Nothing pulls its Sunbird-based iMessage app Nothing Chats from the Play Store after a researcher found messages are not E2EE, attachments are public, and more
Nothing Chats was positioned as an early Sunbird-based route for Phone (2) users to reach iPhone contacts via iMessage, following Nothing's planned early rollout. Its removal immediately turns that interoperability pitch into a security-and-trust failure rather than a product launch.
Nothing Chats is no longer available through the Play Store, cutting off the service for the users targeted by the initial rollout.
Nothing and Sunbird must address reported gaps in encryption and attachment access before they can credibly return the product to users.
Second-order effects
Other efforts to bridge iMessage and Android face a higher burden to explain their architecture and independently substantiate privacy claims; a simple end-to-end-encryption label is insufficient after this failure.
Users evaluating unofficial iMessage access routes may become less willing to trade message privacy for cross-platform compatibility, reinforcing the appeal of established messaging paths.
Third-order effects
If cross-platform messaging workarounds continue to rely on intermediary infrastructure, verifiable security design and clear data-access boundaries will become a central competitive requirement rather than a marketing feature.
The episode points to a broader tension in messaging interoperability: services can reduce platform lock-in only if their privacy model is as trustworthy as the platforms they seek to connect.
The trend: Messaging interoperability is increasingly being judged not just on whether it connects closed ecosystems, but on whether it can preserve auditable privacy protections while doing so.
UPDATE: Nothing has confirmed to @9to5Google that Nothing Chats is being pulled from the Play Store and the launch delayed to “fix several bugs” - what an understatement lol. No word on Sunbird's app, which has all of the same problems. Full statement: https://9to5google.com/..…
We've removed the Nothing Chats beta from the Play Store and will be delaying the launch until further notice to work with Sunbird to fix several bugs. We apologise for the delay and will do right by our users.
Thread time! Summary: - Sunbird has access to every message sent and received through the app on your device. - All of the documents (images, videos, audios, pdfs, vCards...) sent through Nothing Chat AND Sunbird are public. - Nothing Chats is not end-to-end encrypted.
Sunbird has access to every message sent and received through the app. They do this by abusing @getsentry, which is used to monitor errors. But Sunbird logs messages, pretending they are errors. Here are part of the requests (img 1, 3) and their entire “message” (img 2, 4) [image…
the right move, though “several bugs” uhhh kinda undersells what's being reported (a “sending cash though the mail in a transparent ziplock” level of security) egg, meet face
I just want to clarify something. Sunbird *lied* to Nothing. They said messages were end-to-end encrypted. They were not. Sunbird knew this because they upload stuff to Firebase. Nothing should not just “delay the launch.” They should cancel the whole project.
Nothing Chats launched yesterday and there were security concerns within hours. Not even a day later, we've graduated to a full-on privacy nightmare. This is a trainwreck. Full story on @9to5Google: https://9to5google.com/... (tip @Techmeme)
So... Yesterday, Sunbird replied to @KishanBagaria, saying that using HTTP is fine! Because it's part of an initial request and that's it. No it's not fine, it still leaks users' email addresses. But at least it pushed me to look deeper. https://twitter.com/...