XcodeGhost Q&A
apple.com
apple.com
(Nate analyzed a bazillion app store apps using his platform).
This is why I think we can never have absolutely secure computerized voting. No matter how much security you think you have in the form of code audits, paper trails, open source code, at some you're going to have to push a button and trust that the electrical signals inside that magic box of a computer are working the way you think they are.
However, the impact of the infection is pretty limited. It can throw up alerts, open URLs, and do a couple of other things, but nothing particularly bad. Part of this is because of iOS's strong sandboxing. There's only so much malware can do from within a third-party app. Part of this is because this particular bit of malware just doesn't have a lot of functionality in it.
The good news is that the infection isn't persistent. If there's an update to your app that's been built with a good copy of Xcode, you can install that update and you're fine. You don't even need to uninstall first. If there isn't then you definitely shouldn't use that app until an update is available. If you're paranoid you might uninstall it while you wait, but it probably can't do anything in the background.
http://mobile.reuters.com/article/technologyNews/idUSKCN0QO2...
The page also says Apple is working on making it faster for them.
Apple has said that they will now cache downloads inside China to mitigate this.
One of these mirrors had a altered version of XCode that Chinese developers were downloading. One of these developers noticed strange behavior with one of his apps. It was connecting to strange servers on the Internet when he hadn't written the code to do so. This lead to the discovery of malware in some copies of XCode floating around the Chinese portion of the Internet.
I imagine Apple will add some sort of tool verification step to help fix this issue. Another way to help prevent this problem would be to host an official mirror inside China, obviating the need to get Apple tools from unofficial sources.
I don't know what the best answer is, but Gatekeeper could stand to be a little less obstructive when the user legitimately trusts something that the system doesn't know about.
Apple's answer will, sadly, probably be to make it impossible to disable.
The biggest safety precaution against something like this is app sandboxing, which severely limits the amount of damage that a malicious developer can do.
This is a common misunderstanding, and it seems to be one that Apple is happy to spread. Whenever the merits of app review are discussed, some people bring up the security advantages of it. But the fact is, there are none, as XcodeGhost demonstrates nicely. iOS's security is due entirely to the strict sandboxing for third-party apps. App review just lets Apple control what kind of content can be in the store.