Skip to main content

Sunbird — the sketchy iMessage for Android app — just shut down

Sunbird messages app for Android
Nadeem Sarwar / Digital Trends

What was supposed to be an iMessage redeemer for Android smartphone users has quickly been consumed in a chaos of security and utter negligence. Merely days after the Nothing Chats app was removed from the Play Store, the tech at its foundation provided by Sunbird is also taking an unspecified leave, intensifying suspicions of something being seriously wrong.

Sunbird appeared on our radar late last year, promising blue bubbles for Android-to-iPhone messages. It also promised to bundle all messaging apps into a single cluster, somewhat like Beeper. Nothing adopted the Sunbird tech, bundled it into its own app for the Nothing Phone 2, and launched it with an ambitious video. “Sorry, Tim.” That’s the message Nothing CEO Carl Pei sent.

Bring on the blue bubbles.

We believe in windows, not walls. If messaging services are dividing phone users, then we want to break those barriers down.

So… we've developed iMessage compatibility for your Phone (2). pic.twitter.com/kArTGfXlQO

— Nothing (@nothing) November 14, 2023

Over the weekend, I noticed that the Sunbird app’s Google Play Store listing returned a blank page. I originally thought it was unavailable due to some geographic restrictions. The company made no public announcement regarding the same, except notifying members in the Sunbird Discord channel.

“We have temporarily shut down the Sunbird app while we do a detailed security analysis,” the alert said, adding that the company will offer further details when it identifies the “exact occurrences.”

Interestingly, the revelation was first made in the dev-announcements channel of Sunbird’s Discord network. “In an abundance of caution and to protect your confidential data, we are shutting down Sunbird temporarily,” it said.

What I can’t wrap my head around is why it took a day to drop the same information in the public channel. And above all, why did Sunbird fail to make an announcement on its active Facebook and X (formerly Twitter) handles?

In a message that appeared today in the public Discord channel, Sunbird only said “lots going on” but didn’t provide any further technical details or progress on risk mitigations. “We have decided to pause Sunbird usage for now while we investigate security concerns,” says the message.

Digital Trends has reached out to Sunbird’s technical lead, Garin, for more information and will update this story as soon as they respond.

Sunbird only started notifying users via an in-app message. Earlier today, 9to5Google spotted in-app notifications from Sunbird users posted on Reddit, notifying them that the app was temporarily put on hold. It’s the same message that was first shared in the Discord community.

The security risks

The Nothing Chats splash page in the app.
Andy Boxall / Digital Trends

Security specialists at Texts found that the messaging app Nothing Chats was not employing HTTPS security protocols for its messages. Instead, it used the less secure HTTP standard, transmitting messages in unencrypted, plain text. If history has taught us anything about digital security, plain text is bad news.

A separate investigation revealed that all types of communication through Nothing Chats — including text, images, and other media — were sent in this unsecured, easily visible format. Additionally, it was uncovered that all messages sent and stored on Nothing Chats were unencrypted and hosted on a readily accessible Firebase platform.

Further findings showed that after users authenticate using JSON Web Tokens (JWT), which are not secure during transmission, they gain access to Nothing Chat’s Firebase database. This access allows them to view other users’ messages and files, which are sent and stored in real time and in plain text.

Nothing Chats on a Nothing Phone 2 compared with iMessage on an iPhone 15 Pro Max.
iMessage on an iPhone 15 Pro Max (left) and Nothing Chats on a Nothing Phone 2 Andy Boxall / Digital Trends

All of this rings giant security alarms about the Sunbird (and the Nothings Chats) app. It’s especially worrying when it asks for your Apple ID credentials, the magic token that links everything from your emails and personal photos to your banking details.

It would be interesting to see where Nothing and Sunbird go from here. But with Apple embracing RCS and filling the feature gulf for Android-iPhone messaging, I don’t think it would be worth risking your privacy and data security for a hack that gives you blue chat bubbles.

Editors' Recommendations

Nadeem Sarwar
Nadeem is a tech journalist who started reading about cool smartphone tech out of curiosity and soon started writing…
Google just redesigned one of its biggest apps, and it’s bad
Google Chat app on the Play Store.

Google Chat — Google's business-oriented messaging platform that is similar to Slack and Microsoft Teams — just got a big update for its Android and iOS apps. The update dramatically changes how you navigate the app and, uh, well, it sure is something.

Google Chat's mobile app used to be broken up into two pages: Chat (direct messages between you and other users) and Spaces (larger chat rooms for multiple people). As with most apps, you switched between these with a navigation bar at the bottom of your screen.

Read more
These are my 8 favorite charity apps for iPhone and Android
Best charity giving apps.

Donating to charity is a great way to make a positive impact, and it doesn't have to be limited to just the holiday season. You can donate throughout the year, but finding the right organization can be challenging. Fortunately, there are many apps available to help you with this.

No matter what type of smartphone you have, whether it's an iPhone 15 Pro, Samsung Galaxy S23, Google Pixel 8 Pro, or any other mobile device, various apps can assist you in selecting the right charity to support those in need. Better still, some of the apps don't even want to collect your money. Instead, they want you to exercise or walk your dog for charity, give blood, and more.
Blood Donor

Read more
I used the worst app of 2023
An iMessage sent through the Nothing Chats app.

The Nothing Chats app turned the Android-based Nothing Phone 2 into an iPhone — and then into a security and privacy nightmare. What started out as a huge PR win for the new technology brand suddenly became a problem serious enough that it pulled the just-released app from the Google Play Store because it was not effectively securing your data.

We tried the app out on its release day, getting in just before its disappearance. This is what Nothing Chats was like — and what its failure could mean for Nothing.
What happened to Nothing Chats?

Read more