My Message close
GAME JOBS
Latest Blogs
spacer View All     Post     RSS spacer
 
May 21, 2013
 
An Object Of Lust
 
Gamasutra Blog Guidelines - Updated and open for discussion [9]
 
Postmortem: ROBLOX Mobile
 
Fingle marketing effort and numbers [1]
 
Next-Gen Xbox: What Microsoft Needs To Reveal On 21st May [15]
spacer
Latest Jobs
spacer View All     Post a Job     RSS spacer
 
May 21, 2013
 
Blizzard Entertainment
Senior Software Engineer, User Interface
 
Blizzard Entertainment
Senior Technical Artist
 
Blizzard Entertainment
3D Environment Artist, Senior
 
Blizzard Entertainment
Dungeon Texture Artist
 
Blizzard Entertainment
3D Character Artist, Lead
 
Hidden Variable Studios
Senior Designer
spacer
Latest Press Releases
spacer View All     RSS spacer
 
May 21, 2013
 
Unity Empowers Games
Industry with Free
Mobile...
 
- World of Kingdoms -
 
My Virtual Girlfriend
gets a Facelift
 
From Xbox to jukebox
 
Tagoria celebrates its
5th birthday with a...
spacer
About
spacer Editor-In-Chief:
Kris Graft
Blog Director:
Christian Nutt
Senior Contributing Editor:
Brandon Sheffield
News Editors:
Mike Rose, Kris Ligman
Editors-At-Large:
Leigh Alexander, Chris Morris
Advertising:
Jennifer Sulik
Recruitment:
Gina Gross
Education:
Gillian Crowley
 
Contact Gamasutra
 
Report a Problem
 
Submit News
 
Comment Guidelines
Sponsor

 
Apple fixes iOS hack, but now Mac App Store targeted
Apple fixes iOS hack, but now Mac App Store targeted
 

July 23, 2012   |   By Eric Caoili

Comments Post A Comment

More: Console/PC, Smartphone/Tablet, Business/Marketing





Apple has issued a temporary fix for the hack that allows users to download premium content in iOS games and applications for free, but the culprit behind the exploit is now turning his attention to the Mac App Store.

Detailed by Russian hacker Alexey Borodin two weeks ago, the vulnerability affects developers that validated in-app purchases by connecting to the App Store server. Apple attempted to block the service that made the hack possible, but Borodin moved it to another server, and has so far processed tens of thousands of illicit downloads.

Apple has offered a fix for affected game makers by publishing a "best practices" guide that outlines how they can patch the vulnerability in their titles using a private API -- one of the few times the company has actually encouraged developers to use a private API.

This fix, though, is a temporary measure that developers will have to implement themselves. Apple says it will not be able to patch this exploit completely until it puts out the next operating system update for its smartphones and tablets, iOS 6, which is expected to release this fall.

Borodin has conceded defeat, at least when it comes to working around security measures for iOS app purchases: "[The] game is over. Currently we have no way to bypass updated APIs. It's good news for everyone; we have updated security in iOS, developers have their air-money."

However, the hacker unveiled a similar exploit on Friday that circumvents in-app purchase fees on the Mac App Store. Apple has not yet addressed that vulnerability, and Borodin implies that he will have more workarounds ready if the company releases a fix.
 
 
Top Stories

image
Unity's mobile licenses are now free
image
Market's ready for new consoles, but old-gen surprisingly viable
image
The next Xbox: What Microsoft needs to reveal this week
image
Practical ways to deal with problematic player behavior


   
 
Comments


none
 
Comment:
 




 
UBM Tech