Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The problem here is […] I categorically refuse to accept that sort of thing.

It is a perceived problem specifically for you (and, based on the arguments presented so far, it appears to solely based on the personal dislike rather than on objective grounds). If you refuse to accept it, that is solely your personal choice, and I, for one, have no objections to you being able to exercise freedoms to make your own choice(s).

> If you will accept that, then you are a part of the problem.

You have neither moral nor any other right to inflict the sense of collective guilt upon anyone, including myself, who has an opinion distinct from that of yours. What is an adjudged problem for you, is a feature (and not a bug) for some, and is a conscious compromise for some others. I am in the latter category as I have consciously consented to the trade-off after weighing up pros and cons of alternatives existing at the time – it became my personal informed choice.

> In reality, though, there are plenty of ways to combat spam that do not require us to have locked-down phones …

Combating text message spam requires a non-trackable, universal digital identity which is a non-solved problem. SMS and RCS do not solve this problem as they both allow a digital identity to assume one persona exactly: the device owner's phone number. iMessage, o the other hand, offers a stop-gap solution and allows iMessage users to assume one of the many personas (either a default phone number or one of the email addresses registered with iMessage), and it allows the user to select the specific persona on their own volition. Countering spam is a bonus and optional feature that comes as a byproduct of the iMessage way of tackling the identity management, and is not a requirement. Allowing multiple personas in iMessage also allows the user to disassociate themselves from their phone number, change it however frequently they want yet allow their friends circle and relatives to stay in touch via another persona (email address(es) registered with iMessage) – a useful feature when the iMessage user moves to live overseas.

A successful and a badly needed replacement for SMS (the protocol) will have to solve the identity management problem (as well as a morass of present SMS and RCS security vulnerabilities) first before it can become a viable option. And only then, it will have to be pushed out in a centralised manner (e.g. become a mandatory requirement for all 6G or 7G networks) so that no mobile telco would have a chance to opt out from the text messaging protocol upgrade. The adopotion of such a standard will take years, though, as users won't instantly upgrade their devices overnight, so the interoperability between GSM and new style text messages for some time will look exactly like it does today between SMS and iMessage.

As for Google crying foul on not being to interoperate with iMessage, in reality they are shedding crocodile tears and are not telling you what they actually mean by that. Google wants to track every text message to a user across both major mobile platforms (Android and iOS) AND beyond, which is something they can't do today. SMS does not offer a unique transferrable digital ID (other than IMSI which gets incised out once a message hits the SMSC), therefore Google can't link the user to activities on their smartphone to wider activities across all of their devices and the web as mobile phone numbers are not typically used for web browsing and in general app use.

Apple controls the passage of the Rubikon (iMessage) that, once crossed, would instantaly allow Google to find a creative way to track users, so Google wants that (in the same vein as Facebook does). Yet, Google is being coy about their true intentions.

> I get that they make other random decisions for us. Sure, that's inevitable … and move closer and closer to a corporate nanny state.

I vehemently and vociferously object to corporations encroaching on our larger freedoms, and, regretfully, strict regulation and even stricter enforcement of the regulation appears to be the only way to accomplish it.

> Sure, but at present I can wipe my phone and install GrapheneOS or CalyxOS or whatever, and Google will not be able to make any decisions as to what I do on my phone […] But if I'm sold a piece of general-purpose hardware, I expect to be able to do whatever I want with it.

To the best of my knowledge, nearly no-one (apart from Librem) sells general-purpose smartphones today. Each offering comes with a host of pros and cons, yet none of them are neither marketed nor sold as the general-purpose computing hardware.

Also, the option of wiping an OS is not ubiquitous on Android platforms and some handsets have the hardware that stock and alternative Android distribution may or may not support. Therefore, there is no such a thing as a generic Android phone which is what the majority of Android users have. And no, since you are part of the HN congregation, you are not a representative selection of the Android user base.

Apple, on the other hand, sells a package that happens to have a smartphone (or a smartwatch, or a tablet) and an OS (as a conduit into the package), and the nicely wrapped package has well stipulated constraints that one either takes or leaves. Purchasing an iPhone is not mandatory in any jurisdictions that I am aware of, either, therefore an the act of puchasing one is also a personal and conscientious choice.

> Maybe if you use Chrome, but... I don't. So that doesn't happen to me.

Ha, the classic «it does not happen on my laptop!» remark.

Sarcasm aside, it is more insidious than that. I had to log into Google using my work Google account in Safari on my laptop, but because Safari syncs the browser cookies and local storage across devices via iCloud (it is another feature I have consciously consented to), the Google account cookies have made it into my phone via an iCloud sync. Next time when I opened Google Maps on my phone, it pulled the Google cookie + stuff out of the Safari local storage, and I was then instantly and silently logged into Google using my work Google account (I degoogled myself years ago in favour of paid 3rd party services and no longer personal Google accounts). Such a practice, apart from being blatantly deceitful, is borderline nefarious, so, with all due respect, I do not buy into Google's crocodile tears about iMessage.



I think the thing you're missing is that the spam countermeasure we're talking about relies on the sender's phone being locked down, not the recipient's. If spammers can get around this by just using non-locked-down phones, the whole thing is pointless. It only works if you require everyone's phone to be locked down.


That is why I mentioned the universal/global, non-trackable digital identity as a solution and a posion pill for the locked down device. Such a digital identity has to be decentralised, resistant to ID theft attacks and a wide range of other attack vectors and, most importantly, be independent of hardware vendors so they could never wield influence over their users.

If an identity can be verified via a presented assumed persona (supplied as a proxy for the identity in question) as a third party identity verification service call, locking down a device becomes redundant (although the hardware vendor will likely continue to do so for other reasons). It does not seem likely that the identity management is going to be solved any time soon though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: