Mexico's inflation exceeds expectations in 1st half of April    Egypt's gold prices slightly down on Wednesday    Tesla to incur $350m in layoff expenses in Q2    GAFI empowers entrepreneurs, startups in collaboration with African Development Bank    Egyptian exporters advocate for two-year tax exemption    Egyptian Prime Minister follows up on efforts to increase strategic reserves of essential commodities    Italy hits Amazon with a €10m fine over anti-competitive practices    Environment Ministry, Haretna Foundation sign protocol for sustainable development    After 200 days of war, our resolve stands unyielding, akin to might of mountains: Abu Ubaida    World Bank pauses $150m funding for Tanzanian tourism project    China's '40 coal cutback falls short, threatens climate    Swiss freeze on Russian assets dwindles to $6.36b in '23    Amir Karara reflects on 'Beit Al-Rifai' success, aspires for future collaborations    Ministers of Health, Education launch 'Partnership for Healthy Cities' initiative in schools    Egyptian President and Spanish PM discuss Middle East tensions, bilateral relations in phone call    Amstone Egypt unveils groundbreaking "Hydra B5" Patrol Boat, bolstering domestic defence production    Climate change risks 70% of global workforce – ILO    Health Ministry, EADP establish cooperation protocol for African initiatives    Prime Minister Madbouly reviews cooperation with South Sudan    Ramses II statue head returns to Egypt after repatriation from Switzerland    Egypt retains top spot in CFA's MENA Research Challenge    Egyptian public, private sectors off on Apr 25 marking Sinai Liberation    EU pledges €3.5b for oceans, environment    Egypt forms supreme committee to revive historic Ahl Al-Bayt Trail    Debt swaps could unlock $100b for climate action    Acts of goodness: Transforming companies, people, communities    President Al-Sisi embarks on new term with pledge for prosperity, democratic evolution    Amal Al Ghad Magazine congratulates President Sisi on new office term    Egypt starts construction of groundwater drinking water stations in South Sudan    Egyptian, Japanese Judo communities celebrate new coach at Tokyo's Embassy in Cairo    Uppingham Cairo and Rafa Nadal Academy Unite to Elevate Sports Education in Egypt with the Introduction of the "Rafa Nadal Tennis Program"    Financial literacy becomes extremely important – EGX official    Euro area annual inflation up to 2.9% – Eurostat    BYD، Brazil's Sigma Lithium JV likely    UNESCO celebrates World Arabic Language Day    Motaz Azaiza mural in Manchester tribute to Palestinian journalists    Russia says it's in sync with US, China, Pakistan on Taliban    It's a bit frustrating to draw at home: Real Madrid keeper after Villarreal game    Shoukry reviews with Guterres Egypt's efforts to achieve SDGs, promote human rights    Sudan says countries must cooperate on vaccines    Johnson & Johnson: Second shot boosts antibodies and protection against COVID-19    Egypt to tax bloggers, YouTubers    Egypt's FM asserts importance of stability in Libya, holding elections as scheduled    We mustn't lose touch: Muller after Bayern win in Bundesliga    Egypt records 36 new deaths from Covid-19, highest since mid June    Egypt sells $3 bln US-dollar dominated eurobonds    Gamal Hanafy's ceramic exhibition at Gezira Arts Centre is a must go    Italian Institute Director Davide Scalmani presents activities of the Cairo Institute for ITALIANA.IT platform    







Thank you for reporting!
This image will be automatically disabled when it gets reported by several people.



Software pirates use Apple tech to put hacked apps on iPhones
Published in Amwal Al Ghad on 14 - 02 - 2019

Software pirates have hijacked technology designed by Apple Inc to distribute hacked versions of Spotify, Angry Birds, Pokemon Go, Minecraft and other popular apps on iPhones, Reuters has found.
Illicit software distributors such as TutuApp, Panda Helper, AppValley and TweakBox have found ways to use digital certificates to get access to a program Apple introduced to let corporations distribute business apps to their employees without going through Apple's tightly controlled App Store.
Using so-called enterprise developer certificates, these pirate operations are providing modified versions of popular apps to consumers, enabling them to stream music without ads and to circumvent fees and rules in games, depriving Apple and legitimate app makers of revenue.
By doing so, the pirate app distributors are violating the rules of Apple's developer programs, which only allow apps to be distributed to the general public through the App Store. Downloading modified versions violates the terms of service of almost all major apps.
TutuApp, Panda Helper, AppValley and TweakBox did not respond to multiple requests for comment.
Apple has no way of tracking the real-time distribution of these certificates, or the spread of improperly modified apps on its phones, but it can cancel the certificates if it finds misuse.
"Developers that abuse our enterprise certificates are in violation of the Apple Developer Enterprise Program Agreement and will have their certificates terminated, and if appropriate, they will be removed from our Developer Program completely," an Apple spokesperson told Reuters. "We are continuously evaluating the cases of misuse and are prepared to take immediate action."
After Reuters initially contacted Apple for comment last week, some of the pirates were banned from the system, but within days they were using different certificates and were operational again.
"There's nothing stopping these companies from doing this again from another team, another developer account," said Amine Hambaba, head of security at software firm Shape Security.
Apple confirmed a media report on Wednesday that it would require two-factor authentication – using a code sent to a phone as well as a password – to log into all developer accounts by the end of this month, which could help prevent certificate misuse.
Major app makers Spotify Technology SA, Rovio Entertainment Oyj and Niantic Inc have begun to fight back.
Spotify declined to comment on the matter of modified apps, but the streaming music provider did say earlier this month that its new terms of service would crack down on users who are "creating or distributing tools designed to block advertisements" on its service.
Rovio, the maker of Angry Birds mobile games, said it actively works with partners to address infringement "for the benefit of both our player community and Rovio as a business."
Niantic, which makes Pokemon Go, said players who use pirated apps that enable cheating on its game are regularly banned for violating its terms of service. Microsoft Corp, which owns the creative building game Minecraft, declined to comment.
SIPHONING OFF REVENUE
It is unclear how much revenue the pirate distributors are siphoning away from Apple and legitimate app makers.
TutuApp offers a free version of Minecraft, which costs $6.99 in Apple's App Store. AppValley offers a version of Spotify's free streaming music service with the advertisements stripped away.
The distributors make money by charging $13 or more per year for subscriptions to what they calls "VIP" versions of their services, which they say are more stable than the free versions. It is impossible to know how many users buy such subscriptions, but the pirate distributors combined have more than 600,000 followers on Twitter.
Security researchers have long warned about the misuse of enterprise developer certificates, which act as digital keys that tell an iPhone a piece of software downloaded from the internet can be trusted and opened. They are the centerpiece of Apple's program for corporate apps and enable consumers to install apps onto iPhones without Apple's knowledge.
Apple last month briefly banned Facebook Inc and Alphabet Inc from using enterprise certificates after they used them to distribute data-gathering apps to consumers.
The distributors of pirated apps seen by Reuters are using certificates obtained in the name of legitimate businesses, although it is unclear how. Several pirates have impersonated a subsidiary of China Mobile Ltd. China Mobile did not respond to requests for comment.
Tech news website TechCrunch earlier this week reported that certificate abuse also enabled the distribution of apps for pornography and gambling, both of which are banned from the App Store.
Since the App Store debuted in 2008, Apple has sought to portray the iPhone as safer than rival Android devices because Apple reviews and approves all apps distributed to the devices.
Early on, hackers "jailbroke" iPhones by modifying their software to evade Apple's controls, but that process voided the iPhone's warranty and scared off many casual users. The misuse of the enterprise certificates seen by Reuters does not rely on jailbreaking and can be used on unmodified iPhones.
Source: Reuters


Clic here to read the story from its source.