Nothing has removed the Nothing Chats app from Google Play for iMessage compatibility - due to serious security issues
Just a few days ago, Nothing Nothing has released the Nothing Chats app that brings iMessage compatibility to Android. But there are nuances that makes iMessage compatible with Android. And now it had to be removed from Google Play.
What is it this time
The official reason for removing the app is due to several bugs that need time to fix.
We've removed the Nothing Chats beta from the Play Store and will be delaying the launch until further notice to work with Sunbird to fix several bugs.
- Nothing (@nothing) November 18, 2023
We apologise for the delay and will do right by our users.
However, the author of Texts.com and several social media users have published evidence that Nothing Chats has serious security issues. And the reason for this was the company Sunbird, which is the service provider. It was caught lying about end-to-end encryption of messages routed through the servers.
So, to sign up for Nothing Chats, you need to connect to Sunbird's servers using your Apple ID. Sunbird assures that all messages are encrypted. However, as it turns out, the JSON or JWT web tokens generated by the service are again sent unencrypted to another Sunbird server without SSL, allowing an attacker to intercept them. Furthermore, the messages are decrypted and then stored on Sunbird servers, giving an attacker time to access them before the user does.
texts team took a quick look at the tech behind nothing chats and found out it's extremely insecure
- Kishan Bagaria (@KishanBagaria) November 17, 2023
it's not even using HTTPS, credentials are sent over plaintext HTTP
backend is running an instance of BlueBubbles, which doesn't support end-to-end encryption yet pic.twitter.com/IcWyIbKE86
Hopefully, Nothing and Sunbird will fix this and take security seriously. Though now that Apple has announced RCS support, there's no big need for Nothing Chats anymore.
Source: Texts.com, @KishanBagaria