TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Security researcher Charlie Miller booted from Apple Developer Program

191 点作者 cubix超过 13 年前

15 条评论

jjguy超过 13 年前
It's a bad move for apple. A good relationship with the community of security researchers is crucial - they're talented folks and their research results grab headlines. It takes just a tiny amount of corporate humility and public thanks to win their respect, and in return get goodwill. Treating the community badly will get ensure the next guy won't even try to cooperate.<p>Over the last several years, Microsoft's MSRC has balanced this very well. Google has done well recently, too. Lots of clued-in people in both places.
评论 #3209248 未加载
评论 #3209281 未加载
评论 #3209277 未加载
评论 #3209333 未加载
评论 #3211284 未加载
评论 #3209252 未加载
guan超过 13 年前
It’s rude when according to the article he withheld details of the exploit to give Apple time to fix the bug, but the decision is understandable since he did violate the developer agreement. I’m not so sure about “interfering with Apple's software and services” but his activites seem to be covered under “hiding features from [Apple] when submitting them.”
评论 #3209090 未加载
评论 #3209184 未加载
评论 #3209076 未加载
jjtheblunt超过 13 年前
He's got great skills, and NSA training is as good as it gets, but he explicitly violated the rule to not download and run code from a server, to see if the rule would be enforced. They enforced it, just as he'd known they would. There was no point to his doing that other than to get headlines.
评论 #3209225 未加载
feralchimp超过 13 年前
"I don't think they've ever done this to another researcher. Then again, no researcher has ever looked into the security of their App Store. And after this, I imagine no other ones ever will," Miller said in an e-mail to CNET. "That is the really bad news from their decision."<p>Take your wrist-slap like a man, sir.<p>Apparently the grand are also prone to self-aggrandizement. I have a lot of respect for Miller's skills, but he's not the only smart person taking a hard look at App Store security.
评论 #3209378 未加载
评论 #3209808 未加载
评论 #3209209 未加载
MichaelApproved超过 13 年前
Apple is extremely binary. You're either with them or you're not. They don't seem to have flexibility and the only punishment is to be banned.<p>Awful.
评论 #3210254 未加载
pnathan超过 13 年前
As a metanarrative, it's very interesting seeing the conflict between the rules followers and the ethics followers here in this thread.
tomlin超过 13 年前
I feel like if this were an Android flaw, I'd see it in the title. Miller was booted from dev for discovering a major flaw in iOS. A hacker can have full access to the phone and personal data by just downloading an app from the App Store. Definitely worth mentioning in the title.
sdiwakar超过 13 年前
There's always this flip-side to reporting security findings. I don't know the details of Charlie Millers exploit, however had he gone through the process of informing the vendor (in this case Apple) and then allowing sufficient time to address the issue, perhaps a showdown could have been avoided (I'm assuming that he hadn't).<p>People however, also forget that, there are other pressures facing info-sec researchers - such as pressure from management at the company where they work to 'publish' and/or present their findings under the company banner. Often, this irks vendors, because vulnerabilities are used to promote the researcher's (or who they work for) interests.<p>That said, Microsoft, Google and Facebook have very transparent processes &#38; expectations for submitting vulnerabilities.
makira超过 13 年前
Anyone has information regarding the actual vulnerability ? That would be very interesting. Thanks.
super_mario超过 13 年前
Oops. Watch the number of trojans for OS X go up now.
JoeAltmaier超过 13 年前
Its a walled garden; they can do anything they like. Live with it.
Tomis超过 13 年前
The spirit of Steve Jobs lives on.
sigzero超过 13 年前
He uploaded malware to the store in violation of his developers agreement. FAIL.
评论 #3209234 未加载
RusAlexander超过 13 年前
The Apple is changing preferences, now they don't want to have a more secure soft. IMO Steve Jobs wanted.
nchuhoai超过 13 年前
I come into your party as a guest and what I do is steal all your stuff. If you would be a white hat, you would knock at the door and kindly hint me to the loophole instead of just doing it ...
评论 #3209487 未加载