3 ms·
That's a bit of a stretch. Epic abused the security update workflow of the iOS app review system. Specifically, they submitted an update which was not a hotfi
by labcomputer 6y ago
That's a bit of a stretch.
Epic abused the security update workflow of the iOS app review system. Specifically, they submitted an update which was not a hotfix as if it were a hotfix. They (apparently) did that intentionally so that the update would not be inspected closely.
The signature system is built on trust. Apple allows trusted partners to submit hotfixes to address security bugs. Those updates receive expedited (read: cursory) review. Epic abused that trust to push an update which added their own payment system, not to address a bug (security or otherwise).
If Epic is going to abuse the trust of system for submitting security updates, why should they be trusted by the signature system?
- cma 6y agoSource on that? They sent a server update to activate a feature flag on a preexisting build. Apple characterizes this as a hotfix process, but not as their own expedited review hotfix process I don't believe. If that build that first added the unactivated flagged feature used expedited review I don't see any sources saying so. But even then, expedited review isn't exclusively for security, it is also for events (Fortnite has frequent events): "to coincide with an event you are directly associated with," https://web.archive.org/web/20190326213414/https://developer.apple.com/app-store/review/ https://web.archive.org/web/20190326213414/https://developer... Adding an alternate payment option wasn't a security breach for users. This is a complete stretch to relate it to desktop security in any way.
- labcomputer 6y agoI don't have a source. It's an inference based on the public statements of both companies. Apple characterizes it as a hotfix and Epic has not disputed that. Apple has a well-known expedited review process. > This is a complete stretch to relate it to desktop security in any way. I'm sorry, but this makes no sense. The same (apparently untrustworthy) entity is responsible for both Fortnight-the-iOS-game and Fortnight-the-MacOS-game. If you don't trust that entity on one platform, why on earth would you trust them on a different platform?