ADVERTISEMENT
Buzam.net
  • Home
  • Tech News
  • Smartphones
  • Apple
  • Shop
No Result
View All Result
  • Home
  • Tech News
  • Smartphones
  • Apple
  • Shop
Cart / $0.00

No products in the basket.

  • Home
  • Tech News
  • Smartphones
  • Apple
  • Shop
No Result
View All Result
Buzam.net
No Result
View All Result
Home Smartphones

Nothing Chats seems even less secure than we thought

by buzam team
18 November 2023
in Smartphones
0
Nothing Chats on Play Store
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter

C. Scott Brown / Android Authority

TL;DR

  • Concerns about security arose shortly after Nothing Chats was announced.
  • Nothing clarified how Nothing Chats works to reassure users that it is safe to use.
  • New findings show that the app may be less secure than previously thought.

When Nothing announced Nothing Chats, the company claimed its new Phone 2 messaging platform was end-to-end encrypted. Although Nothing insists that its app is private and secure, new findings suggest it is less secure than we initially thought.

Nothing Chats is built on the Sunbird app’s architecture but is designed by Nothing. It is meant to give the Phone 2 compatibility with the iPhone’s iMessage app. To do this, users are required to sign into the app with an Apple ID, which then assigns your account to a virtual instance of one of Sunbird’s Mac Minis. This tricks an iPhone into thinking it is communicating with another Apple device (we tested the Nothing Chat service for ourselves).

This brought up concerns that users would need to place their trust in a third party to keep their Apple ID data and password safe. However, a spokesperson for Nothing clarified that after you log into the app the first time, “credentials are tokenized in an encrypted database” and “cannot be accessed by Sunbird or anyone else even if they had access to the physical server itself.”

Now that the app is publically available for download, users are discovering other security issues. Kishan Bagaria, founder of Texts.com, had his team investigate the app and found the app is sending information over hypertext transfer protocol (HTTP) instead of hypertext transfer protocol secure (HTTPS).

texts team took a quick look at the tech behind nothing chats and found out it’s extremely insecure

it’s not even using HTTPS, credentials are sent over plaintext HTTP

The Texts team also discovered the term “bluebubbles,” suggesting Sunbird is piggybacking its app on the technology developed by BlueBubbles, a rival service that also allows for iMessage access through Android.

However, after this discovery was made, Nothing issued this statement to 9to5Google:

While the protocol is HTTP, all data is encrypted and the key used to encrypt that data is provided via HTTPS so Apple credentials or messages sent via that HTTP request are secure and not open to the public. All sensitive user data such as Apple ID credentials and messages are encrypted at all times. The HTTP is only used as part of the one-off initial request from the app notifying the back-end of the upcoming iMessage connection iteration that will follow via a stand alone communication channel.

Regarding the other part of his tweet, years ago when the servers were being built Sunbird’s co-founder named them Blue Bubbles. Sunbird/Chats is not using an instance of anyone else’s technology – the naming is strictly coincidence.

Additionally, I want to add that from the start, that Sunbird has been focused on security and its ISO27001 certification (Certificate Number: IA-2023-09-21-01), an internationally recognized specification for an information security management system, is a reflection of its commitment to user privacy.

At the end of the day, you’ll need to decide for yourself if you trust Sunbird and Nothing in light of these revelations. Besides, now that Apple has announced it will support RCS in 2024, these apps are on borrowed time anyway.

ShareTweetPin

Related Posts

POCO To Unveil Three New Smartphones: X6, X6 Pro, and M6 5G
Smartphones

POCO To Unveil Three New Smartphones: X6, X6 Pro, and M6 5G

11 December 2023
ZimaCube NAS hands-on: This 6-bay NAS has a lot of potential
Smartphones

ZimaCube NAS hands-on: This 6-bay NAS has a lot of potential

11 December 2023
Photo of an Android phone with Beeper Mini app
Smartphones

Apple confirms it took down Beeper Mini to ‘protect its users’ –

11 December 2023
Week 49 in review: OnePlus 12 and Realme GT5 Pro bring 5,400mAh batteries, SD 8 Gen 3
Smartphones

Week 49 in review: OnePlus 12 and Realme GT5 Pro bring 5,400mAh batteries, SD 8 Gen 3

11 December 2023
Apple's 12.9" iPad Air May Not as Fast as iPad Pro, But Don't Worry
Smartphones

Apple’s 12.9″ iPad Air May Not as Fast as iPad Pro, But Don’t Worry

11 December 2023
Android Auto
Smartphones

Android Auto Gets Updated to Make Parking A Bit Hassle-free

11 December 2023
Next Post
Greg Brockman quits OpenAI after abrupt firing of Sam Altman

Greg Brockman quits OpenAI after abrupt firing of Sam Altman

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Misaka updated to version 3.3.3 with more bug fixes and improvements
  • A look at the race among chip giants to make 2nm chips, as Samsung and Intel see the next leap in chip manufacturing a chance to close the gap with TSMC (Financial Times)
  • POCO To Unveil Three New Smartphones: X6, X6 Pro, and M6 5G
  • macos – Mail.app’s unwanted return to the index screen
  • Quordle today – hints and answers for Monday, December 11 (game #686)

Recent Comments

  1. ufac4 on Prime Video: The 37 Absolute Best TV Shows to Watch
  2. ufa on The AirPods Pro drop back to an all-time low, plus the rest of this week’s best tech deals
  3. 1ufabet on Prime Video: The 37 Absolute Best TV Shows to Watch
  4. ufanance on Prime Video: The 37 Absolute Best TV Shows to Watch
  5. ดูบาสสด on The AirPods Pro drop back to an all-time low, plus the rest of this week’s best tech deals
  • Home
  • About
  • Contact us
  • Privacy Policy
  • Refund and Returns Policy

DISCLAIMER

The information provided on Buzam.net is for general informational purposes only and should not be construed as professional advice.

© 2023 buzam.net . All right go to their respective owners

No Result
View All Result
  • Home
  • Tech News
  • Smartphones
  • Apple
  • Shop

© 2023 JNews - Premium WordPress news & magazine theme by Jegtheme.