Here's the Most Idiotic and Brilliant App Ever
thevine.com.au
thevine.com.au
You just need to HTTP GET the following URL:
http://www.carrotpop.com/smth/php/save_result.php?id=<UID>&nickname=<NICK>&country=&result=<HEIGHT>&latitude=0&longitude=0
* UID looks like an autoincrement ID* NICK is what you entered for the highscore
* HEIGHT is the float value of the height in meters, i.e. "1.23"
In the HTTP response, you get a data structure (not sure which encoding it is, but it is straightforward) of the highscore data:
[[["1.","LIATO","44.19m"],["2.","ROYBOY_91","43.16m"],["3.","YAIR40","35.12m"],["4.","GABRIEL","34.70m"],["5.","KAI","31.10m"],["6.","KAFAC99","21.06m"],["7.","JOSH","20.37m"],["8.","KEANSKI","17.61m"],["9.","EKREM6363","16.10m"],["10.","LORENZO","12.24m"],["2047.","MY BEST TRY","0.71m"],], ...
Edit: just opening the URL http://www.carrotpop.com/smth/php/save_result.php you can see the current stats, encoded as above.But assuming you have control of your home network and aren't just using a Linksys thing out of the box, just logging into the router and watching traffic is by far the most straightforward.
My instinct tells me the simplest solution would be security by obscurity - adding some validation token that the client generates by some obscure and hard to reverse engineer manner. Is there any better way to 'validate' your client?
Use SSL for the requests which makes it harder to sniff the API.
Add some sort of tamper token like you suggest.
Use a specific User Agent string and check for that.
Provide no error messages if any of the above fails.
Won't help - it's trivial to setup a proxy to MITM the traffic.
> Use a specific User Agent string and check for that.
Won't help - it's easy to manipulate a User-Agent. Assuming you're manually creating the GET request (via cURL or other means), then it's only one more option to bypass this.
> Provide no error messages if any of the above fails.
Will make debugging a pain. Also, if I'm an attacker, I'm going to try and clone the request as best as I can the first time, then see what I can get away with.
> Add some sort of tamper token like you suggest.
This is the best option. Not quite sure the best way to implement it, but perhaps some sort of CAPTCHA (this would be a pain), or some kind of random request id, etc. might work.
As for the app itself, cool! I'm glad somebody had the audacity to ship something as outrageous as this. I don't think it will get much of a following, but I suppose if you really don't care about your phone or you're really confident in catching this could be a cool, reckless waste of 10 minutes.
EDIT: For clarification, I don't really side with or against Apple in general on things, so this isn't meant to be a "Apple's always a walled garden, BAH" post, etc...I just really feel any company should let users feel free to destroy hardware. But I understand that might not be the best philosophy to run a multinational company.
EDIT2: Just thought of a way to game this after reading another comment - slap on a Lifeproof case, go in a big pool shallow enough to stand, throw it really high. Eliminates the need to catch it (within...reason...).
Also "13.1 Apps that encourage users to use an Apple Device in a way that may cause damage to the device will be rejected"
Although, what you said about warranties makes sense...however honestly that hasn't kept friends of mine from deliberately breaking their phones just to get new ones.
Did you criticize them when you found out they did that?
As for myself, my iPhone 4 is half-broken and I'm still eeking out whatever life I can get from it before I get the iPhone 6 in the Fall.
The reason is that Apple has a very generous straight replacement policy (at a fraction of the retail new price) even if you don't subscribe to any of their care plans. This is a world different from makers like HTC and Samsung who fully intend to double dip if you have an issue with your device, where a replacement of a broken device costs 100% of its original price (meaning you are paying again for marketing, R&D, profit, markup, etc). I have faced exactly this twice (both with Samsung), once where they claimed nebulous, unproven corrosion damage on a device that had never touched water, and had all clear water sensors. As a user there is nothing I can do to contest this, their warranty being effectively useless through no negligence of mine. They nicely offered to fix it for just over a thousand dollars.
Samsung and HTC and others want you to bust your device. Apple doesn't, because they have a stake in it as well, making no profit from your own misadventure.
I cannot overstate how helpful and efficient the staff were and the process was just so quick and simple. If (mildly idiotic) apps like this being banned are the price of that piece of mind? I pay it gladly.
In the end, he decided it might be irresponsible to leave the app on the market and encourage people to throw around their shiny new expensive phones.
I don't want to throw my phone high into the air, watch it go to pieces and not even get a high score.
"Your phone soared 100 ft. before dying a soldier's death. New high score! Good luck about the phone though."
I'd think that would defeat the purpose of the "...and catch it!" step.
If anything, I'd want such an app to record video or perhaps fire the camera for a still the peak. I'm thinking that would a be huge plus to the idiotic entertainment potential, like a less inane Vine and a slight deterrent from the inevitable result spoofing.
http://www.slashgear.com/squinto-throwable-ball-camera-grant...
Prior art, unfortunately also attempting a patent is at:
http://patft.uspto.gov/netacgi/nph-Parser?Sect1=PTO1&Sect2=H...
Also, a multiplier for the case you describe.
There's a phone recycling bin here at school; I'm tempted to grab a few old android phones and see if I can get one working well enough to try it out.
- on GPS, as mattbessey suggested. (precision: 2m max)
- integrating accelerometer data : Very difficult, as the telephone would spin. Also: measurement errors are integrated too, so not too precise.
Best option is time based:
1) Detect launch/landing time by looking at accelerometer spikes (easy, good time precision)
2) Altitude = 1/2 * g * ((timeLanding - timeLaunch) / 2) ^ 2. Air resistance negligible. g = 9.81 m/s^2.
Also, see their Facebook. They publicly post GPS location of winners, together with StreetView. Is that stated in the app? It can be a privacy concern.
com.carrotpop.www.smth E/AndroidRuntime: FATAL EXCEPTION: main
java.lang.IllegalArgumentException: requested provider gps doesn't exisit
at android.os.Parcel.readException(Parcel.java:1429)
at android.os.Parcel.readException(Parcel.java:1379)
at android.location.ILocationManager$Stub$Proxy.requestLocationUpdates(ILocationManager.java:646)
at android.location.LocationManager._requestLocationUpdates(LocationManager.java:660)
at android.location.LocationManager.requestLocationUpdates(LocationManager.java:482)
at com.ansca.corona.CoronaSensorManager$1.run(CoronaSensorManager.java:163)
at android.os.Handler.handleCallback(Handler.java:615)
at android.os.Handler.dispatchMessage(Handler.java:92)
at android.os.Looper.loop(Looper.java:137)
at android.app.ActivityThread.main(ActivityThread.java:4745)
at java.lang.reflect.Method.invokeNative(Native Method)
at java.lang.reflect.Method.invoke(Method.java:511)
at com.android.internal.os.ZygoteInit$MethodAndArgsCaller.run(ZygoteInit.java:786)
at com.android.internal.os.ZygoteInit.main(ZygoteInit.java:553)
at dalvik.system.NativeStart.main(Native Method)btw, I see com.ansca.corona.CoronaSensorManager in the exception stack trace, suggesting this app was written in Lua using Ansca Corona.
Somehow I doubt that's included in the Android API. ;)
By "known", I assume you mean "known, assuming you want to track down (an trust!) the specs of the ~4,000 different Android devices", correct?
So...CarrotPop is off to a good start I guess.
Visit it on your browser to get started, then on your iPhone to play (App is not tuned for Android accelerometer data yet).
Think of it as the heart of a 2-part high-school physics project:
1. Develop a rocket that will carry your smartphone as its payload.
2. Develop a case that will allow your smartphone to survive the landing.
...and a 2-part college project:
3. Find investors for your high school project, then market it.
4. Profit!
I imagine the strong horizontal acceleration and in-flight rotation of the phone may "throw off" (heh) the height calculation, but it likely would have earned an impressive score.
When I saw it I laughed for a long time :-)
My high score is 604, and I think I want to stop playing this game.
I don't endorse this.
Alternatively: skydiving!
Actually,
13. Damage to device
13.1 Apps that encourage users to use an Apple Device in a way that may cause damage to the device will be rejected
Put together a baseball with an accelerometer, a small digital display and maybe bluetooth as well.
Sell it to schools and individual athletes as a training device. You pitch and it tells you what the speed of the last pitch was. Connect it up to a computer and it will give you a graph of the velocity over time, allow you to track improvements in pitching and track users.
Or does such a thing already exist?
Summary: a professional baseball pitcher might be able to reach fifty metres but the human arm is optimised for throwing horizontally.
I wanted a gaming achievement: "30 seconds in free fall". With a follow-up five minutes. The first one you might get using the Vomit Comet. The second probably requires significantly more expenditure.
I wonder if there is a way to "hack" the accelerometer...
That top score should be the result of manipulating the sensors or the data sent to the server. [edit: ... or measuring some other action than throwing the phone]
If the software is not too picky detecting weightlessness, just holding your phone while inside a fast elevator going down could also work.
A fun, if elementary, physics puzzle.
Or idiotic because the energy spent on this could have been used to build something that actually provided value?