Hacker News new | ask | show | jobs
by bigiain 454 days ago
Yep. Same.

I do not want 3rd party hardware/software vendors to have unrestricted access to the messaging app on my phone that is the only option my bank and PayPal and a bunch of other critical services use for 2FA.

Especially not when the software they want to run is JavaScript, with all it's well known npm dependancy nightmares, _and_ from a founder and team that openly admit iPhones are a second class citizen in their development planning and resources.

And especially especially not when the founders have previously shown their colors when they rugpulled all their customers and effectively bricked all the devices they'd sold.

Even with the limited iMessage/SMS access they have now, I wonder how long it'll be before we see a supply chain attack against Pebble exploiting some 11th level deep npm dependancy on something dumb like leftpad.js, that exfiltrates SMS 2FA codes and first anybody knows about it will be when a bunch of CryptoBros start complaining about their exchange accounts being emptied...

4 comments

> And especially especially not when the founders have previously shown their colors when they rugpulled all their customers and effectively bricked all the devices they'd sold.

As a Pebble user for a long time, I'm not exactly sure what you're talking about here. If you're talking about Fitbit halting services, I can't exactly blame the founder of Pebble for that. Can I blame him for the poor business decisions that led to needing to sell to Fitbit? I guess, but I'm not a business person nor a CEO and have no idea what transpired to lead up to that. But I'm reasonably sure it wasn't malice as you seem to imply.

Psst…there’s JavaScript running on your phone right now.
Sure, but so far as I know none of it has access to the contents of SMS or iMessages.
Then don't grant them the access! This isn't all or nothing! It's a matter of being given a choice (to which you can say "no!") or being given no choice at all.
I'm still using my pebble today, and never stopped. What bricking?