9 ms·
Last year I learned that to publish an app in the App Store or Mac App Store, if it uses encryption of any kind and yes, HTTPS and SSL count, you need an Encryp
by pupeno 11y ago
Last year I learned that to publish an app in the App Store or Mac App Store, if it uses encryption of any kind and yes, HTTPS and SSL count, you need an Encryption Registration (ERN) from the US Bureau of Industry (BIS). Some people claim it's fine to lie to Apple, claim no use of encryption and get in the app store. I'd rather do it the right way.
When I started the process of getting the ERN, I quickly notice it was going to be a long and arduous process and that other people could benefit from the lessons I was learning the hard way, so I decided to document it all in a long blog post.
This is probably one of my most researched pieces ever. The whole process took about two months from the start, researching this thing called ERN, to getting the app published in the Mac App Store, satisfying that what I did was (more or less) correct.
- dangero 11y agoAre you sure HTTPS counts? That seems insane to me.
- nathancahill 11y agoI find that hard to believe too since Apple has basically deprecated HTTP is iOS 9 and OS X 10.11. https://twitter.com/satefan/status/608093548827664384 https://twitter.com/satefan/status/608093548827664384
- profmonocle 11y agoBack when I was doing hobbyist iOS development (2009-ish) I asked Apple developer support about this, and they said it does. Worst part is it doesn't matter if you use a built-in system library like NSURLSession. Simply accessing an HTTPS URL from inside your app triggers this requirement. Some people say the paperwork is easy to fill out yourself, but I was a college student and the legalese scared the crap out of me. And there was no way I could afford to consult a lawyer for a hobby project. My only choice was to use plaintext HTTP for my app (which I wasn't willing to do for this particular app), or to restrict the app to the US and Canada, which doesn't require a government filing. I hated doing it, but I went with option two. Edit: fixed typo.
- eridius 11y agoThat cannot possibly be true. I guarantee you virtually every REST app in the store uses HTTPS and none of them went through all of this. In the latest version of iOS you can't even load HTTP by default and must use HTTPS unless you put a special exception in your Info.plist. Everybody uses HTTPS, and nobody has to go through any of this. So either you asked the wrong question, misinterpreted the answer, or you simply talked to someone who didn't understand your question or otherwise just didn't know themselves.
- eclipxe 11y agoThank you! It is definitely a misinterpretation. Apple makes https mandatory now and there is no way every developer would have to go through this process.
- _up 11y agoI think "only" apps that allow communication are affected. Websites that only pull generic data are safe.
- pupeno 11y agoIf you are pulling through http and http only, yes. If you are using HTTPS, you are encrypting the requests that may contain arbitrary amount of data and the exception doesn't apply to you anymore.
- geofft 11y agoWhy do you say there's no way? This is US law, not Apple's policy, and US law is fully capable of being that dumb. (Whether Apple allows developers to lie to Apple and violate US law is beside the point.) Debian's archive software used to send an automated mail to the US government every time a new package is accepted, just in case it involves crypto: https://github.com/Debian/dak/blob/master/templates/process-new.bxa_notification https://github.com/Debian/dak/blob/master/templates/process-... (Looks like the government told them "Okay, okay, we don't care" at some point, but that was what they determined their legal obligation was after consulting with lawyers about what the law actually said.)
- pupeno 11y agoYes, it does. I talked to legal as well as export compliance department at Apple and they confirmed this. Maybe they were being overly cautious but so was I. With HTTPS, what puts you clearly out of every potential exception, is the fact that you are encrypting the requests. Someone asked about this in the blog and I replied with more information.
- Guvante 11y agoWere you using the built in web capabilities or embedding a library to handle the encryption? In theory Apple's methods for accessing HTTPS should be safe while embedding OpenSSL would not be (unless you linked to a shared object they deployed).
- quasse 11y agoYeah, I'd like to see this answered too. If OP was just using the built in WebKit browser this seems to have all been a big misinterpretation of the rules. If they did indeed roll their own browser with HTTPS, why? The post is a very good guide to navigating that bureaucratic process either way though.
- metafunctor 11y agoI don't think it matters where the encryption capability comes from. The iTunes Connect FAQ says: “If your app uses, accesses, implements or incorporates industry standard encryption algorithms other than those listed as exemptions under question 2, you need to submit for an ERN authorization. Examples of standard encryption are: AES, SSL, https.” There are a lot of exemptions, but only using Apple's HTTPS is not one.
- eps 11y ago> industry standard What about custom crypto then?
- noblethrasher 11y agoThe line between encoding and encryption is blurry, so it would be difficult to enforce without being seeming arbitrary or capricious. On the other hand, custom crypto will almost certainly be defective, so why bother prohibiting it it?
- Guvante 11y agoSounds like Apple is the cause here, since export restrictions don't apply to things that are never exported. If you aren't embedding the algorithm then your code is not exporting the algorithm.
- NamTaf 11y agoHoly crap that is a bureaucratic nightmare. Why does encryption even need to be registered in the first place? I don't see any point beyond the holdover of 'encryption is munitions' which is a pile of crap in the first place.
- weinzierl 11y agoSome say that this kind of policy is coming back. Crypto Wars Part II The Empires Strike Back Kurt Opsahl Deputy Executive Director of the EFF https://media.ccc.de/v/32c3-7386-crypto_wars_part_ii#video https://media.ccc.de/v/32c3-7386-crypto_wars_part_ii#video There is no first part of this specific talk. The talk is only called "Part II" because of the Crypto Wars of the nineties. If you are interested in the "Part I" history https://en.wikipedia.org/wiki/Bernstein_v._United_States https://en.wikipedia.org/wiki/Bernstein_v._United_States is a good starter.
- yuhong 11y agoIt was even worse before 2010, which was why Evernote used 64-bit RC2 encryption.
- pupeno 11y agoThroughout the process I found left-overs from the previous processes and yes, it looked much worse. The worst part for me is that there were steps in the process than though simple, they were not defined anywhere and thus it required me calling various departments to ask for clarifications.
- chrischen 11y agoEncryptions is munitions. It is the modern day "arms" that that the spirit of the 2nd amendment to the US constitution was trying to protect as a fail-safe to an overreaching corrupted government. We don't need to bear arms anymore because we don't walk around dueling people at high noon anymore, but being an information based economy and information based society, encryption is the new gun in the wild world web.
- 11y ago
- madeofpalk 11y agoI think I remember reading that if you're using Apple's APIs and frameworks (like their builtins for HTTPS) then you don't need to go through this rigmarole.
- rosser 11y agoFrom the screen shot of Apple's app submission: "Select yes even if your app is only utilizing the encryption available in iOS or OSX."
- madeofpalk 11y agoI've always interpreted "(ii) your app uses, accesses, implements or incorporates encryption for authentication only" as our uses cases for using HTTPS and thus said that I am exempt.
- deleted 11y ago[deleted]
- vbezhenar 11y agoUnless you are using HTTPS with NULL encryption algorithm, your bytes are encrypted and decrypted, so it's not "authentication only". I think that you can use NULL encryption algorithm and in this case only authentication will be performed. But I'm not sure that standard library will allow to use this algorithm.
- weddpros 11y agoIn that case, simply saving a file would also count as encryption now, since iOS devices are encrypted...
- rbritton 11y agoI'm far from an expert on this area, but I know there are exemptions many apps can qualify for. The most notable of these is that the encryption is limited to authentication [1]. [1]: http://stackoverflow.com/questions/2135081/does-my-application-contain-encryption http://stackoverflow.com/questions/2135081/does-my-applicati...
- danieltillett 11y agoI would have thought this covered https.
- comex 11y agoI'm pretty sure "limited to authentication" means that the data is transmitted in the clear but covered by a signature. HTTPS actually encrypts, so it wouldn't count.
- rbritton 11y agoCould you not also argue that ongoing use of HTTPS after authenticating yourself with the server is to ensure the response is coming from who you intend (i.e., the server authenticating itself to you)?
- geofft 11y agoIANAL, but if you assume law matches cryptographic reality: there's such a thing as the NULL cipher, which most SSL stacks don't support (at least by default) because it's a big footgun. It will let you have traffic that's authenticated but not encrypted.
- pupeno 11y agoWhat would you rather do, argue with the US government or get an ERN and focus on your business? I know my answer ;)
- pupeno 11y agoI talked to a couple of people at Apple and they explicitly told me that use of HTTPS is not covered under the exception. I think that exception was designed to authenticate licences of software. Programs that phone home, get a toke, and decrypt it to verify you paid for it, but that's just a hypothesis.
- HappyTypist 11y agoI am confident that it is not true and the apple dev support rep you talked to have no idea what they were talking about.
- huac 11y agoyou'd think that this is a pretty frequently asked question though, no? how could apple dev support personnel not understand/answer basic questions that affect a significant portion of apple devs?
- eclipxe 11y agoNo I think most devs don't interpret the rules as the OP does. Connecting to an https endpoint is clearly not what they mean here.
- geofft 11y agoOn advice of counsel, or on the intuition that the US government's laws about crypto cannot possibly be that dumb? Because yes, the laws are in fact that dumb.
- pupeno 11y agoI talked to the export compliance department at Apple. There's a chance that they say "yes, get an ERN" because they have nothing to lose and it's safer for them and in fact, there's no need for it. But I doubt it. I will consult a lawyer to make sure my whole process is good if people want me to get ERNs from them (an idea some people floated with me).
- huhtenberg 11y agoAre you US-based?
- narsil 11y agoThe OP and his company are based in London.
- Rafert 11y agoThis seems to be only for US based developers, I can't remember having to fill in more then a handful of radio buttons regarding crypto when I submitted an iOS app as a Dutch developer.
- Joe8Bit 11y agoFrom the blog post the developer's to be based in the UK.
- dchest 11y agoNope, this is for everyone. Apple is exporting your app from US, so they need this paperwork from you. The only other options are: * send Apple a paper promising that you will only distribute your app in US and Canada stores, discarding all other markets. * make your encryption use insecure 64-bit keys. * make your complete app open source. * (some other options, such as when using encryption only for authentication) If you lied to Apple and if US government finds out you export encryption without registration, and if they care enough, they will fine you (http://www.theregister.co.uk/2014/10/17/intel_subsidiary_crypto_export_fine/ http://www.theregister.co.uk/2014/10/17/intel_subsidiary_cry...)
- dhimes 11y agoWhere is your blog?
- pupeno 11y agohttps://carouselapps.com https://carouselapps.com