4 ms·
I first read that as Apple's ID And thought it was like the Microsoft certificate attack. Looks like Macs market share is growing. Was this distributed in the
by nicheuser 13y ago
I first read that as Apple's ID And thought it was like the Microsoft certificate attack.
Looks like Macs market share is growing. Was this distributed in the store?
- pyre 13y agoProbably not. The article said it was from a link in n email. As this was a spearphishing attack, the attacker probably doesn't care that the developer account doesn't work anymore.
- acqq 13y agoExactly. Everybody with 100 USD can get such an ID and then let it be revoked once discovered.
- takluyver 13y agoI thought the point of requiring a payment was that the ID could be traced back to a real person or company, so law enforcement could follow things like this up?
- ajross 13y agoThe point of requiring a payment is to make money. There is no meaningful mechanism to require a true "real human being" identity. It's no different than the presence of a TLS cert on an arbitrary domain, all it tells you is that the attacker cared enough to expend resources on the attack.
- demlulz 13y agoIf Apple wanted to actually 'make money' from its developer program fees, it'd cost a lot more than $99 - even more than it cost before the Mac App Store. I realize that $99 may be a lot of money for people like you, so I appreciate that this might be difficult to grasp at first. Keep trying, I've got faith in you!
- kybernetyk 13y agoThere's no real ID check when you sign up for a paid Apple developer account. A stolen credit card and an email address is enough.
- ryannielsen 13y agoIt was signed with a Developer ID; thus, by definition, it could not have been distributed in the store. Anything distributed through the App Store is signed by Apple. Developer ID signed binaries can only be distributed outside of the store.