Live data from Hacker News

Security researcher Charlie Miller booted from Apple Developer Program

news.cnet.com

41–50 of 116 posts

Re: Security researcher Charlie Miller booted from Apple Developer Program

#41
post #21
post #10

Earlier quoted context omitted.

Putting the exploit in the App Store isn't particularly polite either and doesn't seem to serve any purpose other than generating some publicity for the researcher. It'd be different if he believed Apple wasn't going to fix it or that the exploit was being used or was about to be used in malicious apps - but he doesn't claim that was his motivation.

Except that how else is he supposed to prove that it works other than actually demonstrating it with a real app on the real App Store?

I agree. To demonstrate an exploits effectiveness - it has to be exploited in a realistic situation (in this case the app store).

Re: Security researcher Charlie Miller booted from Apple Developer Program

#42
post #32
post #27

Earlier quoted context omitted.

when you submit a security related bug report to apple - granted my experience dates from 99-2005 - you get: A/ ignored (mail auto reply "we might fix it, don't tell anyone or we'll go after you" B/ bug don't get fixed for 2 or 3 years C/ bug get fixed, you get no credits

I don't know why this is being downvoted. Apple is notoriously horrible at fixing vulnerabilities reported by the general public, unless they're downright critical.

"Unless they're downright critical or enable jailbreaking", you mean.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#43

Earlier quoted context omitted.

I think the risk is primarily bad press. It's not really a "security hole" for apps to add additional runnable code from an external website, when apps can currently contain pretty much anything at all (as long as they don't link to forbidden symbols). Remember that Apple does not see source code, and relies completely on app developers to behave, beyond a few perfunctory checks. And Apple has made it abundantly clea…

The downside is poorer security, which could blow up in their face spectacularly at some point in the future.

I really doubt it. To be blunt, Apple is an existence proof that security on consumer products doesn't provide business value in proportion to its cost. Keeping users safe is seldom worth investing in.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#46
post #40
post #19

Earlier quoted context omitted.

I'd agree more if he didn't submit — and get approved — a working exploit in their store. Without telling them about it. Edit: Now, I don't disagree that just banning him from the program isn't a great idea, and that pulling the app and having someone from the security team send him an email isn't a better one. But it's hard to say this that a bad move on Apple's part.

This hardly qualifies as an exploit. While it allows the app to do something it's not supposed to do, the ability to download and execute additional executable code doesn't actually violate security. The new code is still restricted to the app's sandbox and can't do anything that the original app couldn't potentially have done directly.

It easily qualifies as an exploit, given that Apple's app store model is based on the fact that each app is reviewed beforehand to ensure various properties, including the property that the app does not contain spyware, etc. If Apple approved a harmless app, and then said app downloaded code that snooped on the user's calls or asked for their credit card number, that's an exploit.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#47
post #39

Earlier quoted context omitted.

Hold on here. Is Apple expected to know Charlie Miller is a "security guru", and even if they did, why should he be treated any differently? Security researchers should be held to the same standard as regular developers when reporting bugs/flaws. RTM was convicted of a crime because of his curiosity, and here we have a security researcher who knowingly put users at risk. You ask me, Mr Miller got off lightly.

He did not put users at risk. This vulnerability allows apps to download and execute new code, but that new code is still subject to the app's sandbox. This vulnerability is interesting from a research standpoint, but has zero actual consequences to the security of iOS.

That's not how it's being explained in the popular press.

http://www.forbes.com/sites/andygreenberg/2011/11/07/iphone-...

Re: Security researcher Charlie Miller booted from Apple Developer Program

#48
post #22
post #17

Earlier quoted context omitted.

Developer agreements are not a security mechanism.

And security research does not trump the developer agreement. The guy submitted a real live exploit to the Joe-User facing App Store. What on earth did he expect would happen?

He didn't do anything harmful though. He just demonstrated the capability.

It's the equivalent of making a word document pop up calc.exe. This proves that you've broken the security, but doesn't cause harm.

You have to actually do it to be taken seriously, especially with unreceptive vendors like Apple.

There is really no reason to behave in a hostile way towards a researcher that does this. He's telling you about the problem.

In the security industry, there are many people who seek and find vulnerabilities. Some of them report them, and some of them keep them private and exploit them secretly to attack people's property, or privately sell to others who do the same. Selling these to the underground is big business now.

Let's subtract the people who report things from the above equation (because we ban and vilify them). Now what does your ecosystem look like?

Dumb move, Apple. Dumb move.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#49
post #39

Earlier quoted context omitted.

Hold on here. Is Apple expected to know Charlie Miller is a "security guru", and even if they did, why should he be treated any differently? Security researchers should be held to the same standard as regular developers when reporting bugs/flaws. RTM was convicted of a crime because of his curiosity, and here we have a security researcher who knowingly put users at risk. You ask me, Mr Miller got off lightly.

He did not put users at risk. This vulnerability allows apps to download and execute new code, but that new code is still subject to the app's sandbox. This vulnerability is interesting from a research standpoint, but has zero actual consequences to the security of iOS.

Surely you don't think that having arbitrary code placed within the IOS AppStore isn't a security risk do you? Once malicious code has been approved in the store an attacker need only find a way to break out of the sandbox, which I am sure is possible.

Re: Security researcher Charlie Miller booted from Apple Developer Program

#50
post #43

Earlier quoted context omitted.

The downside is poorer security, which could blow up in their face spectacularly at some point in the future.

I really doubt it. To be blunt, Apple is an existence proof that security on consumer products doesn't provide business value in proportion to its cost. Keeping users safe is seldom worth investing in.

[deleted]
Post reply on HN