmao.
A decent number of other hobbies also involve some collective good-behavior and self-control lest the hammer come down for everyone. Doesn’t take many assholes doing donuts on quads before you’ll find motor access to that area removed or prohibited, etc. Drones also ruined in like 5 years what r/c airplanes had been safely doing for decades. Etc
Hackintosh is already on a death march.
Sooner or later Apple will remove support for all x86 OSX versions.
Its life can be extended a bit by hackers who try to backport the software from ARM to x86.
But you can't sustain the entire Apple ecosystem by volunteer work alone.
Why spend resources trying to kill it when we all know it will die ln its own in a few years?
I know people gotta make a buck though. Sucks.
Would you not be mad at the guy bragging that he’s a member of the Resistance? They are not the Oppressor with the capital O, but they are at least an asshole.
This raises the question: is that a space worth inhabiting? Are hackintosh or homebrew PlayStation games worth it, compared to more open platforms where you are not breaking ToS?
Answers, of course, differ! But the question is worth asking.
Nowadays smartphones are so much more capable and so much more accessible to kids, plus you can even get literal handheld PCs like the Steam Deck, so homebrew is a lot less worthwhile in my opinion (except for just the sake of hacking, since consoles at least tended to have very interesting security/DRM arrangements).
As I am sure we all understood, OP meant on their Android.
I have a TV from 95 am I not allowed to watch Netflix? It runs on my phone.
Yes the limitations are different but you know them beforehand you just go and say it’s unfair I can’t have everything just the way I want it.
You don’t like iMessage - we have plenty of alternatives.
If you told people in 1995 that operating system vendors and service providers would arbitrarily block certain apps to lock you into their ecosystem people wouldn't have believed you.
Whether that was ever fully policy at Microsoft, people sure believed it was.
1995 was also around the time MS was pursing its embrace-extend-extinguish strategy to the internet with internet explorer.
Really? Wasn’t that somewhat common back then?
Correct. iMessage is an Apple service. If you want to make use of Apple services you should probably use Apple products. \_O_/
IE had the majority of the market share on the most popular desktop platform (Windows). Neither Messages nor the iPhone are in that position. Phones are pretty evenly split between Apple and Google in the US (and it's more lopsided in favor of Google elsewhere). Again, by virtue of having competition and having that competition easily accessible there's no monopoly.
There's just a bunch of butthurt Google fanbois who are lamenting the color of… well the color of someone else's text messages on that other person's device. All received messages have a grey background.
Does that change my point about the difference in those examples?
As an Android user, in theory I shouldn't care about iMessage. However, because of the way that iMessage creates schisms, miscommunications, lost communications, broken texting experiences and more between my Android friends and my iPhone friends, I have to. I would like the texting features of these phones to interoperate so we can all text together in peace.
I wrote up a scenario (user story?) that I think helps to explain the problems I think should be solved that seem to fly over so many people's heads, especially when they advocate for over-the-top messaging apps like Whatsapp to solve the problem (particularly in the US context): https://news.ycombinator.com/item?id=38578101
Apple using instant messaging, where no meaningful innovation happened for decades to build their moat is pathetic and disgusting.
The social graph lock in problem is well documented and well understood. If most people use a certain solution (in this case texting, and particularly in regions where its dominant such as the US) then attempts to make a replacement solution whose success depends on mass adoption has an exponentially more difficult time in achieving adoption, because there's no incentive for users early on (because the social graph isnt there).
At least in the US, texting has a ton of "gravity" compared to other forms of messaging because it is built in to every phone and entirely free with your phone plan, so every user knows they can reach every other person they meet via texting.
New platforms gain critical mass more due to circumstance and luck than anything else. Or, such as the case with TikTok, via deep pockets and relentless advertising.
i don't actually think it is. i don't know _anyone_ who uses just a single messaging app (and thereby a single protocol-level social graph). i have some mental map in my head: "if i want to reach friend A, i do it on Signal. friend B: Discord. friend C: SMS/tel/PSTN. friend D: Matrix". i think this is a pretty common experience these days: i'd hazard that my mix of 4 apps is on the _small_ side.
i admire Beeper, JMP.chat, and other groups trying to improve messaging via better abstractions. i think it'd be cool if they could maintain iMessage support, i also think it's not critical to their success. the pain points caused by that graph problem you point to is 1) maintaining that mental map and 2) coordinating large group chats. i don't see that the client-side/Beeper-style solution to this is notably worse if they support only 29 protocols instead of 30: for as long as my peers are reachable by more than one messaging app, the odds of bridging between them isn't radically different.
Nitpicking but I was saying that the general social graph lock in problem (also referred to as chicken/egg) is well documented.
> i don't actually think it is. i don't know _anyone_ who uses just a single messaging app (and thereby a single protocol-level social graph). i have some mental map in my head: "if i want to reach friend A, i do it on Signal. friend B: Discord. friend C: SMS/tel/PSTN. friend D: Matrix". i think this is a pretty common experience these days: i'd hazard that my mix of 4 apps is on the _small_ side.
Hi! Nice to meet you! I use only one messaging app for all of my friends! It's called texting. As far as I know, all of my friends do the same, with the only exception being a few Internet-only friends where we use Discord.
The "mental map" that you are describing is exactly what I want to avoid. I am thankful that I have not had to make one yet, and when people tell me to use over-the-top chat apps like Whatsapp, I can see that the map must be made.
Just because this is the norm, doesn't mean I'm going to do it, especially since we don't do it now. As much as the interoperability problem between RCS and iMessage is an incredibly annoying problem, I would take a single unified messaging experience over some crazy fragmented one with a zillion apps any day.
> 2) coordinating large group chats. > for as long as my peers are reachable by more than one messaging app, the odds of bridging between them isn't radically different.
A little confused by this, because Beeper and other unifying clients cannot in fact make groups which have participants on multiple platforms at all.
You said you need 4 messaging apps right now to communicate with everyone you communicate with. How many of those users also have all 4 of those messaging apps? Obviously it's not all of them, or you'd just use one messaging app. The fact that you need four implies that for a given selection of contacts, there is a chance that it is impossible to create that group chat, because there is no shared platform they are all on. Then you factor in that in some scenarios you need your contacts to include additional contacts, and perhaps your 4 messaging apps needs to grow to make it happen. And of course if you already made the group and you need to just add one more person then you might have to scrap and remake the group somewhere else. But then that group that already has some messages in it still exists, and people will keep texting it! Now you've split your group chats!
On top of this, I want to note that the mental map you have built is also prone to becoming stale. If one of your friends is on Signal and Whatsapp but prefers Whatsapp, but then uninstalls Whatsapp and forgets to tell you, then you very well may send a message to that person and have it never arrive. Of course they might bail out of both Whatsapp and Signal, and just go back to SMS. Now none of your messages will land- you didn't even think they were interested in SMS.
Sure, if they are a close friend its likely they'll let you know. Most people have 1-5 close friends. But most people also have far more contacts in their contact book, and some of those people they might only message a few times a year. That's not a mental map that can be maintained, or if it can, I don't want to.
i admire the resolve. on the other hand i think that rules out iMessage playing much role in that long-term, right? like, they're just never going to play nicely with others, it's not easy for the broader developer base to integrate with much less improve, and so on. so you're back to SMS, and the baseline SMS experience now is pretty limiting and stalled (much as SMTP stalled): a big part of why people leave for app-based messengers is for features like voice memos, video-chat, multi-device (e.g. PC) support, better multimedia support, etc. to say "SMS forever" i think is to say "i'm okay never having these features" -- which is a fine decision but important to note.
> A little confused by this, because Beeper and other unifying clients cannot in fact make groups which have participants on multiple platforms at all.
i'm pointing to where i understand the landscape to be headed. for channel-based chat systems like Discord, irc, Matrix, XMPP/jabber, Slack, it's common enough to find channels which are bridged across 2 or more of those protocols. my experience with ephemeral group chats is that if i want to plan a large enough event i just end up starting multiple group chats, and the unimportant details are chaotic but the important ones like where/when we're meeting i make sure find their way into both chats. there's a possible future where i start two group chats and my client bridges messages between them in the same way those channel-based systems bridge.
Well Apple is implementing RCS, so that's good. But look, I don't really think the blue bubble stuff stems from not being able to put stickers on the conversation. It definitely doesn't come from not being able to emoji-react ("tapback" as Apple calls it) because that still works on SMS, but the SMS participant receives a text message describing the tapback. In Google Messages and other modern clients, that gets interpreted by the phone and turned back into an emoji reaction [1].
I don't think the blue bubble hate comes from people not being able to do inline replies. I don't think it comes from the inability to edit your messages when in an SMS conversation.
The source of the blue bubble hate comes from group chat splitting. When you have an iMessage group chat and you hit Add to add a new user, but that user is not an iMessage user, you are shown a prompt that says "Create a New Group? Contacts not using iMesage can only be added to a new MMS group with the same members. Contacts using email address handles will use a phone number instead."
You are given two options: "Cancel" and "New Group".
If you choose New Group, you'll now have two groups. If you do nothing else, no one knows a new group was created, since no messages were received. If you send a message, its still entirely possible for the other group members to message either or both group chats. Chaos ensues.
It's not clear that Apple is actually going to fix this with RCS. Seems most likely they will not, that group chat splitting will still occur, just replacing SMS with RCS.
> i'm pointing to where i understand the landscape to be headed. for channel-based chat systems like Discord, irc, Matrix, XMPP/jabber, Slack, it's common enough to find channels which are bridged across 2 or more of those protocols.
Bridging is hacky, and involves not showing contact information for each user. You (of course), can't start a DM with such a user, and I'd assume things like @ mentions are ambiguous or nonfunctional.
Sure it _can_ be done, but it is kind of a terrible experience. Even Matrix and IRC have the same problem, and that's one I've actively experienced from both sides (IRC and Matrix).
> my experience with ephemeral group chats is that if i want to plan a large enough event i just end up starting multiple group chats, and the unimportant details are chaotic but the important ones like where/when we're meeting i make sure find their way into both chats.
I commend you, because you take a lot more effort than most humans to make sure things end up on both ends. In my experience, with the humans I have to deal with, its about a 5-10% of the time this happens, and usually its by sending a screenshot of the other group chat with half of the first line of the next message showing more important details that they decided "weren't relevant" or just didnt fit on the phone screen.
Also it should be obvious but some kinds of planning are simply not possible or require people to perform special courier roles to complete. Things like planning for what weekend everyone's free or what elements of a potluck everyone's going to bring are pretty tedious to manage between 2 group chats.
Furthermore, in my experience events that need planning aren't given dedicated ephemeral group chats, instead they are simply planned on whatever group chats they already have. People don't tend to put a lot of thought into making sure people are included, especially if the group chat is large. Some of the family group chats I'm in are 12-14 people. Not all of those people are coming to the potluck. They still use it, and honestly I think that's better than having to juggle every combination of every participant and keep track of whos in each one.
[1] Side note here, after Google started interpreting the (fairly annoying) iPhone tapback SMS messages as tapbacks, Apple introduced a similar feature to interpret tapback SMS messages --- but only for iPhone sent tapbacks. So the scenario is a group chat with 2 iPhone users in it-- the tapbacks show as SMS to the receiving iPhone, but it gets turned back into a tapback emoji reaction. This only works for iPhone style tapback SMS messages. The slightly different format that Google Messages sends is... ignored...
Pretty much the most smug Apple way they could possibly implement that feature... but now the Pixel in the chat works in all cases and the iPhone only works in half the cases, so it actually only hurts Apple users' experiences
Figuring it out is much more fun than just using something else!
Make money, don't make money, cash is unrelated to the definition.
I thought it was about owning anyone's machine to the full extent. Did this change during the past 30 years?
For what?
I own a Mac an iPhone and an iPad but iMessage and FaceTime are entirely useless to me because no one I communicate with on a regular basis uses Apple devices. Same thing with various iCloud sharing features. Not using the family sharing offers is entirely uneconomical as well.
So what happens is that I gravitate to other ecosystems. I use WhatsApp. I upload all my photos to Google Photos. I mirror my iCloud Drive to Google Drive to share and collaborate with people on various things.
I have enabled Apple’s advanced data protection for end to end encryption but it’s entirely farcical as my stuff is all over the place anyway.
Almost everything Apple does in terms of software and services is useless to me. They are not locking me in. They are locking me out.
I’m paying for their excellent hardware, the m-series CPUs in particular, but I’m using my “spare” Pixel phone more often because the software suits me better.
I appreciate a lot of things that Apple does but it’s only a question of time until some other ARM based hardware catches up enough for me to stop overpaying Apple for software I can’t use anyway.
Apple's problem is that they are selling less to me than they could and risk losing me as a hardware customer as well.
Now, I totally get their strategy. It's a bet that net net they are locking more people in than they are locking out. It's hard to tell whether or not this is paying off for them. Not even Apple can know the counterfactuals.
The ball is in the court of Google et al. to make messaging and video chats less frustrating.
iCloud Photos is E2EE if you turn on iCloud’s “Advanced Data Protection”. That migrates the vast majority of your iCloud data into E2EE storage.
What Beeper set out to do was to solve the opposite problem, people who don't have Apple devices, but want to use iMessage.
And the poster above did have an Apple device, and wanted to use iMessage, but didn't seem to realise that iMessage works on Macs too.
The issue is that I as an Apple user want to be able to use iMessage to communicate with Android users.
You're entitled to use or not use iMessage per your preference. You are not entitled to use of iMessage on a platform of your choosing. Where do we stop this? Is Apple then required to create iMessage clients for Windows Phone as well? Perhaps a Blackberry client too? Maybe a website?
If you want to share an iMessage account and all the rest of the ecosystem benefits Apple provides, then get an iPhone. That's how you do that. And you can still absolutely talk to Android users once you have an iPhone, because the iPhone provides the essential middle-agent between iMessage and SMS that enables you to do that. Apple has done this forever and has designed Messages to degrade gracefully: you are not barred from texting anyone who doesn't have an iPhone, instead your message is converted to SMS completely seamlessly and sent from your phone even if you actually sent it from a Mac or iPad.
The endless moaning and whining from people not in their ecosystem about iMessage is so, so fucking tired at this point: from the accusations of platform lockout to the bitching about the fact that SMS messages are green instead of blue, on and on. If you guys are SO HARD UP for that iMessage goodness then just pony up for an iPhone, holy shit. Or at the very least, go bitch up Google's tree so they'll develop a decent messaging client that won't be abandonware within 6 months.
"I own a Mac an iPhone and an iPad but iMessage and FaceTime are entirely useless to me because no one I communicate with on a regular basis uses Apple devices"
and
"The issue is that I as an Apple user want to be able to use iMessage to communicate with Android users."
To sum it up for you as succinctly as I can: I am an Apple customer expressing unhappiness about some aspects of the product and the product strategy.
Welcome! Pixel is all you need.
I use a Mac but an Android phone. Android because I require the ability to install apps from arbitrary sources, including piracy. Mac because modern Windows is so contemptuous towards its users, and desktop Linux falls apart unless you know the intricacies of its internals.
Anyway, transferring files between the two was a pain in the butt that eventually grew so immense I reverse engineered Google's Nearby Share and made this: https://github.com/grishka/NearDrop
Though yes, I'm not North American so iMessage is just a non-issue to me. I don't know anyone who uses it. No one uses SMS for actual messaging between people, everyone's SMS inbox is 99% OTP codes and various other automatic notifications. Literally everyone who I communicate with is reachable through Telegram.
No one "requires" access to theft.
Unless my eyes are just completely missing it, I didn't see anywhere that they said or implied that they weren't using macOS or iOS on their Apple devices.
People often say they are happy to pay a premium for Apple because of the software. So, for someone who doesn't use the unique features of a particular OS+apps bundle maybe they could use another ... which reminded me of the lawsuits that resulted in Microsoft [partners?] having to refund the OS portion of the sale price for those who chose not to use Windows.
It was a leap, but not a huge one IMO.
I know a lot of people who have MacBooks of various types who use Chrome as their browser (and only access their mail through the Gmail web interface), MS Office, etc, rarely using a single one of the Apple bundled apps (save perhaps the very basic ones, like Preview)...and yet, they would never give them up for a Windows computer, because so much of the OS is very fundamentally different to interact with.
My wife won't use Signal because it includes a crypto wallet and crypto transactions are taxable.
Matrix/Element would be my preferred option, but it causes so many security or encryption related issues that it has scared off everyone I tried using it with. Nobody knows what to do with the incessant popups demanding to "verify" something or other. Nobody (including myself) knows why older messages often can't be decrypted.
Telegram is less secure than WhatsApp.
Threema is not free, which makes it difficult for me to ask people to install it. It's not open source either.
iMessage is Apple only.
So what's left besides WhatsApp?
I think the crypto wallet is lame, and am disappointed the Signal folks decided to integrate something like that, but it's entirely opt-in. If she doesn't want to worry about being taxed on crypto transactions, she can simply not use that part of the app. I actually forgot for a second it was there until you brought it up, and I'm a daily Signal user.
I think her concerns are overblown, but it shows how incompatible taxable transactions are with a privacy focused app. The two things should be kept well apart.
[Edit] Politically, it kind of defeats the purpose as well. You want to be able to argue that you have a right to privacy when it comes to personal communication. You don't want to be in a position of having to defend the privacy of trading securities.
Separately, you've either misunderstood her position, or it's poorly thought out, and/or ideologically based.
What path would tax authorities use to ask Signal users (and only Signal users) if they've used cryptocurrency?
Tax law. In the UK, every single payment in cryptocurrencies, however small, is a taxable disposal that you have to include in your tax return if your total proceeds or gains from all investments are above a certain threshold.
I'm not ideologically opposed to cryptocurrencies and neither is my wife. She's just allergic to anything that could potentially raise tax questions.
Edit: On second thought, I don't own a business, so I guess nobody is going to look into my tax fillings with the same suspicion since they do not expect me to be doing anything funny with my accounting.
Doing it correctly is non-trivial. You have to submit a so called computation for each individual disposal, which can easily run into several pages.
The algorithm for working out the cost of a disposal is actually a pretty interesting test case for learning a new programming language or paradigm. Try implementing UK share identification rules in SQL for instance :)
I see it as the result of hacking spirit running the development, not the product team. Currently it can’t compete.
People who contact me over SMS get an immediate phone call from me in response.
Better use matrix which is an open protocol.
When I noticed that there is 2 dollar subscription required to use this app, then all my blame from Apple went to these developers.
You can't really expect to do business with other company's service's without asking permission or cooperating. Especially, if the required interfaces are not exactly public.
Maybe this App had hope as free version, but not as business. What they were thinking.
iMessage is like Discord. It is messaging service tied to specific backend, and also devices in this case.
What if I reverse-engineer Discord, make a commercial application which uses their non-public backend (not with webview) and never tell anything for Discord? Should the "phone" argument hold in this case?
Discord is not the best example, because it 'allows' third-party level clients on some level, but above should not be the case.
It's different, because the only texting app on the iPhone automatically prefers iMessage. Did you make a group with 2 iPhone friends and now you're adding a non-iPhone? Congratulations you now have two group chats. No way to merge it, and you have to manually tell everyone not to use the first one. But they will anyway, and the conversation splits.
Usually people know the consequences of their actions. If they don't use Facebook, Instagram, WhatsApp or any other "currently" popular social platform, there is always risk that you isolate yourself from the part of group which prefers the former.
Is that one person important enough that other group members ditch the other groups?
Here comes the reason why Meta, Discord or any other social platform with enough user base is highly valuable. Social pressure keeps users on their platforms.
Apple is doing the same with iMessage in hopes of pushing device sales. But it is still messaging service. It does not forbid you using regular cellural standards.
The question is that are the set defaults same as known decision? Not for everyone, but I don't think that conversation splitting is good enough argument here to reason why making business in this case would be good decision.
Yes! But it's a social problem created by an intentional product choice that makes their own users have a worse experience in service of retaining their walled garden at the expense of your customers relationships on a service that they are embracing and extending for their own ends...
And they could fix it too. There is zero reason to leave that original iMessage chat around from a technical perspective. They can even put a big scary banner at the end of the iMessage history saying Hey this is not encrypted anymore! watch out!
> Usually people know the consequences of their actions. If they don't use Facebook, Instagram, WhatsApp or any other "currently" popular social platform, there is always risk that you isolate yourself from the part of group which prefers the former.
Yes, choosing not to use the three Meta apps you listed is your own damn fault. You're isolated because of your own poor choices. Just give up and feed the beast instead of, you know, trusting the phone/OS manufacturer you purchased your premium phone from and the carrier that you pay for your phone service.
> But it is still messaging service. It does not forbid you using regular cellural standards.
This is the part that's not actually true, because you cannot make an MMS group with only iMessage participants. You cannot opt out of iMessage on 1x1 conversations either.
Using or not using iMessage isn't actually a choice, it's an automatic "upgrade"
I'm not even sure it's possible to disable iMessage entirely. EDIT: This exists actually
EDIT 2: "Messages app automatically chooses the type of group message to send based on settings, network connection, and carrier plan." https://support.apple.com/en-us/HT202724
[1] https://en.m.wikipedia.org/wiki/Breakup_of_the_Bell_System
It would be proper if iMessage would be the only messaging service phone users can use and installation and usage of the others are restricted.
But anyway, my whole comment is about making commercial messenger with the expense of other product (aka. backend services of Apple) without permission, cooperation or anything else. There aren't official public APIs for iMessage other than for Business use.
„We make use of a service already existing without paying for what could be dirt-cheap if it wasn't run by profiteering gluttons, and you call us criminals.”
I believe that if you want to see hackers as only kids doing „fun stuff” at their desk at night making their (metaphorical and not) parents angry then either you are missing the bigger picture, or capitalism has gotten their ideological claws on the hacker culture and turned it into an obedient bunch of techbros that wouldn’t even dream of making the information free, as it wants to be.
Can you even imagine the reaction if the uBlock Origin folks attempted to make the case that Youtube updating their site to prevent ad blockers from working was some sort of nefarious violation of "the hacker spirit"?
You should not be surprised around the risk of depending on reverse engineered third party integrations which the provider can seek to cut you off of unauthorized interactions.
> It is a bit dicey when you're charging for it, but since Mini was entirely client-side it would be feasible for a free version to exist.
That makes no sense for Beeper.
Which didn’t scale because it doesn’t scale because the blue box stopped working. Sort of like Beeper.
What’s your basis for saying that? Honestly asking. Seems like Beeper’s true purpose could just as well have been to make money.
Of course this is possible without an iPhone. Apple could build it anytime they want, they just don’t. Which I disagree with, but that’s a different argument.
Selling a device that transgressed the boundaries doesn't mean they thought that no boundaries should exist, it just means they knew it was possible to do something technically interesting and would allow them to make money.
If Jobs and Woz thought there should be now penalties for using blue boxes, my guess is that they thought the telco should merely implement a better system, not that everybody should get free access to it.
The site is called "Hacker News" but it's predominantly existed over the years as a funnel for the business-centric Valley industry.
Which is to say that I think you're trying to apply one specific definition of "hacker" when it doesn't really work that way.
An app like Beeper Mini wants to be something like NewPipe for YouTube: installable only if you know how to download F-Droid, maintained by a community of fans, used only by people who understand that Google can break it at any time and it might take days to weeks for it to recover.
What Beeper did instead was build a startup and sell subscriptions to mainstream users, and now that it inevitably broke they come off as very whiny about it. It's not just Silicon Valley business types who see that and wince: it's offensive to old-school hackers too.
I guess I can only speak for myself, but I'm pretty alright with people building apps with the expectation that would-be users will need to know how to install apps.
As for whatever reasons Apple comes up with: that is probably also not going to be relevant as a multinational that is beholden to money is going to have the legal department and PR do that sort of messaging and not anyone on the technical side of things.
Speculating as to why things are the way they are: Apple knows that people in some socioeconomic ecosystems value iMessage as-is, so we can expect their intent to be aligned with keeping that value. Reusing all in-house crypto and account management certainly makes it easier on the engineering side as well.
And to point out the obvious, Beeper was also closed source. I don't trust apple much, but I trust a random startup much less to believe that they're not either doing something dicey, or screwing up the encryption protocol and creating tons of security holes (esp. if it was retro engineered).
Honestly, as you're pointing out the closed source character of all of that, I'd much rather use something like Signal.
It uses a server for bridging APNs to GCM. Sure, that could be maintained on a donation basis, but it’s not completely infrastructure-free in any case.
So yes, it's absolutely possible for this app to be 100% client side and I wish Beeper would've done that to start, if for no other reason than to dispel the misinformation around that BPNs is somehow required for the core operation of the app.
To be fair, they probably thought making this explicit in their How It Works article would be sufficient.
I don't really follow the reasoning. If saving on power, data, and memory usage were more important than the ability to receive messages, it would follow that you were better off carrying around a cinder block than a phone.
And in this case, GCM actually creates potential vulnerability. This should be allowed, and if Google sees it as a problem, they should implement a system service to retrieve from APNs. I believe the API is public.
Backgrounding is problematic when devs do it wrong or disrespect the user, but this isn't one of those cases.
Android preventing background processes in this case is worse for the user.
That sounds extremely unrealistic. If nothing else, you already have GCM – I don’t think it deactivates the persistent connection even if you don’t have any notification registrations.
> Backgrounding is problematic when devs do it wrong or disrespect the user, but this isn't one of those cases.
But how would Google distinguish “disrespecting” from intentional use cases?
I’ve used Android for years, and uncontrollable background services were a big problem.
> unless GCM is considered a major battery drain (hint, it's not)
It’s as much a battery drain as APNs. The point is that I want as few of these persistent connections and background services as possible, and the ideal number is one.
I'm confused. GCM is Google Cloud Messaging. It's also known as FCM or Firebase Cloud Messaging. It is the Google Play equivalent of Apple Push Notification Service (APNs). It's job is just to provide a persistent connection for delivering push notifications.
> I don’t think it deactivates the persistent connection even if you don’t have any notification registrations.
It seems almost impossible to be running an Android phone that has zero push notification subscriptions registered.
> But how would Google distinguish “disrespecting” from intentional use cases?
Via app review and banning apps that abuse those use cases. It turns out you can also decimate the user's battery using the stuff Google still lets you do (like periodic background tasks), but we don't ban those things because otherwise your phone would be useless at that point. Of course both the periodic task system and the persistent background service both would show up in your battery usage statistics, so the user and the system would be plenty aware that the app is misbehaving. And of course Google Play Protect can send along that feedback back to the Play Store in both cases.
> I’ve used Android for years, and uncontrollable background services were a big problem.
Cool, I also have used Android for a long time! Started on the Nexus 5 back in 2013 and have used Android devices ever since.
> and uncontrollable background services were a big problem.
Hm, I wouldn't say they were a big problem but I guess I just used well behaved apps. Certainly restricting background behavior helped battery life, but at what cost?
What you might not realize is that there are a number of permissions that you can declare in the Android manifest that trigger the Play Store review to be... just a little more thorough about your apps behavior. This should be one of those permissions. Using it for a persistent connection to a messaging service is absolutely a valid use case for this sort of thing. That's not the kind of thing that caused battery problems on your older Android phones though.
This is also very analogous in App Store. You declare certain plist declarations that need to be justified, and cause your app to be more carefully reviewed.
[0] https://cs.android.com/android/platform/superproject/+/maste...
That sounds "very possible" to me. Apps can even pop up a dialog on first run instructing the user to disable battery optimization, and then load up that settings page when the user taps a button in the dialog. Certainly some people will be confused by it, still not know what to do, or not want to do it, but it's still quite possible.
And if the user won't do it, the app can still spin up a service with a foreground notification if they really want to keep things working decently well, and use Android's scheduled jobs mechanism to restart the service every 10 minutes (or however often) to catch cases where the service still ends up getting killed.
Kind of silly to buy apple devices (especially iphone) and expect to be able to hack their services. Apple is the last place to look for hacker friendly products. Ffs you can't even run your own software on an iPhone. Spend your hacker energy somewhere worthwhile, on devices and platforms that welcome that kind of tinkering (or at least tolerate it).
There are so many relatively open messaging services. Telegram has a rich API and bots framework. Much more hacker like to build something interesting on that. People trying to force imessage are just fighting a battle that is already lost. Why spend time and energy on something that will perpetuate closed ecosystems even if they succeed?
Just want to point out this isn’t inherently true. For example an insecurely generated session key would work fine but not be secure.
> Of course, it's very unlikely Apple is doing that. Just putting the thought out there.
Apple is doing what? Not using encryption properly? What reason do you have to believe that?
They didn't mean that, they meant siphoning off data client side, for reasons, like CSAM.
The point, which I agree with, is having to trust a single closed source implementation of a client is not so different to trusting the servers of a non E2E service.
"Trusting the servers of a non E2E service" is adding another trusted party.
If you don't trust apple, you don't have an iPhone.
Actually it is documented by Apple themselves that they receive the encrypted messages and the key to decrypt them when iCloud backup is used (unless you and the person you are messaging have specifically enabled their "advanced data protection" feature). They have decrypted messages in response to law enforcement requests.
> If you didn't have iCloud backup enabled then they've always been E2EE.
Correction: if you and the person you're messaging both didn't have iCloud backup enabled. And also it's worth noting that Apple forbids you from using any cloud backup system other than theirs.
If this is true, how is that legal?
1. Don't turn on iCloud Backups and receive E2EE on your messages 2. Turn on iCloud Backups AND advanced data protection and recieve E2EE on your messages
This is not some kind of nefarious plan on their end. Any user service will have a vulnerability on the user end of back-ups. For instance, Whatsapp backups will also have their keys available to Apple/Google. They need to offer this as for most users, the risk of losing their whole digital lives because they forgot their passwords outweights E2EE. For users who find that important, they have the two options listed above. Sounds like an appropriate trade-off to me.
> They need to offer this as for most users, the risk of losing their whole digital lives because they forgot their passwords outweights E2EE.
There is no clear trade-off that is an option.
These apps are not e2ee if almost every user has in effect encryption disabled.
Signal will be backed-up on iCloud _by default_ and client side will be an issue.
No, it absolutely is not. It seems like you don't have a good understanding of how actual E2EE systems work.
(Yes, it would be nice if the user didn't need two passphrases for this use, but Matrix cannot safely revert to key derivation because client could accidentally leak the master password to the server due to existing implementations.)
I've been using matrix. It's e2ee and multiple client sessions seem to be working just fine, they all sync without problems.
Here is the explanation why it's completely impractical and therefore doesn't provide actual privacy, along with other anti-privacy configurations: https://news.ycombinator.com/item?id=37875370
There are ways to opt out. But that's for the margin of people who worry about these things. So what that comment said is very relevant and accurate.
Or, how could you verify that you've been notified about every device added?
If you got iCloud backup enabled then they absolutely siphone everything that happens on your phone. And the disgusting part is that when enabling a new iphone it automatically has it switched on. I remember the case with some terrorists that Apple have to the US authorities everything on the dude's iCloud backups, but the authorities weren't content with only the backups and wanted to crack the phone - so backups have their keys managed by Apple.
And recently, they've released an updated version of cloud sync that doesn't even let Apple have your keys.
But it's perhaps a momentary cultural variation in a sea of changing priorities for Apple. They have embraced right to repair: perhaps in future, "hacker spirit" evolves further to become, a "right" for all citizenry of the Apple-verse, backed by their tremendous business model. In the same way that you can conceptualize (again, without judgement or making regard as to truth or not), that "human rights" emerge not out of a vacuum, but out of what the infrastructure of state can conceive and provide.
In other words, today's action may be but the anachronistic kneejerk of some poobah in the Apple bureaucracy. A vestige of the old guard, perhaps soon dying out.
If that makes sense? :)
CP/M systems eventually died, UNIX startups created by some of those university folks were just as vertically integrated as the mainframes they replaced, leaving only the PC clones.
Had Compaq not gotten lucky, and today's computing landscape would look much different, probably like the laptops and all-in-one PCs that are being pushed nowadays as the OEM margins cannot get any thinner.
It is all but required for a company of this size to take action in this way.
People that imagine otherwise haven't lived through those days.
I'm torn on this. Is it following the hacker spirit to get more people plugged into Apple's closed ecosystem? Maybe? Maybe not? Reverse engineering a proprietary protocol is certainly hacker-y. But building a business around that -- essentially charging people to put more load onto someone else's infrastructure, who have to bear the costs (even a rich behemoth like Apple) -- I'm not sure that qualifies. If we were talking about some open source project that was releasing this app to F-Droid, maybe it'd be more clear?
> The number of Apple apologists that have crawled out to say "see? I told you so!!"
I don't think that's Apple apologism, that's just "duh, obviously Apple is going to try to shut them down, and probably succeed". It's lame. It's just as lame as when AOL kept breaking Gaim/Pidgin's ability to talk AIM's OSCAR protocol. But acknowledging that Apple is going to pull something like that isn't apologism, it's just stating reality.
(As for the AOL/AIM example, I think reverse-engineering OSCAR was actually hacker-spirit-y, as AIM was a free service open to anyone, just they didn't feel like supporting Linux users, as was the SOP of many companies at the time. Linux users were a fairly small percentage of users, so it wasn't a big thing. But there are tons of Android users; more than iOS users, globally, even. That's not really the same, to me.)
In the context of the overwhelmingly saturated messaging space, I think it'd be a lot more hacker-y to bring something like Signal up to the usability standards of iMessage, Whatsapp, Telegram, etc., and evangelize the hell out of it to get people out of closed platforms. Even Signal isn't perfect there, since they refuse to enable federation in the protocol, and only release updates to their server-side software a long time after it's been running in production. But it's certainly better than getting more people hooked in Apple's walled garden.
Agreed here. But I understand deeply why it's appealing for my fellow android users who are tired of being bullied into buying phones they just don't want by their friends who overwhelmingly drink the Kool aid. it's not great, and in the US the effect is very real.
> I think it'd be a lot more hacker-y to bring something like Signal up to the usability standards of iMessage, Whatsapp, Telegram, etc.,
Good idea... what about an existing open standard that is already adopted by a billion devices and can be implemented by any mobile phone manufacturer and carrier network.
Something that takes what's good about SMS and adds all those nice features. I bet we'd have to work together to make end to end encryption interoperable, and some of the fancier stuff is too new to be in the spec yet, but that's not too hard in the grand scheme of things.
Oh, RCS exists.
Yes — it's adversarial interoperability, and that is always a good thing because it breaks lock-ins. Though mostly irrelevant to this particular case, adversarial interoperability also forces the service owner to compete with third-party clients which always put the user first; it removes the service owner's of control over the UX and presentation.
I don't know about AIM, but ICQ also used OSCAR protocol. The official ICQ clients were bloated, shitty and full of ads. Not many people used them. Most people used QIP, Miranda, Pidgin, Adium, Jimm, or even NatICQ. No one cared about how ICQ's owner would make money — and, really, no one should care about that, it's their own problem. Maybe if they made a client that's better than third-party offerings, then people would switch to it. But they never did.
As one of the top posts that presumably the GP post is talking about, precisely. Nowhere was I apologizing for Apple, nor did I "crawl out".
When this product was first announced I observed that Apple was going to shut it down, and that they had obvious avenues (both technically given the way messages are attested to, and legally -- this product is the textbook definition of computer misuse! And they're charging for it making it a slam dunk). Loads of people "crawled out" to gloat that this is it, Apple has no avenue to do anything about it. And then Apple did something. Apple did the easiest, lightest option, but they could go full scorched Earth if they wanted to. I don't want them to, and am not celebrating that, but these are basic obvious facts.
To your other point, exactly. The hacker spirit is getting your friends and family on Signal. It isn't cementing iMessages as the foundation.
This assumes that Apple can periodically extract money from users after they bought the product.
I tried beeper before (not Mini though, so could be wrong about Mini) but it seemed to be running a VM somewhere and passing messages to the MacOS Messages.app via some kind of scripting interface.
So beeper itself (the full version) was not “speaking” iMessage protocol at all.
There was none to begin with. It was an attempt to build a business on top of a virtual macOS.
Edit: sorry, confused them with a different service. This one used previously published research on reverse engineering iMessage to build the business.
*https://ca.pbslearningmedia.org/resource/osi04.soc.ush.civil...
Ranking how much it’s all captured and handed out to buds and pre-IPO AirBnB stock funded. Snooze.
Call me when you want to knock this thing over.
SMS messaging is a feature of the mobile network, and they're sent directly from the device to the carrier SMSC without going through Apple's servers. You might be confusing iMessage with Messages. The former is a messaging platform, the latter is an app that can send messages either via iMessage or SMS (assuming a mobile device, or pairing with an iPhone).
> what an incredibly bad move it would be for them
I don't see it very different from Apple's choice to degrade arbitrarily the experience of messaging with android users. There are infinitely better alternatives to sms for private messaging, Google could say it's encouraging its users to move on them.
Edit: to respond to your edit
Apple is blocking 3rd party access to their own services. Google blocking access to messages delivered via an 3rd party isn't at all the same thing. And the optics of it would be incredibly bad for Google.
Its become like a racial slur the blue vs. green, and that's exactly what Apple wants to sell cellphones. You can't contact the cool kids until you have a blue bubble, that means you're like, cool or something. You can message me if you can afford an iphone apparently.
Take a moment to say this out loud to yourself, so you can hear how fucking ridiculous it sounds. Notwithstanding the trivialization of actual racism, it's just a throughly silly statement.