Live data from Hacker News

Security researcher Charlie Miller booted from Apple Developer Program

news.cnet.com

11–20 of 116 posts

Re: Security researcher Charlie Miller booted from Apple Developer Program

#11
It's a bad move for apple. A good relationship with the community of security researchers is crucial - they're talented folks and their research results grab headlines. It takes just a tiny amount of corporate humility and public thanks to win their respect, and in return get goodwill. Treating the community badly will get ensure the next guy won't even try to cooperate.

Over the last several years, Microsoft's MSRC has balanced this very well. Google has done well recently, too. Lots of clued-in people in both places.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#12
post #9
post #4

Earlier quoted context omitted.

The situation is only understandable from a 'blindly following the rules' perspective. If Apple makes it 'illegal' to probe their AppStore, then only black hats will be the ones doing the probing. How are you supposed to test whether or not Apple will discover a vulnerability during their AppStore approval process if you are going to tell them that one exists?

In this case, he didn't only probe the approval process, but he also released the app containing the exploit into the store for public consumption. Apple's process allows for submitting an app for approval without releasing it into the store once it has been approved.

If the exploit potentially allows downloading and running of unsigned code after release in the app store, how else could one prove that it is in fact a hole, other than by releasing it into the app store to confirm the behavior?

Re: Security researcher Charlie Miller booted from Apple Developer Program

#13

"I don't think they've ever done this to another researcher. Then again, no researcher has ever looked into the security of their App Store. And after this, I imagine no other ones ever will," Miller said in an e-mail to CNET. "That is the really bad news from their decision." Take your wrist-slap like a man, sir. Apparently the grand are also prone to self-aggrandizement. I have a lot of respect for Miller's skills,…

Downrank all you want. Nothing about this move means "Apple now has a bad relationship with security researchers." It just means Apple doesn't want Charlie Miller showing people how to side-load arbitrary code into their sheeps'-clothing apps.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#14
He's got great skills, and NSA training is as good as it gets, but he explicitly violated the rule to not download and run code from a server, to see if the rule would be enforced. They enforced it, just as he'd known they would. There was no point to his doing that other than to get headlines.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#15

He's got great skills, and NSA training is as good as it gets, but he explicitly violated the rule to not download and run code from a server, to see if the rule would be enforced. They enforced it, just as he'd known they would. There was no point to his doing that other than to get headlines.

No, he explicitly violated the rule in order to test the hypothesis that a security hole he'd uncovered would allow unsigned code to be downloaded after release into the app store and run on the device.

The sane response to this would be "Oh, we better fix that. Thanks. We're removing your app BTW." The Apple response was typical of a bureaucracy.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#18
post #3

Earlier quoted context omitted.

That's a bit too charitable to Apple, I think. Yes, the decision is covered by the terms of the agreement - they can do what they did. But since the result of their decision is 1) bad press and 2) increased risk of security holes, it's not "understandable" unless you think Apple is run by morons...

I think the risk is primarily bad press. It's not really a "security hole" for apps to add additional runnable code from an external website, when apps can currently contain pretty much anything at all (as long as they don't link to forbidden symbols). Remember that Apple does not see source code, and relies completely on app developers to behave, beyond a few perfunctory checks. And Apple has made it abundantly clea…

The downside is poorer security, which could blow up in their face spectacularly at some point in the future.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#19
post #11

It's a bad move for apple. A good relationship with the community of security researchers is crucial - they're talented folks and their research results grab headlines. It takes just a tiny amount of corporate humility and public thanks to win their respect, and in return get goodwill. Treating the community badly will get ensure the next guy won't even try to cooperate. Over the last several years, Microsoft's MSRC…

I'd agree more if he didn't submit — and get approved — a working exploit in their store. Without telling them about it.

Edit: Now, I don't disagree that just banning him from the program isn't a great idea, and that pulling the app and having someone from the security team send him an email isn't a better one. But it's hard to say this that a bad move on Apple's part.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#20
post #11

It's a bad move for apple. A good relationship with the community of security researchers is crucial - they're talented folks and their research results grab headlines. It takes just a tiny amount of corporate humility and public thanks to win their respect, and in return get goodwill. Treating the community badly will get ensure the next guy won't even try to cooperate. Over the last several years, Microsoft's MSRC…

A few points:

1. This "guy" apparently didn't try very hard, at all, to cooperate, as evidenced by him putting the exploit itself in the App Store before notifying Apple about it, in direct violation of the dev guidelines.

What good is it to have such guidelines at all if you display in public that you won't enforce them?

2. Microsoft is doing a great job at this? So are we to assume that their security is therefore superior?

3. There are a few clued-in people at Apple, too.

Post reply on HN