Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

He uploaded malware to the store in violation of his developers agreement. FAIL.


Developer agreements are not a security mechanism.


And security research does not trump the developer agreement.

The guy submitted a real live exploit to the Joe-User facing App Store. What on earth did he expect would happen?


He didn't do anything harmful though. He just demonstrated the capability.

It's the equivalent of making a word document pop up calc.exe. This proves that you've broken the security, but doesn't cause harm.

You have to actually do it to be taken seriously, especially with unreceptive vendors like Apple.

There is really no reason to behave in a hostile way towards a researcher that does this. He's telling you about the problem.

In the security industry, there are many people who seek and find vulnerabilities. Some of them report them, and some of them keep them private and exploit them secretly to attack people's property, or privately sell to others who do the same. Selling these to the underground is big business now.

Let's subtract the people who report things from the above equation (because we ban and vilify them). Now what does your ecosystem look like?

Dumb move, Apple. Dumb move.


Maybe he expected a "thanks for showing us this vulnerability, we've pulled your app from the store and are working on a fix to the problem", as a sane response would be.


He could also just have sent them an email about it. Instead he put a malicious app on the store and announced a talk at a security conference. Diplomacy was never his skill.


Perhaps that is a fair point, but can you imagine the fallout if something like this ever slipped through and was downloaded by an actual user?

It is easy to see why they don't take kindly to this sort of thing.


All kinds of nasty things have slipped through to the users. There have been multiple remote root exploits for iOS in the wild for weeks at a time and nobody really cared. There would be no fallout.

I agree that it's easy to see why they don't take kindly to this sort of thing, but it should also be easy to see why they should take kindly to it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: