New services bypass Apple DRM to allow pirated installs without jailbreaking
thenextweb.com
thenextweb.com
The developer of this program keeps opening PayPal accounts, and PayPal keeps shutting them down. In just December, this developer got two PayPal accounts shut down; the latest one was only used for four days before it was whacked.
Dec 24: "PayPal is back online for http://zeusmos.com and http://uhelios.com – Happy Holidays everybody!" -- https://twitter.com/uhelios/status/283260362919395328
Dec 28: "I'm absolutely done with PayPal. This is ridiculous." -- https://twitter.com/uhelios/status/284654128339243009
However, despite careful and detailed explanations to Stripe--and despite them saying they would look into the matter--this website has been operating and taking payments using their payment processing system for months.
Also, while the developer of Zeusmos claims in the "update" to the article that his application was never supposed to encourage piracy, it came by default with its search results coming from a website called AppTrackr, a large repository of cracked applications.
In the last few months, the developer decided he wanted to "stray away from AppTrackr", but the result was not to move further from piracy: it was to become less reliant on that one piracy site and instead use another one called AppCake.
Meanwhile, the developer has often compared his service to Installous, saying on his Twitter account that "its somewhat like Installous, but better"[1] and that it "has many features that Installous does not excel at very well"[2].
Putting this together: you simply get paid developer accounts from Apple (you will need to keep getting more of these, as you will run up against the 100 device limit), ignore the part of the contract you sign that states that you are not allowed to redistribute the certificates they give you, and instead automate a process to log in to Apple's portal, add a UDID to your account, and download an updated provisioning certificate.
Connect this up with a payment processor that is willing to look the other way and an app that is capable of doing the signature process for apps locally for the user, and you are done. The device is already capable of installing certificates and applications that are signed by them from websites (see Test Flight for a commonly-used legitimate example), so the final steps are easy.
(With an Enterprise account, you don't have to worry about the number of devices; however, the contract terms are much stricter, the system has more mechanisms for Apple to turn you off, and Apple will probably care more if you attempt to abuse it. In essence, an app signed by an Enterprise certificate can be installed on any device, anywhere, at any time until the certificate's three-year expiration date hits.)
Once you are only talking about hundreds or even in the low thousands of devices (as opposed to tens of millions), you can satisfy the demand by getting a bunch of friends from your high-school class (the developer of Zeusmos was 15) to register for individual developer accounts and then contribute their Apple ID and passwords to a pool.
Based on what it says in the article (edit: which a friend of mine is telling me might be wrong, so maybe these people are doing something more complex), the other product (Kuaiyong) was using a single Apple Enterprise certificate: you only need one of these to satisfy an infinite number of devices, and they probably were signing the stuff on their server rather than on the client (so not redistributing the certificate).
That said, the rules on how you can use an enterprise distribution certificate are quite strict: you can sign applications used only by 1) employees of your company; 2) customers of your company who are physically present at your company's place of business; or 3) customers of your company who are being physically supervised by an employee of your company while at another location.
Jailbreaking already allows widespread installation of apps Apple won't let in their store. Its utility is far more than piracy.
Edit: I'm not even playing devil's advocate here, this is just honestly what I think, and I think what most people honestly think. Stuff is better when you don't have to pay for it.
Bullshit. Both on Android apps "not holding a candle to iOS counterparts" and your assertion that this has anything to do with piracy.
Ridiculous example for a ridiculous statement. Piracy is not a feature. If piracy was a feature it'd be ridiculously easy to pirate games on all consoles, but it's not.
Your second statement doesn't make any sense. As a user, I consider "ease of getting stuff for free" a feature of a platform. All other things being equal, it's better to get something for free than to pay for it. The difficulty of pirating stuff for consoles is an anti-feature. Your argument is that if X is a feature then consoles would necessarily have it; consoles don't have it; therefore X is not a feature. There is no reason to assume that consoles would necessarily have every possible feature.
Your opinion is valid. Of course getting things for free is great. But, you are not only speaking to most of the hand that feeds you here, but are also forgetting that a majority of the world operates on a cost-benefit... a majority of people are mostly motivated by money to spend their time doing things. And this is what the dude earlier was trying to say... developers (who are motivated by money) will not develop for a device they can't make money off of. Developing is their dumpster diving, just without the dumpster. It's simply an alternate (and arguably easier [un/fortunately]) way of being.
I have a day job and contribute to open source projects in ways that I can. I hope all developers do this, like I hope lawyers do as much pro bono work as they can; but I realize neither is the case.
I'm off to play my dreamcast.
-Matt
Yes and no.
No, in the sense that they are abusing the pay-for Apple developer services in order to get the software pushed to non-jailbroken devices. As such, they are still playing within the DRM system.
But in the case of Zeusmos, yes, Apple's DRM (FairPlay) is broken in that "re-signing" involves signing a copy of the (App Store published) commercial app that had its original DRM removed.
See here: https://github.com/stefanesser/dumpdecrypted
These techniques were how tools like Crackulous worked, which allowed for the stealing of iOS App Store apps in the first place.
They do! I blogged about this a while back, so the links below are for iOS 5, but they have definitely done it in the past.
http://appadvice.com/appnn/2011/08/apple-takes-steps-against...
http://thenextweb.com/apple/2011/08/05/apple-closes-develope...
http://osxdaily.com/2011/08/05/udid-activation-and-ios-5-bet...
Are you sure? A lot of "credit cards" in China are actually debit cards, where you must deposit money in your account up-front before you can spend. I don't see any reason why banks would make it hard for people to get these, since there's virtually no risk of bad debt.
However, there are also potentially strong reasons to avoid it.
1. China dissuades capital exodus. (They actually have a whole government bureau for this, the Foreign Exchange Management Bureau or 'waihuiguanliju') 2. My recent travels about Southeast Asia suggest that the government-run centralized interbank settlement network 'China Union Pay', is being supported by the government as a regional alternative to the de-facto global defaults Cirrus/Maestro (Mastercard) and Visa (Bank of America).
Anyway, the why doesn't matter. It's really the situation.
So, even in the US, if you have bad enough credit, you may not be able to get a debit card even though in theory you shouldn't be able to charge more than you have.
reality != theory
I mean, even their gift card distribution is now so effective (you can buy them everywhere you go) that even without a credit card, the app store is pretty damn comfortable – so even kids are not necessarily forced to pirate.
http://www.autoomobile.com/news/iphone-5-ios-6-untethered-ja...
iPhone 5 & iOS 6 Untethered Jailbreak: Where Art Thou? 15 mins ago by Rick Berke
It has been a few months since the rollout of iOS 6. In that time we have yet to see a successful iOS 6 untethered jailbreak for the two main smartphones in waiting – the iPhone 4S and iPhone 5.
iPhone 5 & iOS 6 untethered jailbreak progress report
This has left iPhone 4S users on iOS 5 and iPhone 5 users left with no option but to remain locked down. So where is the iOS 6 untethered jailbreak? Let’s take a look at the progress so far.
Starting off in September, we saw the first evidence of an iOS 6 jailbreak from chpwn, who gave us a glimpse of an iPhone 5 jailbroken and running Cydia.
Then in October came news from @planetbeing of a tethered iOS 6 jailbreak under development, and the solution was usable but needed a developer account.
Then it November @planetbeing returned and said that he was even closer to a public release but “missing critical pieces.” At the time he showed IntelliscreenX running on an iPhone 5.
Then in December we were met with a number of hoaxes including a very convincing one from Dream JB. Lastly in the last days of the year, famed iOS hacker pod2g in an interview with iDownloadBlog said that he was, “very confident about the next 6 months” when it came to an iPhone 5 compatible iOS 6 untethered jailbreak.
And that’s where the music has stopped. If so, it may be deep into the summer before the iPhone 5 will be jailbroken. We sure hope this isn’t the case.
Given that Apple then continues to sell the iPhone 4, and they continue to sell very well, you have to defend the argument that "DRM is working well for Apple" against "jailbreaking many devices are easy" even if not "jailbreaking all devices are easy". This is especially true given that these old devices not just sell, but sell well.
http://allthingsd.com/20121018/older-iphones-still-selling-l...
I understand that the base exploit is there, but for me at least, the thought of being tethered and not being able to count on my phone when it runs out of battery is tough.
However, for purposes of "DRM has won against piracy", you have to first look at the demographics of piracy: the average person on Hacker News is a technically proficient user who is out a lot and relies on their cell phone for everything in their lives, from driving directions to business calls to reading websites like Hacker News.
Your average pirate is from a fundamentally different set of demographics: one of the most common is a middle-school or high-school student that shares an iPod touch (not an iPhone) with their sibling; the device probably doesn't leave the house much, and was a hand-me-down from the father (who probably doesn't have much time for games anyway).
I thereby take a lot of issue with people who attempt to frame conversations about anything involving normal people--whether it be the benefits of closed ecosystems, how users spend their money, or really anything--by aiming the spotlight on people who have enough money to own an iPhone 5, or even an iPhone 4S: the iPhone 4 is still selling, and it is still selling like hotcakes, because it costs $200 less up-front. I would even argue that it would be selling better than it is if it weren't perpetually sold out ;P.
In all honestly, I am not even certain why anyone would spend $200 to get an iPhone 5 instead of the iPhone 4, and I actually understand many of the various subtle technical differences... to the normal user, though, the only things they really are able to make decisions about are how the iPhone 4S supports Siri (which, of course, the iPhone 4 could easily handle, as demonstrated by the numerous jailbroken users who actually have installed it on that device--but then this device would have nothing at all which differentiates it to the normal consumer ;P), and that the iPhone 5 is slightly taller (which might even be a turn-off) and has a metallic back (which many will perceive as making the phone more sturdy to drops, but AppleCare+ protects against accidental damage--including drops--and costs only $100).
The result is that if you want to discuss what people who feel even slightly money-constrained are doing, you have to do so in the context of the iPhone 4. Yes: there are people who own recent iPhones and pirate, but at least the few I know (grrr) are in a very weird demographic (super-highly technical people who believe it is a moral sin to purchase information bits and will go to insane lengths to never spend a dollar on, say, iTunes).
I think looking at the technical side of things as an attraction for 'normal' consumers, is the wrong way of going about it, especially with consumer electronics. It's pretty evident by now that people want the latest (and perceived best) device, even if the technical differences aren't that massive. It's enough to be able to say to friends, "I got the iPhone 5".
I'd also assume the iPhone 4 being perpetually sold out is either a determined move by Apple to force sales on upper models, or is just a result of having production lines focused on the upper models. I don't doubt they'd sell either though.
Admittedly I used to be that person, as a teenager. Once I got full time employment, I definitely starting buying more things I would pirate, both for the reason that it was a pain getting updates to apps (Apple does well in this regard), and also because there was no financial reason for me not to if I had the money.
Thanks for your time, and thanks for Cydia :)
I don't know how to jailbreak my phone, nor have my dozen or so google searches yielded anything useful, nor do any of my colleagues have jailbroken phones - despite being precisely the type of people who want to.
Jail breaking used to be straightforward a couple years ago, but for anyone with a recent phone (I have an iPhone 5, colleagues have iPhone 4S's) - it's become pretty difficult.
Any links or pointers appreciated though....
In fact, if you consider piracy a feature, you probably purposely purchase an older phone: Apple still sells the iPhone 4, which continues to be trivial to jailbreak.
That’s speculation, sure, but I haven’t heard anyone offer anything better.
Most of the arguments against DRM aren't about it's ineffectiveness in reducing piracy, but rather its implication for privacy and ownership rights.
[1] https://play.google.com/store/apps/details?id=com.bazaar.ins...
The Android Market is also rather slow to take things down. I've seen MP3 downloader apps that just link to gray area music at best and blatant ripoffs of well known games (such as cut the rope and plants versus zombies) stay listed for months. Eventually they seem to disappear, but then another app pops up in its place.
People still aren't able to make arbitrary in app purchases for free? If that is the case piracy might end up making the developer more in the long run.
As someone whose Android app has wound up on some pirate sites, it's not so much the lost revenue I'm worried about. It's the possibility that the version of my app on some Chinese pirate site has been repacked with malware.
Obviously the average consumer and I just don't see eye to eye about something. I have no idea what, though.
Looks like someone is getting shut down.
The PirateBay receives a lot of support when it's mentioned here. I imagine if I opened a "PirateBayForApps" on which I carried both legitimately free apps and pirated apps, I might not receive the same support.