22 ms·
Apple starts rejecting apps with “hot code push” features
- rocky1138 10y agoThe solution is fairly simple: just stop releasing software on that platform. There are millions of customers on more open platforms, so there's really no need to support them anyway.
- penagwin 10y agoI don't care about specific numbers, let's use some from androidauthority.com . ios apps make more revenue then Google Play apps. So what you say? Well you make a LOT more revenue with BOTH gPlay + Appstore then EITHER on their own. http://www.androidauthority.com/google-play-store-vs-the-apple-app-store-601836/ http://www.androidauthority.com/google-play-store-vs-the-app...
- Retra 10y agoAll of life's problems are simple when suicide is your backup plan.
- JonRB 10y agoI am definitely stealing that
- megous 10y agoBoycott is a valid response no matter how much you try to make false analogies. Pulling app out of app store is by no means equivalent to suicide. At most you change your business.
- vecter 10y agoRight, like Uber, Snapchat, Facebook, Clash of Clans, Pinterest, Whatsapp, Instagram, Twitter, Waze, Shazam, Tinder, Match, YouTube, and basically every other app out there pulling out of the App Store would not be suicide. "At most", those companies would just have to "change their businesses".
- intrasight 10y agoIf all those companies did pull out, then it would be the end of Apple.
- vecter 10y agoAbsolutely not. Apple was fine long before these companies came into existence, and Apple will long outlast these companies. New companies would come in to fill the spaces these companies will have left in days.
- Razengan 10y agoAs a user/consumer, I like this. It reduces potentially unpleasant "surprises." Apple have curbed a lot of obnoxious developer practices (and enforced good ones, like the move to 64-bit not long ago) and they, along with Microsoft, probably the only ones with enough muscle to be able to do that.
- smaili 10y agotldr - appears to affect rollout.io customers (at least for those who have replied to the thread so far).
- htormey 10y agoI wonder if this is going to hit non native code push solutions like React Native? Or if Apple are going to start cracking down on apps like Facebook, Twitter or Pinterest that do a lot of A/B testing.
- avolcano 10y agoThis was my immediate question too. Microsoft offers a service called CodePush (https://microsoft.github.io/code-push/ https://microsoft.github.io/code-push/) for React Native and Cordova apps that presumedly could get caught by this. I don't have enough mobile dev knowledge to know whether or not it uses the same APIs that were mentioned in Apple's rejection letter, though.
- htormey 10y agoYep. I use code push in several apps. It's gonna be fun times next time I need to submit an app. I think it might be safe because it doesn't push native code and rollout is all about pushing native changes.
- axemclion 10y agoPM on the CodePush team here. The rejection notice seems to explicitly call out the native methods that are a cause of the issue. CodePush cannot inject private frameworks or expose any methods that React Native already exposes. I would also recommend not using CodePush to completely what an app does.
- joncrane 10y agoI accidentally what the app does.
- vinayan3 10y agoCan you get confirmation that CodePush won't be impacted?
- mmcwilliams 10y ago
- trishume 10y agoHasn't this always been against the App Store terms? I thought the only language you were allowed to download code from the internet and run was Javascript on Apple's VM.
- tyingq 10y agoYes, that's correct. IOS Developer Program License Agreement, section 3.3.2: "3.3.2 An Application may not download or install executable code. Interpreted code may only be used in an Application if all scripts, code and interpreters are packaged in the Application and not downloaded. The only exception to the foregoing is scripts and code downloaded and run by Apple's builtin WebKit framework..."
- empthought 10y ago... or JavascriptCore, which is what React Native uses.
- madeofpalk 10y ago..."provided that such scripts and code do not change the primary purpose of the Application"
- deleted 10y ago[deleted]
- seanclayton 10y agoSo you can add features all you want, just make sure you don't change your todo list app to a dating app and all is fine.
- madeofpalk 10y agoOnce you've 'worked' with Apple's app review for long enough you'll learn that you can't rely on such an assumption.
- RKearney 10y agoI wonder if Apple will apply this rule to everyone, which would be fair, or if they plan on letting big name developers like Facebook or Google continue to violate the rules without consequence.
- LeoPanthera 10y agoThey should pull the Facebook app for this. But I'll eat my hat if they do.
- empthought 10y agoTheir guidelines specifically say that, with prior authorization, the prohibitions do not apply.
- chii 10y agounfortunately, just like any other private platform, they don't need to be consistent or follow the rules all the time. I say, don't go native unless you must (for performance reasons etc). push the web forward instead!
- kyrra 10y agoAre there any sites that document Facebook or Google using hot code push on iOS?
- cbhl 10y agoI'm not sure if they still do this, but Facebook used to ship both code paths in the app binary for new launches, and give Apple instructions on how to test both code paths (e.g. sign in with this special user/pass combo). So they weren't changing app functionality after App Review approval; it's just that for users some of that functionality was gated on a boolean that was fetched over HTTPS.
- geofft 10y agoPutting code behind a feature flag seems entirely fair and a good idea for developers of any size. It's also a thing that can easily affect small developers; if your app requires logging into some existing paid account (enterprise software, a bank's app, etc.), the available features depend on what features the account has paid for. So as part of the review, you send Apple credentials for a test account that has all the features enabled. (Without a test account, they couldn't log in at all.)
- akhilcacharya 10y agoThere's a cynical part of me that thinks this is because Apple is going to announce a similar feature at WWDC
- empthought 10y agoI think that's likely. Why is it a cynical part of you? Either Apple is proactive and aggressive about keeping their platform free of hackishness as a matter of routine, or their store ends up a pile of malware and crashy junk.
- madeofpalk 10y agoThat doesn't seem likely. They 'just' reduced app review down to ~24 hours.
- mmmBacon 10y agoSeems like people have been aware of concerns about violating the TOS with these hot patch frameworks. From April 2016 >>Rollout is aware of the concerns within the community that patching apps outside of the App Store could be a violation of Apple’s review guidelines and practices. Rollout notes both on their FAQ site and in a longer blog post that their process is in compliance. https://www.fireeye.com/blog/threat-research/2016/04/rollout_or_not_the.html https://www.fireeye.com/blog/threat-research/2016/04/rollout...
- obstinate 10y agoA ton of games do this and it is incredibly annoying. I don't want to download an update, then have to download an update. I only wish the same restriction applied to my Android device.
- justinhj 10y agoMost likely most games are updating only game related data and graphics files. Very few games actually use internal scripting that would be needed to do code updates
- Angostura 10y agoThe only app I've got that appears to actually update itself without going through the AppStore is the HSBC mobile banking app. I'd be interested in hearing the discussions going on between Apple and HSBC at the moment.
- algesten 10y agoJudging by how sluggish and annoying the HSBC app is, I think it is a web app framed in a thin launcher from the app store. I.e. it downloads a bunch of javascript/html/css and that executes within a UIWebView/WKWebView. Using caching and localStorage, you can construct such an app to not need to download everything on each launch. The reason that's allowed is because everything executes within a sandboxed browser environment. No native code is downloaded.
- simplehuman 10y agoFrom https://rollout.io/how-it-works/ https://rollout.io/how-it-works/ : Does Rollout comply to Apple’s Guidelines? Yes. As per Apple’s official guidelines, Rollout.io does NOT alter binaries. ... With over 50 million devices already running our SDK, it is safe to say that Rollout complies with with Apple’s development and App Store guidelines. Ouch. Just like the company's future is in danger.
- eridius 10y agoThe first time I saw Rollout I was shocked it wasn't already banned by the App Store. No matter what they say, I can't imagine how they could do what they claim to do without flagrantly violating the guidelines.
- empthought 10y agoIt only started to matter when dumbasses started thinking that using Javascript everywhere was A-OK.
- sctb 10y agoPlease comment civilly and substantively on HN or not at all. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- geofft 10y agoI'm guessing there are two things Apple is worried about. The first is using hot code push to change the purpose of the app after release, e.g., switching a business app into a video game. The second is using hot code push to violate app store review guidelines, like the use of private APIs. You can do hot "code" push techniques that allow the first but not the second, by letting apps update HTML and JS that calls back into pre-existing native code. That's what Cordova / PhoneGap does. I'd guess that Apple will just ban the app and the developer if they catch it. It appears that Rollout started using some API that would enable it to do the second, and Apple is preemptively making sure that it doesn't happen. The wording of the rejection is based on passing computed parameters to introspection routines.
- josh_carterPDX 10y agoDidn't Firebase just introduce Remote Config which touts this very thing?
- pscarey 10y agoAFAIK Remote Config is just a server side key value store with customisable values based on audiences (e.g. random 50% for A/B testing, all people from Country X). This means all behaviour changes will require code to be deployed in the first place. Also, from Firebase Docs[1] "Don't attempt to circumvent the requirements of your app's target platform using Remote Config." [1] https://firebase.google.com/docs/remote-config/ https://firebase.google.com/docs/remote-config/
- josh_carterPDX 10y agoFrom this.... https://www.youtube.com/watch?v=_CXXVFPO6f0 https://www.youtube.com/watch?v=_CXXVFPO6f0 "Firebase Remote Config allows you to change the look-and-feel of your app, gradually roll out features, run A/B tests, and deliver customized content to certain users, all from the cloud without needing to publish a new version of your app."
- pscarey 10y agoWith hot code pushing, you're deploying newly written code/functionality, post release (opening possibility of up MiTM attacks etc). With Remote Config you deploy the code, then decide what to show to users post release. This gives Apple a chance to review all the code submitted to the App Store. In the case of rolling out features an A/B tests, you'd make a release including a feature, but only enable it x% of your users using RC. You can then obviously enable it for everyone if it passes your A/B test or if you're happy its working.
- deleted 10y ago[deleted]
- kposehn 10y agoI'm curious if this has anything to do with the exploits that are in the recent Wikileaks dump. Perhaps Apple saw something in there that raised alarm and an impetus to close the loophole?
- duhhumbug 10y agoThis is just Apple's response to the Wikileaks Vault 7 drop this morning.
- m3kw9 10y agoShould have been banned long ago, why would they have allowed an app to alter major behaviors post review?
- arbesfeld 10y agoWe haven't noticed any issues with AppHub, our service for dynamically updating React Native JavaScript code. We always felt this day would come, however, so we switched directions.
- pyed 10y agoI've always questioned that 'hot code pushing' whenever I face an app that does it, like how on earth is it allowed to begin with ? they basically can send almost any functionality they want skipping Apple's reviewing all together !
- egypturnash 10y agoI really kinda see no problem with Apple doing this. Hack the endpoint the app checks for new code, push malicious code. Or fool the app into checking for new code at your server, push malicious code. I mean I read the headline, thought this sounded eminently sensible, then read the story and saw it was a framework for doing this, and my inner mental model of my security researcher girlfriend leaned forward, started rubbing her hands together, and wanted to start digging for those sweet new vulns.
- mayoralito 10y agoOh, Mario Run! What are you gonna do?
- geofft 10y ago> any code which passes arbitrary parameters to dynamic methods such as dlopen(), dlsym(), respondsToSelector:, performSelector:, method_exchangeImplementations(), and running remote scripts in order to change app behavior or call SPI I would have expected dlopen and dlsym are blacklisted - you can trivially use dlsym to access any blacklisted API. Similarly, I thought SPI ("system programming interface" = private API) was all blacklisted. Am I misreading the message? That said, if this is what they're focused on, it seems like it actively does not impact any apps that hot-push HTML code (e.g., PhoneGap / Cordova). If the only reports are coming from Rollout.io, my guess is that the latest Rollout SDK uses one of these functions (I'd bet method_exchangeImplementations(), i.e., swizzling) with a dynamic parameter, and that the SDK can be changed to just stop doing that.
- deleted 10y ago[deleted]
- qq66 10y agoI wonder what they define as "code." Uber often rolls out "Kittens for a day" style features, some of which are topical and can't have been designed before the previous app update.
- geofft 10y agoThe rejection notice is very clear: > This includes any code which passes arbitrary parameters to dynamic methods such as dlopen(), dlsym(), respondsToSelector:, performSelector:, method_exchangeImplementations(), and running remote scripts in order to change app behavior or call SPI, based on the contents of the downloaded script. Uber can write a "foo for a day" feature, that downloads some strings and some images from the Uber website, but doesn't actually add any functionality. Same with any mobile game that has periodic events. You just write code to implement a generic event, write data to describe the event (name, graphics, level data), and do an update when you think of a different kind of event.
- sjwright 10y agoA topical "special day" feature could easily be defined as a downloadable content blob with zero executable or interpreted code. They probably have a set of special event templates already coded into the application which can then be themed with a few images, colours and text strings.
- leoh 10y agoYou can accomplish some crazy stuff with hot code loading: use private APIs, get around privacy restrictions. In theory, there are a lot of guys reasons for Apple to prohibit this.
- mikeash 10y agoYou can accomplish all of that without loading new code. Apple's private API checks, for example, are easy to get around if you're motivated.
- EGreg 10y agoDoes this mean all Cordova apps may be banned?
- teknologist 10y agoNot necessarily. From the Apple Developer Program License Agreement: > 3.3.2 An Application may not download or install executable code. Interpreted code may only be used in an Application if all scripts, code and interpreters are packaged in the Application and not downloaded. The only exception to the foregoing is scripts and code downloaded and run by Apple's builtin WebKit framework, provided that such scripts and code do not change the primary purpose of the Application by providing features or functionality that are inconsistent with the intended and advertised purpose of the Application as submitted to the App Store.
- deleted 10y ago[deleted]
- applecrazy 10y agoWhat will happen to YouTube? YouTube has been pushing new functionality ahead of updates for me recently. For example, the new "double tap to rewind 10 seconds" feature appeared at random one day (without an any updates)...then eventually the feature is announced in an App Store update. Or is the app review process more subjective?
- sb8244 10y agoThey might have achieved that by pushing it in silently over time and utilizing feature flags. Only going live in an app store update once it was rolled out to everyone.
- wishinghand 10y agoGoogle will absolutely have more wiggle room with rules than smaller developers.
- ChrisMorrisOrg 10y agoHmm, I definitely had to install an update for the YouTube app to receive the double tap to rewind/fast-forward.
- donarb 10y agoThe iPhone also has the ability to automatically update apps in the background if you allow it.
- dilipray 10y ago"Hi there -- I believe that title isn't quite accurate; Apple specifically is referring to behavior of a library called Rollout which lets people dynamically inject Objective-C/Swift. They are doing hot delivery of native, Objective-C code. It's really not about React Native nor Expo. Expo (and the React Native library we use) doesn't do any of that. We also make sure we don't expose ways to dynamically execute native code such as the dlopen() function that Apple mentioned in that message. We also haven't received any messages from Apple about Expo, nor have we heard of any Expo developers receiving the same." - Exponent Team
- deleted 10y ago[deleted]
- dylanpyle 10y agoThough the security justification here is limited to private APIs & native code pushing, the first few sentences of the rejection definitely seem like the "spirit" of the terms includes any significant functionality pushing at all. Wouldn't be surprised if they ramp up enforcement on that.
- jeswin 10y agoThe problem with Apple that you and your customers need to be aware of (or concerned about), is that once a number of your customers sidestep Apple policies w.r.t. pushing or changing features via JavaScript, Apple will change their policies to close that loophole. It's only a matter of time before companies take advantage of this path to sidestep app store approvals.
- Twisell 10y agoAs a client I'm pretty baffled that some developer had specifically bypassed something that I see as a security measure. If an app is modified on the fly to use an undocumented and maybe "forbidden by apple" method in order to bypass security features or worse spy on me I'm clearly not ok. Do you really think the apple ecosystem work because clients see AppStore as a evil cage and that the external developers are all angels with good intentions?
- stevebmark 10y agoThis has always been a requirement for Apple apps, hasn't it?
- adjunct 10y agoI'm Erez Rusovsky, the CEO of Rollout.io Rollout's mission has always been, and will always be about helping developers create and deploy mobile apps quickly and safely. Our current product has been a life saver for hundreds of apps by allowing them to patch bugs in live apps. We were surprised by Apple's actions today. From what we've been able to gather, they seem to be rejecting any app which utilizes a mechanism of live patching, not just apps using Rollout. Rollout has always been compliant with Apple's guidelines as we've detailed in the past here: https://rollout.io/blog/updating-apps-without-app-store/ https://rollout.io/blog/updating-apps-without-app-store/ Our SDK is installed in hundreds of live apps and our customers have fixed thousands of live bugs in their apps. We are contacting Apple in order to get further clarification on why Rollout doesn't fall under the clause that lets developers push JS to live apps as long as it does not modify the original features and functionality of the app. I'll post updates as I have them. Erez Rusovsky CEO Rollout.io
- aristidesfl 10y agohttps://rollout.io/blog/rollout-statement-on-apple-guidelines/ https://rollout.io/blog/rollout-statement-on-apple-guideline...
- nickm12 10y agoI think the part that you're running afoul of is where it says: "new apps presenting new questions may result in new rules at any time." Good luck to you, but it's Apple's sandbox and your product appears to thwart the principles that the Apple App Store has been run on for nearly a decade.
- ma2rten 10y agoYou were relying on a huge loophole. The code runs inside JavascriptCore but it injects native code into the app.
- mahyarm 10y agoAn objc swizzle is not native code injection, it's a function pointer swap. They swizzle the method to their general objc message handler which then executes a piece of javascript code. For swift they basically patch the app before it gets compiled so that every function, if it meets the conditional would execute their javascript code handler instead. No binary code being injected.
- teknologist 10y agoIt seems that most people are overlooking one of the more significant points Apple have made here: "Even if the remote resource is not intentionally malicious, it could easily be hijacked via a Man In The Middle (MiTM) attack, which can pose a serious security vulnerability to users of your app." Source: https://github.com/bang590/JSPatch/issues/746 https://github.com/bang590/JSPatch/issues/746
- orless 10y agoI'm not buying the MITM argument in general. If remote code is downloaded via HTTPS, it could not be hijacked, at least not easily.
- teknologist 10y agoIn an ideal world where apps check/pin certificates and don't disable cert checks to make self-signed certs work in test environments you'd be right. If only this were reality.
- orless 10y agoI'm just pointing out that "remote resource ... could easily be hijacked via a MiTM attack" is technically incorrect. The problem is not the remote resource per se, the problem is trusting developers to implement secure loading of resources. Which is a completely different argument.
- bigiain 10y agoDepends on who you're expecting the MiTM attack to be executed by. Are _you_ secured against, say, an attacker who works at Verisign and can create a valid cert for api.yourdomain.com? Or an attacker who has a buddy who works at GoDaddy who can subvert your dns records so they can trick LetsEncrypt into issuing a valid cert for api.yourdomain.com? Or an elbonian teenage hacker who's just got your AshleyMaddison assword from pastebin and used it to log into your Gmail account and overtaken your dns registrar account to get themselves a valid ssl cert?
- lacampbell 10y agoStuff like this is one of the big reasons I am a fan of web apps over mobile apps. Letting apple or google have control over this channel is just too risky for me.
- swanros 10y agoYou've literally got things upside-down.
- stevehiehn 10y agoI've recently been looking into React-Native. I'm hesitent to commit because i believe there's 'hot code push' potential and Apple will be a b*h about it. I not sure if this is the case thou.
- Mayzie 10y ago> i believe there's 'hot code push' potential It's called CodePush, and it's a plugin for React Native (does not come with it). It is developed by Microsoft: https://microsoft.github.io/code-push/ https://microsoft.github.io/code-push/ Doubt it would get taken down.
- stevehiehn 10y agoInteresting, thanks
- jahewson 10y agoThere's hot code push potential in Swift and Obj-C too.
- 234dd57d2c8dba 10y agoThis is the future everyone is choosing. You don't own your devices, you don't own the apps you write, and you're not smart enough to be able to decide what is "good" code vs "bad" code. Just let the algorithms, corporations, and governments decide what is best for you. It's much easier that way, after all.
- santiagobasulto 10y agoI checked again rollout.io Disrupt presentation (great pitch btw) and the first question they get (Alexandra Chong) is "is it going to be ok with AppStore policies": https://techcrunch.com/2015/09/22/rollout-io-puts-mobile-developers-back-in-control-of-their-apps/ https://techcrunch.com/2015/09/22/rollout-io-puts-mobile-dev...
- pinaceae 10y agoUnderstandable, but there is a deeper problem of course - the app store model is broken for apps that need hotfix capabilities (aka enterprise). We've been meeting with Apple on this topic for years and continue to sideload our app as we need to meet SLAs with our customers. They sign the binaries with their dev certificates, which violates Apple's guidelines too. But, alas, once you have critical mass in a vertical even mighty Apple gets cold feet about shutting your customers down. Why Apple is not able to offer a separate way for certified and audited dev shops to hotfix their iOS apps is beyond me. SAP, MS, IBM - a shitload of big shops would love to pay for this privilege.
- tinus_hn 10y ago'Enterprise' always needs things, and then when these required things are not available enterprise makes do with what is. In this case it isn't required at all though because Apple allows enterprise to sideload apps outside of the review process.
- pinaceae 10y agoBut not as a vendor. Right now we get the certificates from out customers, sign the individual binaries. Then distribute through our own infrastructure. We have our own update mechanism (basically hot code push), cannot have the customer's own IT shop be a barrier to deploy the fix. User sync their apps, if there is an upgrade that gets done inbetween the normal data/content sync.
- Grustaf 10y agoIsn't that exactly what enterprise distribution does?
- pinaceae 10y agoNo, still goes through a check if it is a globally published app (vs. a custom app for just one company).
- deleted 10y ago[deleted]
- diminish 10y agoJust imagine www didn't exist and Apple already had ios and apps. If someone came up with the idea of www and an app called web browser , would apple accept it in the app store? They would only accept it if they build it themselves. At some point is there a risk that Apple may also start to ban the web browser, despite that it's under strict control on IOS?
- grey-area 10y agoThis is why you don't build on someone else's platform. Apple/Google/Platform Owner will always do what's right for them, not the customer, and not the developer, for example banning Amazon from selling books in their kindle app, not allowing competing browsers (they recognise the power of the web as a platform), not allowing competing sales mechanisms (where they don't get a cut), and here not allowing developers to update their apps except through the store mechanism. I have some sympathy with Apple here, and see why they're doing it (they have to control what software is installed for security reasons as well as platform protection), but this is all about control over what you install on your own device. Sometimes their actions will be in the best interests of customers, even if not the best interests of developers, but most of the time their actions are simply aimed at preserving their control of the platform and control of the money flowing through it. The web is the one exception to this rule which works across all platforms and devices (because it is so dumb and simple), and has survived attempts to corral it to a walled-in commercial offering remarkably well.
- ChrisMorrisOrg 10y agoI agree - they're definitely putting the customer's security first. If people want to use an open environment, the web browser is always available on iOS anyway. Apple are completely within their rights to restrict their application platform.
- trhway 10y ago>Apple are completely within their rights to restrict their application platform. it is like to say that GM is completely withing their rights to restrict where you can drive your GM car. Mind you, that is coming in pretty near future too - giving all the computerization/connectivity/self-driving of the cars which would make the cars into GM's "application platform" with DMCA protecting such a platform too like it protects Apple/Google/FB/etc...
- LoSboccacc 10y agoAbout time, as an user it's fucking annoyng when you download an app but will refuse to work unless you're online even when it has zero needs for it
- danappelxx 10y agoTo be fair that's just bad UX, there is no necessity for apps using rollout to access the internet as (I hope) rollout caches the app.
- homakov 10y agoFrom my understanding people are giving rollout push rights to their app store accounts? So rollout can hijack all the apps it controls? It's a hell of a central authority, a security nightmare waiting to happen.
- manmal 10y agoNo, it allows apps to be modified by the apps pulling JS code from rollout's servers. App reviews would be way too slow, and they are exactly the problem that rollout solves. However, review times have improved a lot since then. ADDITION: It works by "swizzling" methods, which is a valid mechanism in Apple's runtimes (like in Ruby or many other dynamic languages). In Swift, this will only work in subclasses of NSObject or its decendants, because only then message dispatch is used.
- deleted 10y ago[deleted]
- BrightAlong 10y agoIt feels so wrong that app security still relies on manual code review. Apple is afraid the app might call certain functions with certain parameters in the future. As an engineer I would not want to rely on human judgment what the code does. The browser sandbox has been proven to work pretty well over the last years. That is why I prefer web apps over native apps.
- milkers 10y agoWhat about Microsoft's infamous Code Push?
- aamederen 10y agoHow does apple understand whether the app can change behaviour according to external factors. Maybe in other words, what is a "behavior change"? For example, google has Tag Manager [1] which I believe is mostly used for managing small UI related changes. Is there a clear documentation or distinction about that? [1] https://developers.google.com/tag-manager/ https://developers.google.com/tag-manager/
- desaiguddu 10y agoAnother big worry is analytics platform like 'AppSee' that is clear violation of consumer privacy.
- algesten 10y agoThat game that is topping the charts "Legacy", explicitly says when you start it that it's downloading patches. Wonder why it isn't blocked?
- jhgg 10y agoPatches could be assets - updated map data - updated textures - updated AI scripts? I don't think these need a full app store update as it's not changing the game from a game to a dating app (for example).
- TeMPOraL 10y agoStill, how do they avoid someone writing an ad-hoc interpreter and reading code from e.g. PNG images? Data == code, as we know.
- d--b 10y agoCould this have anything to do with Wikileak's release of iOS hacks by the CIA?
- ge0rg 10y agoProbably not, the timing is too tight, and if Apple were aware of active exploitation, they would probably compeltely remove / block affected apps, instead of giving the devs a notice to improve the next release.
- deleted 10y ago[deleted]
- reimertz 10y agoI don't see Apple blocking React Native, too many big players using it in production. If you use hot code push together with React Native, then you're borked.
- anta40 10y agoNon iOS/Apple developer here. So, with this "hot code push", is it also possible to update an app (adding new features), and not only bug fixes, directly? If yes, then sounds like you are trying to circumvent the App Store QA process.
- andy_ppp 10y agoReact Native allows you to replace the JS bundle, will this be affected?
- Brotkrumen 10y agoA day after the Vault 7 leaks. Well well well
- Entangled 10y ago"Oh look, I found this tunnel under the border, I'll use it to feed the birds on the other side. I swear to god I'll never use it to smuggle drugs or people" It is too bad people is using it for good causes but the hole has to be closed. Sorry guys.
- godmodus 10y agogood, this sort of stuff screams of abuse potential. devs should re-submit their code to apple, instead pushing "fixes" to phones. i guess it's fair to assume 99% of those pushes are safe (80%? guess it's more like 'benefit of the doubt'), but that 1% the escapes scrutiny is the one piece that makes the whole platform shaky, and honestly, poses a major attack vector. i wonder how often this was abused. as to service like rollout.io, it's a service that was never supposed to be. especially if it serviced hundreds of apps - as a security minded indv. i shudder at the thought of what might have slipped through. edit: after digging into rollout.io and finding out it's based in telaviv, is it wrong to speculate about origins and real purpose of an israeli company that specializes in injecting code into iphone applications?
- elmigranto 10y agoI'm not an iOS developer, so I'm not sure what's possible, but am wondering about React Native apps (and similar technologies too). Here's a scenario: - you publish an app that creates collages; - user gives access to Photos; - you change your JS to upload all the photos to your server. Substitute "photos" part to any iOS permission; isn't this security risk? Should it be allowed under current App Store ToS? Also, what's stopping your JS code from downloading binary code and injecting it via some iOS exploit into "native thread"?
- johnhattan 10y agoThere's not much to prevent that scenario from happening. There's now a "why" section in one of the app's descriptors where you need to describe what you're doing with the permission. So it's not enough to say "I want access to the photos". It's now "I want access to the photos so that I can put them on the screen and let you draw funny pictures on them." But there's little to prevent you from lying about it, and there are so many iOS platform technologies out there now (native, PhoneGap, React Native, AIR, Xamarin) that there's probably no way for Apple to see what you're doing in an automated way.
- rsynnott 10y ago"Starts"? I thought this was always a rule. Maybe they're only starting to enforce it now...
- Avloss 10y agoSurprised this wasn't done sooner tbh. Though obviously this is a blow for developers.
- khana 10y agoGood.
- JulianMorrison 10y agoHot CIA back door push is a misfeature in any app, and Apple are doing the right thing here.
- ksk 10y agoI'd say this is only going to further the arms race. One simple way around this would be to intentionally introduce a bug with a "controlled" exploit that lets you send a specially crafted data packet to your app, and execute shell-code of your choice.
- justinzollars 10y agoThe Unfree web.
- shmerl 10y agoJust ditch Apple. The obnoxious attempt to ban any kind of customization is sickening. Apple like to shoot in their own foot by making life miserable for developers.
- o_____________o 10y agoBut users have no idea how miserable life behind the iron XCode curtain is, so it will continue forever.
- anindha 10y agoDoes this effect React Native apps?
- adjunct 10y agoHi all (Erez from Rollout here) –I appreciate the discussion. Here’s our full statement – please weigh in with any questions https://rollout.io/blog/rollout-statement-on-apple-guidelines/ https://rollout.io/blog/rollout-statement-on-apple-guideline...