Fake app masquerading as password manager LastPass just pulled from App Store
techcrunch.com
techcrunch.com
[0]: https://news.ycombinator.com/item?id=39302640 [1]: https://news.ycombinator.com/item?id=39304732
My company had a version of our communications app in the app store for several years. We decided to sell private-branded versions for some customers where the only differences were the color palette and logo shown on the login screen.
For the app versions we created for customers, one was approved on first review, another required a couple months of back-and-forth with the reviewer, and the third never got approved.
Every update is reviewed.
You and I know, but the great majority of the people in the world do not.
And, of course, we only see the cases where the scam app gets through. The success rate for these scams might be pretty low, but from our perspective we wouldn't know.
Relevance? When there is already an app called LastPass published by LogMeIn with millions of downloads, clearly you don't approve an app called LastPass published by a "Parvati Patel"
https://www.cbr.com/questionable-harry-potter-relationships/...
That reminds me, I still have a bunch of long-tail lastpass-compromised passwords to rotate before someone brute forces my vault.
> You and I know, but the great majority of the people in the world do not.
It's literally an app reviewer's job to know that. Having random people on the street reviewing apps would not be very useful. Although sadly, that may be close to the truth:
https://www.wired.com/story/apples-app-store-review-fix-fail... In a deposition in the Epic lawsuit, Shoemaker said that the qualifications needed to get hired as an app reviewer were that a person “could breathe [and] could think.”
You mean marketing?
:)
I can't say it's unethical either. Some third party made a place where people can publicly post things and try to make them popular.
They're just "hackers", in the positive 80's sense, to me.
The responsibility for "fixing" it or whatever is on the platform.
I agree! It made for interesting search problems to solve for sure.
What are your thoughts on the LassPass app? If they were phishing for LastPass credentials, that's going to be a problem, but if they had a real service then I'm not sure.