Developers who fail to heed Apple’s Mac App Store validation advice could face app piracy

“Mere hours after the opening of the Mac App Store, software crackers have already found a method that could lead to pirating of Mac App Store software,” MacNN reports.

“If left uncorrected, software pirates could conceivably crack and redistribute nearly any application on the Mac App Store,” MacNN reports. “The specific technique is detailed in a post on Pastebin.com (specific post not linked), and Apple is aware of the breach.”

Read more in the full article here.

UPDATE: John Gruber clarifies over on Daring Fireball, “This isn’t true for all paid Mac App Store apps. For apps that follow Apple’s advice on validating App Store receipts, this simple technique will not work. But, alas, it appears that many apps don’t perform any validation whatsoever, or do so incorrectly, like Angry Birds. (Angry Birds checks for a valid receipt, but doesn’t check to see that the bundle ID for the receipt matches its own bundle ID.)”

Full article here.

59 Comments

  1. This still won’t satisfy the open source crowd. Until only pirates make money the world is unfair. May your doors always be open and your locks always be broken I want what you have and I’m damm sure not prepared to work for it.

  2. Yes, the half-reporting is looking back on Apple when it’s actually the fault of developers. Maybe there is something that Apple can do to simplify the process for developers so they don’t leave out this important validation step.

  3. Regarding the DRM in Apple’s Mac App store,

    How Mac’s are you allowed to use the purchased software on? The same 5 allowed with your iTunes account, or just one?

  4. While every reasonable measure should be taken to protect property rights and licenses, there will always be cracks. The benefits of the app store far out weigh minor loss margins to piracy.

  5. This so called Crack/Hack has been well known and has been used by all the hackers since day one, Nothing has been hacked or Cracked, they are using the same methods as they always have by redistributing the “Plist” file.

    Don’t be fooled into believing this is new, it is not, But the truth is the problem was caused by some Mac App Store developers Not following Apple’s advice on validating apps.

    And Only SOME apps could be Hacked or Cracked not all, only a Few Could, and those apps that could be hacked are being removed and fixed to stop the Dev’s short sightedness.

    This was not a Apple’s Problem Folks, It was a Lazy Few Developers that Failed to follow Apples Rules.

    Now why is it Always a Few that don’t Follow the Rules seem to make people want to blame Apple when Apple is not the ones at fault.

    OhHh It’s the Apple haters gang pointing the fingers isn’t it.

  6. your, you’re….

    while we are at it. ” width=”19″ height=”19″ alt=”wink” style=”border:0;” />

    @ Its about time
    “Why did Apple allow developers to submit apps with improper validation? That’s the primary problem here.”

    That’s apple’s only blame in this.

    I’d be willing to bet there is an update to the App store shortly, and some apps pulled (maybe) and a new Requirement to devs. Follow our rules, or be denied.

  7. yeah, i’m on my MBP, not the iPhone.
    So i have to actually Use Caps When I Type. Damn Auto Correct Has Ruined My Typing Skills.

    Not trying to name names or condone the piracy of apps here…
    But all the news of this, speaks of only ONE app.

    The link above, and others i have seen, All point out the one app. Forum posts on those various sites have posters all asking what other apps can be pirated, and it seems that nobody has answers other than that one app.

    Could this be just one lazy developer here? or he’s being picked on in the news reports because of the success of his app before the Mac App Store?

  8. How is this news? Last I remember iLife and the current iWork doesn’t require serial numbers. iLife never has, and there has never been anything stopping people from purchasing a single license and installing it on several Macs. Same with the OS. Never required a SN. As far as 3rd party software, whatever stopped people from sharing the SN from one MS Office or any other app with another Mac. Again, how is this newsworthy? It’s been that way for decades.

  9. @Marty Wells
    “… This shouldn’t of been so easy…” <– No.
    This shouldn’t have been so easy. <– Yes.
    Sorry to pick on you, but I’ve been seeing this error a lot lately.

    Yes. Many Americans are really LOOSING their basic spelling and grammar.

  10. @The Corrector

    Errant code from hacked and normal receipts:
    001010110101010011010101010101010001001101100 < Incorrect
    001010110101010011010001010101010001001101100 < Correct

    @Dennis
    Fault lies with errant developers’s quality control and not Apple or its quality control. Apple simply provided the virtual shop and shelves – developers provided the defective goods for sale.

    ” width=”19″ height=”19″ alt=”wink” style=”border:0;” />

  11. its because Its Apple’s New App Store…. and somebody didn’t follow the rules. (not Apple) so of course, it’s Apple’s Fault.

    Now if MS had this problem, nobody would even report it.

  12. Whether it’s Apple’s fault or the developers fault, I’m not going to worry about it. There will always be software piracy. Hackers will find a way to get the content from the Mac App Store for free. But it’s not the end of the world.

    As long as the piracy is kept underground, and is complicated enough that the average employed person over the age of 25 won’t want to bother, Apple will be just fine.

    ——RM

  13. “Hackers will find a way to get the content from the Mac App Store for free”

    Man, I bet they’re taking all that money they saved by not paying for Angry Birds and investing in the stock market to make millions! Those hackers are such geniuses!!

    *ahem

  14. So if the app does NOT validate, there is no validation performed. If the app DOES validate, there is no problem.

    That’s about the lamest excuse for a “crack” ever. These so-called “pirates” should crawl into a cave and hide from embarrassment at making a big deal about being able to copy an app that is intentionally NOT protected from copying.

    Developers – Unless your app is FREE, you should probably follow Apple’s guidelines, once you settle down from wanting to be first in the Mac App Store…

  15. @mike

    while it looks like its only angry birds, may be others we dont know about.
    Lets say they figure out how to beat it on say Aperture or all the ilife/iwork apps. or the $99.99 apps i seen up there. or all apps for that matter.
    it does add up over time.

    and to most hackers, its not about the saving money. its about being able to DO it.. what someone said they cant do.
    Its not about the ability to pirate a $5 app (on sale BTW, $10 normally)

  16. YESSSS!!!!

    I am SOO GLAD you Apple “elitist” blind followers got what you “NEEDED”, in order to see that Apple is not as perfect as Jobs wants you to believe.
    By the way, I say that as an mac user myself, just not a brainwashed user, as some of you are….

    Well at least we won’t have to “jailbreak” our mac’s, especially when the whole app store/app can be jailbroken…HA!!

    OMG, this has TRULY made my WEEK!!!

    HA!

  17. @GoogledinToronto Their are just to many people who could care less about things like that. You should of just ignored it and moved on ” width=”19″ height=”19″ alt=”smile” style=”border:0;” />

  18. “Yes. Many Americans are really LOOSING their basic spelling and grammar.”

    Really? Jeez. Have you ever considered the may not BE an american?

    Fsck, man. You americans DO think you’re the center of the world, don’t you?

  19. @osxtasy: good for you, and I hope that the shallow satisfaction you got out of this picadillo has made you lots of money.

    Oh wait…

    @lukeskymac: “Fuck, man. You americans DO think you’re the center of the world, don’t you?”

    Yeah we do, but why would something like that bug you? Just ignore it and do your thing, man. The opinions of others and what others think; at least elementary school crap like that; are the lamest things to worry about, and causes so much grief for so many. It is the poison of a happy, productive life.

    Back on topic… Oops. This will be fixed. Next…

  20. For all you early posters, look at the correction. This is not Apple’s doing, it is the developers that didn’t code things exactly as Apple suggested. A small update on the offending Apps should clear this.

  21. I do not understand how a developer not following Apples verification guidelines, and getting cracked, is Apples fault, as suggested in the full article. That is like blaming the airlines because you turned up after they told you the flight was scheduled to leave!

  22. @Arnold Ziffel

    Man, I am with you on the “loosing.”. I have no idea how this spelling made it in to American life, but it is rapidly becoming a scourge! It is Bad enough to see my students and bloggers using it, but i’ve seen it used by professional journalists in major publications.

  23. Note the Gruber update. ONLY if developer does not validate correctly.

    Gruber goes on to say that Apple should test for this. I disagree. That is the job of the developer. You watt money for your app? Apple has provide a good way to secure against piracy. Use it. If you do not – then do not go whining to Apple.

    It is called SQA.

  24. What’s the big deal? This is no different than Apple selling software, based upon the honor code. There’s no difference between Snow Leopard single-user and family pack. You don’t punch in any codes. They trust you to buy the one that applies.

  25. @Fake Yeah that was full of intetional errors. To instead of too, should of instead of should have, could care less instead of could not care less. ” width=”19″ height=”19″ alt=”smile” style=”border:0;” />

  26. Move along, nothing to see here…

    Unfortunately, this will get more play than it deserves. Unfortunately, the news writers will be lazy and not write the story correctly. Unfortunately, the average computer user will believe the news.

    I liked it better when Apple was under the radar. Now everyone is gunning for them. We do it all the time. Find a hero, then tear them apart for sport.

  27. Awesome, why do you retards love giving Apple your money. Don’t you want FREE software??

    Everyday that goes by I realize how much more retarded Macheads are than I thought the day before.

  28. @backlash

    Too late. I already have Aperture and iLife 11. Didnt pay for either one. I love it when people get miffed that someone else got a better deal. Take your high moral ground. Apple was built on anti establishment. Remember Woz using long distance for free? You guys keep paying. Next rounds on me!! Ha suckers!

  29. the installous for mac you speak of, Kickback, that was how the whole thing started. welcome to last year.

    but you think apple wont have an update long before then?

    And i dont care if you got them free, all apple has to do is update the app store, and run a check on the software. if the receipt for a program does not match the program its intended for… deactivated. ad all you got was a demo.
    simple way to cure the problem of idiot developers.
    and i doubt you used the method for aperture and ilife. you prob downloaded the demos and used a serial to “register” the apps, and the app store recognized them as “legit” purchases.

    I know, i also read you could do that yesterday. and i bet many script kiddies like yourself did.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.