Live data from Hacker News

iOS App Store - Fake Microsoft Word 2012 Approved

itunes.apple.com

81–90 of 123 posts

Re: iOS App Store - Fake Microsoft Word 2012 Approved

#81
post #64
post #25

Apple, just a few days ago, also approved (and pulled once there was a lot of online press being caused by it) a fake Cydia. (Cydia is the alternative to the app store that distributes substrate extensions for jailbroken devices.) A bunch of people bought it and then left reviews saying that they had been ripped off. http://cache.saurik.com/tinyimg/cydiascam.png

Maybe it's because it is in Apple's interest to get people pissed off at Cydia?

To take this question seriously fr a moment: the reaction is more to undermine the trust in the App Store's curation; this I one of those scams where the moment after you fall for it you know, in hindsight, that you've been had, so you don't seek retribution on the person being impersonated.

Re: iOS App Store - Fake Microsoft Word 2012 Approved

#82
post #77

Earlier quoted context omitted.

Did you forget about the Cydia marketplace & jailbroken iPhones?

That also brings down the sandbox, which is nice to have when you run apps from developers you wouldn't necessarily trust. Too bad there's no way to side-load unsigned (or signed by a custom CA) apps while still maintaining the sandbox restrictions.

We add some exceptions to the sandbox that I will argue do not decrease your security (as some parts of the sandbox are designed to help Apple, not the device owner). We do not deactivate the sandbox entirely.

Can you tell me where you got this information? It would help in our attempts to mitigate misinformation: a lot of people say a lot of very wrong things about jailbreaking, and it is nice to fix the source.

Re: iOS App Store - Fake Microsoft Word 2012 Approved

#84

Earlier quoted context omitted.

Did you forget about the Cydia marketplace & jailbroken iPhones?

both options void the warranty. I'm an apple fanboy, but what iOS needs is what android, OSX, and Windows has already done.. - a carefully groomed, public facing store monitored by apple (they have already) - allow other app stores for non-monopolistic competition (eg: Amazon's android store) - allow developers to use DRM on their apps - allow app files to be loaded manually by the user

This looks attractive, but does not /really/ help: the reason people use Cydia is not to get apps, but is instead to download "extensions". It is not possible to install these modifications (things "be able to put five icons on the dock instead of the default four") on any of the modern mobile platforms without first jailbreaking: the ability to "side load" an app is honestly kind of boring.

Re: iOS App Store - Fake Microsoft Word 2012 Approved

#85
post #36

Earlier quoted context omitted.

You can change the name, but to do so requires you to change the app metadata in XCode, rebuild a new binary, and upload it back to iTunes Connect like you would any other update. That would trigger another round of reviewing, so in theory you shouldn't be able to "sneak" a name change past Apple.

Exactly, not sure why I got the down-vote above. You can't simply edit the app name and change it after the app has passed review.

Maybe because a lot of people thought you were implying App names can't be changes, period (I upvoted you btw!).

Re: iOS App Store - Fake Microsoft Word 2012 Approved

#86

Earlier quoted context omitted.

I'd be very interested to know in which country these app reviewers are, whether they're educated, whether they're being paid well, and how the working conditions are for them.

You should ask Mike Daisey to check that out for us.

Funny! I prefer non-fiction.

http://www.newyorker.com/online/blogs/evanosnos/2012/03/mike...

http://www.theatlantic.com/international/archive/2012/03/the...

Re: iOS App Store - Fake Microsoft Word 2012 Approved

#87
post #37

Earlier quoted context omitted.

Sorry, but I find that hilarious. Who in their right mind would believe that Apple would let Cydia into their own store? Of course, Apple shouldn't have let the scam app through either, and should remove it ASAP, but consumers do have some responsibility to use their faculties.

That's fairly obvious to us. The problem is that Apple have created an environment where people are encouraged not to use their faculties. Apple insist on acting the way they do with the store, so it falls to them to make sure crap like this never sees the light of day. I mean really, which member of the Apple team allowed Word 2012 through?

Considering the scams people fall for on the web, I'm hard pressed to see this as something Apple created - or do you think social engineering attacks didn't work before the app store?

Re: iOS App Store - Fake Microsoft Word 2012 Approved

#88

Earlier quoted context omitted.

http://en.wikipedia.org/wiki/False_dilemma

This would only hold true if Apple phones were the only decent phones on the market.

The iPad is a one of a kind because of the retina screen. Try it for a week and you'll be banging your head against the wall looking at the pixels on your laptop/desktop screen.

Re: iOS App Store - Fake Microsoft Word 2012 Approved

#89
post #82
post #77

Earlier quoted context omitted.

That also brings down the sandbox, which is nice to have when you run apps from developers you wouldn't necessarily trust. Too bad there's no way to side-load unsigned (or signed by a custom CA) apps while still maintaining the sandbox restrictions.

We add some exceptions to the sandbox that I will argue do not decrease your security (as some parts of the sandbox are designed to help Apple, not the device owner). We do not deactivate the sandbox entirely. Can you tell me where you got this information? It would help in our attempts to mitigate misinformation: a lot of people say a lot of very wrong things about jailbreaking, and it is nice to fix the source.

Wow, that's actually news to me. I based this information on some first-hand experience/reasoning and also on various web pages. In particular:

* After installing OpenSSHd, obviously there is full access to the file system (at least as the "mobile" user, "root" may require a password). So at least this application is able to access more of the file system than a standard sandboxed application, right?

* At least one of the jailbreaks I tried caused iBooks to fail, and according to sources such as http://lumosdigital.com/blog/2011/02/15/apple-cripples-ibook... this is caused by an anti-jailbreak check that fails because sandbox restrictions are lifted

* I remember some drama (via twitter? irc? can't remember) about some .debs shipping with suspicious (setuid) files? (Probably from shady 3rd party repositories)

* None of the jailbreaks I've looked at has ever come with a technical description that explains their particular modifications.

* And finally, the fact that the jailbreak even works shows there are security measures being defeated in some capacity.

I'd love to be corrected on any or all of these points. :)

Re: iOS App Store - Fake Microsoft Word 2012 Approved

#90
post #21

Their other apps: http://itunes.apple.com/us/artist/super-racing-real-games/id... From the looks of it, they're a total scam developer. How does this stuff get into the store? At least two of their apps use the logos of other apps with some quick filtering to change the colors. I guess Apple isn't doing much more than a cursory check against trademarks when approving apps. That seems really dangerous. Copyright infri…

Apple's job is not to do a check against trademarks when reviewing an app. They test for bugs and malicious code. The test private API's aren't being used and they check it meets the public guidelines document.

I've released an app before which infringed on a trademark (accidentally, I didn't realise the name of this sport was trademarked). The owner of the trademark emails Apple, who forwards it to the developer who is told to take action immediately and respond to the trademark owner. If there isn't a quick resolution Apple will take down the app. They even have a check box when you are submitting an update which tells them if you are updating for a legal reason. I presume they would then expedite the review process.

Post reply on HN