Live data from Hacker News

Apple Developer Website Update

news.ycombinator.com

211–220 of 223 posts

Re: Apple Developer Website Update

#211
post #166

Earlier quoted context omitted.

>What I find slightly unnerving is that Apple didn't make this clearer. Apple is not a startup. They were ranked 6th in Fortune 500 for 2013. They are going to be rehearsed, political, and vague with their descriptions. Were you actually expecting them to release a postmortem on their blog with a link to the GitHub repo with the fix?

Sure, but I don't think it's a bad idea to raise the median level of expected standards. It seems reasonable to ask for clearer reports and some kind of a postmortem. One of the hopes for the notion of startups searching / optimizing in these kinds of niche spaces (transparency, communication on a more personal / no-bullshit level, whatnot) might be that these kinds of optimizations will hopefully change what is to b…

If they say X wasn't leaked while it was, they will open themselves for litigation. A company of Apple's size cannot afford to make mistakes there. So, they have to put in weasel words such as "such as".

Also, this isn't a postmortem (yes, we may never see one, it is premature to comment on that _now_)

Re: Apple Developer Website Update

#212
post #204
post #200

Earlier quoted context omitted.

Why?

Credit cards can be cancelled. Home addresses plus other information could be valuable to identity thieves. Maybe it's not that big a deal, but the idea of hackers (criminals?) knowing my name, email and home address seems a bit creepy.

Perhaps if it were a case of a targeted attack I'd agree Identity theft etc doesn't really scale as well as credit card fraud.

Re: Apple Developer Website Update

#217

Earlier quoted context omitted.

I think we, as a society, are ultimately to blame.

I think the human being, as imperfect, is finally to blame.

Are you people out of your mind? The person responsible for this is the unethical human being(or organization) that decided to abuse that security hole and use it to steal our information. Not the engineers, not Apple.

When you see an old lady walking alone in the dark, do you steal her purse because she did not protect herself well enough? I'm sure you don't... So please, don't over complicate things.

Re: Apple Developer Website Update

#218
I can't feel too bad for Apple. They use WW/Struts but when was the last time they contributed to the project? They never have. Open source volunteers do their best but unless big corporations want to spend their own money, and do their own security assessments, and contribute back anything they find, what do you expect? It's great when you get things for free, but when you're sitting on billions, send some back to the community you're using code from.

Re: Apple Developer Website Update

#219

Here's my semi-educated guess for how the attack started: from casual observation (view source, URLs ending with .action, etc) a good chunk of the ADC is written in Java and uses WebWork/Struts2, a framework I helped create years ago. Late last week a security advisory came out that allows for executing malicious code[1]. Atlassian, which uses similar technology, also issued announcements around the same time[2]. My…

technology choices tend to stick around a lot longer than you ever imagine :) It amazes me how true this is. I've learned that assertions such as "this is a mockup and should be replaced ASAP for reasons X Y Z" tend to get ignored by inheritors of proofs-of-concepts for as long as (or longer than) possible. My coworkers wonder why now I fight tooth-and-nail to (from their perspective) over-engineer things from the st…

This is the biggest reason that I hate all of the "go fast and break things" culture around here. There has to be a balance, but big names and investors don't seem to be encouraging them.

Re: Apple Developer Website Update

#220

Earlier quoted context omitted.

They said sensitive information is encrypted and can't be accessed, my interpretation of that is that the plain text can't be accessed but attackers may have the encrypted sensitive information (eg passwords). Depending on the strength of their encryption though, and the key used etc etc.. it might be perfectly accessible. In the absense of transparency on actual encryption details, you're probably better off assumin…

"Depending on the strength of their encryption though, and the key used" I trust that Apple is competent when it comes to encryption at this point. I agree that the statement was ambiguous as to whether the data was actually taken.

Hopefully, but from the comments this an old, hacky system based on old software with critical software vulnerabilities. I don't imagine their encryption reflects that, but until it's clarified it's probably better to assume it does.
Post reply on HN