Live data from Hacker News

How to submit an app to Apple’s App Store when it uses encryption

carouselapps.com

81–90 of 120 posts

Re: How to submit an app to Apple’s App Store when it uses encryption

#81

Don't you wish you hadn't surrendered software distribution authority to a single faceless corporate party? When nobody tried to demand bullshit crypto paperwork? Remember when you could distribute software yourself without getting threatened[1]? Remember when platform vendors didn't take a 30% cut of everything you earned just because they wrote an OS? Not even Microsoft was that evil. I hope you enjoy the world you…

This is unrelated to Apple and it's AppStore. Even if you sold this on your own, you'd be subject to the same rules. https://www.bis.doc.gov/index.php/policy-guidance/encryption

There is an important difference, though. Small companies and individuals often fly under the radar of wacky bureaucratic rules like this, whereas big companies are more visible and are stuck with them. By routing all the small-timers through a big company, they can no longer do that.

You might say, small companies should be following these rules regardless so this is just as well. And I'd probably agree. But it's still a pretty big difference.

Re: How to submit an app to Apple’s App Store when it uses encryption

#82
post #5
post #2

Last year I learned that to publish an app in the App Store or Mac App Store, if it uses encryption of any kind and yes, HTTPS and SSL count, you need an Encryption Registration (ERN) from the US Bureau of Industry (BIS). Some people claim it's fine to lie to Apple, claim no use of encryption and get in the app store. I'd rather do it the right way. When I started the process of getting the ERN, I quickly notice it w…

Holy crap that is a bureaucratic nightmare. Why does encryption even need to be registered in the first place? I don't see any point beyond the holdover of 'encryption is munitions' which is a pile of crap in the first place.

Bureaucratic nightmare? Don't you think that's an exaggeration? Sure, the government's web site UX is atrocious, but at the end of the day, it's just a couple of web forms and E-mail verification, similar to signing up for any web site. Try to legally immigrate to the U.S. and then come back and tell me that this web site is a "bureaucratic nightmare".

Re: How to submit an app to Apple’s App Store when it uses encryption

#83
post #40

Earlier quoted context omitted.

We continue to need to bear arms of all sorts, equal to those that the military uses. As you pointed out, the purpose of the 2nd amendment was to avoid tyranny in a powerful central government. As long as the (federally funded & led) military uses firearms, responsible civilians _must_ also keep & bear them.

The purpose of the second amendment was to avoid tyranny in a powerful central government _over the individual states_. The current (2008) Supreme Court interpretation of the second amendment is controversial because it largely ignores the "well regulated militia" text.[0] [0] https://en.wikipedia.org/wiki/Second_Amendment_to_the_United...

Interpreting the "well regulated militia" text as limiting the right to state militias is an anachronistic, twentieth century attempt to read modern sensibilities into the text. In the eighteenth and nineteenth centuries it wasn't even a debate: the right of individuals to bear arms was understood simply to be the manifestation of their natural right to self defense. Consider texts contemporaneous with the constitution and written in similar places:

Pennsylvania State Constitution, 1776: "The right of the citizens to bear arms in defense of themselves and the State shall not be questioned."

New Hampshire State Constitution, 1783: "All persons have the right to keep and bear arms in defense of themselves, their families, their property and the state."

And, of course, the second amendment itself: "A well regulated militia being necessary to the security of a free state, the right of the people to keep and bear arms shall not be infringed."

Re: How to submit an app to Apple’s App Store when it uses encryption

#84

Not specific to Apple. Same thing has to be done for any other app store, like Google's. Some mentioned that there is an exception if you use OS libraries for encryption. I think that's not the case, but I think using some third party SDKs like Game Center (for which I guess the providers did the paper work) is excepted.

> any other app store, like Google's

Not sure. This looks like a US-centric, bureaucratic thing. I doubt that F-Droid https://f-droid.org/ requires this kind of nonsense when submitting apps.

Re: How to submit an app to Apple’s App Store when it uses encryption

#85
post #40

Earlier quoted context omitted.

We continue to need to bear arms of all sorts, equal to those that the military uses. As you pointed out, the purpose of the 2nd amendment was to avoid tyranny in a powerful central government. As long as the (federally funded & led) military uses firearms, responsible civilians _must_ also keep & bear them.

If that is so, then we have already lost. No firearm held by the citizens can compete with the firepower of the military of today. The spirit of the amendment may have been in the right place and surely worked when the constitution was written but we live in a very different world now and if you still think the an armed citizenry will avoid tyranny, you need to go to youtube and see what the military can now do.

What citizens lack in firepower they make up in numbers. Just the 12.5 million registered hunters in the United States exceed the number of active duty military by an order of magnitude.

There is no possible way that the military of today, with all its tanks and bombs and drones and planes, could even attempt to hold any large portion of America under martial law.

Re: How to submit an app to Apple’s App Store when it uses encryption

#86
post #3
post #2

Last year I learned that to publish an app in the App Store or Mac App Store, if it uses encryption of any kind and yes, HTTPS and SSL count, you need an Encryption Registration (ERN) from the US Bureau of Industry (BIS). Some people claim it's fine to lie to Apple, claim no use of encryption and get in the app store. I'd rather do it the right way. When I started the process of getting the ERN, I quickly notice it w…

Are you sure HTTPS counts? That seems insane to me.

Yes, it does. I talked to legal as well as export compliance department at Apple and they confirmed this. Maybe they were being overly cautious but so was I.

With HTTPS, what puts you clearly out of every potential exception, is the fact that you are encrypting the requests. Someone asked about this in the blog and I replied with more information.

Re: How to submit an app to Apple’s App Store when it uses encryption

#87
post #84

Not specific to Apple. Same thing has to be done for any other app store, like Google's. Some mentioned that there is an exception if you use OS libraries for encryption. I think that's not the case, but I think using some third party SDKs like Game Center (for which I guess the providers did the paper work) is excepted.

> any other app store, like Google's Not sure. This looks like a US-centric, bureaucratic thing. I doubt that F-Droid https://f-droid.org/ requires this kind of nonsense when submitting apps.

Yeah, that's true. I meant US company app stores. But some other countries have these kinds of rules. I know of France.

Re: How to submit an app to Apple’s App Store when it uses encryption

#88
post #84

Not specific to Apple. Same thing has to be done for any other app store, like Google's. Some mentioned that there is an exception if you use OS libraries for encryption. I think that's not the case, but I think using some third party SDKs like Game Center (for which I guess the providers did the paper work) is excepted.

> any other app store, like Google's Not sure. This looks like a US-centric, bureaucratic thing. I doubt that F-Droid https://f-droid.org/ requires this kind of nonsense when submitting apps.

[deleted]

Re: How to submit an app to Apple’s App Store when it uses encryption

#89
post #34

Earlier quoted context omitted.

I would have thought this covered https.

I'm pretty sure "limited to authentication" means that the data is transmitted in the clear but covered by a signature. HTTPS actually encrypts, so it wouldn't count.

Could you not also argue that ongoing use of HTTPS after authenticating yourself with the server is to ensure the response is coming from who you intend (i.e., the server authenticating itself to you)?

Re: How to submit an app to Apple’s App Store when it uses encryption

#90
post #63
post #45

Earlier quoted context omitted.

This seems to be only for US based developers, I can't remember having to fill in more then a handful of radio buttons regarding crypto when I submitted an iOS app as a Dutch developer.

Nope, this is for everyone. Apple is exporting your app from US, so they need this paperwork from you. The only other options are: * send Apple a paper promising that you will only distribute your app in US and Canada stores, discarding all other markets. * make your encryption use insecure 64-bit keys. * make your complete app open source. * (some other options, such as when using encryption only for authentication)…

Only US citizens are likely vulnerable to the attempts to fine though.
Post reply on HN