Apple Can Remotely Disable iPhone Apps
mikesd81 writes "Engadget reports Apple has readied a blacklisting system which allows the company to remotely disable applications on your device. It seems the new 2.x firmware contains a URL which points to a page containing a list of 'unauthorized' apps — a move which suggests that the device makes occasional contact with Apple's servers to see if anything is amiss on your phone. Jonathan Zdziarski, the man who discovered this, explains, 'This suggests that the iPhone calls home once in a while to find out what applications it should turn off. At the moment, no apps have been blacklisted, but by all appearances, this has been added to disable applications that the user has already downloaded and paid for, if Apple so chooses to shut them down. I discovered this doing a forensic examination of an iPhone 3G. It appears to be tucked away in a configuration file deep inside CoreLocation.'" Update: 08/11 13:07 GMT by T : Reader gadgetopia writes with a small story at IT Wire, citing an interview in the Wall Street Journal, in which this remote kill-switch is "confirmed by Steve Jobs himself."
I Am Rich app, anyone?
It's better than having a lot of malicious programs out there, using data or sending personal information, with no way of recalling them.
Shouldn't be used unless it's deemed "dangerous".
"I am rich" for instance is a legitimate app, although without much purpose. But let's be honest, a lot of apps in the app store has little or no purpose. A 12$ flash light, anyone?
Given the unpatched Kaminsky DNS stuff on desktop OS X, or even just spoofed ips, doesn't this mean that a malicious attacker might be able to spoof the apple "ban list" and disable core functionality? How long until this can be exploited with a list of the core os x daemons thus "bricking" the phone until ?
ok can we please just get all the apple fans make their excuses early on. the iphone is a fiasco but nothing will take their blinkers off, so lets just let them get it off their chest early.
If you mod me down, I will become more powerful than you can imagine....
http://daringfireball.net/2008/08/core_location_blacklist : "An informed source at Apple confirmed to me that the âoeclblâ in the URL stands for âoeCore Location Blacklistâ, and that it does just that. It is not a blacklist for disabling apps completely, but rather specifically for preventing any listed apps from accessing Core Location â" an API which, for obvious privacy reasons, is covered by very strict rules in the iPhone SDK guidelines."
Sorry guys. This is brouhaha over nothing. The blaclist in question does NOT disable apps remotely but instead disallows listed apps form accessing the CoreLocation framework. See http://daringfireball.net/2008/08/core_location_blacklist
So how long before Net Share gets disabled?
Unfortunately I missed this app when it was on the App Store and I've been looking for a way to install it, but I suspect now that even if I succeed, that it will get disabled by Apple in the coming weeks/months.
iPhone newbie question:
Is there a way to install apps which have been removed from the App Store by somehow getting the binary?
Oh, come on don't you spoil our neat little flamefest based on mere guesswork and Anti-Apple bias with your boring and irrelevant facts, please.
I mean this if Slashdot, if you want news, please go to CNN.com. Ah, damned, they don't want their stories being diluted by facts either...
There are two rules for success:
1. Never tell everything you know.
This sort of problem is now years past the place where it can be solved by "voting with your dollars," or hoping that exposing the problem will create bad PR and shame the company into correcting it.
I don't know what parts of our constitution are still operative today, but if we can't get the public interested in privacy rights, get Congress interested in passing appropriate legislation, making "phoning home" against the law--and getting those laws enforced--then Apple and Microsoft and Sony and everyone else will continue to do whatever is technologically feasible, convenient, and supportive of their corporate goals.
It's naive to think that there are Good Companies and Evil Companies and that the answer is to put your faith in the Good Companies.
Of course, I do hope that exposing the problem creates bad PR and shames Apple into fixing it.
"How to Do Nothing," kids activities, back in print!
Except that it doesn't. The blacklist in question does not blacklist applications on the phone. It's a registry of applications which the user denies access to the "Core Location" service - i.e, when you don't want the phone to use GPS or triangulation data for privacy reasons. Seems perfectly reasonable to me. I don't want apps broadcasting my location without permission.
... and then they built the supercollider.
Couple of hours before this story got onto the /. front page, Engadget had this scoop:
http://www.engadget.com/2008/08/11/jobs-60-million-iphone-apps-downloaded-confirms-kill-switch/
Steve Jobs has confirmed the kill-switch, and defends it as a "responsible" way to make sure they can deal with it if a malicious app finds its way into the App Store.
Get with the times, editors!
sig:- (wit >= sarcasm)
512$ ought to be enough for anyone
It's not youPhone, it's iPhone. And so it phones.
More and more it feels like every iPhone belongs to Steve - people are just leasing it from him. There's just *no way* a phone should contact another server without the user knowing it or expressly permitting it, and there's absolutely no way in hell it should disable an application which the user deliberately installed, period. The end.
Where can I sign up for the really expensive phone with no buttons, locked into a single provider, that I can't modify or enjoy in any way (except the approved ways I suppose).
I'd really like one of those.
Imagine if you weren't allowed to use roads because a bus company complained about your driving 3 times. --skunkpussy
Well if that seems perfectly reasonable to you, iPhone isn't really for you since currently no applications are blocked from using your GPS...
is that so mr anonymous coward? that's odd, since my iPhone pops up a message ""app_name" would like to use your current location" the first time each app tries to access the GPS since the last reboot. seems to me you're talking right out your ass
TIAEAE!
It's probably in the terms and conditions of ownership, and thus every owner has given permission already.
It's not like Apple is collecting user information here. It's a HTTP GET as far as I can tell, with no information being supplied to Apple, just a list of applications that are bad and that the user shouldn't run for their own protection.
Going beyond this into the realm of assuming that apple are collecting user data, disabling applications they just don't like, etc, is stupidity on the level of people who believe in conspiracy theories.
Will you kindly shut the fuck up already? We've had about 5 posts like this so far, all of which contradict the following respective pieces of obvious logic and in-your-face authoritative evidence:
1. Just because someone uncovered one URL which is likely to be a Core Location services blacklist, it doesn't automatically disqualify that there are [i]other[/i] blacklists which disable an app entirely.
2. Steve Jobs announced (see recent WSJ article summarized e.g. on macrumors.com) that iPhone has remote app disabling. To announce this if it's not true would be monumentally stupid for two reasons:
(a) He knows he'll piss off a minority contingent of privacy advocates. (shame that it's only a minority, but if there's one thing we learn from our dear country, it's that its citizens generally get exactly what they deserve)
(b) At some point, a malicious app [i]will[/i] appear. Imagine the reaction if, everyone with eyes looking to Apple to disable it, SJ responds with "oh, my bad, actually we can't disable stuff".
In conclusion, the iPhone has remote app disabling. Apple can remotely disable any of your apps. Your apps are remotely disable-able.
In other news, the iPhone developer agreement apparently must include the "we can pull any of your apps from the store for an arbitrary reason aside from the ones mentioned explicitly in the agreement" clause, since removal of _I Am Rich_ was, Apple claims, a "judgment call". Meanwhile, removal of _NetShare_ was due to the ability - the developer seems to have concluded, after a period of silence - to use it to break your service agreement on some of the many global networks iPhone is available for. This is all made harder by an NDA which specifically prohibits an iPhone developer community, let alone any open source + Free software, since you're [i]not allowed to talk about your code[/i].
At the risk of confronting the No True Scotsman fallacy, no true developer codes for the iPhone. It's a get-rich-quick gamble, where Apple may pull your foundations from under you at a whim (as they've already three times to developers) and where you must code alone and in secret.
Hmmm, explains a lot - though I can see a lot of infringement cases come up. Including one against patent infringement lawyers. I wonder who'll represent Apple there?
politicians are like babies' nappies: they should both be changed regularly and for the same reasons
You know it's really sad when a poster doesn't even RTFA or read the RTFT(thread). Engadget, and now Slashdot.. Are people on the internet really that illiterate now and just follow the leader? After MANY posts (many by me and many by others) on Engadget, people STILL insist "APPLE IS GETTING SUED!" or "Ha! What are you fanboys going to say to this?" and the best one "Haha Same as the Microsoft WGA". Anyways I've already made too many posts and feel redundant, but rumors and speculation to get THIS far is simply sickening.
... that as soon as someone dares to post something other than the usual expressions of paranoia and criticism, other less free-minded individuals accuse him of sheep mentality, or drinking the kool aid? Someone else has to see the irony in that!
You know, there is a difference between trolling and pointing out the flaws in your reasoning. Just saying.
Uh, yes it's justifiable. Apple wants its product to behave this way, and I purchase their devices knowing they want to control everything. Don't buy the phone if you want an open market model! Hell you shouldn't own any Apple product if that's the kind of market you prefer, it is simply not their thing.
Besides, as other posters have pointed out, it's not phoning home to control apps, it's to prevent malicious use of CoreLocation because Apple cares about privacy.
(okay I'm not actually arguing they care, but that's the impression they want to give. It protects their profit margin)