Categories: Tech & Society

How Apple Is Fighting iOS In-App Purchase Hack

On Friday, Apple issued a brief statement that it was looking into a published workaround that lets iOS users get in-app purchase content for free. It doesn’t look like Apple has found a true solution yet. But it’s certainly been busy this weekend, including taking down the original demonstration video on YouTube and getting PayPal to block donations.

The workaround was published last week by Alexey Borodin, a Russian hacker who demonstrated in a (now inaccessible) video on YouTube that with the installation of two certificates and a tweak to an iPhone’s Wi-Fi settings, he could bypass the step that requires payment for extra content within some iOS apps. (Macworld has more detail on how he’s doing it.)

By Friday afternoon, an Apple representative told us the company was “investigating.”

Here’s what Apple has done since then, according to The Next Web:

Over the weekend, Apple began blocking the IP address of the server used by Russian hacker Alexey V. Borodin to authenticate purchases.

It followed this up with a takedown request on the original server, taking down third-party authentication with it, also issuing a copyright claim on the overview video Borodin used to document the circumvention method. PayPal also got involved, placing a block on the original donation account for violating its terms of service.

What Apple hasn’t done? Actually gotten in touch with Borodin, according to the report.

And Borodin isn’t backing down, he says he has responded to Apple’s manuevers by moving his server to another (unnamed country) and is using a different PayPal account to gather donations for his project. So, while Apple is attempting to contain this security breach, developers can’t rest easy yet — the problem has not yet been solved.

Via: GigaOm

Prateek Panda

Prateek is the Founder of TheTechPanda. He's passionate about technology startups and entrepreneurship and enjoys speaking to new founders every day. Prateek has also been consistently regarded as one of the top marketing experts in the region.

Recent Posts

Kryterion and Automattic are changing what it means to be a professional WordPress developer

A question that has quietly frustrated WordPress developers and the businesses that hire them for…

14 hours ago

Skilling & Upskilling the Workforce: EntertainmentTech, Fintech, Software Engineering, Sustainability & CSR

The Tech Panda takes a look at the efforts at skilling, upskilling, and reskilling in…

18 hours ago

Cybersecurity in the Age of AI: Why India Must Build Talent, Not Just Tools

India’s digital transformation is accelerating at an unprecedented pace. From digital payments and e-governance platforms…

22 hours ago

AI Launches: Customer Experience, Healthtech, RegTech, Conversational AI & Marketing Technology

The Tech Panda takes a look at recent launches in the superfast field of Artificial…

2 days ago

AI Tools India’s MSPs Must Prioritize to Scale Revenue Without Straining Capacity

Artificial intelligence has moved beyond experimentation and is now actively reshaping how Managed Service Providers…

3 days ago

New tech on the block: Fintech, Agtech, Trading, Workspace-as-a-Service & Lab Grown Jewelry

The Tech Panda takes a look at recent tech launches. Fintech: First-of-Its-Kind Forex Card with…

3 days ago