8 ms·
Security researcher Charlie Miller booted from Apple Developer Program
- guan 15y agoIt’s rude when according to the article he withheld details of the exploit to give Apple time to fix the bug, but the decision is understandable since he did violate the developer agreement. I’m not so sure about “interfering with Apple's software and services” but his activites seem to be covered under “hiding features from [Apple] when submitting them.”
- Codayus 15y agoThat's a bit too charitable to Apple, I think. Yes, the decision is covered by the terms of the agreement - they can do what they did. But since the result of their decision is 1) bad press and 2) increased risk of security holes, it's not "understandable" unless you think Apple is run by morons...
- epistasis 15y agoI think the risk is primarily bad press. It's not really a "security hole" for apps to add additional runnable code from an external website, when apps can currently contain pretty much anything at all (as long as they don't link to forbidden symbols). Remember that Apple does not see source code, and relies completely on app developers to behave, beyond a few perfunctory checks. And Apple has made it abundantly clear that they don't care about bad PR in the security community. So there's really no downside to cutting out Charlie Miller, in Apple's eyes. The winner here is Charlie Miller's career.
- dasil003 15y agoThe downside is poorer security, which could blow up in their face spectacularly at some point in the future.
- ootachi 15y agoI really doubt it. To be blunt, Apple is an existence proof that security on consumer products doesn't provide business value in proportion to its cost. Keeping users safe is seldom worth investing in.
- pyre 15y agoThe situation is only understandable from a 'blindly following the rules' perspective. If Apple makes it 'illegal' to probe their AppStore, then only black hats will be the ones doing the probing. How are you supposed to test whether or not Apple will discover a vulnerability during their AppStore approval process if you are going to tell them that one exists?
- btn 15y agoIn this case, he didn't only probe the approval process, but he also released the app containing the exploit into the store for public consumption. Apple's process allows for submitting an app for approval without releasing it into the store once it has been approved.
- kstenerud 15y agoIf the exploit potentially allows downloading and running of unsigned code after release in the app store, how else could one prove that it is in fact a hole, other than by releasing it into the app store to confirm the behavior?
- eridius 15y agoApps that you load onto the device yourself from Xcode are still signed, and are still governed by the sandboxing rules. You can demonstrate that the exploit works in your app by loading it on via Xcode, at which point the only difference submitting it to the AppStore makes is proving that it gets past the AppStore submission process (which isn't the interesting part about this exploit).
- masonlee 15y agoYou cannot yourself with Xcode install the very same signed "Distribution" binary that you submit to the App Store. The closest you can get is one signed for "Ad Hoc" distribution, but even those binaries interact with the OS differently than a "Distribution" binary. In-app purchasing, for example, differs between the two. That said, this guy broke the legal agreement that we partly rely on for trusted computing in iOS. He can be thankful if he doesn't get sued, and he should have gone about it differently if not willing to face the minimal consequences of violating the legal agreement.
- pvg 15y agoPutting the exploit in the App Store isn't particularly polite either and doesn't seem to serve any purpose other than generating some publicity for the researcher. It'd be different if he believed Apple wasn't going to fix it or that the exploit was being used or was about to be used in malicious apps - but he doesn't claim that was his motivation.
- mpyne 15y agoExcept that how else is he supposed to prove that it works other than actually demonstrating it with a real app on the real App Store?
- pvg 15y agoIt seems he was pretty sure it was going to work - there's nothing magical about the App Store, he'd found a way to get around the code signing checks. I'm sure that once the vulnerability was fixed, he'd get credit. It's just that this sort of thing won't get you in forbes. I personally don't really think there's anything at all wrong with a bit of harmless, nerdy limelight-seeking to boot, if that's what he was doing. Acting like he was somehow mistreated is what seems a bit iffy.
- kenjackson 15y agoThe problem is Apple could claim, "In our app verification process we can ensure such an exploit could never make it to the app store." The only way to test the full-scope of a vulnerability is to test it in a real world scenario, which means keeping it from Apple. Unfortunately, I know of no other way to do it, unless companies like Apple create security groups that work with people like Charlie and give him an exemption to submit, and not notify other parties at Apple.
- pvg 15y agoIf that's the problem, it's a different problem. If I'm reading the article right, he did submit the exploit, companies like Apple do have channels to receive and respond to vulnerabilities and to credit people who find and report them. There's nothing in the information released so far on this that suggests he was, in fact, facing such a problem.
- sigzero 15y agoHe uploaded malware to the store in violation of his developers agreement. FAIL.
- mahmud 15y agoDeveloper agreements are not a security mechanism.
- 5hoom 15y agoAnd security research does not trump the developer agreement. The guy submitted a real live exploit to the Joe-User facing App Store. What on earth did he expect would happen?
- mikeash 15y agoMaybe he expected a "thanks for showing us this vulnerability, we've pulled your app from the store and are working on a fix to the problem", as a sane response would be.
- 5hoom 15y agoPerhaps that is a fair point, but can you imagine the fallout if something like this ever slipped through and was downloaded by an actual user? It is easy to see why they don't take kindly to this sort of thing.
- mikeash 15y agoAll kinds of nasty things have slipped through to the users. There have been multiple remote root exploits for iOS in the wild for weeks at a time and nobody really cared. There would be no fallout. I agree that it's easy to see why they don't take kindly to this sort of thing, but it should also be easy to see why they should take kindly to it.
- st3fan 15y agoHe could also just have sent them an email about it. Instead he put a malicious app on the store and announced a talk at a security conference. Diplomacy was never his skill.
- feralchimp 15y ago"I don't think they've ever done this to another researcher. Then again, no researcher has ever looked into the security of their App Store. And after this, I imagine no other ones ever will," Miller said in an e-mail to CNET. "That is the really bad news from their decision." Take your wrist-slap like a man, sir. Apparently the grand are also prone to self-aggrandizement. I have a lot of respect for Miller's skills, but he's not the only smart person taking a hard look at App Store security.
- feralchimp 15y agoDownrank all you want. Nothing about this move means "Apple now has a bad relationship with security researchers." It just means Apple doesn't want Charlie Miller showing people how to side-load arbitrary code into their sheeps'-clothing apps.
- jjcm 15y agoHe's certainly not the only researcher looking at the app store, then again, he needs to play the victim a little bit right now if he wants to get public support. Public support and media attention may very well be his only ticket back into the developer program.
- Confusion 15y agoDon't assume what a news source presents as a quote is actually a quote. God knows what Miller actually said.
- nchuhoai 15y agoI come into your party as a guest and what I do is steal all your stuff. If you would be a white hat, you would knock at the door and kindly hint me to the loophole instead of just doing it ...
- deleted 15y ago[deleted]
- jjguy 15y agoIt's a bad move for apple. A good relationship with the community of security researchers is crucial - they're talented folks and their research results grab headlines. It takes just a tiny amount of corporate humility and public thanks to win their respect, and in return get goodwill. Treating the community badly will get ensure the next guy won't even try to cooperate. Over the last several years, Microsoft's MSRC has balanced this very well. Google has done well recently, too. Lots of clued-in people in both places.
- Xuzz 15y agoI'd agree more if he didn't submit — and get approved — a working exploit in their store. Without telling them about it. Edit: Now, I don't disagree that just banning him from the program isn't a great idea, and that pulling the app and having someone from the security team send him an email isn't a better one. But it's hard to say this that a bad move on Apple's part.
- mikeash 15y agoThis hardly qualifies as an exploit. While it allows the app to do something it's not supposed to do, the ability to download and execute additional executable code doesn't actually violate security. The new code is still restricted to the app's sandbox and can't do anything that the original app couldn't potentially have done directly.
- humbledrone 15y agoIt easily qualifies as an exploit, given that Apple's app store model is based on the fact that each app is reviewed beforehand to ensure various properties, including the property that the app does not contain spyware, etc. If Apple approved a harmless app, and then said app downloaded code that snooped on the user's calls or asked for their credit card number, that's an exploit.
- ghshephard 15y agoFirst - I think just general manners, as well as established protocol, would have the security researcher let Apple know ahead of time what he would be doing. A simple email sent prior to uploading this code would have been sufficient to cover his bases - I'm surprised he didn't do that. Second - Unless I'm mistaken - his proof of concept was more a violation of Apples TOU, it didn't really attempt to copy credit card numbers, or snoop on users calls - so, in that sense, it wasn't an exploit. Net-Net - nobody comes out of this looking good, but Apple makes it clear that they are prepared to back up the language of their Developer TOU with actions.
- jjtheblunt 15y agoHe's got great skills, and NSA training is as good as it gets, but he explicitly violated the rule to not download and run code from a server, to see if the rule would be enforced. They enforced it, just as he'd known they would. There was no point to his doing that other than to get headlines.
- kstenerud 15y agoNo, he explicitly violated the rule in order to test the hypothesis that a security hole he'd uncovered would allow unsigned code to be downloaded after release into the app store and run on the device. The sane response to this would be "Oh, we better fix that. Thanks. We're removing your app BTW." The Apple response was typical of a bureaucracy.
- 5hoom 15y agoThe lesson I would take away from this is that Apple should provide a mechanism for security vulnerabilities to be reported officially so that researchers don't have to engage in these sort of dubious activities. Whether they listen to the reports or not is another matter. Anyway, is there any special reason why reporting via https://ssl.apple.com/support/security/ https://ssl.apple.com/support/security/ won't work?
- nookiemonster 15y agoCharlie is one of the founders of the controversial "no more free bugs" movement. The amount of skill necessary to identify AND exploit bugs is so great that the bug reports themselves have value,far beyond attribution in the patch notesand a T-Shirt. This is especially true when there is in fact a lack market of bad people willing to pay good money for 0 day vulns. thus, reporting vulns that way doesnt necessarily make sense. Charlie's walking a fine line: He is not a BadGuy, but he also isn't giving away security consulting to companies with 200 billion market capitaliazations. Apple should pay him good money to look at this stuff. Otherwise, its going to be only BadGuys.
- chalst 15y ago
- MichaelApproved 15y agoApple is extremely binary. You're either with them or you're not. They don't seem to have flexibility and the only punishment is to be banned. Awful.
- st3fan 15y agoWhat Miller did was clearly a violation of the Dev Program Contract that he signed. There is no flexibility indeed when it comes to putting trojans on the store.
- sdiwakar 15y agoThere's always this flip-side to reporting security findings. I don't know the details of Charlie Millers exploit, however had he gone through the process of informing the vendor (in this case Apple) and then allowing sufficient time to address the issue, perhaps a showdown could have been avoided (I'm assuming that he hadn't). People however, also forget that, there are other pressures facing info-sec researchers - such as pressure from management at the company where they work to 'publish' and/or present their findings under the company banner. Often, this irks vendors, because vulnerabilities are used to promote the researcher's (or who they work for) interests. That said, Microsoft, Google and Facebook have very transparent processes & expectations for submitting vulnerabilities.
- RusAlexander 15y agoThe Apple is changing preferences, now they don't want to have a more secure soft. IMO Steve Jobs wanted.
- makira 15y agoAnyone has information regarding the actual vulnerability ? That would be very interesting. Thanks.
- JoeAltmaier 15y agoIts a walled garden; they can do anything they like. Live with it.
- Tomis 15y agoThe spirit of Steve Jobs lives on.
- tomlin 15y agoI feel like if this were an Android flaw, I'd see it in the title. Miller was booted from dev for discovering a major flaw in iOS. A hacker can have full access to the phone and personal data by just downloading an app from the App Store. Definitely worth mentioning in the title.
- super_mario 15y agoOops. Watch the number of trojans for OS X go up now.
- pnathan 15y agoAs a metanarrative, it's very interesting seeing the conflict between the rules followers and the ethics followers here in this thread.