Skip to main content

Sunbird — the sketchy iMessage for Android app — just shut down

Sunbird messages app for Android
Nadeem Sarwar / Digital Trends

What was supposed to be an iMessage redeemer for Android smartphone users has quickly been consumed in a chaos of security and utter negligence. Merely days after the Nothing Chats app was removed from the Play Store, the tech at its foundation provided by Sunbird is also taking an unspecified leave, intensifying suspicions of something being seriously wrong.

Sunbird appeared on our radar late last year, promising blue bubbles for Android-to-iPhone messages. It also promised to bundle all messaging apps into a single cluster, somewhat like Beeper. Nothing adopted the Sunbird tech, bundled it into its own app for the Nothing Phone 2, and launched it with an ambitious video. “Sorry, Tim.” That’s the message Nothing CEO Carl Pei sent.

Recommended Videos

Bring on the blue bubbles.

We believe in windows, not walls. If messaging services are dividing phone users, then we want to break those barriers down.

So… we've developed iMessage compatibility for your Phone (2). pic.twitter.com/kArTGfXlQO

— Nothing (@nothing) November 14, 2023

Over the weekend, I noticed that the Sunbird app’s Google Play Store listing returned a blank page. I originally thought it was unavailable due to some geographic restrictions. The company made no public announcement regarding the same, except notifying members in the Sunbird Discord channel.

“We have temporarily shut down the Sunbird app while we do a detailed security analysis,” the alert said, adding that the company will offer further details when it identifies the “exact occurrences.”

Interestingly, the revelation was first made in the dev-announcements channel of Sunbird’s Discord network. “In an abundance of caution and to protect your confidential data, we are shutting down Sunbird temporarily,” it said.

What I can’t wrap my head around is why it took a day to drop the same information in the public channel. And above all, why did Sunbird fail to make an announcement on its active Facebook and X (formerly Twitter) handles?

In a message that appeared today in the public Discord channel, Sunbird only said “lots going on” but didn’t provide any further technical details or progress on risk mitigations. “We have decided to pause Sunbird usage for now while we investigate security concerns,” says the message.

Digital Trends has reached out to Sunbird’s technical lead, Garin, for more information and will update this story as soon as they respond.

Sunbird only started notifying users via an in-app message. Earlier today, 9to5Google spotted in-app notifications from Sunbird users posted on Reddit, notifying them that the app was temporarily put on hold. It’s the same message that was first shared in the Discord community.

The security risks

The Nothing Chats splash page in the app.
Andy Boxall / Digital Trends

Security specialists at Texts found that the messaging app Nothing Chats was not employing HTTPS security protocols for its messages. Instead, it used the less secure HTTP standard, transmitting messages in unencrypted, plain text. If history has taught us anything about digital security, plain text is bad news.

A separate investigation revealed that all types of communication through Nothing Chats — including text, images, and other media — were sent in this unsecured, easily visible format. Additionally, it was uncovered that all messages sent and stored on Nothing Chats were unencrypted and hosted on a readily accessible Firebase platform.

Further findings showed that after users authenticate using JSON Web Tokens (JWT), which are not secure during transmission, they gain access to Nothing Chat’s Firebase database. This access allows them to view other users’ messages and files, which are sent and stored in real time and in plain text.

Nothing Chats on a Nothing Phone 2 compared with iMessage on an iPhone 15 Pro Max.
iMessage on an iPhone 15 Pro Max (left) and Nothing Chats on a Nothing Phone 2 Andy Boxall / Digital Trends

All of this rings giant security alarms about the Sunbird (and the Nothings Chats) app. It’s especially worrying when it asks for your Apple ID credentials, the magic token that links everything from your emails and personal photos to your banking details.

It would be interesting to see where Nothing and Sunbird go from here. But with Apple embracing RCS and filling the feature gulf for Android-iPhone messaging, I don’t think it would be worth risking your privacy and data security for a hack that gives you blue chat bubbles.

Nadeem Sarwar
Nadeem is a tech journalist who started reading about cool smartphone tech out of curiosity and soon started writing…
iOS 18’s new iMessage features make me wish everyone I know had an iPhone
Screenshots of new iMessage features in iOS 18.

Without fail, one thing always happens during the iOS segment at Apple’s Worldwide Developer Conference (WWDC): I have a moment where I want more people I know to own an iPhone and use iMessage because it always looks a whole lot more fun than my usual message apps.

It’s not evidence of iMessage being generally superior, though; it’s about something else. And this was especially true at WWDC 2024.
There's something about iMessage

Read more
Here’s how iOS 18 will make iMessage better than ever
Close-up photo of the Messages app on an iPhone.

We can't wait for Apple's Worldwide Developers Conference (WWDC 2024) keynote on Monday, June 10. During that event, Apple will undoubtedly introduce iOS 18 for iPhones, including the iPhone 15 Pro. The rumor mill has long suggested that iOS 18 may be a giant iPhone update.

Now, Bloomberg's Mark Gurman has given us a peek at what changes could be coming to iMessage in the upcoming software update.

Read more
Apple just admitted defeat to Android phones
A Google Pixel 8 Pro in Porcelain (left) with an iPhone 15 Pro in Blue Titanium held in hand.

For years, Apple’s smartphones have held a decisive upper hand over Android devices in one crucial aspect: the longevity of the software support cycle. In a nutshell, as long as your phone keeps getting updates, it will run just about fine.

Brand assurances play a crucial role in buyer behavior, as long-term update support means your phone will not only get new tricks but also security flaws patched. Notably, Apple is not into the habit of quoting how many years it will offer software support for each device, but it has held the crown for a while.

Read more