Mac App Store Piracy Concerns on Launch Day
Posted 01/07/2011 at 6:01am
| by J.R. Bookwalter
Apple’s new Mac App Store is barely a day old, and already there are concerns that its walled garden isn’t as secure as developers might hope. At least one popular app already has a cracked version available, with one hacker claiming to have already defeated Apple’s Mac App Store security.
AppleInsider is reporting on some launch day woes for Apple’s new Mac App Store which could provide headaches for software developers. It appears that apps that don’t follow the company’s rigid validation advice are susceptible to being easily cracked -- particularly those that “check only for a valid receipt, without checking whether the receipt matches the app’s bundle ID,” according to Daring Fireball’s John Gruber.
“On the day of the store's launch, reports emerged that a simple cut-and-paste workaround had been discovered that illegally 'cracks' some paid apps,” AppleInsider reported. “Crackers apparently found that replacing the receipt and signature files in some paid app packages, which can be downloaded from third-party sites, with the receipt from a free app allows the app to run in some cases.”
The wildly popular Angry Birds was among the games susceptible to this type of crack, which is likely to have that gaping hole plugged just as quickly now that it’s exposed -- or at least give those angry fowl even more reason to be hostile.
Meanwhile, a hacker known as Dissident has announced to Gizmodo that they have cracked Apple’s security for the Mac App Store with something called “KickBack.” However, it appears to be simply a threat and not a problem at the moment, since the hacker doesn’t plan to release the crack “until well after the store’s been established,” apparently in an effort to protect developers.
"When we feel that [the Mac App Store] has a lot of crap in it, we'll probably release Kickback," concluded Dissident.
The Mac App Store launched on Thursday as part of a Mac OS X 10.6.6 update, with more than 1,000 apps available.
Follow this article’s author, J.R. Bookwalter on Twitter