Apple’s iMessage is one of the most popular communication platforms. This is why many people love their iPhone. But, iMessage is also the reason why many people don’t switch to Android, because they don’t want to be left out of group chats. And well, the embarrassment of the green bubble is also a primary reason. Recently, Carl Pei announced the ‘Nothing Chats’ app to bring iMessage to Android. However, amid security concerns, the app has been Removed from Play Store,
According to a recent post on X (formerly Twitter), the company says it has removed its Nothing Chats beta app from the Play Store. The launch will be delayed “until further notice”, and Nothing said it will work with Sunbird (which created the technology that enabled iMessage functionality in Nothing Chat).fix many bugs,
We have removed the Nothing Chats beta from the Play Store and will delay the launch until further notice to work with Sunbird to fix several bugs.
We apologize for the delay and will take appropriate action for our users. — Nothing (@Nothing) 18 November 2023
Nothing added that it would be’Correct by our users‘, so hopefully the company has plans to work on these issues. But what are these issues and should you be concerned? Let’s look into this.
Privacy and security concerns in Nothing Chats app: Details
Nothing Chats beta brings iMessage to Android; but found unsafe
As revealed by teardown of the app by select Android app developers and security researchers Nothing Chats app is not safe at all, While Nothing and Sunbird claim that iMessage simulating a chat app has ‘End-to-end encryption‘, instead it has been considered the opposite.
Findings show that various information such as contact information, message content and even attachment data can all be hacked. In. Obviously, user data that is sent via Sunbird’s technology over HTTP remains unsafe during transit, Additionally, it turns out that Sunbird can read all of your messages and view the media you share with actual iMessage users using the Nothing Chat app. The investigation is shared by a developer named dylan roussel On X (formerly Twitter).
Additionally, the team that developed WordPress and Tumblr recently published their findings regarding Sunbird/Nothing Chats security. This pointed to three major issues: Data Vulnerability in Transit, on data residual vulnerabilityAnd Insider Threat/Data Exposure Too. You can read their detailed report at the link above.
Thread time!
Summary:
– Sunbird has access to every message sent and received through the app on your device.– All documents (images, videos, audios, PDFs, vCards…) sent via Nothing Chat and Sunbird are public.
– Nothing Chats is end-to-end encrypted. – Dylan Roussel (@evowizz) 18 November 2023
The Text team took a quick look at the technology behind Nothing Chat and found it to be extremely insecure
It’s not even using HTTPS, credentials are sent over plaintext HTTP
The backend is running an instance of BlueBubbles, which does not yet support end-to-end encryption pic.twitter.com/IcWyIbKE86– Kishan Bagaria (@KishanBagaria) 17 November 2023
So, what do you think about the removal of Nothing Chats app from Play Store? Do you think the project will survive and iMessage will eventually come to Android? Would you use an app to emulate iMessage despite security concerns? Do let us know your thoughts in the comments below.