Handy Light: Tethering App Camouflaged as Flashlight
appshopper.com
appshopper.com
Apple should include a warning on the box to that effect.
(+) I don't actually own an iPhone.
I think a model that the web has followed is better: apps should be ranked based on some organic factors (e.g.: content of description + reviews) and the best apps can just float to the top. Security can be ensured via reviews/ratings + sandboxes access to phone's core functions.
Can't do any of that on the iPhone. It's the app store or you figure out some way to beat Apple's security.
Since we can assume that there are no public APIs that support tethering setup, we can also assume that it's still possible for them to be used in rogue apps and for developers to have access to private data.
Apple rejects apps that use private APIs.
Couldn't you write the instructions necessary to make the private API call on the stack at runtime and then simply execute an assembly jump instruction?
Even better/worse, you also have direct access to the camera(s), which means you don't need to prompt the user or display anything on-screen to capture photos or video.
I know Android clearly warns users about an app's capabilities. Does anyone know if that opt-in, or is it derived by some type of code analysis?
However, during app runtime, only those listed capabalities are provided to app. If the app tried to use something else, it would get exception. Short of bug in the platform, there is no way getting around.
EDIT: He's just a kid
> Hi, I'm Nick Lee, an aspiring 15-year-old web designer and programmer. I consider ...
himself.
If he wants to get a regular job later /or/ if he wants to launch a product later, having his name in the headlines helps quite a lot.
i don't want to say "there is no such thing as bad publicity" because there is, but in this case, enough people, I think, will feel that a tethering application is 'not evil' and that this was overall a good thing to make it a net win for the programmer.
Even if apple blocks him forever (I don't know their history... would they really say "no, f-ck you" five years from now?) and even if the apple platform remains dominant (I will be very surprised if apple continues its dominance after Jobs runs out of spare parts.) there are plenty of companies that make iphone apps that I'm sure would be happy to hire the kid.
And there are plenty of other platforms out there to work on, too.
aka Robert Tappan Morris. That's a name you should recognize. :-)
In a few years this tethering will free on the iPhone (think competition) and common place or obsolete (multiple SIMs, same contract) and no one will care.
Or could some novel proxy otherwise keep alive a tunnel to another machine in the background? The latest iSSH app says it can keep a session alive for 10 minutes in the background -- though it's not clear if it can relay significant data while backgrounded.
http://developer.apple.com/iphone/library/documentation/uiki...
"This method lets your application continue to run for a period of time after it transitions to the background."
http://developer.apple.com/iphone/library/documentation/iPho...
...it sounds like a background audio app could do arbitrary other things while remaining unsuspended, and receiving audio callbacks, as long as it also keeps playing audio. (I'm sure Apple would frown on such behavior, and ultimately thwart it, but it seems like the framework gives enough discretion to the app to do other things.)
My guess is Pandora has some fairly sophisticated server-side streaming that responds to ACK/FIN-type feedback from the iPhone client.
I've always found it to be quite weird that the App Store is so closed, but a person with a developer certificate and MobileProvision can install whatever he wants and can do whatever he wants so long as the apps are codesigned. $99/yr is less than a couple coffees a month (or a good sushi plate) and way less than your phone bill, and is quite worth it for the bored hacker who wants to keep the warranty.
I attempted to buy it but it requires iOS 4. (I have a 2G...)
Of course, you'll have to get tricky to use SSH via the SOCKS proxy, but it can be done.
1. Download and compile connect.c (http://www.taiyo.co.jp/~gotoh/ssh/connect.c or http://www.meadowy.org/~gotoh/ssh/connect.c).
gcc connect.c -o connect -lresolv
2. sudo cp connect /usr/local/bin/connect-proxy
3. cd ~/.ssh Add new config file as shown below (if existing, then be careful - backup/modify)
File: ~/.ssh/config
Host *
ProxyCommand connect-proxy -R both -4 -S proxy:<proxy-port> %h %p
4. Test ssh to one of your hosts
Note: If you're not using the proxy, you need to disable the global config with a script or something to nuke it on demand.
However, it only works with Safari. It does not work with Chrome, Firefox, or any mail protocols (POP / IMAP / SMTP).
Mail.app works over the global systems SOCKS proxy as such it works without any issues what so ever.
If they were going to kill an app, I'd assume they would have killed that. And they didn't. Or if they claimed to have killed it then they failed.
I bought this app. I'm more than willing to support the the Rebellion. I haven't actually verified that this app works as demonstrated but for a dollar it's worth the risk. I have no intentions of paying another $20 a month to AT&T.
Even as a flash light HandyLight outperforms myLite. When I start it - it's immediate white.
As a current iOS developer, I’ve always wondered what the financial repercussions of getting pulled from the App Store would be. I wouldn’t be surprised if Apple refused to pay the kid his post-commission cut from what he was able to sell due to this kind of hidden behavior.