Close Menu
Ztoog
    What's Hot
    The Future

    Barbarian is Getting a Video Game Adaptation

    Mobile

    User discovers fix for silent iPhone alarms after sleeping through important things

    Technology

    New ‘X’ Sign on Twitter’s Headquarters in San Francisco Is Under Investigation

    Important Pages:
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    Facebook X (Twitter) Instagram Pinterest
    Facebook X (Twitter) Instagram Pinterest
    Ztoog
    • Home
    • The Future

      OPPO launches A5 Pro 5G: Premium features at a budget price

      How I Turn Unstructured PDFs into Revenue-Ready Spreadsheets

      Is it the best tool for 2025?

      The clocks that helped define time from London’s Royal Observatory

      Summer Movies Are Here, and So Are the New Popcorn Buckets

    • Technology

      What It Is and Why It Matters—Part 1 – O’Reilly

      Ensure Hard Work Is Recognized With These 3 Steps

      Cicada map 2025: Where will Brood XIV cicadas emerge this spring?

      Is Duolingo the face of an AI jobs crisis?

      The US DOD transfers its AI-based Open Price Exploration for National Security program to nonprofit Critical Minerals Forum to boost Western supply deals (Ernest Scheyder/Reuters)

    • Gadgets

      Maono Caster G1 Neo & PD200X Review: Budget Streaming Gear for Aspiring Creators

      Apple plans to split iPhone 18 launch into two phases in 2026

      Upgrade your desk to Starfleet status with this $95 USB-C hub

      37 Best Graduation Gift Ideas (2025): For College Grads

      Backblaze responds to claims of “sham accounting,” customer backups at risk

    • Mobile

      Motorola’s Moto Watch needs to start living up to the brand name

      Samsung Galaxy S25 Edge promo materials leak

      What are people doing with those free T-Mobile lines? Way more than you’d expect

      Samsung doesn’t want budget Galaxy phones to use exclusive AI features

      COROS’s charging adapter is a neat solution to the smartwatch charging cable problem

    • Science

      Nothing is stronger than quantum connections – and now we know why

      Failed Soviet probe will soon crash to Earth – and we don’t know where

      Trump administration cuts off all future federal funding to Harvard

      Does kissing spread gluten? New research offers a clue.

      Why Balcony Solar Panels Haven’t Taken Off in the US

    • AI

      Hybrid AI model crafts smooth, high-quality videos in seconds | Ztoog

      How to build a better AI benchmark

      Q&A: A roadmap for revolutionizing health care through data-driven innovation | Ztoog

      This data set helps researchers spot harmful stereotypes in LLMs

      Making AI models more trustworthy for high-stakes settings | Ztoog

    • Crypto

      Ethereum Breaks Key Resistance In One Massive Move – Higher High Confirms Momentum

      ‘The Big Short’ Coming For Bitcoin? Why BTC Will Clear $110,000

      Bitcoin Holds Above $95K Despite Weak Blockchain Activity — Analytics Firm Explains Why

      eToro eyes US IPO launch as early as next week amid easing concerns over Trump’s tariffs

      Cardano ‘Looks Dope,’ Analyst Predicts Big Move Soon

    Ztoog
    Home » Nothing’s iMessage app was a security catastrophe, taken down in 24 hours
    Gadgets

    Nothing’s iMessage app was a security catastrophe, taken down in 24 hours

    Facebook Twitter Pinterest WhatsApp
    Nothing’s iMessage app was a security catastrophe, taken down in 24 hours
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp

    Enlarge / The Nothing Phone 2 all lit up.

    Ron Amadeo

    (*24*)

    It seems corporations that stonewall the media’s security questions truly aren’t good at security. Last Tuesday, Nothing Chats—a chat app from Android producer “Nothing” and upstart app firm Sunbird—openly claimed to have the ability to hack into Apple’s iMessage protocol and provides Android customers blue bubbles. We instantly flagged Sunbird as a firm that had been making empty guarantees for nearly a yr and appeared negligent about security. The app launched Friday anyway and was instantly ripped to shreds by the Internet for a lot of security points. It did not final 24 hours; Nothing pulled the app from the Play Store Saturday morning. The Sunbird app, which Nothing Chat is simply a reskin of, has additionally been put “on pause.”

    The preliminary gross sales pitch for this app—that it could log you into iMessage on Android for those who handed over your Apple username and password—was a enormous security pink flag that meant Sunbird would want an ultra-secure infrastructure to keep away from catastrophe. Instead, the app turned out to be about as unsecure as we anticipated. Here’s Nothing’s assertion:

    Nothing Chat's shut down post.

    Nothing Chat’s shut down submit.

    (*24*)

    How unhealthy are the security points? Both 9to5Google and Text.com (which is owned by Automattic, the corporate behind WordPress) uncovered shockingly unhealthy security practices. Not solely was the app not end-to-end encrypted, as claimed quite a few occasions by Nothing and Sunbird, however Sunbird truly logged and saved messages in plain textual content on each the error reporting software program Sentry and in a Firebase retailer. Authentication tokens have been despatched over unencrypted HTTP so this token could possibly be intercepted and used to learn your messages.

    Advertisement

    The Text.com investigation uncovered a pile of vulnerabilities. The weblog says, “When a message or an attachment is obtained by a person, they’re unencrypted on the server aspect till the shopper sends a request acknowledging, and deleting them from the database. This implies that an attacker subscribed to the Firebase Realtime DB will at all times be capable to entry the messages earlier than or in the mean time they’re learn by the person.” Text.com was capable of intercept an authentication token despatched over unencrypted HTTP and subscribe to adjustments occurring to the database. This meant reside updates of “Messages in, out, account adjustments, and so on” not simply from themselves, however different customers, too.

    Text.com launched a proof-of-concept app that might fetch your supposedly end-to-end encrypted messages from Sunbird’s servers. Batuhan Içöz, a product engineer for Text.com, additionally launched a software that may delete a few of your information from Sunbird’s servers. Içöz recommends that any Sunbird/Nothing Chat customers change their Apple password now, revoke Sunbird’s session, and “assume your information is already compromised.”

    9to5Google’s Dylan Roussel investigated the app and located that, in addition to all the public textual content information, “All of the paperwork (photographs, movies, audios, pdfs, vCards…) despatched by Nothing Chat AND Sunbird are public.” Roussel discovered 630,000 media recordsdata are at present saved by Sunbird, and apparently he might entry some. Sunbird’s app recommended that customers switch vCards—digital enterprise playing cards stuffed with contact information—and Roussel says the private info of two,300-plus customers is accessible. Roussel calls the entire fiasco “most likely the largest ‘privateness nightmare’ I’ve seen by a telephone producer in years.”

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp

    Related Posts

    Gadgets

    Maono Caster G1 Neo & PD200X Review: Budget Streaming Gear for Aspiring Creators

    Gadgets

    Apple plans to split iPhone 18 launch into two phases in 2026

    Gadgets

    Upgrade your desk to Starfleet status with this $95 USB-C hub

    Gadgets

    37 Best Graduation Gift Ideas (2025): For College Grads

    Gadgets

    Backblaze responds to claims of “sham accounting,” customer backups at risk

    Gadgets

    Snapdragon X Plus Could Bring Faster, More Powerful Chromebooks

    Gadgets

    This AI Tool Can Detect Scams in Photos, Videos and WhatsApp

    Gadgets

    Digital frame maker Aura introduces the Aspen, a $229 frame with more intelligent features

    Leave A Reply Cancel Reply

    Follow Us
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    Top Posts
    Gadgets

    visionOS 1.1 tries to make Personas less unsettling, plus other Apple OS updates

    Enlarge / A blurry, ghostly Persona in visionOS 1.0. They ought to not less than…

    Science

    Can any English word be turned into a synonym for “drunk”? Not all, but many can.

    The lads from Edgar Wright’s 2013 sci-fi comedy World’s End know when to begin consuming…

    Gadgets

    WhatsApp Tests AI-Generated Stickers To Enrich Communication

    Now below the Meta umbrella, WhatsApp has begun testing an thrilling AI-generated stickers function —…

    Mobile

    Top 10 trending phones of week 34

    Samsung Galaxy A54 prolonged its streak on prime of our trending chart for one more…

    Technology

    YouTube may face billions in fines if FTC confirms child privacy violations

    Four nonprofit teams searching for to guard youngsters’ privacy on-line requested the Federal Trade Commission…

    Our Picks
    Science

    Bees make speedy decisions using tiny brains

    AI

    Computer vision system marries image recognition and generation | Ztoog

    Science

    Peregrine lunar lander experiences ‘critical loss of propellant’ following successful launch

    Categories
    • AI (1,483)
    • Crypto (1,745)
    • Gadgets (1,796)
    • Mobile (1,840)
    • Science (1,854)
    • Technology (1,790)
    • The Future (1,636)
    Most Popular
    Gadgets

    Netflix raises prices up to 17% amid new contracts, licensing costs

    Crypto

    One Thing Left For A $110K Price

    Technology

    Robot Videos: Robot Bug, Murderbot Sci-Fi Series, and More

    Ztoog
    Facebook X (Twitter) Instagram Pinterest
    • Home
    • About Us
    • Contact us
    • Privacy Policy
    • Terms & Conditions
    © 2025 Ztoog.

    Type above and press Enter to search. Press Esc to cancel.