There's a story going around today about a new hack that appears to allow users to bypass iTunes and steal in-app purchases "for free". I put "for free" in quotation marks because, as Ally pointed out in her editorial on app theft, there's no such thing as free. This time, however, the cost could be something more than money. The way I understand it, the hack in question uses a proxy, requires you to install a bogus certificate, and change DNS settings. That allows the transaction to be intercepted before it reaches iTunes, and that's what lets it cheat developers out of payment. It's also what could let the hacker collect all your information instead.
And that's dangerous.
There's a reason good guy hackers like the iPhone and Chronic dev team urge people not to steal apps -- it hurts everyone. A hack designed expressly to steal in-app purchases, by definition, isn't run by a good guy. The hacker in question is also asking for donations -- for money in exchange for helping you cheat developers out of the money they worked hard for and earned.
As proofs of concept, as a way to discover vulnerabilities that get passed on to Apple so they can be fixed, hacking and hackers can be extremely beneficial to hardening security and making all of our iPhones and iPads safer to use.
This isn't that.
This is stealing, and while it will certainly cost developers money, it could cost you a lot more. Worse than that, it's the perfect way to trick people into giving you access to their devices and credentials. Maybe this particular hacker isn't interested in abusing that, but how do we know? How do we know no one else will use the same hack to steal device and transaction information?
The easiest way to steak anything from anyone is to ask them for it.
No way in hell am I trusting anyone to essentially man-in-the-middle my iTunes connections, and no way in someplace even darker and hotter am I helping them do it.
Cry FUD if you want, but for me, saving $0.99 on Smurfberries isn't worth exposing my data or account.
UPDATE: Matthew Panzarino and Matt Brian of The Next Web have done some digging into how the hack works and how both developers and Apple could better secure the process.
UPDATE 2: Lex Friedman of Macworld has given the hack a similar look.
UPDATE 3: Jim Dalrymple of The Loop got a response from Apple PR, who say they're investigating.
We may earn a commission for purchases using our links. Learn more.
Elevate your Apple Watch with this elegant bracelet-style Wearlizer band
This pretty rhinestone-enhanced Apple Watch bangle bracelet looks more like jewelry on your wrist than a health and fitness band.
Ukraine's Foreign Minister alludes to resolution over Apple Maps and Crimea
Ukraine's Foreign Minister Vadym Prystaiko has hinted at a resolution to the Apple Maps Crimea controversy, after meeting with Apple VP Lisa Jackson at Davos.
macOS Catalina bug sees displays reset to max brightness after sleep
Some users are reporting their macOS Catalina machines are setting themselves to maximum brightness after waking from sleep
Don't lose important data on your Mac, make sure to back it up!
One of the most important things you should be doing with your Mac is backing up all of its data. Here are some of our favorite solutions for backing up your most important files, should anything ever happen.