Live data from Hacker News

Security researcher Charlie Miller booted from Apple Developer Program

news.cnet.com

1–10 of 116 posts

Re: Security researcher Charlie Miller booted from Apple Developer Program

#2
It’s rude when according to the article he withheld details of the exploit to give Apple time to fix the bug, but the decision is understandable since he did violate the developer agreement. I’m not so sure about “interfering with Apple's software and services” but his activites seem to be covered under “hiding features from [Apple] when submitting them.”

Re: Security researcher Charlie Miller booted from Apple Developer Program

#3
post #2

It’s rude when according to the article he withheld details of the exploit to give Apple time to fix the bug, but the decision is understandable since he did violate the developer agreement. I’m not so sure about “interfering with Apple's software and services” but his activites seem to be covered under “hiding features from [Apple] when submitting them.”

That's a bit too charitable to Apple, I think. Yes, the decision is covered by the terms of the agreement - they can do what they did. But since the result of their decision is 1) bad press and 2) increased risk of security holes, it's not "understandable" unless you think Apple is run by morons...

Re: Security researcher Charlie Miller booted from Apple Developer Program

#4
post #2

It’s rude when according to the article he withheld details of the exploit to give Apple time to fix the bug, but the decision is understandable since he did violate the developer agreement. I’m not so sure about “interfering with Apple's software and services” but his activites seem to be covered under “hiding features from [Apple] when submitting them.”

The situation is only understandable from a 'blindly following the rules' perspective. If Apple makes it 'illegal' to probe their AppStore, then only black hats will be the ones doing the probing.

How are you supposed to test whether or not Apple will discover a vulnerability during their AppStore approval process if you are going to tell them that one exists?

Re: Security researcher Charlie Miller booted from Apple Developer Program

#6
post #3
post #2

It’s rude when according to the article he withheld details of the exploit to give Apple time to fix the bug, but the decision is understandable since he did violate the developer agreement. I’m not so sure about “interfering with Apple's software and services” but his activites seem to be covered under “hiding features from [Apple] when submitting them.”

That's a bit too charitable to Apple, I think. Yes, the decision is covered by the terms of the agreement - they can do what they did. But since the result of their decision is 1) bad press and 2) increased risk of security holes, it's not "understandable" unless you think Apple is run by morons...

I think the risk is primarily bad press. It's not really a "security hole" for apps to add additional runnable code from an external website, when apps can currently contain pretty much anything at all (as long as they don't link to forbidden symbols). Remember that Apple does not see source code, and relies completely on app developers to behave, beyond a few perfunctory checks.

And Apple has made it abundantly clear that they don't care about bad PR in the security community. So there's really no downside to cutting out Charlie Miller, in Apple's eyes. The winner here is Charlie Miller's career.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#7
"I don't think they've ever done this to another researcher. Then again, no researcher has ever looked into the security of their App Store. And after this, I imagine no other ones ever will," Miller said in an e-mail to CNET. "That is the really bad news from their decision."

Take your wrist-slap like a man, sir.

Apparently the grand are also prone to self-aggrandizement. I have a lot of respect for Miller's skills, but he's not the only smart person taking a hard look at App Store security.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#9
post #4
post #2

It’s rude when according to the article he withheld details of the exploit to give Apple time to fix the bug, but the decision is understandable since he did violate the developer agreement. I’m not so sure about “interfering with Apple's software and services” but his activites seem to be covered under “hiding features from [Apple] when submitting them.”

The situation is only understandable from a 'blindly following the rules' perspective. If Apple makes it 'illegal' to probe their AppStore, then only black hats will be the ones doing the probing. How are you supposed to test whether or not Apple will discover a vulnerability during their AppStore approval process if you are going to tell them that one exists?

In this case, he didn't only probe the approval process, but he also released the app containing the exploit into the store for public consumption. Apple's process allows for submitting an app for approval without releasing it into the store once it has been approved.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#10
post #2

It’s rude when according to the article he withheld details of the exploit to give Apple time to fix the bug, but the decision is understandable since he did violate the developer agreement. I’m not so sure about “interfering with Apple's software and services” but his activites seem to be covered under “hiding features from [Apple] when submitting them.”

Putting the exploit in the App Store isn't particularly polite either and doesn't seem to serve any purpose other than generating some publicity for the researcher. It'd be different if he believed Apple wasn't going to fix it or that the exploit was being used or was about to be used in malicious apps - but he doesn't claim that was his motivation.
Post reply on HN