Slashdot Mirror


Apple Can Remotely Disable iPhone Apps

mikesd81 writes "Engadget reports Apple has readied a blacklisting system which allows the company to remotely disable applications on your device. It seems the new 2.x firmware contains a URL which points to a page containing a list of 'unauthorized' apps — a move which suggests that the device makes occasional contact with Apple's servers to see if anything is amiss on your phone. Jonathan Zdziarski, the man who discovered this, explains, 'This suggests that the iPhone calls home once in a while to find out what applications it should turn off. At the moment, no apps have been blacklisted, but by all appearances, this has been added to disable applications that the user has already downloaded and paid for, if Apple so chooses to shut them down. I discovered this doing a forensic examination of an iPhone 3G. It appears to be tucked away in a configuration file deep inside CoreLocation.'" Update: 08/11 13:07 GMT by T : Reader gadgetopia writes with a small story at IT Wire, citing an interview in the Wall Street Journal, in which this remote kill-switch is "confirmed by Steve Jobs himself."

11 of 550 comments (clear)

  1. Re:Refunds by HungryHobo · · Score: 5, Insightful

    I still don't get why it was pulled.
    Let rich idiots throw their money away on tat.

  2. Re:excuses, let it rain by SoupIsGoodFood_42 · · Score: 5, Insightful

    How about we stop pretending that philosophical issues are the most important things when someone buys a product? Yeah, Apple products are more closed and restrictive, but they work for me. And until I get burnt by them bad enough to consider switching, I have no problem with them. I mean, they do behave pretty well for a Corporation. No need to spread FUD at the first sight of something that may not be ideal.

  3. Apple can kiss my shiny metal ass by Nycran · · Score: 5, Insightful

    More and more it feels like every iPhone belongs to Steve - people are just leasing it from him. There's just *no way* a phone should contact another server without the user knowing it or expressly permitting it, and there's absolutely no way in hell it should disable an application which the user deliberately installed, period. The end.

  4. Re:makes sense to me.. by muffen · · Score: 5, Insightful

    Shouldn't be used unless it's deemed "dangerous".

    Who decides what's dangerous? Are pirated apps going to be deemed dangerous? If you bypass certain security measures, is that dangerous? I don't like control being taken away from me (where "me" in this case is any end-user).

    Even if the intent is to only blacklist malware, does apple have a research lab to determine whats malicious and what isnt? Will they tell us how they decide on malware? What if you release an app that is infected with malware, the app is still legit whereas the malware part of the code is not. What happen if that app gets blacklisted, can it be revoked? If the iPhone contacts a webpage every now and then, will apple pay the bill for the connection?

    I don't like this, at the moment I don't like it because they did it without saying they are doing it. Going forward, they should say what they intend to block and give the enduser and option of either using the "service" or not... especially since the end-user is the one paying the bill for the datatransfer, the amount of money is imho completely irrelevant.

  5. Re:It's not called a 'phone home' by bestinshow · · Score: 5, Insightful

    It's probably in the terms and conditions of ownership, and thus every owner has given permission already.

    It's not like Apple is collecting user information here. It's a HTTP GET as far as I can tell, with no information being supplied to Apple, just a list of applications that are bad and that the user shouldn't run for their own protection.

    Going beyond this into the realm of assuming that apple are collecting user data, disabling applications they just don't like, etc, is stupidity on the level of people who believe in conspiracy theories.

  6. Re:makes sense to me.. by Trogre · · Score: 5, Insightful

    Wow. Just... wow

    Let's change the players a bit:
    "Engadget reports Microsoft has readied a blacklisting system which allows the company to remotely disable applications on your Vista PC."

    Do we still feel warm and protected?

    --
    "Nine times out of ten, starting a fire is not the best way to solve the problem." - my wife
  7. Re:excuses, let it rain by linhares · · Score: 5, Insightful

    Apple really does have an incredible buisness model. Lesser companies work out what people want then try to provide that to them at the lowest cost. Apple tells it's fans what they should want and then sells it to them for a remarkably high price. I never would have thought such a system would work.

    That business model is called religion.

  8. Re:makes sense to me.. by rsmith-mac · · Score: 5, Insightful

    Based on what Apple has told developers since the start of the program, revocation appears to be certificate based; Apple is revoking the developer's certificate for that program, which breaks the authentication chain and prevents the application from running. As for what they can block, it does not look like this would be effective against a jailbroken kernel, since much of the authentication chain is patched out anyhow; in other words they wouldn't be able to revoke: the jailbreak, applications for it, and perhaps even regular applications once the jailbroken kernel is installed.

    As for what they'll revoke, that's the bigger question. Apple has not shown to be particularly hostile towards the jailbreak community in the past; even if they could revoke it, I don't believe they will. The real test on this policy would be the NetShare application, it's an application Apple has ceased to allow post-release and if the revocation system were to be abused it would be the prime target. So far Apple has not revoked it, even though they've had ample time to do so.

    That leaves us with malware. I don't find this to be something hard to define, but perhaps other Slashdot readers do. If the application is legit but has a problem (backdoor for exploiting the Mobile account, for example) I'd assume Apple will revoke the certificate for the bad application and let the author issue an updated version as long as they didn't intentionally create a problem (which is grounds for being expelled from the AppStore program). If it's outright malware that somehow passed Apple's QC, then they'll still revoke it, will not issue further certificates to the guilty party, and since they had to sign up for the program, track the guilty party down and sue them for computer crimes in some form.

    I'm not too worried about this (I consider blocking malware from running a good thing) but I can see why other people here would be worried. In either case it's a well thought-out system that seems to cover every contingency, so there shouldn't be any "friendly fire" of applications being unintentionally revoked.

  9. Doesn't anyone else find it funny... by TheVelvetFlamebait · · Score: 5, Insightful

    ... that as soon as someone dares to post something other than the usual expressions of paranoia and criticism, other less free-minded individuals accuse him of sheep mentality, or drinking the kool aid? Someone else has to see the irony in that!

    --
    You know, there is a difference between trolling and pointing out the flaws in your reasoning. Just saying.
  10. Re:Refunds by D+Ninja · · Score: 5, Insightful

    If I try to sell a shiny piece of rock for a stupidly high price and even put up a big sign saying "THIS DOES NOTHING USEFUL, ALL IT DOES IS SHOW YOU CAN AFFORD IT!"

    ...a nice, subtle reference to the diamond industry.

    Nice.

  11. Re:Refunds by Moryath · · Score: 5, Insightful

    malicious app kill switch

    "For your security."

    "For your own good."

    "For the children."

    I've got a message for Apple, quite simple - I am perfectly capable of deciding for myself what I want on my iPhone, or any other computing device I own.

    If you can't understand that, and continue down this road, then the chances of my buying an iPhone (of any generation) are most definitely going to diminish to nothingness.

    I already kicked Verizon to the curb for locking down the phone and trying to force me into their own ridiculous $/month ringtone service when I have perfectly good midi, wav, and mp3 files to make ringtones of myself. Don't think I won't go to a provider that has the sense to let me work with things MY way.