Apple brass discussed disclosing 128M iPhone hack, then decided not to
arstechnica.com
arstechnica.com
> Apple did ultimately inform users that downloaded XcodeGhost apps, and also published a list of the top 25 most popular apps that were compromised. Apple removed all of the infected apps from the App Store , and provided information to developers to help them validate Xcode going forward.
> XcodeGhost was a widespread attack, but it was not effective or dangerous. At the time, Apple said that it had no information to suggest that the malware was ever used for any malicious purpose nor that sensitive personal data was stolen, but it did collect app bundle identifiers, network details, and device names and types.
So in other words, it was used only on a few high value targets, rather than being used to serve up ads to all 128M users.
Still not much better...
Worked just fine. Developers circumvented it. Should’ve been the red flag.
For the anti-regulation guys, please explain how free market helps in this or similar cases and why a law to demand transparency for this cases is also evil. (I am still waiting on other threads an explanation that regulation that only forces transparency and what is tracked and shared is bad and free market solves it better)
Edit: And if you were infected via way of an update, the update mechanism is Apple's software asked Apple's servers if there was any updates, and when Apple's servers said yes they downloaded software from Apple's servers and deployed it on your phone.
To argue by analogy, Amazon is responsible for goods they sell on there store that they don't even distribute themselves... https://www.theverge.com/2021/5/1/22414185/california-appeal...
Walmart in turn can go after Campbell for the cost of the refunds, but the end purchasers aren't a party to that suit. Campbell (and maybe Walmart directly) can also go after the criminal for damages, again not the consumers problem.
Wow, you are arguing here without even reading the article or understanding the reality!
Short resume for the lazy : Apple guys were working on creating the emails to inform the victims (stuff like send the emails in the correct language) but in the end they never sent the emails. So from your example, some guys knew they sold some food that had poison in it(somehow the bad guys were clever to sneak pass their guards and put poison in the cans), the guys were concerned and were ready to go and announce the victims that they might need to do some health checks. But then Timmy said "the poison is not that strong, let's wait and see , if nobody notices we do nothing , we don't want the people to know that our walls and guards are not as great as our PR and fanboys claim to be. That would mean that out best PR line `think about grandma` was a lye all along"
But also... you do understand that we're talking about analogous but not identical laws here right? The context of this entire thread is laws that specifically require notifying people of data breaches, and not laws that require recalling bad food.
When Apple/Google review fails (it will never be a perfect review process), reasonable people would say that Apple/Google would not only remove the malware from the store but they would also at least notify the victims.
It's their platform, their APIs, their sandbox, their store, their verification, their rules, but when something goes wrong, it's someone else's fault. That doesn't seem fair (even though it's legal currently).
Does this also mean Microsoft is at fault when someone writes malware that exploits Chrome on Windows? After all it’s the Windows platform and API. Should I also blame RMS when someone writes malware in C? After all they might have used the libc.
Say someone put malware on Ubuntu or Debian official repos, the developers find it and silently cleanup the mess but keep it quiet because of PR. Who should notify the victims> the package maintainer, the individuals responsible for the malware, the distribution as a whole?
If the Microsoft Store or Steam distributed malware, even if they I expect from them to aknowledge what happened, plans to improve the situation and the victims should recieve an email or notification in the store with what happened,and what should they do.
I am not asking for Apple to get the blame for the malware , just to acknowledge that the Store is not 100% safe and this can happen (bad for PR) and let the victims know.
https://gdpr-info.eu/art-33-gdpr/
edit: Also California requires notifying the residents directly and if over 500 residents were effected also the attorney general
Remember the class action lawsuit that forced Apple and other companies to admit that the products have a defect and provide compensation. Without a law and regulation those people would not have got their fair justice.
Also I do not see how free markets could prevent some company selling you bad products, and when the PR is bad enough just re-branding and start over. Or how free markets can help with imported products that could be unsafe, you need basic regulation that impose transparency (who made the product, what it contains and other related information).
Is it enough to even support a neighborhood coffee shop?
I think theoretically the argument above makes sense, but in reality it doesn't. The market that exists doesn't provide a solution because the barrier to entry is basically infinite. Even Microsoft couldn't offer an alternative to iOS and Android because Microsoft couldn't do it alone. It's a natural monopoly problem, which means normal market arguments don't work.
Help me understand.
Another related problem is that regulations often inentivize ignorance; the originator is usually better off not learning about breaches, so they are not as vigilant as many users think they should be.
>“For the anti-regulation guys, please explain how free market helps in this or similar cases...”
And a further comment asking:
>”Help me understand.”
Given the response, it appears as though my attempt at elucidation is not appreciated; this being the case, I will refrain from further explanation.
You also "forgot" to explain what is wrong with regulation about transparency(tell me what you pt in the food, tell me if you are tracking me, tell me if you are aware that my device has a defect)
The only thing that elucidates is that libertarian ideology is largely a fantasy.
Where are all these guarantees and audits and vendors? Nowhere. Absolutely nowhere.
This is a completely nonsensical libertarian fantasy.
> XcodeGhost billed itself as faster to download in China, compared with Xcode available from Apple. For developers to have run the counterfeit version, they would have had to click through a warning delivered by Gatekeeper, the macOS security feature that requires apps to be digitally signed by a known developer.
Let's not pretend that one greedy billionaire is the good one here.
Plus Epic does not really proposes the same kind of walls as Apple do. The worst they can do are exclusive titles on some typically somehow open platforms (and yep I guess they would take a deal to have an authorized store on a closed one, but for now I'm not sure such beasts exist anyway -- and again, why would it be worse than a monopoly?), they don't even sell only that, and the people they get exclusivity from had the choice to do something else anyway (without renouncing to whole platforms)
Who's doing that?
If Apple's AppStore isn't protecting users, why not let there be competing AppStores and let users decide which serves them best?
I don't care about which billionaire benefits the most, I care about options. IOS has zero options (that don't void your phone) if your app isn't approved by Apple.
Out of curiosity, are you responding to me or digesting my point? I’m not pretending anything.
https://www.theverge.com/2021/4/21/22385859/apple-app-store-...
https://www.theverge.com/2021/2/8/22272849/apple-app-store-s...
This is a lot to unpack. Let me narrow it down here:
- Developers submit app to AppStore
- Apple scans it, manually reviews it, certifies it meets security, privacy, and quality guidelines
- Apple allows users to download the app from the AppStore
- Users assume apps on the AppStore are secure because Apple loudly proclaims this
- Users are infected with malware
And this isn't Apple's fault? Of course this isn’t a tenable position for Apple. There’s no way to catch everything. But they market this, and use it as justification for their walled garden.
This is a valid point, and also the reason this particular attack is so interesting. Apple's system relies on holding people/companies accountable for submitting malware. Apple has the power to knock a company out of the App Store, so the company is incentivized to not push the limits. This hack is an attack directly on this relationship-based system. It's an attack on Apple's ability to punish. This doesn't make Apple's system worthless, just worth less.
Also, it was less malware and more just a low-profile privacy invasive SDK.
>Well, this Epic lawsuit...
And this is the issue that no one seems to be getting. Epic will lose. As a gaming company they never really have a case, I do admire them to have the courage to go against the largest cooperation in modern history. But it provide enough materials for their end goal for other parties, whether that is EU or US regulators.
First, it's not just Apple. The App Store/ecosystem concept is a newish concept, and probably needs completely new types of regulation outside of anti-trust. Apple, Google, MS, Sony, Nintendo, etc... are for the most part monopolies in their respective worlds, but fail at the traditional monopoly definition. Waiting for a company to achieve an AT&T or Standard Oil level level of power is an outdated way of thinking. Apple also doesn't have anywhere near that level of power.
given that individuals have brought up cases that ultimately landmarked as Surpreme court rulings, I have to say this is the oddest take on the lawsuit I've seen yet.
Calling exclusives “anti-consumer” is basically nonsense. Exclusives have been a mainstay of the gaming world for ages. The actual harm they cause to the consumer is minimal, no different than first party titles do (like Valve’s own Half-Life, etc).
how can we do that?
Can I use in game currency bought from somewhere else in FortNite?
If he was, he would be against exclusives, but he pays handsomely for those.
- Epic marketplace has a few exclusive video game titles for their marketplace.
- Their games can be installed on multiple platforms.
- Also, there are dozens of competing video game marketplaces, each with their own exclusives. You can't play Zelda on PC.
Vs.
- There are only two brands of smartphones. Everyone is forced into this duopoly.
- iPhone is a device that doesn't let users repair it
- iPhone is a device that doesn't let users install their own software
- iOS forces all commerce through Apple's tax rails
- iOS prevents forming a relationship with customers as it gives businesses a disposable fake contact. These are "Apple's customers", not yours.
Businesses have two choices: fuck off and die of irrelevancy, or put on the Apple gimp suit and get fucked. There's no way this was ever legal. We've all just been gaslighted by Apple's mind-bending PR. They've constructed the biggest monopoly of all time.
As far as relationships, I don’t want every business to have relationship with me. For those companies that need one, they can have users register.
How is the App Store any more illegal than the consoles? Yes every physical game you buy for a console still has to be approved by the console makers.
Apple is the only game in town, and they bully everyone. Their rise to this position and stranglehold over all commerce was an illegal move that will be corrected by the DOJ.
Imagine if AOL controlled the Internet and all websites had to pay 30% to AOL. That's the world we live in with Apple.
Not to mention that there is also the web.
No website has to pay Apple 30%. In fact, no dating app has to pay Apple 30%. They can all force you to pay on the web and Apple won’t get any cut.
Do you think Tinder would have caught on as a website? Apple trained people to use apps.
Furthermore, what about real time video transcoding? Apple kept their web browser purposely hobbled to force people into their dungeon. You can't use a multitude of modern, advanced capabilities with safari. How can I do advanced workloads in parallel, at high performance, in the background? I can't because Apple.
You can’t do advanced workloads in the background with native apps on iOS. Apple strictly limits what an app can do in the background to conserve battery life. Safari doesn’t stop running in the background.
I don’t know about performance, but if someone could write a performant JS/web assembly transcoder that could run on the web, since iOS devices routinely trounce all Android devices with respect to browser performance, I’m sure it could be done.
it's not about what "could work", a 15fps game "could work".
it's "what is successful". And for a mobile audience, UI/UX engineers have spend decades determining that after a certain amount of lag, that experience is lost.be it for technical or political reasons, Safari and by extension, much of HTML 5 cannot meet this UX criteria. So an application has an massive advantage.
>but if someone could write a performant JS/web assembly transcoder that could run on the web
Sounds like a Progressive Web App: https://web.dev/what-are-pwas/
They've come far but are far from perfect. It's also moot in this case, since certain optimizations would need to rely on understanding Safari's infrastructure. Which is closed source. They can optimize it for webkit, but any web dev can tell you that interplatform quirks are the 2nd 90% of the battle.
- GoG will give you DRM free downloads
- Steam allows you to give out keys for free then use their infrastructure to download/manage the game (humble bundle steam keys)
- None of them force exclusives as far as I know
> Businesses have two choices: fuck off and die of irrelevancy, or put on the Apple gimp suit and get fucked.
No they don't. There's plenty of businesses that are alive and well and not getting fucked by anyone.
But you don't know if this is their only end goal.
Internally this is probably a high-risk high-reward kind of plan, but this is a wild guess.
If they could sell digital goods using their own payment system within the app like Amazon can with Amazon Video, what would they gain from this?
The PR doesn’t tell the story like what came out during court procedures.
the ability to potential lauch EGS on IOS. Success or not, they want that opportunity to try.
I suspect they would still want to. My personal suspicion about the motivation behind this case is that it's not really about Epic Game's profit, but Tencent's. Tencent owns 40% of Epic Games, and owns a lot of companies who stand to make a lot more money if Apple's forced to open up the app store.
Though, it is true that Apple never disclosed the full list of compromised Apps or how many users are affected. Also, I am not sure that sending Emails to affected users would be effective. Most of affected users come from China, and a significant portion of them use phone number instead of Email to register App Store account.
[0] https://web.archive.org/web/20151101142446/http://www.apple....
> The infections were the result of legitimate developers writing apps using a counterfeit copy of Xcode, Apple’s iOS and OS X app development tool. The repackaged tool dubbed XcodeGhost surreptitiously inserted malicious code alongside normal app functions.
This was shown by Ken Thompson is 1984 I thought [1]
Since I remember the ‘Apple was not doing true binary level review’ coming up when I talked to an iOS developer literally a decade ago about the App Store (back in Android 1.1 SDK days) - he even mentioned this type of attack as a possibility - and they obviously haven’t changed that, there are probably a ton more like this out there that have slipped under the radar due to smaller scope, or less clear impact.
There is no technology we have today, whether it is mobile, server side, Linux kernel or whatever that accepts random code from strangers (that is what you doing with pirated s/w) and detects intentionally written malicious code.
Not much beyond a desire to not make a lie of their "curated, secure walled garden" PR.
> XcodeGhost billed itself as faster to download in China, compared with Xcode available from Apple. For developers to have run the counterfeit version, they would have had to click through a warning delivered by Gatekeeper, the macOS security feature that requires apps to be digitally signed by a known developer.
Seems like a real world version of the Trusting Trust attack where the compiler is inserting malicious code.
[0] https://users.ece.cmu.edu/~ganger/712.fall02/papers/p761-tho...
It just took some data from allowed phone APIs and sent it to a server, which is allowed. And maybe opened some other apps through deeplinking, which is also allowed.
How is a reviewer to know that the code in the app wasn't put there intentionally by the developer?
Maybe force everything through DNS and include a list of domains in the app submission. You might be surprised at how many people can connect when you include an IP in the app that couldn't connect via DNS though; if your user base is big enough, it adds up.
Now not disclosing it is on them but at the same time, it was the apps who were hacked and I can see it falling to them to disclose?
Does that line of communication remain open after the app is deleted on the device?
For non-walled-garden platforms, like most desktop operating systems, a program being available for download isn't yet a bypass of any security feature. It'd have to do something forbidden like privilege escalation for me to count it as a OSX/Windows/Linux hack.
iBooks won't sync ePub files I add manually.
<A bunch of other niggles, too many to list>
Now we find out Apple cares more about its image, than quality.
I've been wanting to move away from Apple for a while, but this finalises it. I'll be doing one final upgrade to the ARM chips, then putting effort into moving away. Including funding projects if needed.
This is a really bad look for Apple. It's clear they're not worthy of my trust.
Not so much now, they've found a cash cow and seem to be entranced by it.
On a side note, sometimes getting older feels like being in a Twilight Zone episode. Like I woke up and, for some reason everyone is calling records and 45s 'vinyls'.
Or I mention 'Cary Grant' and people just stare at me blankly because his memory has been erased from existence.
This Apple comment is one of those moments: it feels like yesterday Apple's talent for software was common knowledge, and suddenly today I'm in a parallel universe where Apple has always created buggy garbage.
I am saying that design is their forte and that their engineering culture is mostly focused around it, software is built to impress.
Their products are meant to be the final form, not a tool to build something else.
And this has implications for the quality of the code, fortunately they also inherited a lot from the Unix culture, but overall I've rarely been impressed by the quality of their software, and I've sometimes been appalled by it.
Itunes, Quicktime or the first iterations of OSX...
Where's the regulations to protect consumers?
Oh right, the US regulators don't protect consumers. At all. Even though that's what they're supposed to do.
More references at: https://en.wikipedia.org/wiki/XcodeGhost
Here's what Apple[1] said[2] at the time:
"We've removed the apps from the App Store that we know have been created with this counterfeit software," said Apple spokeswoman Christine Monaghan.
"We are working with the developers to make sure they're using the proper version of Xcode to rebuild their apps," said Christine Monaghan.
I see only one other mention of it in the article (aside from the title) with zero additional context, and surprised to see zero occurrences of it here.
A Google search of “Apple brass” turns up nothing, as well, besides other references to this article.
Am I the only one that has never heard this term, and also curious by its reference in the article’s headline?
No, we're not pro-$bigco or anti-$bigco. HN comments just need to be better than this.
I don’t truly believe Apple is interested in user privacy as a core value but it is a hell of a differentiator compared to Google. On this topic, my interests and theirs happen to align for the time being.
Opening the App Store app transmits your hardware serial number to Apple, like a permanent supercookie, linking it to your email address and phone number and city-level location via client IP.
I'd much rather have multiple services, each of them isolated to the data that is relevant to providing their specific service than one service having it all.
Not saying breaches never happen with apple or google of course, it's just less often than your trusty todo list app being pwned and your clear text passwords being dumped online.
You raise a very good point though. You can't judge the security of a company by any metric except their record. It would be interesting to have a registry that logs breaches, how severe they are, and give an overall rating to them.
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
I too wish iCloud backups were E2E encrypted, but that is a very different claim from "Apple assumes you desire privacy from everyone but Apple." Apple knows you want privacy from Apple; their privacy policy is quite explicit about what data Apple cannot see.
iCloud Backup is not e2e encrypted, which means Apple either gets the full iMessage and SMS history (in the case of Messages in iCloud being disabled), or gets the e2e encryption key to decrypt the synced Messages in iCloud (which they already have, due to running iCloud).
Your link describes in detail what Apple can and cannot read. They seem to want their customers to know. So how did you conclude "Apple assumes you desire privacy from everyone but Apple?"
If you don’t enable backups for iMessages, they stay on your device.
Nowhere does it describe a back door that the FBI has access to.
The backups are enabled by default, on your device, as well as the devices of everyone else you iMessage with.
For iMessage to be end to end secured, you need to turn off iCloud Backup on each and every device you have, and everyone you iMessage with needs to turn off iCloud Backup on each and every device they have. If either you or your conversation partner misses a single device, Apple will get either the message text itself in the backup (if Messages in iCloud is disabled) or the message sync encryption key (if Messages in iCloud is enabled).
In practice, this never happens. Non-e2e iCloud Backup is an iMessage cryptographic backdoor.
A backdoor is a very specific claim that isn't backed up.
Defaults matter.
Apple had a plan to secure it, and (I understand) a partial implementation. It was killed specifically to aid surveillance capabilities. If that isn't a backdoor, I don't know what is.
You're not going to find proof in the EULA.
Luckily they’re too expensive to be the biggest player in most of the world. But they’re part of a duopoly.
Didn't work, so they try something else to differentiate.
If this wouldn't work, they will just adjust targets.
They failed for multiple reasons:
> With tight creative control of ads, an insistence on taking a 30% cut of all ad revenues, and a prickly attitude to sharing customer data, the platform won few fans in the media industry.
But iAd launched before their "protection of user privacy' stance. Not after it.
= They couldn't monetize it, so only after that they attack it and "protect user privacy".
That's a disingenuous claim. While iAd did predate Apple pushing privacy as a mainstream marketing angle, it certainly did not predate Apple taking a strong position on consumer privacy. This had been a theme in Apple's corporate decisions for at least the past fifteen years, likely longer.
Furthermore your own quoted paragraph belies your own assertion. iAd failed in part because of Apple's "prickly attitude to sharing customer data".
Quotes from a contemporary article:
But advertisers became increasingly perturbed that Apple refused to give them access to the wealth of data iAd had on its consumers from Apple’s hundreds of millions of iTunes accounts.
Stefan Bardega, media agency ZenithOptimedia’s chief digital officer, told us: “iAd has long been a story of unfulfilled potential. Apple has unique customer level data that is hugely interesting to advertisers but has struggled to access that data in a way that doesn’t conflict with the core business.”
Another media agency ... said: “For me, they never understood that they needed to behave like a media owner, rather they could go it alone charging what they wanted, not sharing data, no third-party tracking...”
https://www.businessinsider.com.au/why-apple-is-pulling-dire...
If you believe Apple's marketing, how do you explain Google not bowing to China and therefore not bowing to China's influence, while Apple seems to be doing just that.
Eg. https://www.wired.com/story/apple-china-censorship-apps-flag...
Caring about user privacy shouldn't have exceptions, no?
I didn't say that you did, in fact I explicitly said the opposite. I don't even know where that quote came from. I just pointed out that YOUR choice of quote contradicted your argument.
> If you believe Apple's marketing
I don't believe their marketing. I believe the profit motive, and I believe their actions they've taken in the face of Government and corporate demands for data access.
> Caring about user privacy shouldn't have exceptions, no?
You are falling into a weird self-defined trap of binary thinking. It seems you're asserting that in order to have concern for customer privacy requires privacy to veto literally all other concerns. I never said—no sane person has ever said—that Apple's concern for consumer privacy is their number one motivating directive. Everything is a matter of degrees; a matter of competing priorities.
Personally I don't pick Apple products to protect my data from my Government. I pick them because I want that pile of data to be siloed away from the likes of Google, Facebook, and the countless number of unethical data aggregators that I've never heard of. Apple's selfish commercial motivation to keep my data away from their competitors suits me just fine.
Put simply, Apple's functional concern for my privacy—regardless of the purity of their motives—works for me.
In my experience, Android users are generally not plagued by this misconception to as great an extent.
Why would a company do something in the interest
of the consumer if it was not in their interest
There are many reasons, but if for no other: so that emails like this don't leak and cause you bad PR! There's a whole school of thought around being 'customer focused' that boils down to the Golden Rule (but in MBA-speak). I don't know how many 'customer focused' businesses really walk the walk; probably not that many in situations where doing so requires real guts.We call that "ethics", IIRC. It's depressingly rare.
This doesn't match my anecdata, but perhaps things have changed in the past few years.
The lesson here is that it's probably important to do things like the non-apple battery warnings etc because the scammers and hackers will not stop attacking the platform.
The lesson here is that you cannot rely on Apple to act in your interest if they think doing so will hurt them. Note that they aren't special here, any other company will probably act similarly, the difference is that Apple apologists would have you believe they, ahem, think differently.
Important thing to keep in mind is that the emails in the article were from 2015, not 2021. Apple was not marketing privacy as heavily back then as they do now. Not trying to justify their action back then at all, as I firmly believe they should’ve notified users, but context matters imho.
Steve Jobs
All Things Digital Conference, 2010
Notice I didn’t say they weren’t pushing privacy at all, I said not as heavily.
Apple has had privacy and security as a core part of their marketing since forever. They also had a whole set of ads and comments in keynotes about how secure and privacy focused OSX was, taking shots at Windows.
I went back and skimmed through the past decade of Apple commercials, keynotes, and interviews by execs. After doing so I stand behind my point that privacy was not marketed the same pre 2017ish as it was after that. Yes, you’d see mentions here and they, but not until around 2017 did it become center stage and the apparent lens through how everything is viewed.
This is a very subjective thing though, so how about we disagree and commit?
Did the directly affected companies do the notifications?
I thought Apple had sort of a separate setup in china (data center etc) to mitigate some of the issues there impacting the rest of their user base.
How? This is a simple case of "code execution results in code execution". iOS is already sandboxed, so the impact was limited. I'm not sure what you'd expect apple to do, other than have some sort of system that can detect arbitrary malicious code.
Yes, I totally believe that Apple did not know about NSInvocation and the half a dozen other ways to dynamically call methods.
This is their job to know.
Top management isn't there to act as some infinite well of knowledge, they're there to speak about issues that have been distilled down to them on a higher level with other relevant teams
What you're effectively saying is that Apple's "VP of Software" or something not knowing every line of source code in IOS is "not a valid defense"
And then top management etc.