Nothing launched the Nothing Chats messaging platform final week to dismantle messaging limitations between Android and iOS gadgets in collaboration with Sunbird. The messaging app permits Nothing Cellphone 2 customers to ship and obtain texts by way of iMessage enabling messages to seem as blue bubbles on iMessage. It additionally helps texting over the RCS protocol to different Android telephones, together with SMS and MMS. Nevertheless, since its announcement, a number of customers have voiced issues over the safety and privateness problems with the service. Now, the Carl Pei-led UK startup has pulled the beta for its new messaging app from the Google Play Retailer attributable to privateness issues.
Nothing has pulled the Nothing Chats beta from Google Play Retailer saying it’s “delaying the launch till additional discover to work with Sunbird to repair a number of bugs”. The corporate didn’t specify the bugs or deal with any privateness points.
We have eliminated the Nothing Chats beta from the Play Retailer and might be delaying the launch till additional discover to work with Sunbird to repair a number of bugs.
We apologise for the delay and can do proper by our customers.
— Nothing (@nothing) November 18, 2023
The removing got here after customers extensively criticised the system for transmitting Apple ID credentials by way of HTTP quite than the safer HTTPS. Customers are required to log in with their Apple ID by the Nothing Chats app to make use of iMessage companies. This routes the login by a Mac positioned in a distant server farm. Kishan Bagaria, the founding father of Texts.com, took to X to name the app “extraordinarily insecure,” claiming that messages despatched with Sunbird’s system are usually not end-to-end encrypted and it depends on a BlueBubbles-powered backend.
texts staff took a fast take a look at the tech behind nothing chats and discovered it is extraordinarily insecure
it is not even utilizing HTTPS, credentials are despatched over plaintext HTTP
backend is operating an occasion of BlueBubbles, which does not assist end-to-end encryption but pic.twitter.com/IcWyIbKE86
— Kishan Bagaria (@KishanBagaria) November 17, 2023
Moreover, Dylan Roussel (@evowizz) pointed out that Sunbird has entry to each message despatched and obtained by the app in your system. The entire paperwork (photographs, movies, audio, PDFs, vCards…) despatched by Nothing Chats and Sunbird are public.
In the meantime, one other X person wukko(@uwukko) posted findings that the Nothing Chats app sends all messages and media attachments to Sentry. Additional, “all” knowledge is distributed and saved by Firebase, and it is also utterly unencrypted.
The Nothing Chats app was constructed to carry iMessage assist to Android. It allowed blue bubble conversations from an Android telephone with iMessage customers and in addition helps RCS (Wealthy communication companies) between appropriate gadgets. The app additionally will get options like end-to-end encryption, group messaging, reside typing indications, high-resolution media sharing, learn and supply receipts, and responding with reactions, with extra claimed to come back sooner or later.