Apple developer site has been down for a full day now

Kaido

Elite Member & Kitchen Overlord
Feb 14, 2004
48,518
5,340
136
Heard it was hacked. Dunno if it's true.
 

BuCkDoG

Member
Jun 13, 2013
41
0
0
No one really knows what happened, but yes you are correct. It has been down for quite some time now.
 

Subyman

Moderator <br> VC&G Forum
Mar 18, 2005
7,876
32
86
Apple confirmed the developer portal was breached by malicious hackers. They are working to figure out what exactly happened and trying to secure the portal for further attacks. Who knows when it will be back, they are rebuilding the database completely. Anyone that has rebuilt a DB knows it can take forever, no telling how large Apple's is.
 

Rakehellion

Lifer
Jan 15, 2013
12,182
35
91
Apple Developer Website Update

Last Thursday, an intruder attempted to secure personal information of our registered developers from our developer website. Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers&#8217; names, mailing addresses, and/or email addresses may have been accessed. In the spirit of transparency, we want to inform you of the issue. We took the site down immediately on Thursday and have been working around the clock since then.

In order to prevent a security threat like this from happening again, we&#8217;re completely overhauling our developer systems, updating our server software, and rebuilding our entire database. We apologize for the significant inconvenience that our downtime has caused you and we expect to have the developer website up again soon.


TM and copyright © 2013 Apple Inc. 1 Infinite Loop, MS 96-DM, Cupertino, CA 95014.
All Rights Reserved / Privacy Policy / My Apple ID
 

manly

Lifer
Jan 25, 2000
11,349
2,362
136
Apple Developer Website Update

Last Thursday, an intruder attempted to secure personal information of our registered developers from our developer website. Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers’ names, mailing addresses, and/or email addresses may have been accessed. In the spirit of transparency, we want to inform you of the issue. We took the site down immediately on Thursday and have been working around the clock since then.

In order to prevent a security threat like this from happening again, we’re completely overhauling our developer systems, updating our server software, and rebuilding our entire database. We apologize for the significant inconvenience that our downtime has caused you and we expect to have the developer website up again soon.


TM and copyright © 2013 Apple Inc. 1 Infinite Loop, MS 96-DM, Cupertino, CA 95014.
All Rights Reserved / Privacy Policy / My Apple ID
coming from Apple, that's a fairly extensive answer. I'm surprised they didn't just offer 2-factor authentication and call it a day.
 

Kaido

Elite Member & Kitchen Overlord
Feb 14, 2004
48,518
5,340
136
Apple's Developer Center Hacked by Security Researcher, Data Unharmed:

http://gizmodo.com/apples-developer-center-hacked-by-security-researcher-864846271

Apple revealed late yesterday that its Developer Center had been forced out of action by "an intruder"&#8212;but a researcher has provided evidence to confirm that the downtime was a result of his identification of a security vulnerability.

Apple claimed in a statement that an intruder had attempted to steal personal information about registered developers from the site. But Ibrahim Balic, a security researcher from the UK, claims that he recently found 13 bugs within the website's system which allowed him to secure data from more than 100,000 users.

He claims to have approached Apple with details from 73 user accounts&#8212;all Apple employees&#8212;to illustrate the flaw, offering to help them fix things. Balic claims Apple's response was to shut down the Developer Center. That happened Tuesday; Apple only issued a statement Sunday.

It certainly seems that Balic's claims match up with events in terms of timing and data collection. Balic himself claims to be &#8220;a bit irritated&#8221; that Apple has publicly announced the situation as a security breach rather than a constructive piece of research&#8212;and it remains to be seen what Apple will do about his involvement. It is, at least, comforting to know that the data isn't being used maliciously.
 

smackababy

Lifer
Oct 30, 2008
27,024
79
86
So this Balic guy is irritated that he breaches Apple's security, and they claim it was a security breach? His intentions might have been all well, but unless he was commissioned to find these flaws, he did not offer a "constructive piece of research". Apple doesn't know his intentions or anything he might have done with the data. He can claim all he wants, but he still hacked them.
 

BuCkDoG

Member
Jun 13, 2013
41
0
0
Im sure Apple will do their fair share of investigations into the issue and see what happens from there. Quite interesting though if you ask me.
 

stlcardinals

Senior member
Sep 15, 2005
729
0
76
coming from Apple, that's a fairly extensive answer. I'm surprised they didn't just offer 2-factor authentication and call it a day.

They already have 2-Factor Authentication for Apple IDs.

I'll try and find the story I read, but it stated that after the guy downloaded the first small set to demonstrate the bug he submitted to Apple, he preceded to download ~100,000 more.
 

stlcardinals

Senior member
Sep 15, 2005
729
0
76
This was the "security researcher's" post in the comments of the TechCrunch article. The bolded below is by me.

http://techcrunch.com/2013/07/21/ap...ter-has-potentially-been-breached-by-hackers/

Hi there,


My name is ibrahim Balic, I am a security researcher. You can also search my name from Facebook's Whitehat List. I do private consulting for particular firms. Recently I have started doing research on Apple inc.

In total I have found 13 bugs and have reported through http://bugreport.apple.com. The bugs are all reported one by one and Apple was informed. I gave details to Apple as much as I can and I've also added screenshots.

One of those bugs have provided me access to users details etc. I immediately reported this to Apple. I have taken 73 users details (all apple inc workers only) and prove them as an example.

4 hours later from my final report Apple developer portal gas closed down and you know it still is. I have emailed and asked if I am putting them in any difficulty so that I can give a break to my research. I have not gotten any respond to this... I have been waiting since then for them to contact me, and today I'm reading news saying that they have been attacked and hacked. In some of the media news I watch/read that whether legal authorities were involved in its investigation of the hack. I'm not feeling very happy with what I read and a bit irritated, as I did not done this research to harm or damage. I didn't attempt to publish or have not shared this situation with anybody else. My aim was to report bugs and collect the datas for the porpoise of seeing how deep I can go within this scope. I have over 100.000+ users details and Apple is informed about this. I didn't attempt to get the datas first and report then, instead I have reported first.

I do not want my name to be in blacklist, please search on this situation. I'm keeping all the evidences, emails and images also I have the records of bugs that I made through Apple bug-report.

He also posted a YouTube video showing the un-redacted details of Apple Developers.
 

Tegeril

Platinum Member
Apr 2, 2003
2,907
5
81
"I only stole a little bit of data and when Apple didn't sing my praises, I just grabbed as much as I could. I'm not acting maliciously at all."

Riiiiiiiight.
 

Subyman

Moderator <br> VC&G Forum
Mar 18, 2005
7,876
32
86
Still down today. Hopefully it won't last much longer, I've got to sign people up for beta testing. I'm surprised the story isn't getting more coverage.
 

Subyman

Moderator <br> VC&G Forum
Mar 18, 2005
7,876
32
86
New info:

We apologize for the significant inconvenience caused by our developer website downtime. We've been working around the clock to overhaul our developer systems, update our server software, and rebuild our entire database. While we complete the work to bring our systems back online, we want to share the latest with you.

We plan to roll out our updated systems, starting with Certificates, Identifiers & Profiles, Apple Developer Forums, Bug Reporter, pre-release developer libraries, and videos first. Next, we will restore software downloads, so that the latest betas of iOS 7, Xcode 5, and OS X Mavericks will once again be available to program members. We'll then bring the remaining systems online. To keep you up to date on our progress, we've created a status page to display the availability of our systems.

If your program membership is set to expire during this period, it will be extended and your app will remain on the App Store. If you have any other concerns about your account, please contact us.

Thank you for your continued patience.

So it will be a gradual roll out of features. No ETA though.
 

RampantAndroid

Diamond Member
Jun 27, 2004
6,591
3
81
Bug reporter just lit up green in the last hour. Might we be seeing stuff light up fully in the next couple of days?
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |