Welcome to the Cloud - "Your Apple ID has been disabled."
hanselman.com
hanselman.com
Apple caught the problem and e-mailed me to ask if it was me. I told them no. They disabled my account, refunded the gift card money, and asked me to write them once I was satisfied that my computer was secure (just in case it was key-logged [I was not].)
I wrote them back the next day and told them everything was good to go. They enabled my account and I signed in and changed my password.
I didn't lose any of my purchased items and I could have had the account back the same day had I chosen to.
I recall a while back that there were quite a few iTunes accounts that had been compromised. I used a very non-trivial password, too, so I'm rather surprised that mine was one of the compromised accounts. I'm still curious as to how it happened.
The only thing I would recommend to Scott Hansleman is to drop PayPal. They can be easier for small donations online, but with how far behind the curve they are in consumer fraud protection I refuse to make purchases with paypal anymore.
* = possibly not their own; they might own the apps that you're buying or make money through affiliate networks. And of course they could buy gift cards with your cards and sell them on eBay through another payment account.
Password strength is a red herring. Password reuse is a far bigger problem then weak passwords.
Even if the password was unique to iTunes, a key logger on your computer could have intercepted it.
Does Apple always use HTTPS? Otherwise it might have been intercepted when you were on an insecure wifi network.
* the fact they "allow the purchase first" and "warn later." * their warning email has no fraud or dispute mechanism * I've never purchased a game like this so they my usage pattern should be a red flag
Apple should have fraud systems as powerful and convenient as VISAs.
The same goes for purchasing something like you've never purchased before. Hell, one of the commercial strengths of the App Store/iTunes concept is that it gets people to do exactly that. There's nothing particularly suspicious about that.
We don't implement such paranoid measures either in other web-services or in real live, so I find it rather overblown to demand Apple does this.
The one thing I agree with is that there should be a better fraud reporting mechanism.
Yes "we" do. Steam doesn't let you authenticate, let alone buy stuff, from a new computer without entering a code that they'll email to you. Takes all of ten seconds--start up Steam, go to my email client, paste the code in, done.
And it works great. So what's the complaint?
So, in a world where customers can easily chargeback fraudulent charges, I think having security measures that are too paranoid is a great way to lose customers for no real advantages to the customer security.
I would not give Steam as an example of a successful payment system implementation.
> We don't implement such paranoid measures either in other web-services or in real live, so I find it rather overblown to demand Apple does this.
Google Two-Factor Authentication, Facebook emails you when someone logs on using an unknown computer, Steam does the same, and I'm sure there are more examples.
It's only paranoia until something happens.
But I do agree that as the iTunes store grows, the anti-fraud mechanism should be vastly improved along the way. IIRC Apple just began to send those emails out to remind costumers of suspicious activity due to rampant credit card theft. Clearly Apple hasn't done enough to minimize users effort and loss. I'm skeptical of utilizing usage pattern though, App Store genius recommendation is laughable.
They could always do something like what Steam does - the first time you try to buy something with a new device, you must enable it by typing in a code that is emailed to you.
Apple's new-device-detection algorithm doesn't seem to be perfect - I was vacationing and bought an app, and it was flagged as a new device (I got the mail for my purchase), despite it being the same one I've been using for a few years.
I have had this happen with Steam countless times, it's made me hate the Steam Guard system. I have a long complex password for Steam and I don't play online so my account isn't high risk at all.
However I use a number of different browsers on different machines and reset them frequently. As a result, almost every purchase I've made through a browser from Steam since that system was implemented has required me re-authenticating the "new device".
Personally, I'm not a fan. I'm positive it would get an even worse reception from the general public, too. Steam users aren't necessarily savvy but they are typically willing to jump through technical hoops for a particular endgame. I wouldn't say the same for iOS users, by and large.
This is a tricky one. Increasing security without adding complexity or alienating users that have grown used to the current system is very difficult. I'm not ready to jump all over Apple for this, it's not a problem with an obvious & popular solution that they are just choosing to ignore, this is something every company in the world is struggling with right now and they all have a different way of combatting it, each with their own unique pros and cons.
Not necessarily. My credit card was refused just two days ago because the purchase seemed unfamiliar to Chase. And it's common (and often annoying) for cards to be blocked when you travel abroad.
I think it'd be fair for a new device from a different location to be blocked. Not a thorough check, but an email would work. But in that domain you can never find a compromise that works with everyone.
Really? So you'd like to be actively prevented from purchasing your first app on any new device you purchase in the future?
Awesome.
http://daringfireball.net/linked/2011/08/12/itunes-account-h...
I don't see how that makes a difference if your iTunes account is compromised. Or perhaps it's because your creditcard company is more likely than Paypal to alert you to suspicious activity?
Though, in any case, one thing you can be sure of is that when he blogs about something, it gets significant attention in the tech sphere. You wouldn't be able to link a fix directly to him afterwards, but I think it's fair to say that his blow-horn is loud enough to have some influence.
EDIT: No, seriously. If someone has no idea who Gruber is and they click through to his site, tell me where on the screen they would see information that answers the implicit question "Who is Gruber and why would him finding out about this problem aid its resolution".
I retract my snark, or at least a little bit of it.
Google "Gruber Apple" is your friend.
After reading this story, I'm glad I couldn't give my credit card information to iTunes.
I just changed my password to one more unique (I was reusing it elsewhere), and finding the place to do so was surprisingly hard to find (IMO, it's harder than adding payment information).
One of the main gripes seems to be that Apple "let this happen" -- but enabling app commerce is what they do. Someone gets ahold of your credit line, they go buy stuff. Best Buy doesn't "let it happen", neither does Visa. After the fact they are just mandated to limit the damage to which you're responsible.
I'm not sure I could tolerate it any other way. Personally, I would not enjoy a system where some human calls me up every time I make an app purchase. I feel Apple's sin of omission is forgivable here and see it as laudable that some software algo that stopped it after $40 bucks or so. I'll be interested to read, however, whether or not Apple holds this gentleman accountable for those purchases and whether or not they fallback onto the credit card provider for damage limits.
But very bad ratings on the Japanese store [2], saying things Google translates as "Amount has been exploited to gain unauthorized access".
Based on this and on anto1ne's comment about Chinese "gift cards" [3], my guess is that the company is legit and that someone sells iTunes usernames passwords to individual gamers looking for extra points.
There's another company mentioned in these discussions: Kamagame Poker. In fact, if you Google "Kamagame poker chip" the first two hits are people on Apple forums complaining about unauthorized charges. Same phenoma as above: great reviews in the US store, bad reviews in the Japanse store.
Perhaps the Japanese are not interested in these two games, so a larger percentage of their downloads are scam related, while in the US the majority of downloads is legitimate?
So here's an opportunity for some automated detective work:
1 - scrape all applications with in app purchases
2 - scrape US and Japanese reviews
3 - look for rating differentials (and of course terms like 'fraud', 'charge')
Follow up with more manual labor:
1 - where are most of the customers of these apps? (China?)
2 - are these companies related? (I have no reason to suspect these two, but the bigger picture might look different)
[0] http://investing.businessweek.com/research/stocks/private/sn...
[1] http://itunes.apple.com/en/app/id428912410?mt=8
Also, the "do_not_reply@apple.com" seems like a strange address for an email like this. It should be "fraud@apple.com" (note: probably doesn't exist) or at least provide a link to the list of phone numbers at http://support.apple.com/kb/HE57 or the online support system at https://expresslane.apple.com/.
Unfortunately, the conclusion of this rather long thread: https://discussions.apple.com/thread/2178698?start=0&tst... seems to be that Apple isn't legally liable for this, and that you need to take it up with your bank.
It sounds to me like the developer of the app purchased might be in on this - there are apparently multiple reviews saying that the same thing happened to other people. Or maybe said hacker(s) just like playing that particular game?
Edit: I completely agree that do_not_reply is the wrong address from which an email like this should be coming.
Then we jump to some stuff about his AppleID being disabled? What?
1 - someone got their hands on Apple's private encryption keys
2 - some got their hands on a list of Apple id's or device UDID's
3 - Apple knows this, but wants to fix the problem behind the scenes and keep it under the radar.
My memory of Apple's in App Purchase system is a bit rusty, but my guess is a combination of 1 and 2 is enough to cheat it into buying products on someone else's behalf.
Then again, it could also just be a reused password.
1. Allowing new devices to buy stuff without two-factor auth is weak sauce. 2. The larger meta-point that when we rely on the cloud in a big way, it hurts when we are locked out.
The possibility I hinted at is that someone just "pretends" they have an iPhone and communicate with the Apple server directly. I don't know how their algoritm works, but it may be the case that they only need an Apple id and some secret key that is stored on the device. In that case asking the user for their password is just a way to protect the user when they lose their actual device. That would be pretty insecure from Apple's side. They should at least use the password to generate a key pair. (This doesn't necessarily require anyone to steal secret keys from Apple I just realize)
I completely agree with your second more general point. See also my comment on the Paypal thread: http://news.ycombinator.com/item?id=2880194
Scott's not dumb though to fly without antivirus/firewalls on his own PCs.
Your iPad/iPhone, on the other hand, are almost certainly running no antivirus and no firewall. Because who needs such inconveniences, eh?
Here's a fairly recent presentation outlining some of the security practices around IOS 4:
http://trailofbits.com/2011/08/10/ios-4-security-evaluation/
There's also a practice in China to use apps as a kind of fraud, or maybe money laundering. I've seen once a chinese wallpaper app, with each wallpaper for sale at $99, making thousands on the appstore.. when you think about it, it's easy to post an wallpaper app, set the price, and you get money through Apple, without any traces.
What I really hate about all this is that Apple still force you (or make it very difficult not to) to have a CC linked to your itunes account, even though you plan to never buy anything.
So again, depending on when it happened, you may simply not have received the receipt yet.
Apologies for the blunt question, but you've often run anti-Google, anti-Apple stories and are well known as a 'kept blogger'.
Consider these posts in recent history: http://www.hanselman.com/blog/ReviewMicrosoftTouchMouseForWi... (critical of MS hardware)
http://www.hanselman.com/blog/HackersCanKillDiabeticsWithIns... (well-researched article)
http://www.hanselman.com/blog/RequestForCommentsIssuesWithNE... (a common question raised among .Net developers)
[0] Migrating a Family to Google Apps from Gmail, Thunderbird, Outlook and others: The Definitive Guide http://www.hanselman.com/blog/MigratingAFamilyToGoogleAppsFr...
[1] Installing iTunes http://www.hanselman.com/blog/InstallingITunes7On64bitWindow...
As for the Tumblr, I created that at the suggestion of my friend Anil Dash.
So, as someone in Microsoft that works in their Marketing department then I thought that was a fair question to ask (which I notice you didn't answer the question btw).
When are you running your story on 'How Microsoft ripped me off with fraudulent Xbox Charges?' or is that not just as relevant. Perhaps set-up a community tumblr site where we can share stories too?
@rodneydd
Deleted comment
This post doesn't contribute positively to the discussion, and doesn't address the actual question raised by the parent as to the OP's motivation for creating his blog.