Live data from Hacker News

Security researcher Charlie Miller booted from Apple Developer Program

news.cnet.com

31–40 of 116 posts

Re: Security researcher Charlie Miller booted from Apple Developer Program

#31
post #22
post #17

Earlier quoted context omitted.

Developer agreements are not a security mechanism.

And security research does not trump the developer agreement. The guy submitted a real live exploit to the Joe-User facing App Store. What on earth did he expect would happen?

Maybe he expected a "thanks for showing us this vulnerability, we've pulled your app from the store and are working on a fix to the problem", as a sane response would be.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#32
post #27
post #24

Earlier quoted context omitted.

He is foolish if he did not expect this. My guess is he's doing it for the notoriety and succeeded. A job well done. Next time he either should submit a bug report to Apple or avoid using their products.

when you submit a security related bug report to apple - granted my experience dates from 99-2005 - you get: A/ ignored (mail auto reply "we might fix it, don't tell anyone or we'll go after you" B/ bug don't get fixed for 2 or 3 years C/ bug get fixed, you get no credits

I don't know why this is being downvoted. Apple is notoriously horrible at fixing vulnerabilities reported by the general public, unless they're downright critical.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#33
post #31
post #22

Earlier quoted context omitted.

And security research does not trump the developer agreement. The guy submitted a real live exploit to the Joe-User facing App Store. What on earth did he expect would happen?

Maybe he expected a "thanks for showing us this vulnerability, we've pulled your app from the store and are working on a fix to the problem", as a sane response would be.

Perhaps that is a fair point, but can you imagine the fallout if something like this ever slipped through and was downloaded by an actual user?

It is easy to see why they don't take kindly to this sort of thing.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#34
post #23
post #21

Earlier quoted context omitted.

Except that how else is he supposed to prove that it works other than actually demonstrating it with a real app on the real App Store?

It seems he was pretty sure it was going to work - there's nothing magical about the App Store, he'd found a way to get around the code signing checks. I'm sure that once the vulnerability was fixed, he'd get credit. It's just that this sort of thing won't get you in forbes. I personally don't really think there's anything at all wrong with a bit of harmless, nerdy limelight-seeking to boot, if that's what he was doi…

The problem is Apple could claim, "In our app verification process we can ensure such an exploit could never make it to the app store." The only way to test the full-scope of a vulnerability is to test it in a real world scenario, which means keeping it from Apple.

Unfortunately, I know of no other way to do it, unless companies like Apple create security groups that work with people like Charlie and give him an exemption to submit, and not notify other parties at Apple.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#35

"I don't think they've ever done this to another researcher. Then again, no researcher has ever looked into the security of their App Store. And after this, I imagine no other ones ever will," Miller said in an e-mail to CNET. "That is the really bad news from their decision." Take your wrist-slap like a man, sir. Apparently the grand are also prone to self-aggrandizement. I have a lot of respect for Miller's skills,…

He's certainly not the only researcher looking at the app store, then again, he needs to play the victim a little bit right now if he wants to get public support. Public support and media attention may very well be his only ticket back into the developer program.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#36
There's always this flip-side to reporting security findings. I don't know the details of Charlie Millers exploit, however had he gone through the process of informing the vendor (in this case Apple) and then allowing sufficient time to address the issue, perhaps a showdown could have been avoided (I'm assuming that he hadn't).

People however, also forget that, there are other pressures facing info-sec researchers - such as pressure from management at the company where they work to 'publish' and/or present their findings under the company banner. Often, this irks vendors, because vulnerabilities are used to promote the researcher's (or who they work for) interests.

That said, Microsoft, Google and Facebook have very transparent processes & expectations for submitting vulnerabilities.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#37

He's got great skills, and NSA training is as good as it gets, but he explicitly violated the rule to not download and run code from a server, to see if the rule would be enforced. They enforced it, just as he'd known they would. There was no point to his doing that other than to get headlines.

No, he explicitly violated the rule in order to test the hypothesis that a security hole he'd uncovered would allow unsigned code to be downloaded after release into the app store and run on the device. The sane response to this would be "Oh, we better fix that. Thanks. We're removing your app BTW." The Apple response was typical of a bureaucracy.

But he did more than just test it and remove the app from the store. He left it up there and people presumably were downloading it. Another Forbes article[1] says:

> But the researcher for the security consultancy Accuvant argues that he was only trying to demonstrate a serious security issue with a harmless demo, and that revoking his developer rights is “heavy-handed” and counterproductive.

But as he demonstrated in his YouTube video it wasn't just a harmless demo, he had a shell that he could run on anyone's phone who downloaded his app.

Further, he didn't even have to put it up for sale at all except to perform his publicity stunt. The code signing aspect doesn't change when you are developing on your device locally. He could have submitted the app and not even put it up for sale at all. If the exploit worked in dev it would work on the store, and if they approved it he really didn't have to test it at all. Of course he's a curious guy - I think we can all relate to and appreciate that - so he could have chosen not to release it to the store on approval, then if approved put it up for sale only long enough to try it out, and then removed it from sale again.

I don't agree that they should have terminated his account, but neither are they really that out of line in doing so. I also don't think he would have opened a shell to anyone else's phone but the fact remains that he still had the ability to do so.

[1] http://www.forbes.com/sites/andygreenberg/2011/11/07/apple-e...

Re: Security researcher Charlie Miller booted from Apple Developer Program

#38
post #33
post #31

Earlier quoted context omitted.

Maybe he expected a "thanks for showing us this vulnerability, we've pulled your app from the store and are working on a fix to the problem", as a sane response would be.

Perhaps that is a fair point, but can you imagine the fallout if something like this ever slipped through and was downloaded by an actual user? It is easy to see why they don't take kindly to this sort of thing.

All kinds of nasty things have slipped through to the users. There have been multiple remote root exploits for iOS in the wild for weeks at a time and nobody really cared. There would be no fallout.

I agree that it's easy to see why they don't take kindly to this sort of thing, but it should also be easy to see why they should take kindly to it.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#39
post #11

It's a bad move for apple. A good relationship with the community of security researchers is crucial - they're talented folks and their research results grab headlines. It takes just a tiny amount of corporate humility and public thanks to win their respect, and in return get goodwill. Treating the community badly will get ensure the next guy won't even try to cooperate. Over the last several years, Microsoft's MSRC…

Hold on here. Is Apple expected to know Charlie Miller is a "security guru", and even if they did, why should he be treated any differently? Security researchers should be held to the same standard as regular developers when reporting bugs/flaws. RTM was convicted of a crime because of his curiosity, and here we have a security researcher who knowingly put users at risk. You ask me, Mr Miller got off lightly.

He did not put users at risk. This vulnerability allows apps to download and execute new code, but that new code is still subject to the app's sandbox. This vulnerability is interesting from a research standpoint, but has zero actual consequences to the security of iOS.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#40
post #19
post #11

It's a bad move for apple. A good relationship with the community of security researchers is crucial - they're talented folks and their research results grab headlines. It takes just a tiny amount of corporate humility and public thanks to win their respect, and in return get goodwill. Treating the community badly will get ensure the next guy won't even try to cooperate. Over the last several years, Microsoft's MSRC…

I'd agree more if he didn't submit — and get approved — a working exploit in their store. Without telling them about it. Edit: Now, I don't disagree that just banning him from the program isn't a great idea, and that pulling the app and having someone from the security team send him an email isn't a better one. But it's hard to say this that a bad move on Apple's part.

This hardly qualifies as an exploit. While it allows the app to do something it's not supposed to do, the ability to download and execute additional executable code doesn't actually violate security. The new code is still restricted to the app's sandbox and can't do anything that the original app couldn't potentially have done directly.
Post reply on HN