4 ms·
> but the app store review process makes it harder to sneak one by. Imo the key question is: If you can find an exploit in the iOS sandbox, will the app store
by Dagonfly 4y ago
> but the app store review process makes it harder to sneak one by.
Imo the key question is: If you can find an exploit in the iOS sandbox, will the app store review really stop you? Compared to the expertise required to find such an exploit, it should be pretty trivial to obfuscate it or load the payload remotely after install.
- duskwuff 4y ago> Imo the key question is: If you can find an exploit in the iOS sandbox, will the app store review really stop you? The App Store review is two-pronged -- it includes some human QA testing, and it also includes some automated screening of your executable, which includes checking for any suspicious library imports or strings. (This sometimes trips up applications which happen to use method names which happen to match up with Apple's internal APIs.) While it isn't entirely impossible for a malicious application to slip past this examination, it's significantly harder than for an Enterprise application which doesn't go through this process at all.
- saagarjha 4y agoApp Store Review’s automated scanning is quite trivial to get around, most iOS developers can either attest to doing so themselves or knowing someone who has done this.