Apple Developer Website Update
31–40 of 223 posts
Re: Apple Developer Website Update
#32Earlier quoted context omitted.
+1
Same. It'd be helpful if they'd have a permalink for the email, as I'd imagine a lot of developers (including myself) have/will post to hacker news.
Re: Apple Developer Website Update
#33Hmm so it only takes a few days to "completely overhaul" their developer systems? Not sure I believe this is what they're actually doing. And why haven't they updated their server software before? I know mistakes can never be completely avoided, but this seems slightly amateurish for a company with so much cash.
They've already been down a few days and haven't said when they'll be back up so it's impossible to know yet how long it'll take.
Re: Apple Developer Website Update
#34Re: Apple Developer Website Update
#35If the intruder is a patent troll-er, getting developers’ names and mailing addresses can be pretty harmful.
Re: Apple Developer Website Update
#36> Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers’ names, mailing addresses, and/or email addresses may have been accessed. So they can't rule out the possibility that sensitive personal information, which cannot be accessed, has been accessed. Got it. Apparently our intelligence, which cannot be insulted, has been in…
Re: Apple Developer Website Update
#37Re: Apple Developer Website Update
#38Well at least it was "only" the dev center, and not iCloud and iMessage!
Re: Apple Developer Website Update
#39> Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers’ names, mailing addresses, and/or email addresses may have been accessed. So they can't rule out the possibility that sensitive personal information, which cannot be accessed, has been accessed. Got it. Apparently our intelligence, which cannot be insulted, has been in…
Re: Apple Developer Website Update
#40Earlier quoted context omitted.
That's not a long time to receive a letter like this. That's as fast as Apple instantly responds to anything, esp. considering the weekend. And the site was down, so it was clear something was going on. It is also extremely transparent in the sense that people were wondering this exact thing even earlier today, and now received a response detailing that this is an extremely severe breach, as opposed to something else…
Well I'm giving them a hard time due to the massive schadenfreude, obviously. Still, this is very vague about what the 'sensitive personal information' is (passwords?), what was encrypted, what was hashed, was it using a proper hashing scheme, etc. And announcing it just because people have started to speculate is damage control, not taking responsibility.
It's possible it took them a few days to figure out exactly what was taken and waited until they had as much info as possible to make a statement. I doubt Apple would be following blogs during a situation like this with someone making the decision: "oh, people have started to speculate about what's happening - I think we should make a statement."