"Nothing's iMessage App: A Security Disaster Pulled from Google Play Store in 24 Hours"

1 min read
Source: Ars Technica
"Nothing's iMessage App: A Security Disaster Pulled from Google Play Store in 24 Hours"
Photo: Ars Technica
TL;DR Summary

Nothing Chats, a chat app developed by Android manufacturer "Nothing" and Sunbird, claimed to be able to hack into Apple's iMessage protocol and give Android users blue bubbles. However, the app was found to have numerous security issues, including lack of end-to-end encryption, storing messages in plain text, and sending authentication tokens over unencrypted HTTP. Both 9to5Google and Text.com uncovered vulnerabilities, with the latter releasing a proof-of-concept app that could fetch supposedly encrypted messages from Sunbird's servers. Personal information of users, including vCards, was also found to be accessible. The app was taken down within 24 hours of its launch, and users are advised to change their Apple IDs and assume their data is compromised.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

2 min

vs 3 min read

Condensed

79%

535115 words

Want the full story? Read the original article

Read on Ars Technica