<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0" xmlns:osnews="http://www.osnews.com/rss2#">
	<channel>
		<title>OSNews: </title>
		<link>http://www.osnews.com/story/25309/iOS_Dev_Sneaks_Malware_Into_App_Store_Feels_Wrath_of_Apple</link>
		<description>Exploring the Future of Computing</description>
		<language>en-us</language>
		<copyright>Copyright 2001-2013, David Adams</copyright>
		<webMaster>adam+nospam@osnews.com</webMaster>
		<lastBuildDate>Fri, 24 May 2013 08:44:00 GMT</lastBuildDate>
		<image>
			<url>http://www.osnews.com/images/osnews.gif</url>
			<title>OSNews.com</title>
			<link>http://www.osnews.com</link>
		</image>
		<item>
			<title>...</title>
			<link>http://www.osnews.com/thread?496473</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?496473</guid>
			<description>lol<br />
 <br />
What they should have done is hire the guy.Edited 2011-11-08 17:15 UTC</description>
			<pubDate>Tue, 08 Nov 2011 17:14:00 GMT</pubDate>
			<author>donotreply@osnews.com (Hiev)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Gutsy move</title>
			<link>http://www.osnews.com/thread?496474</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?496474</guid>
			<description>I'd be worried that apple men dressed as feds would come to tear my place apart. <img src="/images/emo/smile.gif" alt=";)" /></description>
			<pubDate>Tue, 08 Nov 2011 17:24:00 GMT</pubDate>
			<author>donotreply@osnews.com (Alfman)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Gutsy move</title>
			<link>http://www.osnews.com/thread?496475</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?496475</guid>
			<description><div class="cquote">I'd be worried that apple men dressed as feds would come to tear my place apart. <img src="/images/emo/smile.gif" alt=";)" />  </div><br />
<br />
Heck even I regularly look over my shoulder.</description>
			<pubDate>Tue, 08 Nov 2011 17:26:00 GMT</pubDate>
			<author>donotreply@osnews.com (Thom_Holwerda)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Gutsy move</title>
			<link>http://www.osnews.com/thread?496505</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?496505</guid>
			<description>Or better yet, Fed's working for Apple. <br />
<br />
Actually this guy could potentially face persecution for doing this. Not that he would deserve it but the pertinent law is so out of whack.</description>
			<pubDate>Tue, 08 Nov 2011 19:46:00 GMT</pubDate>
			<author>donotreply@osnews.com (kristoph)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>I don't see the problem</title>
			<link>http://www.osnews.com/thread?496519</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?496519</guid>
			<description>This guy knowingly violated the terms of service of the app store and is then surprised when he gets kicked out?<br />
<br />
Good on him for finding the security flaw.  Good on him for reporting it to Apple.  However that's as far as it should have gone.  Sneaking in an app is way over the line, since he has actually compromised real devices.<br />
<br />
If he wants to get more publicity he could release the info to the public.  Sure, this is a more effective publicity stunt, but the reaction from Apple is totally appropriate.</description>
			<pubDate>Tue, 08 Nov 2011 20:56:00 GMT</pubDate>
			<author>donotreply@osnews.com (leos)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Charlie Miller</title>
			<link>http://www.osnews.com/thread?496521</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?496521</guid>
			<description>Ah.. Charlie Miller is a bit of a meveric. It's also unlikely Apple could entice him on to the payroll, as he is a general Security Researcher, not Apple specific.</description>
			<pubDate>Tue, 08 Nov 2011 21:13:00 GMT</pubDate>
			<author>donotreply@osnews.com (henderson101)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: I don't see the problem</title>
			<link>http://www.osnews.com/thread?496534</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?496534</guid>
			<description><div class="cquote">Good on him for finding the security flaw. Good on him for reporting it to Apple. However that's as far as it should have gone. Sneaking in an app is way over the line, since he has actually compromised real devices.  </div><br />
<br />
He had to prove his exploit worked. Had he not done this, Apple would've simply said &quot;our review process will catch it, so no problem, now bugger off&quot;.</description>
			<pubDate>Tue, 08 Nov 2011 22:03:00 GMT</pubDate>
			<author>donotreply@osnews.com (Thom_Holwerda)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: I don't see the problem</title>
			<link>http://www.osnews.com/thread?496539</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?496539</guid>
			<description><div class="cquote">He had to prove his exploit worked. Had he not done this, Apple would've simply said &quot;our review process will catch it, so no problem, now bugger off&quot;. </div><br />
<br />
The article says he reported the vulnerability to Apple. I wonder if he got any sort of response before publishing his app ...</description>
			<pubDate>Tue, 08 Nov 2011 23:00:00 GMT</pubDate>
			<author>donotreply@osnews.com (WorknMan)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: I don't see the problem</title>
			<link>http://www.osnews.com/thread?496540</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?496540</guid>
			<description><div class="cquote">"<i>Good on him for finding the security flaw. Good on him for reporting it to Apple. However that's as far as it should have gone. Sneaking in an app is way over the line, since he has actually compromised real devices.  </div><br />
<br />
He had to prove his exploit worked. Had he not done this, Apple would've simply said &quot;our review process will catch it, so no problem, now bugger off&quot;. </i>"<br />
<br />
In which case the responsible thing would have been to take down the app immediately after it was approved.  But he didn't.</description>
			<pubDate>Tue, 08 Nov 2011 23:01:00 GMT</pubDate>
			<author>donotreply@osnews.com (rhavyn)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: I don't see the problem</title>
			<link>http://www.osnews.com/thread?496598</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?496598</guid>
			<description><div class="cquote">"<i>Good on him for finding the security flaw. Good on him for reporting it to Apple. However that's as far as it should have gone. Sneaking in an app is way over the line, since he has actually compromised real devices.  </div><br />
<br />
He had to prove his exploit worked. Had he not done this, Apple would've simply said &quot;our review process will catch it, so no problem, now bugger off&quot;. </i>"<br />
<br />
And that is their prerogative.  The market will punish them if they ignore it and it leads to widespread exploits.</description>
			<pubDate>Wed, 09 Nov 2011 06:33:00 GMT</pubDate>
			<author>donotreply@osnews.com (leos)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Missing the point</title>
			<link>http://www.osnews.com/thread?496623</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?496623</guid>
			<description>To the people saying that Apple did the right thing and he shouldn't complain about the ban: you are missing the point.<br />
<br />
We've been told repeatedly that thanks to the review process whatever we download from the App Store is safe. Well, guess what? That is not the case and, think about it, how could it be? Even when the source code is available, auditing software is hard and, even if this was the case, with a gazillion apps on the store and (I suspect) only a handful or reviewers in the staff, how could they possibly catch everything?<br />
<br />
In other words: you can't believe everything you hear (even if it comes from Apple) and a bit of caution is still advisable. In this respect iOS is no different from any other other platform: it's safer to stick to well known, reputable developers.<br />
<br />
On a more technical note, it seems to me that Miller's application wasn't malware per se: the application behaved normally until he instructed it to download the malicious payload, didn't it?<br />
<br />
<br />
RT.</description>
			<pubDate>Wed, 09 Nov 2011 09:37:00 GMT</pubDate>
			<author>donotreply@osnews.com (karunko)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Comment by zima</title>
			<link>http://www.osnews.com/thread?497276</link>
			<guid isPermaLink="true">http://www.osnews.com/thread?497276</guid>
			<description>What's really curious is how the claims of iOS safety persist despite often quite quick emergence of jailbreak-via-Safari - essentially, a root access exploit when accessing a random website.</description>
			<pubDate>Tue, 15 Nov 2011 23:53:00 GMT</pubDate>
			<author>donotreply@osnews.com (zima)</author>
			<category>Comments</category>
		</item>
	</channel>
</rss>
