I've re-written this comment five or six times in an attempt to find the most charitable interpretation, but I just cannot comprehend how it made it through your filter and out onto the internet.
SMS is insecure and no one should use it. RCS isn't that much better and history is a lesson that it returns to a partner that isn't trustworthy.
SMS can be read but it is still at least somewhat decentralized. It isn't being funneled to a single party whose business model is profiling users.
Stuff like this happens all the time and the internet has always been like this. I'm sure older users will remember even older examples
On a more serious note though, in the end Apple absolutely has the power of increasing everyone's capability and security by doing something like setting up a playbook of how iMessage could just use Signal protocol and how other actors could join in, or really anything else but doing this.
Right now I can presume a basic level of device security across all iMessage threads I have. Beeper deranges that: E2EE is still there, but Beeper exposes my correspondence to device security weaknesses from other OEMs, malware, keyloggers, screen scrapers, etc. as a result of lax app marketplace security & privacy.
It seems to me to be entirely disingenuous to suggest that Beeper increases security: in fact, the opposite is true.
> in the end Apple absolutely has the power of increasing everyone's capability and security by doing something like setting up a playbook of how iMessage could just use Signal protocol and how other actors could join in, or really anything else but doing this.
I don't see why any company should be denigrated for not helping the users of another competing platform, particularly when doing so likely comes at the cost of increasing the risk to its own users.
Hmmming and hawing over "OEMs... and ...lax app marketplace security" seems like quite a high bar to hold, a bar so high it ceases to be useful. Remember, iPhone users can disable passwords on their iPhone entirely; if that's not something you ever worry about, then worrying about a minority of OEM's seems like mere pretext to keep your comfy walled garden all to yourself.
Subjective, speculative.
> when in reality
I think you mean "when in my opinion".
> they are making a decision on improving their profit
Speculative, and "improving their profit" is clumsy enough vocabulary that it's a red flag on continuing to discuss this with you.
> regardless if it decreases security of its customers and other people
The plurality of countervailing perspectives in this thread – which you have failed to address or refute, as far as I can tell – ought to indicate to you that it is arguable that Apple's decision in this case increases security of its customers.
> It is undeniable and silly to argue against.
I'll let others judge who seems silly here.
My point stays exactly the same. You haven't said anything real against it.
Is that really true though? Jailbroken phones, iMessage may still work. Any device security gets thrown out the window.
You also can't expect everyone to have an Apple device for security, which we've seen time and time again SS7 being weak - So is the requirement to remove SS7, for everyone to jump on the Apple train?
I see Beeper as doing Apple a service, not so much a competing platform, but a gateway to the iMessage ecosystem - 'Hey, this would be pretty cool to use without this app and have it native' vs the 'Only Apple devices can use this.'
Apple closes exploits which allow jailbreaking, precludes it in the EULA. What more would you have them do?
Preventing jailbreaking is not a good thing, in part since that's what allows us to check on what Apple is doing on the device, in regards to privacy, security and e2e encryption. If nobody can check, do you suppose we just accept their statements about the device as fact?
iMessage using SMS to communicate with Android devices increases the risk to iOS users. Apple customers are still Apple customers when they communicate with Android users.
Every risk you describe is still present in the current implementation of iMessage when communicating with Android users, except the risks are much greater because SMS is much easier to exploit and intercept than an E2EE protocol would be.
A message platform that forces Apple users to use an insecure protocol when communicating with Android users decreases the security and privacy of Apple users.
So even an imperfect implementation of real E2EE between Apple and Android users, even with all the risks you describe above, is still an improvement in security over what we have right now: a situation where Apple forces iMessage users to use to what is quite possibly the least secure communication method possible when communicating with their friends and family in different ecosystems.
It's not necessarily about helping the users of another competing platform, Apple users who are using normal iPhones are sending unencrypted and unsecured messages to their friends and family members because Apple is more interested in vendor lock-in than it is interested in making sure that its customers are able to communicate securely with their contacts.
The idea that Apple users would suddenly stop caring about security or that they wouldn't want their conversations encrypted just because they're talking to someone else who's on an Android device is very strange to me -- it suggests that Apple is willing to sacrifice security for paying iOS users just to keep Android users from seeing any of the benefits of those security improvements.
Yes, there may exist reasons to distinguish between locked down vendor-controlled devices where users do not have the autonomy to change device settings that could damage encryption, and devices where users do have that autonomy. I understand that concern, even if I think it's usually disengenous. But there is really no reason and no excuse (especially now that we know how easy it would be for Apple to take its encryption multiple-platform) for going beyond distinguishing between those devices, and going so far as to actively drop all security measures and all encryption from those conversations. It's like saying that because a window can be broken we might as well take the door off of its hinges and put up a "burglars welcome" sign -- and, incredibly, it's claiming that anyone who tries to replace the door without permission is somehow decreasing security. Apple doesn't just distinguish between controlled and uncontrolled environments, it removes the door entirely by dropping its users into a messaging format with no end-to-end encryption at all. It's a bad policy that hurts Apple users and decreases their safety.
The smartphone is the single most important device for modern life and society. It's news, photos, communications with loved ones, work, entertainment, food, paying for practically everything...
And it's just two companies. Two companies with an iron grip over such a wide and diverse set of functionalities that, taken together, should be as inalienable as free speech.
- They control what you can put on the devices (or in the cases where they're open, they scare you or make it exceedingly difficult).
- They tax all innovation happening on the platform. Because web is second class. If you build an app, you have to pay for ads against your own brand. You can't have a customer relationship (yet Google and Apple get that). You have to keep up with their release cycles on their timeline. They can deny you or ban you at any point. They take 30% of your margin. You're forced to use their billing. In many cases, they actively develop software that competes with you.
- They're extremely user hostile. The devices aren't easily repairable, the batteries force upgrade cycles, and they do stupid things that make your kids want to buy the most expensive model for clout. Green and blue bubbles, etc.
- On top of this, they're gradually eating away at every related industry. The music industry. The credit cards and payments and finance industry. The film industry. It's all getting absorbed into the blob that is the locked down smartphone.
- They turn their devices into "CSAM detection dragnets" (read: five eyes, US, China, and every other entity that wants to surveil).
This is fucking absurd and it needs to stop.
We need more than two device and platform manufactures.
Apps should be at least one of: (1) portable, (2) freely installable from the web without scare tactics, (3) web should be first class / native
The device provider shouldn't be able to use their platform play to maintain dominance. The cost of switching should be zero until there are enough new peer-level competitors.
I could keep going... the status quo is a tax on the public, a tax on innovation, and a really overall unfortunate situation.
Sent from my Librem 5.
That basically makes it a non-option for the overwhelming majority of people, and it was still an issue 6 months ago.
I really want to like the Librem but it's hard to justify the price tag when you're going to have to carry another phone around with you anyway.
The battery thing is not an issue for me in practice. I carry a spare battery (they're swappable), but I never actually need it because there's USB-C chargers everywhere I go, and I made it a habit to plug it in whenever I can.
A phone should adapt to your lifestyle. You should not have to adapt your lifestyle to your phone.
Edit: Actually it did happen when I opened a Firefox tab with a heavy js and left it open with deactivated suspend, which you shouldn't do on any phone (and even then it's more than a couple of hours).
that would be nicer than the current situation where they take away 30% of your revenue
There's also the mountain of 'mobile first' (aka mobile-only) garbage out there, and stuff that is nerfed on mobile unless you download the app (so they can squeeze telemetry out of you).
Don't get me wrong, I'm not defending Apple or Google - far from it - but I'm saying there's a lot of real crap going on in tech right now.
To be fair, I am a curious person and use both android and iOS. I use onedrive and (sigh) icloud for storing photos. On my android phone, I can actually have it sync pictures to onedrive and nowhere else (and it'll free up the storage, even! I think...). On iOS it either fills your phone up and then nags you constantly to manually delete pictures, or you use iCloud. There's no other choice.
it's going to become illegal not to have one in california! so you better invest NOW!!!
go to double U double U double U blah blah blah dot yadda yadda yadda
*full disclaimer, this technology is patent pending**
**doubly full disclaimer, "patent pending" in the sense that the invention is still to be invented, the panel of experts said 20 (more) years!
> The app doesn’t connect to any servers at Beeper itself, only to Apple servers, the way a “real” iMessage text would.
https://techcrunch.com/2023/12/05/beeper-reversed-engineered...