“Mere hours after the opening of the Mac App Store, software crackers have already found a method that could lead to pirating of Mac App Store software,” MacNN reports.
“If left uncorrected, software pirates could conceivably crack and redistribute nearly any application on the Mac App Store,” MacNN reports. “The specific technique is detailed in a post on Pastebin.com (specific post not linked), and Apple is aware of the breach.”
Read more in the full article here.
UPDATE: John Gruber clarifies over on Daring Fireball, “This isn’t true for all paid Mac App Store apps. For apps that follow Apple’s advice on validating App Store receipts, this simple technique will not work. But, alas, it appears that many apps don’t perform any validation whatsoever, or do so incorrectly, like Angry Birds. (Angry Birds checks for a valid receipt, but doesn’t check to see that the bundle ID for the receipt matches its own bundle ID.)”
Full article here.
Bad, very bad!
Correct and prosecute.
This still won’t satisfy the open source crowd. Until only pirates make money the world is unfair. May your doors always be open and your locks always be broken I want what you have and I’m damm sure not prepared to work for it.
Quality Assurance at Apple has really taken a slide down the slippery slope in the last few years. I really hope they get their act together.
Really I’m surprised this got by Apple with 50+ billion they can afford a host of hackers to keep the egg off their face. This shouldn’t of been so easy. Heads should roll.
As usual, only half the story is being reported here. To arrive at an informed opinion, please read: Without Proper Code Validation, Mac App Store Downloads Are Easily Bootlegged
For apps that follow Apple’s advice on validating App Store receipts, this simple technique will not work. But, alas, it appears that many apps don’t perform any validation whatsoever, or do so incorrectly, like Angry Birds.
Yes, the half-reporting is looking back on Apple when it’s actually the fault of developers. Maybe there is something that Apple can do to simplify the process for developers so they don’t leave out this important validation step.
Regarding the DRM in Apple’s Mac App store,
How Mac’s are you allowed to use the purchased software on? The same 5 allowed with your iTunes account, or just one?
@Marty Wells
“… This shouldn’t of been so easy…” <– No.
This shouldn’t have been so easy. <– Yes.
Sorry to pick on you, but I’ve been seeing this error a lot lately.
While every reasonable measure should be taken to protect property rights and licenses, there will always be cracks. The benefits of the app store far out weigh minor loss margins to piracy.
Gabriel has it right.
Some jumped the gun on the blame.
But Apple will be the one to fix the Developer errors
@The Corrector
Your correct
This so called Crack/Hack has been well known and has been used by all the hackers since day one, Nothing has been hacked or Cracked, they are using the same methods as they always have by redistributing the “Plist” file.
Don’t be fooled into believing this is new, it is not, But the truth is the problem was caused by some Mac App Store developers Not following Apple’s advice on validating apps.
And Only SOME apps could be Hacked or Cracked not all, only a Few Could, and those apps that could be hacked are being removed and fixed to stop the Dev’s short sightedness.
This was not a Apple’s Problem Folks, It was a Lazy Few Developers that Failed to follow Apples Rules.
Now why is it Always a Few that don’t Follow the Rules seem to make people want to blame Apple when Apple is not the ones at fault.
OhHh It’s the Apple haters gang pointing the fingers isn’t it.
Why did Apple allow developers to submit apps with improper validation? That’s the primary problem here.
@ GoogleinToronto
Me thinks it should be “Oll Korrect”
your, you’re….
while we are at it.
” width=”19″ height=”19″ alt=”wink” style=”border:0;” />
@ Its about time
“Why did Apple allow developers to submit apps with improper validation? That’s the primary problem here.”
That’s apple’s only blame in this.
I’d be willing to bet there is an update to the App store shortly, and some apps pulled (maybe) and a new Requirement to devs. Follow our rules, or be denied.
Your just being silly Backlash, it’s Apple not apple.
Right on Gabriel!
Yes, right arm! Gabe!
yeah, i’m on my MBP, not the iPhone.
So i have to actually Use Caps When I Type. Damn Auto Correct Has Ruined My Typing Skills.
Not trying to name names or condone the piracy of apps here…
But all the news of this, speaks of only ONE app.
The link above, and others i have seen, All point out the one app. Forum posts on those various sites have posters all asking what other apps can be pirated, and it seems that nobody has answers other than that one app.
Could this be just one lazy developer here? or he’s being picked on in the news reports because of the success of his app before the Mac App Store?
How is this news? Last I remember iLife and the current iWork doesn’t require serial numbers. iLife never has, and there has never been anything stopping people from purchasing a single license and installing it on several Macs. Same with the OS. Never required a SN. As far as 3rd party software, whatever stopped people from sharing the SN from one MS Office or any other app with another Mac. Again, how is this newsworthy? It’s been that way for decades.
@Marty Wells
“… This shouldn’t of been so easy…” <– No.
This shouldn’t have been so easy. <– Yes.
Sorry to pick on you, but I’ve been seeing this error a lot lately.
Yes. Many Americans are really LOOSING their basic spelling and grammar.
@Backlash
You know auto correct replaces Ballmer with “baloney”. I’m just saying.
@The Corrector
Errant code from hacked and normal receipts:
001010110101010011010101010101010001001101100 < Incorrect
001010110101010011010001010101010001001101100 < Correct
@Dennis
Fault lies with errant developers’s quality control and not Apple or its quality control. Apple simply provided the virtual shop and shelves – developers provided the defective goods for sale.
its because Its Apple’s New App Store…. and somebody didn’t follow the rules. (not Apple) so of course, it’s Apple’s Fault.
Now if MS had this problem, nobody would even report it.
Whether it’s Apple’s fault or the developers fault, I’m not going to worry about it. There will always be software piracy. Hackers will find a way to get the content from the Mac App Store for free. But it’s not the end of the world.
As long as the piracy is kept underground, and is complicated enough that the average employed person over the age of 25 won’t want to bother, Apple will be just fine.
——RM
“Hackers will find a way to get the content from the Mac App Store for free”
Man, I bet they’re taking all that money they saved by not paying for Angry Birds and investing in the stock market to make millions! Those hackers are such geniuses!!
*ahem
The only solution to this problem, as I see it, is for Apple to copy Microsoft and introduce “Windows Genuine Advantage”. Or rather in Apple’s case, “Macintosh Genuine Advantage”.
So if the app does NOT validate, there is no validation performed. If the app DOES validate, there is no problem.
That’s about the lamest excuse for a “crack” ever. These so-called “pirates” should crawl into a cave and hide from embarrassment at making a big deal about being able to copy an app that is intentionally NOT protected from copying.
Developers – Unless your app is FREE, you should probably follow Apple’s guidelines, once you settle down from wanting to be first in the Mac App Store…
@mike
while it looks like its only angry birds, may be others we dont know about.
Lets say they figure out how to beat it on say Aperture or all the ilife/iwork apps. or the $99.99 apps i seen up there. or all apps for that matter.
it does add up over time.
and to most hackers, its not about the saving money. its about being able to DO it.. what someone said they cant do.
Its not about the ability to pirate a $5 app (on sale BTW, $10 normally)
I am amazed at how many people didn’t read or maybe didn’t understand the article before they posted complaints about Apple.
Perhaps they read it before it was updated?
As long as Apple gets the money, they really don’t care if pirates screw someone (ie consumer, developer). Rotten Apple abounds.
@robin
They’re —> yes
There –> no
Geez! Please get the this thread’s program…
YESSSS!!!!
I am SOO GLAD you Apple “elitist” blind followers got what you “NEEDED”, in order to see that Apple is not as perfect as Jobs wants you to believe.
By the way, I say that as an mac user myself, just not a brainwashed user, as some of you are….
Well at least we won’t have to “jailbreak” our mac’s, especially when the whole app store/app can be jailbroken…HA!!
OMG, this has TRULY made my WEEK!!!
HA!
@GoogledinToronto Their are just to many people who could care less about things like that. You should of just ignored it and moved on
” width=”19″ height=”19″ alt=”smile” style=”border:0;” />
“Yes. Many Americans are really LOOSING their basic spelling and grammar.”
Really? Jeez. Have you ever considered the may not BE an american?
Fsck, man. You americans DO think you’re the center of the world, don’t you?
@osxtasy: good for you, and I hope that the shallow satisfaction you got out of this picadillo has made you lots of money.
Oh wait…
@lukeskymac: “Fuck, man. You americans DO think you’re the center of the world, don’t you?”
Yeah we do, but why would something like that bug you? Just ignore it and do your thing, man. The opinions of others and what others think; at least elementary school crap like that; are the lamest things to worry about, and causes so much grief for so many. It is the poison of a happy, productive life.
Back on topic… Oops. This will be fixed. Next…
For all you early posters, look at the correction. This is not Apple’s doing, it is the developers that didn’t code things exactly as Apple suggested. A small update on the offending Apps should clear this.
Holy frijole! “LOOSING” ? Really ?
Never mind the Mac App Store – call the spelling and grammar police!
MDN needs to update this post.
ugh I’ll bet it’s the oss people agian
I’ll bet cydia even hired someone
🙁
man that sucks
I do not understand how a developer not following Apples verification guidelines, and getting cracked, is Apples fault, as suggested in the full article. That is like blaming the airlines because you turned up after they told you the flight was scheduled to leave!
@Arnold Ziffel
Man, I am with you on the “loosing.”. I have no idea how this spelling made it in to American life, but it is rapidly becoming a scourge! It is Bad enough to see my students and bloggers using it, but i’ve seen it used by professional journalists in major publications.
@observer
Their are just…… < no!
There are just….. < yes!
Sorry, just trying to keep up with the REAL “The Corrector”
Note the Gruber update. ONLY if developer does not validate correctly.
Gruber goes on to say that Apple should test for this. I disagree. That is the job of the developer. You watt money for your app? Apple has provide a good way to secure against piracy. Use it. If you do not – then do not go whining to Apple.
It is called SQA.
Awesome!
Can you say “Installous” for my Mac!
May cracked apps never die.
Just multiply.
jmmx sums up the issue nicely.
isn’t it interesting how, in general, the people who whine the loudest are the lazy ones who just didn’t do a good job in the first place?
What’s the big deal? This is no different than Apple selling software, based upon the honor code. There’s no difference between Snow Leopard single-user and family pack. You don’t punch in any codes. They trust you to buy the one that applies.
@Fake Yeah that was full of intetional errors. To instead of too, should of instead of should have, could care less instead of could not care less.
” width=”19″ height=”19″ alt=”smile” style=”border:0;” />
Fake Corrector:
That was a joke. Note thee other errors.
@Uncle Al
Thanks, yeah I did, just didn’t want to be ostentatious about it.
…thee!? You’re pulling my leg right?!
Move along, nothing to see here…
Unfortunately, this will get more play than it deserves. Unfortunately, the news writers will be lazy and not write the story correctly. Unfortunately, the average computer user will believe the news.
I liked it better when Apple was under the radar. Now everyone is gunning for them. We do it all the time. Find a hero, then tear them apart for sport.
Awesome, why do you retards love giving Apple your money. Don’t you want FREE software??
Everyday that goes by I realize how much more retarded Macheads are than I thought the day before.
@Jim
Maybe because we’re mature grownups with jobs instead of entitled little sh*ts who live with their parents and expect everything to be given to them?
——RM
@backlash
Too late. I already have Aperture and iLife 11. Didnt pay for either one. I love it when people get miffed that someone else got a better deal. Take your high moral ground. Apple was built on anti establishment. Remember Woz using long distance for free? You guys keep paying. Next rounds on me!! Ha suckers!
UPDATE!
Hacker sites say installous for mac in February!! Isnt life grand!
Its good to be the King
the installous for mac you speak of, Kickback, that was how the whole thing started. welcome to last year.
but you think apple wont have an update long before then?
And i dont care if you got them free, all apple has to do is update the app store, and run a check on the software. if the receipt for a program does not match the program its intended for… deactivated. ad all you got was a demo.
simple way to cure the problem of idiot developers.
and i doubt you used the method for aperture and ilife. you prob downloaded the demos and used a serial to “register” the apps, and the app store recognized them as “legit” purchases.
I know, i also read you could do that yesterday. and i bet many script kiddies like yourself did.
Very nice and helpful information has been given in this article. It’s a most important post. Please every one visit this site quickly. Thanks.
Chevrolet Manual Steering Gear Box