Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Probably not. The article said it was from a link in n email. As this was a spearphishing attack, the attacker probably doesn't care that the developer account doesn't work anymore.


Exactly. Everybody with 100 USD can get such an ID and then let it be revoked once discovered.


I thought the point of requiring a payment was that the ID could be traced back to a real person or company, so law enforcement could follow things like this up?


There's no real ID check when you sign up for a paid Apple developer account. A stolen credit card and an email address is enough.


The point of requiring a payment is to make money. There is no meaningful mechanism to require a true "real human being" identity. It's no different than the presence of a TLS cert on an arbitrary domain, all it tells you is that the attacker cared enough to expend resources on the attack.


If Apple wanted to actually 'make money' from its developer program fees, it'd cost a lot more than $99 - even more than it cost before the Mac App Store. I realize that $99 may be a lot of money for people like you, so I appreciate that this might be difficult to grasp at first. Keep trying, I've got faith in you!


this isn't reddit.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: