Topics:
Security loopholes surface on Mac App Store
Barely a day after the launch of the Mac App Store came news of how a number of security loopholes were allowing some apps to be downloaded for free. The problem appears to be related to how some developers have not followed Apple's (NASDAQ: AAPL) recommendation on validating the legitimacy of a purchase. In some instances, this allowed users to key in valid receipt numbers, belonging to other apps, which were treated as legitimate by apps failing to verify the purchaser with the ID listed on the receipt.
Sophos security researcher Chester Wisniewski reports that some developers have not implemented other checks that could allow their apps to be modified and used as a Trojan. Also disconcerting is news that hacker "Hackulous" has created an application called "Kickback" that can crack the protection of any application on the Mac App Store. Hackulous says it will only release Kickback later--after more developers have listed their software on the Mac App Store.
For more on this story:
- check out this article at eWeek
- check out this article at Naked Security Blog
- check out this article at TechRadar
Related Articles:
Apple to shutter its Mac OS X download site come Jan. 6
Many apps violate privacy on the sly
A road map for mobility through 2020




Comments