Earlier quoted context omitted.
And security research does not trump the developer agreement. The guy submitted a real live exploit to the Joe-User facing App Store. What on earth did he expect would happen?
Maybe he expected a "thanks for showing us this vulnerability, we've pulled your app from the store and are working on a fix to the problem", as a sane response would be.
Security researcher Charlie Miller booted from Apple Developer Program
81–90 of 116 posts
Re: Security researcher Charlie Miller booted from Apple Developer Program
#82Earlier quoted context omitted.
Hold on here. Is Apple expected to know Charlie Miller is a "security guru", and even if they did, why should he be treated any differently? Security researchers should be held to the same standard as regular developers when reporting bugs/flaws. RTM was convicted of a crime because of his curiosity, and here we have a security researcher who knowingly put users at risk. You ask me, Mr Miller got off lightly.
He's pretty well known because of his series of 0-day exploits at CanSecWest.
Re: Security researcher Charlie Miller booted from Apple Developer Program
#83Earlier quoted context omitted.
So how do you prove the DDoS vector exists unless you DDoS someone's site? How do you prove the SQL injection vector exists unless you take over someone's site? etc., etc. This was far from a harmless proof-of-concept app, and "I just wanted to prove I could" isn't sufficient justification for it.
You don't need to "take over someone's site" to prove that their site has a SQLI vector, just put in a little string somewhere.
Re: Security researcher Charlie Miller booted from Apple Developer Program
#84Re: Security researcher Charlie Miller booted from Apple Developer Program
#85Earlier quoted context omitted.
when you submit a security related bug report to apple - granted my experience dates from 99-2005 - you get: A/ ignored (mail auto reply "we might fix it, don't tell anyone or we'll go after you" B/ bug don't get fixed for 2 or 3 years C/ bug get fixed, you get no credits
Submitting a security bug report to the Chromium project was a delight compared to submitting one to Apple. It was obvious that the engineers working on Chromium cared about the problem and were competent. On the other hand, I mightaswell have been reporting the Apple bug to a brick wall or a black hole.
Re: Security researcher Charlie Miller booted from Apple Developer Program
#86Earlier quoted context omitted.
You don't need to "take over someone's site" to prove that their site has a SQLI vector, just put in a little string somewhere.
In the UK, using SQL injection to "put a little string somewhere" would be illegal.
Re: Security researcher Charlie Miller booted from Apple Developer Program
#87It's a bad move for apple. A good relationship with the community of security researchers is crucial - they're talented folks and their research results grab headlines. It takes just a tiny amount of corporate humility and public thanks to win their respect, and in return get goodwill. Treating the community badly will get ensure the next guy won't even try to cooperate. Over the last several years, Microsoft's MSRC…
I'd agree more if he didn't submit — and get approved — a working exploit in their store. Without telling them about it. Edit: Now, I don't disagree that just banning him from the program isn't a great idea, and that pulling the app and having someone from the security team send him an email isn't a better one. But it's hard to say this that a bad move on Apple's part.
Re: Security researcher Charlie Miller booted from Apple Developer Program
#88It's a bad move for apple. A good relationship with the community of security researchers is crucial - they're talented folks and their research results grab headlines. It takes just a tiny amount of corporate humility and public thanks to win their respect, and in return get goodwill. Treating the community badly will get ensure the next guy won't even try to cooperate. Over the last several years, Microsoft's MSRC…
Hold on here. Is Apple expected to know Charlie Miller is a "security guru", and even if they did, why should he be treated any differently? Security researchers should be held to the same standard as regular developers when reporting bugs/flaws. RTM was convicted of a crime because of his curiosity, and here we have a security researcher who knowingly put users at risk. You ask me, Mr Miller got off lightly.
Re: Security researcher Charlie Miller booted from Apple Developer Program
#89It's a bad move for apple. A good relationship with the community of security researchers is crucial - they're talented folks and their research results grab headlines. It takes just a tiny amount of corporate humility and public thanks to win their respect, and in return get goodwill. Treating the community badly will get ensure the next guy won't even try to cooperate. Over the last several years, Microsoft's MSRC…
I'd agree more if he didn't submit — and get approved — a working exploit in their store. Without telling them about it. Edit: Now, I don't disagree that just banning him from the program isn't a great idea, and that pulling the app and having someone from the security team send him an email isn't a better one. But it's hard to say this that a bad move on Apple's part.
For the record, without a real app in the AppStore, people would say Apple wouldn't approve an app that took advantage of this flaw.
Re: Security researcher Charlie Miller booted from Apple Developer Program
#90Earlier quoted context omitted.
So how do you prove that it's possible to get this kind of exploit into the store unless you submit it to the store?
So how do you prove the DDoS vector exists unless you DDoS someone's site? How do you prove the SQL injection vector exists unless you take over someone's site? etc., etc. This was far from a harmless proof-of-concept app, and "I just wanted to prove I could" isn't sufficient justification for it.