this post was submitted on 12 Jan 2024
1 points (100.0% liked)

random

1 readers
57 users here now

Catch-all for uncategorized or purely random content. Also, "random" items from the Fediverse may appear here.

Rules

Do not post or link to any illegal and/or copyrighted material.

Any sensitive or inappropriate submissions will be removed.

Be respectful of other people's opinions and behave yourselves.

founded 1 year ago
MODERATORS
 

Apple's most valuable intangible asset isn't its patents or copyrights - it's an army of people who believe that using products from a $2.89 trillion multinational makes them members of an oppressed religious minority whose identity is coterminal with the interests of Apple's shareholders.

--

If you'd like an essay-formatted version of this thread to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:

https://pluralistic.net/2024/01/12/youre-holding-it-wrong/#if-dishwashers-were-iphones

1/

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 1 points 10 months ago (10 children)

That's where #BeeperMini comes in: it's a third-party Android version of iMessage that builds on the work of a teenager who reverse-engineered iMessage and found a way to let Android users receive secure messages sent by Apple customers:

https://pluralistic.net/2023/12/07/blue-bubbles-for-all/#never-underestimate-the-determination-of-a-kid-who-is-time-rich-and-cash-poor

34/

[–] [email protected] 1 points 10 months ago (9 children)

This was an immense service to Apple customers, correcting a gaping security vulnerability in Apple's flagship product, that had been deliberately introduced, putting the company's profits ahead of its customers' safety and privacy.

Apple immediately rolled out a series of countermeasures to block Beeper Mini. When The @[email protected]'s @[email protected] asked them why, Apple said they did it to protect their customers' security (!!):

https://www.theverge.com/2023/12/9/23995150/beeper-imessage-android-apple-statement

35/

[–] [email protected] 1 points 10 months ago (8 children)

The company claimed that there was some nonspecific way in which Beeper Mini weakened the security of Apple customers, though they offered no evidence in support of that claim. Remember, the gold standard for security claims is #ProofOfConcept code, not hand-waving:

https://nostarch.com/gtfo

36/

[–] [email protected] 1 points 10 months ago

@[email protected] IIRC, I think that the argument was that Beeper was a literal man-in-the-middle. Ergo, the blue bubble which means it’s encrypted was now silently decrypted by a party (Beeper) that users didn’t choose and couldn’t opt out of. Beeper literally made it work by running iMessage on their own Macs and relaying the messages to the app, right? That architecture undermine iMessage security for anyone unknowingly routing messages through that, no?

load more comments (7 replies)
load more comments (7 replies)
load more comments (7 replies)