Hacker News new | ask | show | jobs
by danaris 927 days ago
Not fake devices, fake credentials. Beeper Mini is explicitly using a different method to access the iMessage system than Beeper and some other previous services; it's not spinning up virtual Macs and bouncing off them. Because of that, it also doesn't require you to hand your Apple ID login & password over to Beeper in cleartext just to make it work.

At least, from what I've read over the past few days.

1 comments

I don't think the credentials are faked. The author's blog post seems to give the details. He is publishing a public key to Apple's servers and figured out how to read the public key of other users. It seems like he is using the normal Apple encryption path from there. Although I don't fully understand the details.

https://jjtech.dev/reverse-engineering/imessage-explained/