How the CIA Might Target Apple's XCode
schneier.com
schneier.com
I think this part is the most interesting: by manipulating Xcode, the spies could compromise the devices and private data of anyone with apps made by a poisoned developer
I know iOS allows us to block an app from utilizing data over cellular, I guess the concern would then be on wifi networks.
As always you can never be certain, but assuming Android has also been targetted would help to explain some odd bits compiled into things like the Android Uber app [1]. My gut tells me that researchers ought to look at the Apple version.
[1] http://www.gironsec.com/blog/2014/11/what-the-hell-uber-unco...
You could always... not be the one
Getting an Apple Private Key for signing the binary is also just a few blackmails and a gag order away. The average Apple engineer sure doesn't like to end up in jail for a prolonged time just because they happened to "find" some illegal material on one of his computers.
The sad truth is, the frameworks for something like this are already in place. There are "elements" in the government which have total control and surveillance at the very top of their agenda.
Controlling the media is easy (see Chinese, Russian State Televion etc.) but you also need to control the Internet these days. China is already really "good" at this and the US is also doing the groundwork, it's not as easy for them as it is for the Chinese, because they don't want to kill their tech sector and the billions of revenue for good overnight, so they have do introduce these things more slowly.
This is one of those cases where the betrayal of the NSA/GCHQ/Spy-Agencies-of-the-5-eyes-nations is really obvious. We can no longer trust our developer tools...
Last time I've checked apple was an US company. https://en.wikipedia.org/wiki/Patriot_Act
>If you distrust all software that isn't open source
Sadly, this isn't enough. A lot of people are pushing for deterministic builds for exactly this reason.