Live data from Hacker News

Apple Developer Website Update

news.ycombinator.com

181–190 of 223 posts

Re: Apple Developer Website Update

#181

Earlier quoted context omitted.

It's a strange world we live in when every time we're told by a big corp that our personal info was compromised, we're grateful for being told. This is the worlds most cashed-up corporation. They could buy entire countries, yet they made a conscious choice not to update their server software or hire more competent sys-admins. There shouldn't be a way for them to gain marketing wins out of this. There should be a law…

This isn't about marketing. It's about a security breach. And security breaches take time (> 2 days) to properly investigate and report. It's entirely possible that this is a massive oversight by Apple and they've been extremely negligent in their security policies. It's equally possible that there's some bug (that either you or I could easily have made the mistake of introducing) that's resulted in this being possib…

> if it turns out to be negligence on Apple's part, I'll be very angry

I doubt you'll need to get angry - because if it's negligence, you/we won't be told.

Re: Apple Developer Website Update

#182
post #93
post #70

Earlier quoted context omitted.

"why companies tells us DAYS after something serious happened" Companies are people. And all the relevant parties involved in handling this may not be accessible to make a decision as quickly as needs to be done. Or at least quickly enough to satisfy all people. Do you feel you suffered any harm in particular by the delay of three days?

I'm mainly complaining about the delay in telling us anything. What I would love is an update whenever they suspect an intruder has accessed sensitive information. Many websites like Dropbox and last.fm do have a server status where they tell us if they have any planned maintenance or just general status of the server. Why can't Apple and the rest of the big companies do that? Also, Apple first said it was just regul…

Likely because if you say "we are investigating a possible data leak" and then end with "we discovered it was an undocumented maintenance event by someone on the engineering staff, we have added more detailed logging as well as a better maintenance process so we can be clear about this in the future", many people will think the worst. It's unfortunate.

Re: Apple Developer Website Update

#184

> Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers’ names, mailing addresses, and/or email addresses may have been accessed. So they can't rule out the possibility that sensitive personal information, which cannot be accessed, has been accessed. Got it. Apparently our intelligence, which cannot be insulted, has been in…

Alternately, inside the reality distortion field developers’ names, mailing addresses, and/or email addresses is not sensitive personal information.

If by "reality distortion field," you mean the legal community, then yes. Having been through something similar recently, the lawyers will likely be making sure everyone involved understands the concept of PII: https://en.wikipedia.org/wiki/Personally_identifiable_inform...

Re: Apple Developer Website Update

#185

> Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers’ names, mailing addresses, and/or email addresses may have been accessed. So they can't rule out the possibility that sensitive personal information, which cannot be accessed, has been accessed. Got it. Apparently our intelligence, which cannot be insulted, has been in…

Alternately, inside the reality distortion field developers’ names, mailing addresses, and/or email addresses is not sensitive personal information.

One of the understood requirements of publishing an app on the App Store is that developers must provide some means for customers to contact them directly (support page, email address, etc). If you're selling apps on the app store, people can already peddle their wares to your email account.

So yeah, developer's names, addresses and emails are not secrets by any means. Why would anyone buy an app from someone they had no means of identifying?

Re: Apple Developer Website Update

#186
For what it's worth, Wednesday morning at 4am I had an email account associated with my developer account compromised(they both stupidly used the same password). This account was used for almost nothing but accessing my developer accounts at Apple. At the time, I thought my Apple accounts might be in trouble and I immediately changed all my Apple related passwords as well as regained control of my email account. I'm now wondering if the breach might have gone the other direction...

Re: Apple Developer Website Update

#187

Here's my semi-educated guess for how the attack started: from casual observation (view source, URLs ending with .action, etc) a good chunk of the ADC is written in Java and uses WebWork/Struts2, a framework I helped create years ago. Late last week a security advisory came out that allows for executing malicious code[1]. Atlassian, which uses similar technology, also issued announcements around the same time[2]. My…

So what you're saying is that it's your fault that I can't update my provisioning profile? No just kidding--Honestly, while you may feel responsible, the project has been up and running for a while. The current maintainers are responsible for the bugs that show up regardless of who designed the original code base. Definitely appreciate you shedding light on the situation since Apple hasn't really given us to much information.

Re: Apple Developer Website Update

#188

Here's my semi-educated guess for how the attack started: from casual observation (view source, URLs ending with .action, etc) a good chunk of the ADC is written in Java and uses WebWork/Struts2, a framework I helped create years ago. Late last week a security advisory came out that allows for executing malicious code[1]. Atlassian, which uses similar technology, also issued announcements around the same time[2]. My…

So what you're saying is that it's your fault that I can't update my provisioning profile? No just kidding--Honestly, while you may feel responsible, the project has been up and running for a while. The current maintainers are responsible for the bugs that show up regardless of who designed the original code base. Definitely appreciate you shedding light on the situation since Apple hasn't really given us to much inf…

Both are responsible, and responsibility can add up to more than 100%.

Re: Apple Developer Website Update

#189

For what it's worth, Wednesday morning at 4am I had an email account associated with my developer account compromised(they both stupidly used the same password). This account was used for almost nothing but accessing my developer accounts at Apple. At the time, I thought my Apple accounts might be in trouble and I immediately changed all my Apple related passwords as well as regained control of my email account. I'm…

At the time I re-secured the two accounts, I also changed my apple developer account to a new email with 2-factor auth. Apple is still sending these announcements to the email I changed >72 hours ago.

Re: Apple Developer Website Update

#190

Earlier quoted context omitted.

So what you're saying is that it's your fault that I can't update my provisioning profile? No just kidding--Honestly, while you may feel responsible, the project has been up and running for a while. The current maintainers are responsible for the bugs that show up regardless of who designed the original code base. Definitely appreciate you shedding light on the situation since Apple hasn't really given us to much inf…

Both are responsible, and responsibility can add up to more than 100%.

I think we, as a society, are ultimately to blame.
Post reply on HN