Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Nothing Chats has already been pulled from Google Play over privacy issues (theverge.com)
18 points by sadeshmukh on Nov 18, 2023 | hide | past | favorite | 6 comments


Yeah, so they didn't reverse engineer anything, they literally take your password and then have you approve them registering a Mac mini they control as a trusted device in iCloud.

At that point they have access to your entire iCloud account: messages (obviously), docs, browser history, browser tabs, iTunes/App Store account if you're using a single account, etc. Oh yeah, and that Mac mini is now a trusted device, so it can approve adding new devices to your account if they're compromised (or malicious, but lets give them the benefit of the doubt).

Now based on the problems presented in this article I don't think I would trust their data management or security practices at all, they clearly don't give a damn about customer privacy (beyond their already overt removal of message privacy/e2ee).


> The app promised to let Nothing Phone 2 users text with iMessage, but it required allowing Sunbird, who provides the platform, log into users’ iCloud accounts on its own Mac Mini servers, which... isn’t great?

Can you register multiple iCloud accounts to a given Apple device and use both simultaneously? I can't otherwise see how this could possibly be cost effective, or feasible, or scalable.


It's one iCloud account per user account, but arbitrarily many user accounts per machine.


Definitely, every macOS local account can have a different iCloud account logged in.


Logging messages in the clear to Sentry, Firebase is embarrassing for an app that purports to make messages unreadable to Nothing.


but unreadable to nothing means readable to everything/everyone. maybe that is what they meant after all




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: