8 ms·
As usual, Gruber was right on the money. Via Threads yesterday: "My prediction is that Apple will make changes—fixing bugs and/or closing loopholes—that break
by dmillar 3y ago
As usual, Gruber was right on the money. Via Threads yesterday:
"My prediction is that Apple will make changes—fixing bugs and/or closing loopholes—that break Beeper Mini. It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature.
It’s a very nice app, remarkably clever, and for now works like a charm, but if Apple wanted an iMessage client for Android they’d release an iMessage client for Android. Seems irresponsible for Beeper to charge a subscription for an unsupported service."
https://www.threads.net/@gruber/post/C0k1VgyMGZN?hl=en https://www.threads.net/@gruber/post/C0k1VgyMGZN?hl=en
- goodluckchuck 3y agoIt looks to me like there is an advantageous business relationship between Beeper and their customers. As a general rule, Apple is free to change their programs and how they work. However, I think there’s a plausible argument for tortious interference here if the sole purpose was to prevent interoperability.
- School-Cotton 3y agoAre you a lawyer because Apple stopping third parties from using their service being in any way illegal sounds extremely hard to believe
- MBCook 3y ago> The CFAA prohibits intentionally accessing a computer without authorization or in excess of authorization, but fails to define what “without authorization” means. - From the National Association of Criminal Defense Lawyers Other way around. If anything, it sounds to me like Beeper Mini was acting illegally by accessing Apple’s servers in a way they didn’t give permission for. The CFAA is ripe for abuse. I’m not saying applying it here would be just or not, only that Apple likely wasn’t the one acting illegally.
- bee_rider 3y agoWouldn’t it be the users, rather than Beeper Mini, that are doing the accessing?
- dwaite 3y agoBeeper mini includes a hosted service to receive APNS notifications (meant for Apple software) So I would summarize it as the corporate entity connecting to an Apple API and using it in undocumented ways that they reverse engineered, intercepting messages meant only for Apple software, doing so without prior permission, for purpose to selling access to services which would normally be covered by an Apple EULA. It is not quite like a smaller word processor wanting to be able to import Word documents - without tying into Apple's service, Beeper Mini has zero value.
- goodluckchuck 3y agoI think that’s certainly an argument that Apple would make. However, it seems that this app was simply sending requests and receiving responses that there was no code injection or compromise of Apple servers, or of credentials, or anything of that sort.
- chmod775 3y agoYes, they didn't violate the law as you think it ought to be written. They may very well have violated the law as it is actually written.
- simondotau 3y agoIt's also entirely possible that no law has been violated by anyone at all. What Beeper Mini did is probably not illegal. What Apple did in response is probably not illegal.
- ntqvm 3y agoNot particularly relevant due to lawsuits involving game cheating, where the circumstances are very similar. Beeper is lucky they weren't sued under the DMCA anti-circumvention clause, as they clearly were bypassing the technological measures Apple uses to prevent genuine devices from connecting to iMessage & Apple services.
- goodluckchuck 3y agoThat’s fair, but compare it to SMS. What if Apple blocked SMS messages sent via cellular carriers, which are also using their services (software on phones, etc.) Then suppose it wasn’t malicious SMS or spam, but legitimate messages sent using a competitor’s product (e.g. from all Samsung phones).
- freedomben 3y agoMaybe (or maybe not) plausible, but I think it's irrelevant, because there's no way a small company like Beeper could beat Apple's lawyers at this game. It will end up bankrupting Beeper long before it would even matter.
- gnicholas 3y agoThis is unfortunate, but not untrue. Even just going through discovery on this issue would be quite expensive — and would be critical to proving Beeper's case.
- madeofpalk 3y agoThat's like getting upset after getting bad dating advice from a vending machine.
- cqqxo4zV46cp 3y ago[flagged]
- tptacek 3y agoThere's a bunch of reasons why this is unlikely to be tortious interference, but one of the obvious ones is the contractual Terms & Conditions that apply between Apple and its users; I doubt Beeper is liable here, but if interference was a thing, my bet (not a lawyer!) is that the liability would point the other direction.
- gnicholas 3y agoMy read of GP's comment was that the claim of tortious interference would be by Beeper against Apple (for interfering with Beeper's relationship with Beeper's customers).
- tedunangst 3y agoApple is not preventing anyone from downloading beeper, or giving beeper money, or running beeper software. They are exercising control over their own servers.
- paulryanrogers 3y agoBlocking interpretability could be illegal, especially as they near market dominance
- lotsofpulp 3y agoiMessage is nowhere near market dominance. As evidenced by the ease of use and popularity of alternatives such as SMS/Whatsapp/Signal/Wechat/etc
- AlexandrB 3y agoI agree. The obsession with "blue bubbles" is something I only hear about from tech writers. No one I communicate with in the real world has ever mentioned it. Supposedly teenagers care about this, but that seems like a poor basis for anti-trust action. At the same time, I miss the era of rich third party client ecosystems for things like AIM or MSN messenger. Blocking interoperability is a bummer for innovation.
- gnicholas 3y agoNot sure why this is getting downvoted – IAAL and this is definitely something worth considering. This particular type of law varies from state to state, and can be quite broad. I've talked with other lawyers about it in the past, and my understanding is that it's frequently asserted when companies make counterclaims in business litigation. That doesn't mean it's a sure winner, just that it's a live question until more info is known. I imagine Apple would say they need to tighten up any parts of their system that could allow for spoofing or other security issues, and that was their 'legitimate' reason to make these changes.
- cqqxo4zV46cp 3y agoI’m not a lawyer, but I do know how computers work. I’d bet the farm on the very safe assumption that any protocol change that blocks a third-party client at the very least can plausibly be claimed to be in service of security, and most likely be a legitimate claim in reality. It is probably being downvoted because it’s incredibly far-fetched.
- gnicholas 3y agoI agree that this would be their argument. But as other commenters mention, this area could be a minefield for Apple due to their dominance in various markets. It's possible they wouldn't want to get sucked into a lawsuit about this, even if they thought they could win, since they might end up making statements that would have a larger detrimental effects in other cases/potential cases.
- D13Fd 3y agoI think most or all states recognize that the defendant’s actions must not be justified or privileged. It’s hard to imagine how Beeper would meet that element on these facts.
- willseth 3y agoHow are you going to make a case for tortious interference when the would be interferee is profiting by using the interferer’s resources without payment?
- goodluckchuck 3y agoFrom beepers website, there’s no use of apples servers when iMessages are sent from a beeper user to a beeper user. Rather, they only pass through Apple when sent to an iPhone user and in that case it’s the iPhone user that’s utilizing apples resources. And in that case there’s an Apple device owner, who is paid for the right to use iMessage servers.
- willseth 3y agoWow that’s a hell of a stretch, but A+ for effort I guess. By that logic, they’re only stealing 50% of Apple’s iMessage resources for iPhone users.
- tedunangst 3y agoWell, obviously, if those messages aren't using Apple's servers, then Apple hasn't stopped them, so there's no interference.
- tiahura 3y agoNot sure that's worth much congratulation. Is there anyone that didn't think the exact same thing as soon as they saw the story?
- kyleyeats 3y agoThe "well duh" crowd says "well duh" no matter what happens.
- jjulius 3y agoMmm, absolutes.
- deleted 3y ago[deleted]
- tiltowait 3y agoI heard/saw quite a few people saying Apple either couldn't or wouldn't cut them off—and that even if they did, it would take a while. They were ridiculous takes, yes, but apparently made in earnest.
- jeroenhd 3y agoWhile it would ruin the experience in practice (not being able to receive any notifications), I don't see why someone couldn't perfectly reverse engineer the protocol. Beeper made several design decisions that made the app super easy to use (i.e. using a single certificate that wasn't supplied by a user's phone), but if you extract the necessary source material from an old jailbroken iDevice, you could create an iMessage clone that Apple can't ban without either legal action or breaking compatibility with all easily jailbroken iOS devices. Back in the days of AIM and MSN, even large companies used reverse engineering to get chat interoperability, and it was so successful that AIM left open an RCE vulnerability to push shellcode so that Microsoft couldn't chat through their service.
- _rs 3y ago
- treyd 3y ago>It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. I don't follow this logic at all. Shouldn't supporting thirdparty clients be desirable if security is a primary feature in the interest of transparency? Especially if the reference client is proprietary and undocumented.
- bombcar 3y agoThird party clients offer many more cases for average users to lose their security, because you can’t prevent malicious actors from releasing “SuperMessengerSecure” that just mirrors everything off to a server somewhere.
- Grustaf 3y agoHow would third-party clients _increase_ security (other than indirectly, by people using SMS less)? On the contrary, third-party clients is a gigantic security hole, since Apple can't even know if a client app is spying on users.
- jlarocco 3y ago> On the contrary, third-party clients is a gigantic security hole, since Apple can't even know if a client app is spying on users. Security isn't about Apple knowing if an app is spying on users, but about THE USERS knowing that nobody is spying on them. At best a third party iMessage client can only be as secure as iMessage itself because the back end is still closed and has no transparency, so it's the weakest link. If Apple (or a third party) is spying on the back end then no client can be safe. > How would third-party clients _increase_ security (other than indirectly, by people using SMS less)? They can increase security by breaking a single target into multiple targets, by increasing competition around security and privacy issues, by having more people use and work with the protocols and able to spot potential problems, by encouraging more transparency around issues when they arise, and by having alternatives readily available if one of the clients is found to be compromised or insecure. And of course open source clients can be verified and validated by other developers and security professionals.
- orangecat 3y agoIf an "unsanctioned" client can compromise iMessage security, then there was no actual security other than obscurity.
- sdfhbdf 3y agoI didn't compromise the security of iMessage as a whole, it just exploited a way to get people into the system that was not planned. Imagine there is a theme park that has normal ticket booths and some requirements there to get in. Then there comes a Beeper that finds a hole in the fence on the perimeter and sets up their ticket booths there. It's in theme park's best interest to close that hole and cut off the revenue stream of somebody pigging back on their theme park.
- ancientworldnow 3y agoExcept they charge a thousand dollars to enter and then let everyone else in for free but they have to wear a badge and the pictures they get from the roller coaster photo booth are 240p.
- sircastor 3y agoAnd no one is obligated to come to the Theme park. There's an entire world of people who never visit the theme park, mock the people who do, and couldn't care less about it. But some people want to be included as going to the park, when they don't. Some people are very judgy and don't want to talk to people who don't go to the park... Okay, I've stretched the metaphor out enough.
- hamandcheese 3y agoAlmost 60% of America is in the theme park.
- simondotau 3y ago> Except they charge a thousand dollars A Lamborghini Urus costs $230k so I guess it's morally acceptable to break into a dealership and steal it.
- quickthrower2 3y agoEasy to be right on the money here. This is the default MO. Regardless of if you are paying for it or are licensed or are doing it despite the tech giant whose toe you are tickling. Twitter API springs to mind.
- deleted 3y ago[deleted]
- jlarocco 3y agoHis first sentence about privacy and security is nonsense, but his second sentence hits the nail on the head. If the richest company in the world wanted their chat app to run on Android, it would by now. It's strange Apple doesn't sell an iMessage Android app, but I'm sure they've had somebody do the math and found out that it's more money for Apple in the long run if they don't.
- shultays 3y agoBecause there are people that buys iphone just to get a blue bubble, why would Apple want to stop that?
- paulmd 3y agoyou’re talking to a forum that is probably 50% iPhone and has very good technical reasons to do so, this is insulting and it’s absurd that it’s so casually normalized to directly insult people in this fashion
- idle_zealot 3y agoHow did you manage to take this as a personal insult? Some people buy an iPhone for the blue bubble, some have what they believe to be good technical reasons to buy one, some people like the aesthetics, some people buy one out of habit. Stating that each category exists is not an insult to those who fall outside it.
- paulmd 3y ago> How did you manage to take this as a personal insult? years and years of "apple sheeple" variants tend to take their toll, you're just the latest in an endless parade of microaggressions even if you don't think your particular case was notable. why is it so important for you to push on the idea apple users being thoughtless trend-followers? just don't do that, be better. you can do it. the next time you feel like posting that, simply take a deep breath and don't post it. there is just no reason to go around posting that "[device that 50% of people own] users are all doing it for [trite/dismissive reason]" in the first place, let alone on a tech forum where everyone has very specific reasons for their tech purchases. and it's so completely normalized, android users do it so routinely and don't even think that what they are saying is offensive. it's literally the classic microaggression problem.
- mcfedr 3y agoThe primary feature of iMessage is lock-in. Everything else is secondary.
- tempodox 3y ago> Seems irresponsible for Beeper to charge a subscription for an unsupported service. Completely wrong. It's a job-seeking ad. “Look, I'm ruthless enough to fuck over users who buy this bogus subscription.” Which SV startup wouldn't pay millions for a crook of that caliber?
- crest 3y ago> It’s untenable that there’s unsanctioned client software for a messaging platform for which privacy and security are a primary feature. What a stupid take on the situation. At most it's untenable to Apples short term financial interests. A well designed protocol and implementation would be even better at protecting user privacy and security especially from a privileged attacker like the service provider and anyone able to put covert pressure on them. The only way in which vendor lock-in helps the the existing users is that spammers and scammers have to invest additional money to acquire Apple devices to create new accounts instead of just phone numbers and a labor to create accounts.
- paulmd 3y agothis sounds like proof of stake to me yes, you can indeed build a secure system on the basis of increasing the economic cost of attack beyond reasonable levels and by forcing attackers to repeatedly slash their stake to perform an attack
- windexh8er 3y agoOn the money, but unsurprising. Gruber is an Apple fan-boy through and through and it doesn't take much of a guess to posit the exact "prediction" he made. It was clear Apple was never going to put up with this, but it was likely accelerated by all of the media attention. Apple is, however, nothing for "privacy and security" beyond what they need to do to be marginally better, and that's a stretch these days. If Gruber really believes what he wrote he's full-on living in Apple's orchard behind the walled garden that Tim Cook splendidly gatekeeps. But because Apple puts marketing dollars behind ads that say "privacy" and "security" it must be so! This is why it's always funny to me when the trope of the hour is the mass privacy failures of Signal through use of phone numbers. And then the author turns around and types out an iMessage to a blue-bubble friend. I really hope we can move beyond the Apple reality distortion machine and move to truly user focused platforms that aren't designed to steal user data or make the board richer. Apple has become rotten.
- rpgbr 3y agoTo be fair, that was an easy prediction.