4 ms·
Obfuscation seems like a great way to get your developer account suspended. I suspect Apple is doing a lot more than just basic static analysis of the binary on
by TillE 2y ago
Obfuscation seems like a great way to get your developer account suspended. I suspect Apple is doing a lot more than just basic static analysis of the binary on disk.
Glad they went with a config option instead.
- veeti 2y agoThey are opaquely rejecting apps for just literally containing the string "itms-services" in the binary and you still give them credit for a more sophisticated analysis? Lol.
- nozzlegear 2y agoWe can assume that a simple string search is one of the basic checks they do before moving onto more advanced checks.
- malfist 2y agoWhy can we assume that?
- zarathustreal 2y agoBecause it’s less effort to implement?
- oldpersonintx 2y ago[dead]
- youcantcook 2y ago[dead]
- coldtea 2y agoEvery story I've seen over the years about MAS/iOS AS rejections point to their checks not being advanced at all.
- doctor_eval 2y agoYou’re assuming that’s all they are doing, and that it’s all they will ever do, but neither assumption is supported by any evidence. Apple is saying what test broke, not that other tests aren’t running.
- CivBase 2y agoIf they did are doing more, why are the apps getting rejected?
- nomel 2y agoNo. See the above article for more information, specifically the discussion linked [1]. > Some light obfuscation of the magic string appears to avoid the issue. It is a simple string match causing the failure. [1] https://discuss.python.org/t/handling-incompatibilities-with-app-store-review-processes/56011 https://discuss.python.org/t/handling-incompatibilities-with...
- doctor_eval 2y agoFair enough, though I was really just saying that simply because they are doing something simple doesn't mean that don't (or, more importantly, won't) do something complex. In the LWN article discussion it's mentioned that Apple doesn't like obfuscation, presumably this means they can detect some forms of it. Put another way: if it was my app, and this string wasn't important to me, I wouldn't want it obfuscated, I'd want it removed.
- kemayo 2y agoDepends. The actual rule being "violated" isn't that the app can't contain the string "itms-services". Rather it's: Guideline 2.5.2 - Performance - Software Requirements The app installed or launched executable code. Specifically, the app uses the itms-services URL scheme to install an app. i.e. the app can't try to trigger an install of another App Store app. The app in question isn't doing that, it's just that the basic check is incompetent for the rule it's supposed to be checking and the reviewer isn't doing any manual checking after that to see if it was a false-positive. So obfuscating the string, if you're genuinely not trying to install other apps, should leave your app just as non-violating as it was before... just not tripping the badly written check. Apple can of course be arbitrary and capricious after that point.
- deleted 2y ago[deleted]