Frankly, I'm a lot more concerned with bugs that have to deal with input handling than SDK bugs that developers can use to do bad things.
This is likely a non-issue for those of us who haven't jailbroken our devices.
Frankly, I'm a lot more concerned with bugs that have to deal with input handling than SDK bugs that developers can use to do bad things.
This is likely a non-issue for those of us who haven't jailbroken our devices.
What? Are you suggesting that OS security bugs are in fact non-issues because static analysis can detect programs that exploit these bugs?
No, it doesn't work that way. You can always encode program logic in a way that will defeat static analysis. All you have to do is write a little interpreter with PEEK, POKE, and JUMP opcodes, then encode your actual exploit logic using the little instruction set you've just created. You can make this sort of indirection as elaborate as you want, and there's no way for static analysis to see through it all. When this kind of technique is used for DRM, it takes months of expert human analysis to figure out what's going on. No way some scanner is going to do that, especially if (unlike in the DRM cracking case) there's no clear indication that there's something to discover and decode in the first place.
This analysis is a joke, it just scans strings inside binaries against the list of symbols corresponding to what Apple considers to be Private API. Gamed exploit can be uploaded to the App Store and binary will pass their analysis with flying colors