maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   Competitors (https://talk.maemo.org/forumdisplay.php?f=4)
-   -   Tricking Apple with disguised apps (https://talk.maemo.org/showthread.php?t=58962)

ysss 2010-07-23 06:27

Re: Tricking Apple with disguised apps
 
Quote:

Originally Posted by kureyon (Post 761752)
What I said:



Apple's app approval procedure is far from transparent or consistent, but similarity to already approved apps has been used to reject apps before. But the bottom line is Apple can reject apps because they can. Unless the app they reject comes from Google and Google wouldn't accept the rejection without a fight and Apple eventually backed down :cool:

I understand if people like to rant against Apple due to Apple's popularity/success/failure/style/etc; I'm just amused when they change their tune all the time and contradict themselves to suit the flavor of the day.

There's no shortage of rants against Apple's 'censorship' in the AppStore approval policy. <implying hardship to get into the AppStore; limiting the selection/quantity?>

There's also no shortage of rants against the sheer number of apps in Apple's AppStore.

So which is it?

On a serious point; if this thing happens in Ovi Store (or maemo/MeeGo repos), how should the crufts be 'censored' so they don't see the light of day and unnecessasrily 'bloat the apps numbers'.

aanckar 2010-07-23 06:28

Re: Tricking Apple with disguised apps
 
Quote:

Originally Posted by Duffer (Post 761759)
Just out of interest, I know it's open source but could this happen to N900 apps, does the code get checked in new applications?

Could anything (malicious?) slip in by obscurification?

Could the 'compiled' version on extras differ from the source code made available? What checks are in place?

Not trying to be funny, just interested!

Here you can see for yourself what is tested.

tswindell 2010-07-23 06:30

Re: Tricking Apple with disguised apps
 
Unless the app is non-free the source is the same, once uploaded into extras-devel auto builder you can't modify the code for that version at all as it goes through our QA process.

The code is usually looked at by those of us that are curious. That being said, it is always a possibility. I'm sure any issues would be found out quite soon and we don't deny apps, even if your mobile operator might have issue with it.

The iPhone and the ability to tether to an external source is something of a damaging app as Apple tell operators to charge an extra dataplan charge for that service (for some uknown reason) ...

Even if you don't understand progranning, you're also free to look at the code your self. I'm sure even a non-programmer would be able to see something neferious.

ysss 2010-07-23 06:33

Re: Tricking Apple with disguised apps
 
Unless packages are uploaded as src to an autobuild+package facility, is there a quick and simple way to verify that the binaries submitted are bulid from the referenced sources?

maxximuscool 2010-07-23 06:41

Re: Tricking Apple with disguised apps
 
LOL watched this and laugh my arse off.

*Nobody want to hear it from a black guy* LOL


http://www.youtube.com/watch?v=VMl_7...layer_embedded

* I literally blew away from the phone *

http://www.youtube.com/watch?v=CMLKd...eature=related

te37v 2010-07-23 07:57

Re: Tricking Apple with disguised apps
 
@maxximus: haha YES! those vids were funny

GameboyRMH 2010-07-23 13:04

Re: Tricking Apple with disguised apps
 
Huh, so they don't examine the source? I'm surprised the app store hasn't been overrun with malware in that case.

Joorin 2010-07-23 13:12

Re: Tricking Apple with disguised apps
 
Quote:

Originally Posted by ysss (Post 761779)
Unless packages are uploaded as src to an autobuild+package facility, is there a quick and simple way to verify that the binaries submitted are bulid from the referenced sources?

I'm not really sure if I understand your question but if you're asking if there is a way to link a specific source to a specific binary, the general answer is "No".

An easy way to handle this is for the creator to compile it, make a hash (MD5, SHA1) and publish it together with the source code. This is often used to check that packages that are to be installed came through download intact.

Then you can yourself check the binary that you've downloaded.

But, keep in mind that you need to trust the hash maker and that the same source can be compiled differently, but correctly, by two different compilers.

Flandry 2010-07-23 13:16

Re: Tricking Apple with disguised apps
 
The comments to that blog post are tragicomical. They remind me of the brainwashed citizens of the USSR that came to visit, closely monitored, as part of an international dance festival. They really couldn't believe that there was more freedom outside the "wall"...or that the supermarkets weren't massive PR hoaxes to fool them...etc.

kureyon 2010-07-23 15:04

Re: Tricking Apple with disguised apps
 
Quote:

Originally Posted by ysss (Post 761772)
There's no shortage of rants against Apple's 'censorship' in the AppStore approval policy. <implying hardship to get into the AppStore; limiting the selection/quantity?>

Censorship does not imply limiting the quantity. My point is that Apple has a very fickle app approval policy that is non-transparent ...

Quote:

So which is it?
Indeed. It seems whether an app is approved or not depends on which side of bed Jobs got out and what he had for breakfast the week before.


All times are GMT. The time now is 16:01.

vBulletin® Version 3.8.8