The Macrosite for News, Analysis and Opinion about the Future of the Internet
Kim Davis

Apple Battles Russian Hacker

Written by Kim Davis
7/25/2012 13 comments
DISCUSS     Email This

A fascinating duel has been underway this month between Russian hacker Alexey Borodin and the mighty Apple. Long lauded for the security of its products, Apple has been dealing with an exploit that permitted purchases to be made inside iOS apps without the customer being charged.

Borodin estimates that some 8.4 million such purchases were allowed by the exploit. By a conservative estimate, this entails a loss of a similar dollar amount, split 70/30 between the app vendors and Apple. It's been an expensive affair, then, as well as an embarrassing one.

Borodin's method, which involved using bogus certificates and a special server setting to fool apps into thinking they were communicating directly with the Apple Store, and receiving receipts from it, was published two weeks ago, and adopted with such glee by consumers that the Website where it was posted was overwhelmed by traffic. Apparently, people like something for nothing?

The weakness in Apple's system, according to Borodin, was that in-app receipts were generic, containing no specific user data, and were thus "easy to spoof."

Apple moved swiftly to patch the damage by installing APIs to validate each individual app purchase. It has also said that the iOS 6 update, due soon, will provide a permanent fix. Borodin has conceded defeat in this first skirmish, admitting that his exploit cannot bypass the new APIs.

Also, in typically provocative "grey hat" fashion, Borodin claims to have performed a public service: "It is a good news for everyone, we have updated security in iOS, developers have their air-money." Hey, thanks.

Apple will doubtless be overjoyed to learn that Borodin has now moved on to helping out with security on app purchases made via Mac OS X. He has developed a slightly elaborated version of the previous exploit. This time, in addition to bogus certificates and the server setting, would-be freeloaders require an app called "The Grim Receiper," easily found online.

As before, Borodin is exploiting the Apple Store's reliance on receipts rather than on data that securely identifies a purchaser's account or device. Apple's purchasing system clearly has a conceptual and structural flaw, not just a technical one.

Apple has yet to respond to Borodin's latest move -- which, again, is so public that he can claim to be Apple's security savior -- and indeed, Borodin has been crowing about its failure on his blog.

Of course, with friends like Borodin, who needs cybercriminals?

Related posts:

— Kim Davis Follow me on TwitterVisit my LinkedIn pageFriend me on Facebook, Community Editor, Internet Evolution

DISCUSS     Email This
Current display:       newest comments first       display in chronological order
Page 1 of 2   Next >
Mashka
Researcher
Saturday August 4, 2012 6:36:45 AM
no ratings

Hm..Interesting. The guy I Know offered me to crack my Iphone - so I can download all programs for free, but I thought that it wasn't a good idea. It's pretty simple,  you can find all directions online

The funny thing for me was that the guy who offered me that, developed an application for Iphone by himself and he developed a  paid application and he still downloaded other apps for free- didn't make sense for me at all.

scucci
IQ Crew
Monday July 30, 2012 9:48:02 AM
no ratings

Good point - Apple is also great at public relations as we saw with the Java exploit that hit them a few months back. They're like Willy Wonkas factory. No one knows what goes on in there.

Bolingbroke
IQ Crew
Thursday July 26, 2012 10:17:19 AM
no ratings

 I hadn't heard about this.

 Ron, the fact that most everyone hasn't heard about this is the rub and you would be expected to know about this. Where the heck did Kim dig this up from? Certainly not on any front page, not headlining a web site, not featured on a tv morning show. As long as Apple keeps this item buried the myth of its invulnerability will continue.

"If a tree fall in a forest ... ", you know the rest of it.

Paul Whyte
Researcher
Thursday July 26, 2012 9:34:07 AM
no ratings

What's so endearing about this hacker? If it had been Google, I would have understand considering your usually harsh take on anything that is Google.

Paul Whyte
Researcher
Thursday July 26, 2012 9:25:38 AM
no ratings

"Also, in typically provocative "grey hat" fashion, Borodin claims to have performed a public service: "It is a good news for everyone, we have updated security in iOS, developers have their air-money." Hey, thanks."

There is always enough reasons to encourage the likes of Borodin to test the security readiness of these OSs. We hate cyber criminals but from time to time cyber tricks that are aim to test the security readiness of our infrastructure are really welcome. 

scucci
IQ Crew
Wednesday July 25, 2012 11:23:52 PM
no ratings

Apple is no different than any other operating system. Once you get people focusing on the OS or apps they'll find vulnerabilities. They just need a reason to start looking.

scucci
IQ Crew
Wednesday July 25, 2012 11:22:34 PM
no ratings

Spoofed certs are becoming the hackers/malware writers entry into completely owning a device or appliation (I.E Flame, Comodo, etc.).

It's hard to have complete trust in anything these days.

Ron_Miller
Rank: Web master
Wednesday July 25, 2012 6:38:36 PM
no ratings

Kim:

Great post. I hadn't heard about this. I don't know why but I find this Russian hacker suprisingly endearing. Maybe there's just something attractive about sticking it to the man. :)

smkinoshita
Thinkernetter
Wednesday July 25, 2012 4:21:37 PM
no ratings

I'm indifferent to Apple but even I'm highly amused by how one hacker is publicly causing so much trouble for them.

kenton
IQ Crew
Wednesday July 25, 2012 4:20:11 PM
no ratings

Is Apple's internal development team so bad at finding these things that Apple is actually letting other people do it for them? Apple's normal behaviour in this kind of a situation would be to go after Borodin with all guns blazing. Locking him out of the app store and suiing him and everything around him. But in this case they are just fixing the problems. Sounds to me like they need him right now.

Page 1 of 2   Next >
The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
previous posts from Security Clan Editor's Blog
Kim Davis
Kim Davis   5/21/2013   13 comments
Extending existing US wiretap laws to give federal agencies easier backdoor access to Internet communications -- especially real-time P2P services like VoIP -- will give, not only aid and comfort, but also technical assistance, to the country's enemies. Not to mention cyberthieves.
Kim Davis
Kim Davis   5/15/2013   13 comments
When David E. Sanger of The New York Times broke the news that the United States was responsible for the Stuxnet malware exploit against Iran's nuclear program, Senator John McCain accused the administration of deliberately leaking the story to enhance President Obama's national security record.
Kim Davis
Kim Davis   5/8/2013   14 comments
The Gamma Group's business of supplying surveillance technology exclusively for use by government agencies may be legitimate. But not when it poses as the popular, free, open-source web browser Firefox.
Kim Davis
Kim Davis   5/1/2013   41 comments
If you were concerned about Twitter handing over your private data to the government, think again.
Kim Davis
Kim Davis   4/24/2013   18 comments
Yesterday's hack of the official Associated Press Twitter feed demonstrated the enormous risk attached to the platform's lazy, single factor approach to security.
5
of
Reiter's Block
iPhone Maps Fiasco Teaches Universal Lesson

9|26|12   |   3:15   |   36 comments


The Apple Maps fiasco raises questions for enterprises about how they handle application development and launches.
Reiter's Block
In Siri We Can't Trust

5|29|12   |   3:12   |   12 comments


If Apple's Siri changes her answer about what the best smartphone is, how can you really trust her and other voice "assistants"?
Kim Davis
Murdoch's Scandal for the Digital Age

4|27|12   |   3:06   |   16 comments


The Murdoch/News International scandal has all the elements of the digital age, from phone-hacking through embarrassing emails to agile digital reporting.
Reiter's Block
Apple, AT&T Magically Turn 3G Into 4G

3|14|12   |   2:26   |   5 comments


Apple's new iPhone update on AT&T phones magically turns 3G into 4G... if you believe in "1984."
what.the.ferraro
Goodbye, Real Life. Hello Video in a Hat

3|2|12   |   2:36   |   18 comments


Are you officially done interacting with society? There's a hat for that.
what.the.ferraro
Disturbing Holiday Trends on the Web

12|23|11   |   2:54   |   9 comments


Celebrate the holidays the World Wide Web Way, with holiday-themed digital app farms, creepy Santa photo Websites, and more, more, more!
Wisdom of the Big Chair
Smart Phones, Dumb Users

10|7|11   |   2:38   |   3 comments


Smartphone users are aware that their systems are open to possible security breaches. But NPD Group found that more than 82 percent of them do not have any security software on their phones. That's just dumb.
Kim Davis
News of the World Hacking Makes Front Page Again

8|17|11   |   2:52   |   8 comments


News International is in deep trouble again: New evidence suggests that James Murdoch and others may have misled Parliament. We're shocked. Shocked!
what.the.ferraro
President Obama Elected Mayor!

8|16|11   |   2:40   |   6 comments


President Obama may soon earn the badge as "Mayor" of the White House, thanks to his joining the mobile check-in service, FourSquare. Let's all sigh in unison, shall we?
Reiter's Block
TabCo's Secretive Tablet Computer

8|12|11   |   2:38   |   14 comments


A new company will launch its tablet on August 15. While its commercials have been boastful, it's also provided almost no product details.
IETV: the thinkerNet on film
5
of
Kim Davis
Big-Data Can’t Always Sell Wine

5|21|13   |   2:23   |   4 comments


Whole Foods Global Wine Purchaser Doug Bell told me about some of the constraints on using analytics in the US wine market.
Paul J. Fleuranges
Digital Signage Keeps NYC Subway Straphangers on Track

5|6|13   |   3:51   |   No comments


New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
Kim Davis
Fast Forward to the Future

4|23|13   |   2:29   |   20 comments


A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
Mitch Wagner
Google Launches Its Most Depressing Service Yet

4|15|13   |   2:59   |   10 comments


Google's new Inactive Account Manager lets you control how Google disposes of your accounts when you die.
Second Shooter
Argument Over Top-Level Domains Is 'Stupid'

4|11|13   |   2:07   |   3 comments


The whole Amazon.reader debate is a double-stupid. It's stupid to think that there's any e-book buyer who doesn't know Amazon's URL, and it was stupider to let ICANN launch the whole free-form TLD initiative to start with.
Kim Davis
Ladies, Your Tablet Awaits

3|21|13   |   2:22   |   37 comments


ePad Femme is the world’s first tablet “made exclusively for women.”
Wisdom of the Big Chair
NFC Moves Into the Mainstream

3|20|13   |   2:16   |   No comments


While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
Wisdom of the Big Chair
Integrating Security Into Your Cloud Contract

3|19|13   |   3:35   |   No comments


Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
Brian Baron
How Edmunds.com Collects Customer Information

3|18|13   |   1:15   |   No comments


Edmunds separates customers into segments based on the info it collects on its site and from partners, and uses that to push out custom content, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
Brian Baron
How Edmunds.com Uses Analytics to Customize Site

3|14|13   |   0:47   |   No comments


The automotive website uses propensity modeling to target ads and customer registration forms, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
an IBM information resource
sponsored content
big blue blog
an IBM information resource
sponsored content
Expert Integrated Systems: Changing the Experience & Economics of IT
In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Keep Critical Data With a Knowledge Management System
Taimoor Zubair
Fortune 500 companies lose at least
$31.5 billion a year by failing to share knowledge. A Knowledge Management System (KMS) can help companies significantly reduce these costs.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE