Hacker News new | ask | show | jobs
by andreasley 3579 days ago
According to this article [1], the compromised app was indeed signed – but with a different Developer ID than usual.

Anyone with a credit card can sign up for Apple's developer program and start signing apps.

[1] http://www.welivesecurity.com/2016/08/30/osxkeydnap-spreads-...

2 comments

> According to this article [1], the compromised app was indeed signed – but with a different Developer ID than usual.

That's the terrible part about all of this. Having signed applications without any verification of the signer is pointless.

A simplistic, yet more secure approach, would be to have domain validated keys that could be used to sign applications. Browsers could then verify that the application downloaded from example.com was signed with a key for example.com. I think OSX already stores "This was downloaded from the scary internets!" in a separate resource fork so this info could go there as well. Maybe even cut out the middle mad and put them in DNS SRV records so you don't even need a central CA. If DNS gets compromised the client's have bigger problems already.

Unfortunately like all things like this, it'd be forever before it's widespread enough to be useful.

It's not completely pointless, as it allows Apple to (silently and quickly) release updates which distrust that Developer ID, however a stronger protection would be to pin apps to a particular Developer ID.
So Apple/the bank/a warrant can return his name?
The credit card was most likely stolen. You can buy them in bulk from some websites.
US cards used to go for around $2.50 a pop several years back. Way cheaper in bulk. Not sure about now though.