this post was submitted on 19 Nov 2023
111 points (100.0% liked)

Technology

37712 readers
219 users here now

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 2 years ago
MODERATORS
top 16 comments
sorted by: hot top controversial new old
[–] Hiko0@feddit.de 64 points 11 months ago (3 children)

Well, how could anyone think that circumventing encryption with a shady middle-man tool wouldn‘t be a privacy nightmare?

[–] jmcs@discuss.tchncs.de 36 points 11 months ago

They pinky swore that they wouldn't look.

[–] deliux@discuss.tchncs.de 8 points 11 months ago (1 children)

But to give credit where it's due, it's not worse than plain SMS.

[–] hatedbad@lemmy.sdf.org 7 points 11 months ago

SMS is literally the bottom of the barrel though

[–] bedrooms@kbin.social 8 points 11 months ago

EU politicians

[–] semi@lemmy.ml 60 points 11 months ago* (last edited 11 months ago) (6 children)

From the FAQ of the Sunbird website (the tech powering Nothing Chats):

Will the app be open source?

Some of the messaging community believes that software that is open source is more secure. It is our view that it is not. The more visibility there is into the infrastructure and code, the easier it is to penetrate it. By design, open source software is distributed in nature. There is no central authority to ensure quality and maintenance and by putting that responsibility on Sunbird, development would not be feasible. Open source vulnerabilities typically stem from poorly written code that leave gaps, which attackers can use to carryout malicious activities.

To help satisfy our own ambitious goals of providing total privacy and security, we are currently undergoing a third party audit that will validate our security, encryption and data policies and plan on receiving ISO 27001 certification after launch.

This was a huge warning sign when the first round of news about Nothing Chats came around, so I'm glad we're now getting early confirmation that security by obscurity still is a horrible idea and doesn't work

[–] Pantherina@feddit.de 21 points 11 months ago

Lol

Open source vulnerabilities typically stem from poorly written code that leave gaps, which attackers can use to carryout malicious activities.

Dont write or accept bad code then?

[–] astraeus@programming.dev 16 points 11 months ago

This is hilarious. How are we supposed to develop good software if everyone is able to show us where all the flaws are?

[–] erwan@lemmy.ml 13 points 11 months ago

It's funny, they could have said they're not going to release to open source without waving those giant red flags.

[–] azerial@lemmy.dbzer0.com 13 points 11 months ago (1 children)

Right i posted the same thing on another nothing chats thread a few days ago. It's such a bizarre statement that's just not true.

[–] semi@lemmy.ml 14 points 11 months ago* (last edited 11 months ago)

Right! The last I remember hearing the "closed source is more secure" argument was about fifteen years or so ago, so it's surprising that it is being pulled up from the dead.

[–] smeg@feddit.uk 12 points 11 months ago (1 children)

Transparency? No, security through obscurity!

[–] scrubbles@poptalk.scrubbles.tech 8 points 11 months ago

Which is obviously what they were counting on, fingers crossed no one notices we're using http

[–] GameWarrior@discuss.online 2 points 11 months ago* (last edited 11 months ago)

I feel like I've been shilling beeper a lot recently. They may or may not read my messages but at least they open source their inferstructure and contribute to the FLOSS projects they use.

[–] Plume@beehaw.org 48 points 11 months ago

I'm still shocked by the fact that people actually like or even trust Nothing when, personally, the company gives me nothing but bad vibes since the very beginning. This tech-bro-crypto-bullshit / Elon Musk-esque / Cybertruck-esque marketing and attitude is a massive red flag to me. Can't say I'm surprised about this.

[–] autotldr@lemmings.world 10 points 11 months ago

🤖 I'm a bot that provides automatic summaries for articles:

Click here to see the summaryNothing has pulled the Nothing Chats beta from the Google Play store, saying it is “delaying the launch until further notice” while it fixes “several bugs.” The app promised to let Nothing Phone 2 users text with iMessage, but it required allowing Sunbird, who provides the platform, log into users’ iCloud accounts on its own Mac Mini servers, which... isn’t great?

The removal came after users widely shared a blog from Texts.com showing that messages sent with Sunbird’s system aren’t actually end-to-end encrypted — and that it’s not hard to compromise it.

The app launched in beta yesterday after being announced earlier this week.

9to5Google pointed to a thread from site author Dylan Roussel, who found that part of Sunbird’s solution involves decrypting and transmitting messages using HTTP to a Firebase cloud-syncing server and storing them there in unencrypted plain text.

Roussel posted that the company itself has access to messages because it logs them as errors using Sentry, a debugging service.

Sunbird claimed yesterday that HTTP is “only used as part of the one-off initial request from the app notifying back-end of the upcoming iMessage connection.”


Saved 34% of original text.