4 ms·
Having the initial pass specify the public key that it accepts for updates would be sufficient. Having an association with an Apple developer account doesn't he
by robryk 3y ago
Having the initial pass specify the public key that it accepts for updates would be sufficient. Having an association with an Apple developer account doesn't help for the updates problem at all AFAICT.
The only reason I came up with for the blessed-by-Apple requirement I came up with is selling fake tickets. There is no way to tell (with or without that requirement) whether a pkpass file with a "ticket to concert X" is actually legit. So, one can try to combat the (potential?) problem by responding to complaints of fraud by revoking the corresponding developer's account. However, that doesn't seem like a solution either: developer account are probably way cheaper than how much you can gain on fraud before you get caught in that way.
- lxgr 3y agoYeah, I also found the justifications for Apple requiring passes to be signed pretty vague. Locking things down is just the default for Apple; it's usually only in later iterations that they open up integrations to the broader ecosystem. On the face of it, it's really weird to require passes to be signed: I can always just store a PNG or PDF showing the same bar code in my photo library or files app and present that. Imagine iOS only displaying signed PDFs!