Meet Two Security Researchers Apple Hates (Video) 146
This video is a half-hour speech given by Dino Dai Zovi and Charlie Miller, two people Apple corporately hates because of their success in finding security holes in Apple operating systems and software. Both Charlie and Dino have been mentioned on Slashdot before and probably will be again. This is a chance to see how they sound and look in person, talking to a small "by invitation only" group. They have a book to push, too: The iOS Hacker's Handbook. (Please note that this book is supposed to help you secure iOS and iOS apps, not exploit security holes in them.)
Slashdot happily accepts video submissions. Do you have one to share with other Slashdot users?
Silly and inflammatory (Score:5, Insightful)
Seriously... why the inflammatory headline? other than creating link bait. Why would Apple hate them? They're doing the R&D on security for them...
Re:Silly and inflammatory (Score:5, Informative)
Re: (Score:1)
Charlie and Dino sounds like some kids adventure movie. What's up with that?
Re: (Score:2)
Re:Silly and inflammatory (Score:5, Informative)
well Charlie did get banned from the app store for 1 year for finding a security hole. Perhaps they dont hate him but they got pretty miffed at him.
No, he was banned because he deliberately violated the terms of the appstore by creating a tool that collected end user information instead of disclosing the issue to apple.
Re: (Score:2)
Re: (Score:2)
No. The right thing to do would be to follow standard full disclosure [wikipedia.org] principles. What he did is the rough equivalent of releasing an exploit into the wild.
Re: (Score:2)
So like the OP said, he was banned because he deliberately violated the terms of the appstore by creating a tool that collected end user information instead of disclosing the issue to apple.
Thanks.
Re: (Score:2)
Re:Silly and inflammatory (Score:5, Informative)
Actually he got banned for breaking the store terms and conditions, not for discovering a security hole.
The headline is just linkbait - Apple does not hate people who discover security holes in its software, it's quite the opposite. They take time to mention and thank people who find specific bugs in their security update notes and have been doing for many years when they close that particular hole.
Re: (Score:2)
Isn't this anti-competitive behavior?
Re: (Score:1)
No. It's not. He violated the App Store ToS and got banned from the service. How exactly is that 'anti-competitive behavior'?
Re: (Score:2)
How do you figure that taking a percentage for selling a good - which practically every fucking store in the whole fucking world does - is "anti-competitive"? Are you new to this we call "the real world"?
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Your attempt to defend Apple is just sad.
Re: (Score:2)
I wasn't aware that Converse was owned by Target. From wikipedia [wikipedia.org]:
Target has many exclusive deals with various designers and name-brands, including Michael Graves, Isaac Mizrahi, Mossimo Giannulli, Fiorucci, Liz Lange, and Converse among others.
Re: (Score:2)
The point is that target has a special exclusive relationship with those products. It's exclusive to them. In the case of the iPhone, the customer owns the device. They want to put something on it...where exactly does apple come in?
"they aren't forcing them to sign exclusivity agreements"
But the exclusivity is technologically enforced.
Ramen can sell it's noodles anywhere else. Not just target. But where can an iOS developer sell his/her iOS programs? Nowhere else.
Suppose that Microsoft had to approve every
Re: (Score:2)
Re: (Score:2)
And if Microsoft insisted on "approving" every software that ran on a PC you would be ok with this? If not, then it's double standards.
Also, for me this is less about legal/illegal and more about being an asshole.
Re: (Score:2)
Re: (Score:2)
I didn't say anyone was forcing me to use Apple products. And I was talking about the PC market. Why should PCs and smartphones be any different? This is not about what's legal/illegal but about being jerks. Apple is being a jerk.
Also, once the phone is purchased, it belongs to the customer. Ethically Apple should have no right to dictate what apps are installed on to it.
Re: (Score:2)
Re: (Score:2)
Neither of which changes the fact that one approach is good and the other is bad. I think I can safely say that the world as a whole is better of because Windows programs could be run by anyone and installed from any source.
Re: (Score:2)
Re: (Score:2)
Remember that only an investigation can reveal whether something is anti competitive or not. It depends on the market share and the amount of abuse. Remember that when Apple refused to approve the Google voice app, it was pressure from the FCC that finally got them to approve it. After all, it's "their store" right? They can refuse any app they want.
Apparently not. Just because Apple is following the letter of the law doesn't mean that they can't be held to be anti competitive in the future.
Re: (Score:2)
My point is talking about the practice not the company. Why doesn't Apple do the right thing and allow everyone to install whatever they want on their devices?
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Despite the malware, the entire world is better off for Windows on the PC being open to everyone. It has brought the age of computing to the masses as there's no centralized software control. If Apple truly wanted to do the right thing, they must open their platform.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
Why should Apple make a distinction between the PC platforms and smartphones?
Re: (Score:2)
Why should MS? Probably the same reasons. On a PC, the UI is far more capable and so installation and removal of software is easier. Even so malware has been a huge problem. Update mechanisms were wildly inconsistent. Software purchasing/distribution on mobile was not easy for most consumers. Thus the average mobile user did not buy much software and mobile developers did not invest in making software. It was a chicken and egg problem.
Way back when Steve Jobs announced the model, these were the barr
Re: (Score:2)
I lauded MS for their open approach on the PC model. I don't recall lauding them for any closed system.
Re: (Score:2)
Re: (Score:2)
When I think of PCs, Windows comes to mind first - OS X doesn't even enter the equation. So I talked about Windows and not OS X. What's eating you?
Re: (Score:2)
Re: (Score:2)
It's not hypocritical because I never praised Microsoft's smartphone model. Come on dude - let it go. What's bugging you so much?
Re: (Score:2)
Re: (Score:2)
It IS great. And iOS IS bad. What's the deal? Since iOS has a much larger market share than Windows mobile, the latter needn't be mentioned. Simple.
Re: (Score:2)
Re: (Score:2)
If the market share of one company is overwhelming, I obviously talk about that more than the others. I can't be expected to ALSO mention dozens of others just to be "balanced and fair". If MS has a significant mobile market share, they would have been honored with a reference. Since Apple has a large one, they get screwed. Hardly surprising.
Re: (Score:2)
Re: (Score:2)
Umm...in case you didn't notice, Android allows sideloading of apps. Apple is the biggest offender when it comes to closed mobile systems. And I repeat (in a tired tone) - I never lauded MS's mobile strategy. I just think they're irrelevant in that area and not worth mentioning.
If you had to criticize a company for a closed mobile OS, it would of course be Apple since they are the largest offender.
Re: (Score:2)
Re: (Score:2)
"Complaining that iOS and closed and Windows is open"
I was comparing software philosophies. Those are the same regardless of platform and doesn't change from between PCs and smartphones.
Re: (Score:2)
And they are both the same. Why is it so hard for you to admit that MS and Apple have the same exact philosophies? The fact that one has more marketshare than the other makes no difference. Having more marketshare does not change the facts. Your points are illogical and biased. Let's construct your arguments a different way:
"I think Mary is prettier than Suzy because she's blonde."
"Both Mary and Suzy are blonde."
"Well, Mary is a cheerleader."
"They are both cheerleaders."
"Still Mary is prettier beca
Re: (Score:2)
Next you'll want me to include Linux in my list of OSs as well. Market share may not mean anything to YOU. It does to me. Apple has the largest market share amongst closed OS systems. So it catches my criticism since they're the biggest targets.
Let it go dude.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
When you have a huge market share, you have a duty to keep your platform open. Otherwise you're a douche. Which is why companies which small closed platforms don't get mentioned. You're forgiven if you have a minuscule market share. Not if you have a big one.
Re: (Score:2)
Re: (Score:2)
If tomorrow Apple has a tenth of the marketshare, I won't criticize them anymore since I won't view them as having an ethical responsibility to keep their platform open.
Re: (Score:2)
Re: (Score:2)
"So when Apple had 0% apps when the iPhone launched, they weren't douchebags."
No. Since they didn't have market share, they had no ethical responsibility to keep it open.
"So when MS switched from an open model to a closed one for smartphones, they're not douchebags?"
Strictly speaking MS smartphones were open with Windows Mobile for a long time. I know because I used several. Sideloading and installation was very much allowed. But as I said, a lower market share doesn't convey any expectations.
When it comes
Re: (Score:2)
You are anti-competitive when you breath air and eat food someone else could have used. I think you should kill yourself since you seem to feel that anti-competitive behavior is wrong.
Re: (Score:2)
Re: (Score:2)
Re: (Score:1, Insightful)
Yes, because he did so without their permission and violated the ToS. That hardly means they hate him. Only a moron would think that someone is just going to welcome you with open arms when you do stuff they explicitly didn't approve.
Gasp! He violated the sacred ToS and revealed to the world that apple's walled garden isn't going to keep out all malware [itproportal.com]?!? NO!!!! It was perfect before, he obviously broke it! BURN HIM!!!
Only a moronic company would punish someone for pointing out a security problem to them. The lesson Apple appears to have been trying to teach Charlie is that the next time he discovers a security hole in the app store, he should sell that information to criminals.
Re:Silly and inflammatory (Score:5, Insightful)
You do realize that Google banned him for life, whereas Apple only banned him for a year... right?
May we safely conclude that you hate Google and their products with the fiery intensity of a thousand supernovas, given your screed about Apple?
Re: (Score:2)
I've searched for many different combinations of "charlie miller", "banned", "google" and "playstore", but all I found was his ban from Apple and his research on NFC and Playstore bouncer vulnerabilites. Is there something I've missed?
Re: (Score:2)
Ah, missed it at 50 seconds in the video, but still can't find any details. Their blog post [duosecurity.com] on Bouncer hack mentions they've "been in touch with the Android security team and will be working with them to address some of the problems weâ(TM)ve discovered" and their NFC hack didn't need any Google account at all. May be someone can find more?
Re:Silly and inflammatory (Score:5, Informative)
I found this:
Dr. Miller admits to being banned from the Google app store as well. In fact Miller's wife was also recently denied a developer account by the Google Play Store.
here: http://www.ethicalhacker.net/content/view/438/1/ [ethicalhacker.net]
Re: (Score:2)
http://twitter.com/0xcharlie/statuses/231200006038761472 [twitter.com]
Result # 9 from the google search: "Charlie Miller Google Play Ban" from Mr. Miller's own twitter feed, in his own words. He was banned for, in his words, "being associated with Jon Oberheide" - one of the researchers who discovered a flaw in Android's Bouncer security program that he exploited by putting multiple bogus apps up on the Play Store.
So... he didn't even exploit the security hole in Google Play - he just happened to be 'working with or as
Re: (Score:2)
Re: (Score:2)
What's this? Suddenly getting reasonable when the target is Google rather than Apple?
Re: (Score:2)
Re: (Score:3, Insightful)
No, as I said, it's amazing how reasonable you have become now we find out Google issued a bigger ban than Apple did. It's a shame your original post was littered with shouting and multiple exclamation marks and sarcasm, and you didn't show your reasonable side from the outset.
Now, just for fun, given that this is the very same security researcher, can you give me an example of what he could have done that would make Google's lifetime ban for him and his wife reasonable. (In the light of a 1 year ban for br
Re: (Score:2)
Re: (Score:2)
I couldn't immediately find any second source verifying that he had been banned from google
He says it himself in the video. Of course you could chose to doubt him, but he's also the source of the story that Apple banned him for a year.
From the article I linked to, apple seems to have punished him for making it clear that there were holes in their app store security. Not actually exploiting them.
No. He sent an app to the app store that had a secret feature to download arbitrary code from a server. That is indistinguishable from malware, and does indeed break the ToS.
Presumably he did the similar
Re: (Score:2)
Re: (Score:2)
This is really not debatable, or questionable, or a question of "if and why" - they banned him, for life. It is in the video, from Miller himself, who says, around 50 seconds into the linked video, "The good thing about Apple is, it's only a 1 year ban, where I'm banned from Google for... lifetime." Or, if you're really concerned that somebody somehow spliced in a convincing fake of his voice on that video, you can read it in his own words, from his twitter feed:
http://twitter.com/0xcharlie/statuses/23120 [twitter.com]
Re: (Score:1, Insightful)
"Why would Apple hate them"
uh, maybe because Apple likes to keep any of its security issues quiet rather than watch these two guys publicly expose iPhone issues the way the entire open-source Android developer community does for Android Phones. What these two guys are doing is contrary to the walled-garden business model that is Apples creed.
Re: (Score:2)
Because there is a good portion of people who do not understand, it is not what you do but how you do it.
There is a fine line of being a companies best friend and worst enemy. It just goes on to how you approach a problem.
Re:Silly and inflammatory (Score:4, Interesting)
Funny thing is, at about 50 seconds into the video, Charlie says, "The good thing about Apple is, it's only a 1 year ban, where I'm banned from Google for... lifetime."
Huh, imagine that. I guess Google must "corporately hate these guys" even more than Apple!
Apple should love them (Score:5, Insightful)
Even go so far as to pay them. Finding these holes should be done before harm happens. Futher, Apple should review their coders who leave the gaps in and train (or sack) them.
Re: (Score:2)
Further, there is no way that the person who broke into your house is responsible. It is your fault for not h
Hate? (Score:5, Informative)
Re:Hate? (Score:5, Funny)
Stop bringing facts into this!!
Re: (Score:3)
This just shows the article submitter's bias.
Re: (Score:3)
And richly deserved. They've become the new Microsoft with their 'our way or the highway' mentality.
I have a lot of respect for what Steven Jobs has accomplished and envy for his money. However, the business tactics he instilled at Apple and that his successors have promelageted are reprehensible. I do what I can do steer peiople away from all things Apple.
Re: (Score:1)
I gladly and joyfully negate your efforts at every opportunity. Apple hardware isn't a good fit for everyone, but I never hesitate to endorse it when appropriate.
Every for-profit business is "anti-competitive" based on the slashdot definition of that term. It's become entirely meaningless.
Apple isn't Microsoft. They don't act like Microsoft. They don't look like Microsoft. The comparison is so absurd that it demonstrates that you are an unthinking asshole.
Re: (Score:2)
I gladly and joyfully negate your efforts at every opportunity. Apple hardware isn't a good fit for everyone, but I never hesitate to endorse it when appropriate.
It isn't about the quality of their hardware, as nice as it may be, it is about getting sucked into their evil vortex.
Every for-profit business is "anti-competitive" based on the slashdot definition of that term. It's become entirely meaningless. Apple isn't Microsoft. They don't act like Microsoft. They don't look like Microsoft.
They are, realatively speaking, worse. It is kind of like Yahoo vs Google. Yahoo makes no bones about being in it for the money. Google, on the other hands, stands behind the notion of answering to a higher value. And then stooping lower than Yahoo would. I 'trust' Yahoo more than Google, at least in terms of their face value. Don't forget, Jobs built the first Apple as a tool for stea
Re: (Score:3)
Evil Vortex?
Evil Vortex?
Please disconnect from the Internet before you do yourself a mischief.
Re: (Score:2)
Re: (Score:2)
Re: (Score:2)
http://en.wikipedia.org/wiki/Psychological_projection [wikipedia.org]
Peruse at your leisure.
Re: (Score:2)
Recess is over, kids. Time to get back to class.
This is Slashdot. Recess is never over. Endless summer and all that.
Scumbags (Score:5, Funny)
All they do is hurt Apple's good name. Apple needs to have these idiots sent to prison, something they should be doing more of during this global assault of this proud American corporation.
Re: (Score:2)
Subtle troll is anything but subtle.
Re: (Score:2)
Sorry man, I just used up my last mod points. Otherwise I would have modded you 'Funny'. My sides are hurting!
I hate headaches... (Score:2)
But it turns out, most of my headaches are MY FAULT. By following bad eating habits, for example, I create sub-optimal nutritional conditions which, at times, results in discomfort. Other causes of headaches might result from other conditions within my preventative control. And it is my failure to manage those conditions which is the cause of my headaches.
Apple? Are you listening? Manage your conditions and you will have fewer headaches.
Re: (Score:2)
summary (Score:1)
reads like it was written by a 1st year PR student.
Hate? (Score:2)
Astronomers Hate Her. Housewife discovers 10 secrets for firm abs.
Re: (Score:2)
Well, Apple sent them free copies of Lion, so the answer depends on what you thought of Lion.
Talk about a stupid headline... (Score:5, Informative)
That headline is pretty damned stupid. It's like the stuff I've seen before on internet scams
"Doctors hate this bodybuilder - see how he keeps growing 20 lbs of muscle per week!"
"The U.S. Government hates this guy - see how one guy never pays taxes!"
"Women hate this doctor - find out how to get any women you want by taking this new secret pill!"
Link-bait Headline (Score:2, Offtopic)
The headline reminds of those cheesy ads on (as one example) snopes.com: "Find out why dermatologists hate this guy."
"Use this silly old trick to lose stubborn belly fat."
Slashdot encourages you to watch the video Apple doesn't want you to see!!!11
Re: (Score:2)
Well then, you should have posted much sooner. For future reference, if there are already a lot of comments in the thread, yours won't be one of the first.