Security researcher Charlie Miller booted from Apple Developer Program
news.cnet.com
news.cnet.com
Over the last several years, Microsoft's MSRC has balanced this very well. Google has done well recently, too. Lots of clued-in people in both places.
Edit: Now, I don't disagree that just banning him from the program isn't a great idea, and that pulling the app and having someone from the security team send him an email isn't a better one. But it's hard to say this that a bad move on Apple's part.
Second - Unless I'm mistaken - his proof of concept was more a violation of Apples TOU, it didn't really attempt to copy credit card numbers, or snoop on users calls - so, in that sense, it wasn't an exploit.
Net-Net - nobody comes out of this looking good, but Apple makes it clear that they are prepared to back up the language of their Developer TOU with actions.
But yeah if you dont have time to make a small web server the timer idea could also work.
Your second question is a good one, but given is context, it is unrelated. If apple signs a python interpreter, they do so at their peril, for obvious reasons.
[1] Or perhaps someone beat him to it: he may not have seen the acceptance mail before someone already noticed the app? I'm not familiar with the exact process: do you need to give final approval or can the app be in the store for a while without you knowing it?
How do you prove the SQL injection vector exists unless you take over someone's site?
etc., etc.
This was far from a harmless proof-of-concept app, and "I just wanted to prove I could" isn't sufficient justification for it.
We don't know what his level of communication was with Apple, but it doesn't appear that he notified them before testing this exploit. Had they refused to address the issue or otherwise brushed him off, this would be a reasonable escalation. The same story on r/netsec [1] is being linked to a Forbes article [2], which claims he notified Apple three weeks ago. That's not a ton of time.
Ultimately, he very much violated their ToS and Apple is well within their rights to give him the boot. Whether that was a smart decision on their part remains to be seen.
[1] http://www.reddit.com/r/netsec/comments/m48gx/charlie_miller... , http://www.reddit.com/r/netsec/comments/m3uwo/mac_hacker_cha...
[2] http://www.forbes.com/sites/andygreenberg/2011/11/07/apple-e...
> .. otherwise this was a mute point.
"moot". Pretty please, the word is "moot."Otherwise, while I think you've got a point (he could have used pricing to ensure no one ran his app), that isn't the issue here. The disclosure is. No one is contending he did something evil with his code, it's that Apple is mad about his code and disclosure. I don't think making it unlikely to be purchased would have helped.
It indicates both a security flaw in the platform itself, and a security flaw in the app store approval process, both should be highlighted.
For the record, without a real app in the AppStore, people would say Apple wouldn't approve an app that took advantage of this flaw.
1. This "guy" apparently didn't try very hard, at all, to cooperate, as evidenced by him putting the exploit itself in the App Store before notifying Apple about it, in direct violation of the dev guidelines.
What good is it to have such guidelines at all if you display in public that you won't enforce them?
2. Microsoft is doing a great job at this? So are we to assume that their security is therefore superior?
3. There are a few clued-in people at Apple, too.
A job well done.
Next time he either should submit a bug report to Apple or avoid using their products.
They deserve that criticism and it's true, but I can see where they would prioritize actually enforcing those rules, especially in a big publicly-visible incident.
Obviously the best choice from HN's moral point of view is to be more open, more even-handed and less draconian about rules in the first place. But failing that, I can see why they try for "even-handed" over "less draconian," given their own priorities.
RTM was convicted of a crime because of his curiosity, and here we have a security researcher who knowingly put users at risk. You ask me, Mr Miller got off lightly.
http://www.forbes.com/sites/andygreenberg/2011/11/07/iphone-...
Charlie is extremely well known in the security community. They know who he is. This isnt their first trip to the rodeo with Charlie.
If it was the same app, then does that imply the sandbox for a stockmarket app allows access to the address book?
Judging from the article, he did neither - so don't run crying about "that's so rude".
And Apple has made it abundantly clear that they don't care about bad PR in the security community. So there's really no downside to cutting out Charlie Miller, in Apple's eyes. The winner here is Charlie Miller's career.
How are you supposed to test whether or not Apple will discover a vulnerability during their AppStore approval process if you are going to tell them that one exists?
That said, this guy broke the legal agreement that we partly rely on for trusted computing in iOS. He can be thankful if he doesn't get sued, and he should have gone about it differently if not willing to face the minimal consequences of violating the legal agreement.
I personally don't really think there's anything at all wrong with a bit of harmless, nerdy limelight-seeking to boot, if that's what he was doing. Acting like he was somehow mistreated is what seems a bit iffy.
Unfortunately, I know of no other way to do it, unless companies like Apple create security groups that work with people like Charlie and give him an exemption to submit, and not notify other parties at Apple.
The sane response to this would be "Oh, we better fix that. Thanks. We're removing your app BTW." The Apple response was typical of a bureaucracy.
Anyway, is there any special reason why reporting via https://ssl.apple.com/support/security/ won't work?
The amount of skill necessary to identify AND exploit bugs is so great that the bug reports themselves have value,far beyond attribution in the patch notesand a T-Shirt. This is especially true when there is in fact a lack market of bad people willing to pay good money for 0 day vulns.
thus, reporting vulns that way doesnt necessarily make sense. Charlie's walking a fine line: He is not a BadGuy, but he also isn't giving away security consulting to companies with 200 billion market capitaliazations. Apple should pay him good money to look at this stuff. Otherwise, its going to be only BadGuys.
> But the researcher for the security consultancy Accuvant argues that he was only trying to demonstrate a serious security issue with a harmless demo, and that revoking his developer rights is “heavy-handed” and counterproductive.
But as he demonstrated in his YouTube video it wasn't just a harmless demo, he had a shell that he could run on anyone's phone who downloaded his app.
Further, he didn't even have to put it up for sale at all except to perform his publicity stunt. The code signing aspect doesn't change when you are developing on your device locally. He could have submitted the app and not even put it up for sale at all. If the exploit worked in dev it would work on the store, and if they approved it he really didn't have to test it at all. Of course he's a curious guy - I think we can all relate to and appreciate that - so he could have chosen not to release it to the store on approval, then if approved put it up for sale only long enough to try it out, and then removed it from sale again.
I don't agree that they should have terminated his account, but neither are they really that out of line in doing so. I also don't think he would have opened a shell to anyone else's phone but the fact remains that he still had the ability to do so.
[1] http://www.forbes.com/sites/andygreenberg/2011/11/07/apple-e...
Take your wrist-slap like a man, sir.
Apparently the grand are also prone to self-aggrandizement. I have a lot of respect for Miller's skills, but he's not the only smart person taking a hard look at App Store security.
Awful.
People however, also forget that, there are other pressures facing info-sec researchers - such as pressure from management at the company where they work to 'publish' and/or present their findings under the company banner. Often, this irks vendors, because vulnerabilities are used to promote the researcher's (or who they work for) interests.
That said, Microsoft, Google and Facebook have very transparent processes & expectations for submitting vulnerabilities.
The guy submitted a real live exploit to the Joe-User facing App Store. What on earth did he expect would happen?
It is easy to see why they don't take kindly to this sort of thing.
I agree that it's easy to see why they don't take kindly to this sort of thing, but it should also be easy to see why they should take kindly to it.
It's the equivalent of making a word document pop up calc.exe. This proves that you've broken the security, but doesn't cause harm.
You have to actually do it to be taken seriously, especially with unreceptive vendors like Apple.
There is really no reason to behave in a hostile way towards a researcher that does this. He's telling you about the problem.
In the security industry, there are many people who seek and find vulnerabilities. Some of them report them, and some of them keep them private and exploit them secretly to attack people's property, or privately sell to others who do the same. Selling these to the underground is big business now.
Let's subtract the people who report things from the above equation (because we ban and vilify them). Now what does your ecosystem look like?
Dumb move, Apple. Dumb move.