Month: September 2015

Apple Makes Sure Developers are Using Legitimate Copy of Xcode

XCodeLogoApple on Tuesday issued a notice to developers, informing them how they can make sure their copy of Xcode is legitimate — a precaution necessitated by the appearance of malware on the iOS App Store in China.

Those malicious apps were built with a counterfeit version of Xcode, which developers may have been prompted to download from outside sources because of Internet speed and connectivity issues in China. As a result, Apple instructed developers to download Xcode directly from the Mac App Store or from its developer website, and to leave Gatekeeper enabled on all of their systems to protect against tampered software.

Developers can verify their copy of Xcode is legitimate by opening terminal on a Gatekeeper-enabled system and typing the following:

To read the rest of the article, click here.

Modified Version of Xcode allows Developer to Sneak In Malware

XCodeLogoApple has reported that it has found a modified version of its Xcode developer app that allows a developer to inset Malware into an iOS App, and then "fools" Apple's checks and balances to allow it to be distributed on to the app store.

The company issued a statement to the New York Times about this situation by saying:

"To protect our customers, we've removed the apps from the App Store that we know have been created with this counterfeit software," spokeswoman Christine Monaghan said to the publication.

About 40 infected apps made it onto the App Store, according to security researchers with Palo Alto Networks. Some of the apps were extremely high-profile.  Including [name withheld], which has later issued a statement saying that their app has been recompiled with the correct version and has been made available to its customers, so any Malware that may have been in the previous version is no longer there.

The modified versions of Xcode were hosted on cloud storage run by China's Baidu. Baidu has already deleted the offending software, and Apple told the Times that it's working with developers to make sure they're using an authentic Xcode release.

It's not clear how many people may have downloaded infected apps. The embedded malware can, however, launch websites that will download additional malicious code, or generate pop-ups asking people for sensitive data. Many of the sites collecting stolen data have been shut down.

Palo Alto noted that to get a modified version of Xcode, affected developers would've had to disable Apple security features. The hackers also appear to have exploited the tendency for Chinese developers to download Xcode from local servers, since connections to Apple servers can be much slower.

Apple has traditionally positioned its platforms as being more secure than Android or Windows. In fact the strict rules and review process for the App Store have generally kept out most malware, but the size of this latest breach is unprecedented.

Current and future developers that may have downloaded the offending version are asked to delete it and get the correct version in the Mac App Store.

iOS 9 Has Fastest Adoption Rate Ever – Already Installed on 1/2 iOS Devices

iOS9IconiOS 9 is already on pace to be downloaded by more users than any other software release in Apple's history, marketing chief Phil Schiller said in a press release. The company's figures are based on access to the App Store as of Saturday, Sept. 19.

Apple's official numbers are even better than outside estimates, which pegged adoption at 36 percent. In contrast, Google currently reports that only 21 percent of active Android users have obtained some version of Android 5.0 Lollipop since it first became available nearly a year ago.

iOS 9 became available to download last Wednesday. The free update includes more advanced iPad multitasking, a News app, search and Siri enhancements, and under-the-hood improvements like better battery life and a smaller download size.

iOS 9 can be downloaded free via iTunes or as an over-the-air update through the Software Update function in iOS's Settings app. People must have at least an iPhone 4s, iPad 2, or fifth-generation iPod touch.

Via: AppleInsider.com

You may have Missed:

Verified by MonsterInsights