Slashdot Mirror


Tor Project: Fake Tor App Has Been In Apple's App Store For Months

itwbennett (1594911) writes "For the past several months Tor developers have unsuccessfully been trying to convince Apple to remove from its iOS App Store what they believe to be a fake and potentially malicious Tor Browser application. According to subsequent messages on the bug tracker, a complaint was filed with Apple on Dec. 26 with Apple reportedly responding on Jan. 3 saying it would give a chance to the app's developer to defend it. More than two months later, the Tor Browser app created by a developer named Ronen is available still in the App Store. The issue came into the public spotlight Wednesday when people involved in the Tor Project took to Twitter to make their concerns heard. Apple did not respond to IDG News Service's request for comment."

39 of 78 comments (clear)

  1. strange priorities ... unless they already knew by Anonymous Coward · · Score: 5, Insightful

    Apple can burn a book in seconds for showing a little bit of flesh, yet an application may be getting their users tortured in dictatorships and it takes them months to fix.

    I think we know who's been working for the NSA and then denying involvement; don't we.

    1. Re:strange priorities ... unless they already knew by Anonymous Coward · · Score: 4, Informative

      Please put an NSFW warning. Some of us browse /. on the clock.

    2. Re:strange priorities ... unless they already knew by John.Banister · · Score: 5, Informative

      In a similar example when Apple pulled the 500px Photo App "the company was informed of the removal just a few moments before it was pulled from the store," certainly not given months to defend it. In an effort to help Apple with their priorities, here's a link to the 50+ Best Apps for Watching Porn on iPhone.

    3. Re:strange priorities ... unless they already knew by ArcadeMan · · Score: 3, Insightful

      "It's a disturbing example of the excesses of American prudishness."

      Please put an NSFW warning. Some of us browse /. on the clock.

      Indeed.

    4. Re:strange priorities ... unless they already knew by ArcadeMan · · Score: 5, Insightful

      Typical American knee-jerk reaction. Showing a nude body is wrong but showing someone getting shot in the head is normal.

    5. Re:strange priorities ... unless they already knew by Impy+the+Impiuos+Imp · · Score: 1, Offtopic

      Please put an NSFW warning. Some of us browse /. on the clock.

      Thank you. "NSFW" is brilliant -- anything to lead me at work to porn faster.

      --
      (-1: Post disagrees with my already-settled worldview) is not a valid mod option.
    6. Re:strange priorities ... unless they already knew by lgw · · Score: 5, Insightful

      Clearly the TOR team is going about this wrong! Stop telling Apple "this app causes your customers to be tortured to death" - Apple cares not. Instead tell Apple "please pull this app, my kid used it to watch porn". Gone in 60 seconds.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    7. Re:strange priorities ... unless they already knew by Anonymous Coward · · Score: 2

      In other words, it's only NSFW if you're American.

    8. Re:strange priorities ... unless they already knew by Smauler · · Score: 1, Funny

      OP clearly said next to the link "showing a little bit of flesh". What did you think that meant?

    9. Re:strange priorities ... unless they already knew by coofercat · · Score: 1

      All those boobs - they're not for children you know ;-)

    10. Re:strange priorities ... unless they already knew by ahabswhale · · Score: 1

      FYI: watching videos or viewing images of people shot in the head would also be considered NSFW in the US.

      --
      Are agnostics skeptical of unicorns too?
  2. TOR on Apple? by Anonymous Coward · · Score: 5, Funny

    If you're trying to use TOR on an Apple device, you're doing it wrong.

    1. Re:TOR on Apple? by asmkm22 · · Score: 3, Funny

      "Take a TOR of our lovely walled garden!"

    2. Re:TOR on Apple? by GumphMaster · · Score: 2

      Mmmm, chutney

      --
      Patent litigation: A doctrine of Mutually Assured Destruction... in which everyone seems willing to push the button
  3. Typical Apple idiocy by bazmail · · Score: 5, Interesting

    They took about 30 seconds to take down that breast feeding app (a BREAST!!!), but something so utterly evil like an app that promises anonymity and delivers spyware gets to live on for months? Sounds like Apple may have received a National Security letter about this fake Tor app (i.e. leave it alone!) and are playing dumb.

    1. Re:Typical Apple idiocy by uCallHimDrJ0NES · · Score: 3, Funny

      CORRECT!!!

      --
      Cloudiot: A person who does not see offsite storage as a way to lose control over access to his or her own data.
  4. profit before security. by bloodhawk · · Score: 2, Insightful

    nothing new here, Apple have always put profits before security

  5. Would have liked to see more information by SuperKendall · · Score: 3, Insightful

    The article was pretty slim (even the links to discussion within) on detail as to just WHAT they consider to be adware/spyware about the app...

    I would hope that some random person could not an app pulled because of it simply having ads.

    The spyware thing is way more a concern - so in what aspect is it spyware? Is it sending back everything you browse to some third party? The problem is that even in that case, I don't know it should necessarily be pulled - that could just be metrics the app developer is collecting. It's shady but not necessarily a reason to pull the app. All of the comments I could see related to being "spyware" were about ads knowing location, but that's not uncommon for ads, and a user can simply deny location services when the are running the app (as I do for any browser I run).

    Also of course, there's the claim that the app is a "fake" which would imply it does not actually browse using TOR. It doesn't seem that way from the reviews - those could be faked of course but it seems like you would ALSO see reviews noting it does not work at all. It's not like people do not LOVE to read one-star reviews for an app when they are unhappy for any reason....

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
    1. Re:Would have liked to see more information by Anonymous Coward · · Score: 2, Insightful

      It was last updated on Nov. 6 and only one of the three customer reviews so far includes a complaint about how ads are being displayed, with the reviewer noting that the app is very good at what it does otherwise.

      vs.

      Tor Browser in the Apple App Store is fake. It's full of adware and spyware. Two users have called to complain. We should have it removed.

      I think the root cause of the complaint is the Tor Project afraid that this app will tarnish their [adjective] name. You are right that neither the story nor the Tor panic page have anything even mildly resembling evidence of wrongdoing with the app in question.

      As often as I am disgusted by Apple, there needs to be some actual evidence of wrongdoing to justify removing an app. None has been presented, so I cannot side with the Torers until they manage to provide some.

    2. Re:Would have liked to see more information by SuperKendall · · Score: 1, Interesting

      If the app sends back a message to it's developer showing what you looked at then that is a serious security breach.

      That's a reason not to trust the app for the intended use, but not a good reason to pull the app from the store. Apple's job is not to make sure that the app operates 100% as described, but that it falls within the guidelines for being on the store and lives up to the app description. The app says it "helps" you with security but that's as far as it goes, and would be true for anyone monitoring just the HTTP URL's accessed by the app (if it's really using TOR).

      The thing is we have no-one saying it is in fact reporting back anything to anyone - all I can find is complaints ads make use of location! Location which the app user has to approve the app getting access to.

      If you are a Russian citizen using this app because of a real need for anonymity, you would not approve it accessing location...

      --
      "There is more worth loving than we have strength to love." - Brian Jay Stanley
  6. Apple's Behind by Anonymous Coward · · Score: 1

    The app store has been having an increasing share of issues in the past year.

    I pulled my entire app catalog in protest over missing and misfiled reviews going on six months now.

    The usual Apple message:
    "We are aware of the issue but remain unable to give you a timeline on when the issue will be resolved."

    Something big will have to happen to focus efforts on cleaning up the app store; the cracks in the infrastructure are there and growing.

  7. Not fake... by Anonymous Coward · · Score: 2, Interesting

    as much as "not an official release".

    When you are working with something like the TOR network and you want to stay as secure and (hopefully) as safe as possible, you want everything to be officially released. If the browser bundle in the store is not official, you don't know *exactly* what is in it or if they added anything to it. That alone is scary. Especially if you know & trust the TOR project and expect the same from the app as you get from their other browser bundles.

    "Fake" is definitely the wrong way to describe it ( if it actually does use TOR ), but it definitely makes a bigger impression than "unofficial".

  8. Re:slashtards by bazmail · · Score: 2

    3/10. Your troll skills need work.

  9. "unofficial" would be a better path to takedown by SuperKendall · · Score: 3, Insightful

    "Fake" is definitely the wrong way to describe it ( if it actually does use TOR ), but it definitely makes a bigger impression than "unofficial".

    From further reading on the app, it seems that even though "unofficial" does not sound as impressive, it's the better path to taking down this app. The app seems to be using a copyrighted TOR logo without permission, and also linking to the TOR site for support even though that is not owned by the developer.

    If they want to pull the app they should note the copyright violations to Apple rather than the vague claims of "spyware" without proof. Apple treats copyright claims very seriously. The developer could put the app back up using a different logo and support link, but that's OK until someone can prove real harm from using the app.

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
    1. Re:"unofficial" would be a better path to takedown by AmiMoJo · · Score: 4, Insightful

      "Tor Browser Bundle" is the name of the official secure browser/Tor app distribution. This app was using the name but was not associated with the creators of the real Tor Browser Bundle at all, and apparently contained advertising and spyware which as well as putting users at risk was damaging the reputation of the official bundle. Since it wasn't open source or audited there is no way to really know how well it worked, but the fact that it had advertising suggests that it was not particularly well designed since adverts themselves leak information about the user.

      Apple apparently doesn't treat copyright claims from non-commercial entities very seriously, as evidenced by the bug report. It took people using their personal contacts to get things moving in the end. If the people at Apple who review apps before releasing them to the app store were half way competent they would never have allowed it in the first place. They clearly didn't understand that the claims it was making could't really be true (due to the advertising at the very least) and a quick google would have revealed that the name was ripped off.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    2. Re:"unofficial" would be a better path to takedown by DaveV1.0 · · Score: 1

      So, what you are saying is that TOR shouldn't free and open ala FLOSS, yes?

      --
      There is no "-1 offended" or "-1 you don't agree with me" mod options for a reason.
    3. Re:"unofficial" would be a better path to takedown by david_thornley · · Score: 1

      In other words, it's something of a trademark issue.

      Is there an actual legal entity called "The Tor Project"? If not, is there somebody who has standing to tell Apple "That's our trademark!"?

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  10. Trademark Violation by Anonymous Coward · · Score: 2, Insightful

    Tor is a trademark of the Tor Project. If the app is advertising itself as the Tor Browser, it's a clear trademark violation.

    1. Re:Trademark Violation by Goaway · · Score: 2

      Wait, so we like trademark law in this thread? Because I just came from another thread where trademark law was literally Hitler, and I forgot to change.

    2. Re:Trademark Violation by pipedwho · · Score: 4, Informative

      Trademark/Copyright/Patent law aren't all inherently viewed as bad when implemented and executed properly. However, there are numerous examples (some of which appear on Slashdot) when the holder/government have overstepped the mark. This creates a feeling that the best solution to stop the abuses is to remove the system all-together. Here are some examples of the good/bad dichotomy:

      Trademarks protecting an obvious brand-name: OK
      Trademarks protecting a vague/generalised name/design: BAD

      Patents protecting a clearly novel, non-obvious and very specific invention: OK
      Patents on broad general topics and/or obvious incremental improvements: BAD

      Copyright protecting a creator from having their clearly original work from being re-distributed commercially for a short time (14 years): OK
      Copyright on a few bars of music that appear in the middle of a song from 75 years ago that could easily have been re-created without ever being exposed to the original: BAD

    3. Re:Trademark Violation by Bogtha · · Score: 1

      Trademark law, like copyright, is relatively sensible as it is designed to be used. Trademark law is designed to protect customers, not corporations. It's there so that when you buy a FooBar, you know you are getting a genuine FooBar and not a knock-off. However some people treat it like ownership of words and use it as a club to censor people. That's what people usually object to, not trademarks as they were intended to be used.

      --
      Bogtha Bogtha Bogtha
    4. Re:Trademark Violation by DaveV1.0 · · Score: 1

      Not exactly. They could say it is "A TOR(tm) browser" and be perfectly safe.

      --
      There is no "-1 offended" or "-1 you don't agree with me" mod options for a reason.
    5. Re:Trademark Violation by david_thornley · · Score: 1

      Trademarks are neither copyrights or patents. From my perspective:

      Under trademark law, I can't write software and try to fool people into thinking it came from you. Under copyright law, I can't borrow your software; I have to write my own. Under patent law, I can't write my own blasted software, and that ticks me off.

      --
      "When you have eliminated the unacceptable, whatever is left, however improbable, must be the truthiness" - Holmes
  11. Re:Nonsense. by Krojack · · Score: 4, Funny

    Because it's an iPhone! Apple knows what's best and they even examined the code! Geez..

    Do not question the Apple Gods.

  12. Re:NSA says to keep it in there. by PPH · · Score: 1

    Browser app created by a developer named Ronen

    Ronin?

    Didn't anyone see the movie and understand the plot?

    --
    Have gnu, will travel.
  13. Apple by koan · · Score: 2, Insightful

    So the timing for that SSL "flaw" was nice.
    http://daringfireball.net/2014...

    Plus now that it's come out Apple was pretty much on board with the NSA and their recent encryption weakness is anyone surprised.
    http://www.theguardian.com/wor...

    http://www.theguardian.com/wor...

    http://www.theguardian.com/wor...

    Not to mention every iPhone is a WiFi scanner + Geographical locator.

    --
    "If any question why we died, Tell them because our fathers lied."
  14. Re:What was the complaint by lgw · · Score: 2

    In short, people use TOR to avoid being jailed, tortured, and or killed by local authorities for their web browsing habits. There have been fake TOR apps before created and pushed specifically to find undesirables. There's reason to worry about anything unofficial, and the stakes are high.

    I doubt this is an NSA effort, as they can break TOR for specific users they target. But it's very easy for an ad display to de-anonymize the user (because it's very hard to stay anonymous on the web - fingerprinting and timing attacks are both pretty easy), and it's the governments who would need that bit of help that pose the most risk to their own citizens.

    If this were a year ago, I'd suspect this was some Silk Road guy pushing an app to display his own wares when the app went there, but to judge by the news stories I've seen the FBI has been pretty effective at arresting people who displease the US government on TOR (and it seems they did kill wilileaks as a result, which I suspect was the primary goal of all that), so it's mostly about people in China/Iran/etc. who are benefitting from TOR these days.

    --
    Socialism: a lie told by totalitarians and believed by fools.
  15. File DCMA TakeDown Notice by Anonymous Coward · · Score: 1

    File a takedown notice claiming copyright infringement. That should get it down immediately 'cause it would cost Apple money.

  16. Re: I don't see a problem.. by Anonymous Coward · · Score: 1, Interesting

    I've been using a tor app In the app store

    If you're trying to use TOR on Apple or Microsoft OSs, you're doing it wrong.