[1] http://blog.off-by-one.mobi/2009/10/in-app-purchase-and-stat...
Simple And Safe In-App Purchase Using Parse
11–20 of 22 posts
Re: Simple And Safe In-App Purchase Using Parse
#12Earlier quoted context omitted.
Newsstand also includes background downloading, issue management and an issues list. Some sort of library is also needed, so users can see what they have downloaded and what is on the device. Most indie developers I know struggle with these things if they don't use a pre-packaged publishing suite, like Adobe Digital Publishing or Magster.
Thank you for the thoughtful response. I guess no, we don't have the support for these. To satisfy my curiosity, are there a lot of indy newsstand developers? Wouldn't most newsstand apps be made by larger media companies?
Re: Simple And Safe In-App Purchase Using Parse
#13Have you tested whether this is effective in eliminating jailbroken hacks? [1] In my experience, this has been the bulk of illegal transactions being made for in app purchases and its tough to validate server-side. I agree though that making the IAP process less complex is a win for developers. [1] http://blog.off-by-one.mobi/2009/10/in-app-purchase-and-stat...
Re: Simple And Safe In-App Purchase Using Parse
#14Have you tested whether this is effective in eliminating jailbroken hacks? [1] In my experience, this has been the bulk of illegal transactions being made for in app purchases and its tough to validate server-side. I agree though that making the IAP process less complex is a win for developers. [1] http://blog.off-by-one.mobi/2009/10/in-app-purchase-and-stat...
The article explains quite well what IAP makes secure and what it does not. If you are using IAP to deliver content stored on Parse, Parse's SDK (and server code) makes this process very secure. The attack goes like this:
1) the attacker fakes receipt and sends it to Parse hoping that Parse will deliver the content, 2) Parse will send the receipt to Apple and ask if the receipt is valid and indeed for the product that is being requested, 3) Apple will acknowledge that this receipt is fake or for a product not being required, 4) Parse rejects the request, and no content is delivered. Success.
However, if you are using IAP to unlock features that are already shipped with the app, IAP does not prevent against binary manipulation attacks.
-Andrew
Re: Simple And Safe In-App Purchase Using Parse
#15Is anyone familiar with how this would compare to using iOS 6's IAP content-hosting feature?
Officially we should not be commenting on iOS 6 given the non-disclosure nature of the preview. Maybe I can discuss what Parse offers that would be difficult for anyone else (Apple/Google/Amazon) to match: 1. iOS 4, iOS 5 compatibility. Today, the most common iOS development target platform is still iOS 4. Using Parse your in-app purchase will be able to work for the customers who are not on the newest iOS platform.…
I think that's incorrect unless you are not selling the content through IAP. You would still need to create an IAP product in order to complete the iTunes IAP receipt validation.
However, for most games, it's designed so users buy virtual currencies and content purchases are not directly tie in to IAP products.
Re: Simple And Safe In-App Purchase Using Parse
#16Have you tested whether this is effective in eliminating jailbroken hacks? [1] In my experience, this has been the bulk of illegal transactions being made for in app purchases and its tough to validate server-side. I agree though that making the IAP process less complex is a win for developers. [1] http://blog.off-by-one.mobi/2009/10/in-app-purchase-and-stat...
When one of my apps was pirated a few years ago, I became extremely interested in iOS security. Based on my knowledge, I can vouch for the accuracy of the article you linked to. The article explains quite well what IAP makes secure and what it does not. If you are using IAP to deliver content stored on Parse, Parse's SDK (and server code) makes this process very secure. The attack goes like this: 1) the attacker fake…
Re: Simple And Safe In-App Purchase Using Parse
#17Earlier quoted context omitted.
Officially we should not be commenting on iOS 6 given the non-disclosure nature of the preview. Maybe I can discuss what Parse offers that would be difficult for anyone else (Apple/Google/Amazon) to match: 1. iOS 4, iOS 5 compatibility. Today, the most common iOS development target platform is still iOS 4. Using Parse your in-app purchase will be able to work for the customers who are not on the newest iOS platform.…
>> 3. Hosting content on Parse requires no App Store review, thus introducing no delay/resubmission via iTunes Connect. I think that's incorrect unless you are not selling the content through IAP. You would still need to create an IAP product in order to complete the iTunes IAP receipt validation. However, for most games, it's designed so users buy virtual currencies and content purchases are not directly tie in to I…
Re: Simple And Safe In-App Purchase Using Parse
#18Earlier quoted context omitted.
When one of my apps was pirated a few years ago, I became extremely interested in iOS security. Based on my knowledge, I can vouch for the accuracy of the article you linked to. The article explains quite well what IAP makes secure and what it does not. If you are using IAP to deliver content stored on Parse, Parse's SDK (and server code) makes this process very secure. The attack goes like this: 1) the attacker fake…
Awesome, in theory this is how it should work. I'm actually more curious as to how you handle it practically though. Because for us, validating the receipt from Apple takes time, so if you are first making a request to Parse and then Parse has to make a request to Apple, the added latency poses a real threat to the user cancelling the transaction, especially on a mobile device with a crappy connection. This is why I…
Re: Simple And Safe In-App Purchase Using Parse
#19Earlier quoted context omitted.
Awesome, in theory this is how it should work. I'm actually more curious as to how you handle it practically though. Because for us, validating the receipt from Apple takes time, so if you are first making a request to Parse and then Parse has to make a request to Apple, the added latency poses a real threat to the user cancelling the transaction, especially on a mobile device with a crappy connection. This is why I…
Most of the jail broken cracks are trivial to detect client side. Otherwise... They aren't going to pay anyway, might as well make the experience better for payers and not block on validation( but still track invalid transactions). And besides, if they're willing to install a hackers DNS server and ssl cert, they won't have money for long.
Re: Simple And Safe In-App Purchase Using Parse
#20Is anyone familiar with how this would compare to using iOS 6's IAP content-hosting feature?
Officially we should not be commenting on iOS 6 given the non-disclosure nature of the preview. Maybe I can discuss what Parse offers that would be difficult for anyone else (Apple/Google/Amazon) to match: 1. iOS 4, iOS 5 compatibility. Today, the most common iOS development target platform is still iOS 4. Using Parse your in-app purchase will be able to work for the customers who are not on the newest iOS platform.…
I imagine we'll see that shift significantly in the next few months, with iOS 6 around the corner.