• United States



by John P. Mello, Jr.

Apple closes developer site after researcher’s intrusive hack

Jul 23, 20134 mins
Access ControlAppleData and Information Security

Researcher who clipped 100,000 user records from Apple developer site to prove a point criticized by some security pros for his conduct

After keeping developers in the dark for four days, Apple acknowledged on Sunday that a website it maintains for about 275,000 developers had been taken offline because of security concerns.

“Last Thursday, an intruder attempted to secure personal information of our registered developers from our developer website,” the company explained in a notice posted at the site. “Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers’ names, mailing addresses, and/or email addresses may have been accessed.”

“In order to prevent a security threat like this from happening again, we’re completely overhauling our developer systems, updating our server software, and rebuilding our entire database,” Apple said.

Apple did not respond to a request to comment on the breach for this story, but told TechCrunch that it waited three days before informing developers of the breach in order to make a proper assessment of what data had been exposed in the breach.

The company added that no credit card numbers were compromised, and neither were any iTunes accounts.

Some developers say they’re inconvenienced by the shutdown but relatively sanguine about it. “It didn’t affect us and we are happy how the situation was handled by Apple,” Simonas Bastys, a member of the development team at Pixelmator, said in an email.

John Gruber, a developer who also runs the Daring Fireball blog, said in an email, “I can say, so far, that the outage has been a minor inconvenience.”

“My team can’t access WWDC session videos, for example” Gruber said. “Not a show stopper, but annoying.”

A Turkish security researcher, Ibrahim Balic, said he found the vulnerability in the website and informed Apple about it. He noted in a tweet: “Apple!! This is definitely not an hack attack !!! I am not a hacker, I do security research.”

[Also see: Business lessons learned in iCloud hack]

In a comment posted to TechCrunch, Balic said he’d reported 13 bugs to Apple. One of them allowed him to access user details at the developer site.

At first he extracted information for 73 Apple employees and sent them to Apple as a sort of proof of concept. Apparently, he kept exploiting the vulnerability to test its scope and now has the details of more than 100,000 users.

Balic did not respond to a request for comment for this story.

The researcher is being criticized by some security pros for his conduct. “Without Apple’s explicit authorization to conduct penetration tests on their website, even with good intentions the act was unethical,” said Richard Westmoreland, a security analyst with SilverSky.

However, Westmoreland said that exposing the vulnerability kept Apple from falling prey to watering hole attack, a targeted attack on a special interest website.

“If the attack had remained undetected, the portal could have been used in a watering hole attack similar to what compromised Facebook developers’ machines earlier this year,” Westmoreland said.

Kevin O’Brien, an enterprise solutions architect with CloudLock, noted that what Balic did was illegal under U.S. law, but the ethical dimensions of his actions are a bit murky. “In this case,” O’Brien said in an email, “the researcher went public in a way that damaged Apple reputationally if not financially.”

“While the full details of what, when and how this information was disclosed are still under wraps and will likely remain so, the determination of whether or not this was an ethical hack is contingent upon whether Apple was given sufficient advance notice of the exploit before the breach was made known to the broader security community,” he said.

Balic’s actions after penetrating Apple’s website troubles Kevin Morgan, CTO of Arxan. “Once he found a flaw that allowed him to access any internal records, was it ethical to extract those records,” Arxan told CSOonline. “No. It was not. It was a clear violation of proprietary information, and a variety of laws as well.”

Chet Wisniewski, a security advisor with Sophos, said Balic certainly acted irresponsibly, but Apple, while a victim, isn’t totally blameless. “Apple’s reluctance to engage the security community openly is probably what led to this,” he said in an interview.

“What this researcher did was illegal,” Wisniewski said. “It’s a crime and it’s not very bright to do that, but had Apple engaged him, he probably wouldn’t have done it.”