7 ms·
> Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers’ names, m
by jpdoctor 13y ago
> Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers’ names, mailing addresses, and/or email addresses may have been accessed.
So they can't rule out the possibility that sensitive personal information, which cannot be accessed, has been accessed. Got it.
Apparently our intelligence, which cannot be insulted, has been insulted.
- jordanthoms 13y agoAlternately, inside the reality distortion field developers’ names, mailing addresses, and/or email addresses is not sensitive personal information.
- Turing_Machine 13y agoAnyone who has my name can find my email address with a simple Google search. My mailing address is on all kinds of public records.
- robryan 13y ago"Give me a list of all registered developers email addresses" is a little harder though.
- ptwiggens 13y agoHow are names, mailing addresses, and email addresses sensitive personal information? I would imagine that for most of the people signed up, it wouldn't be that hard to track down their name and email just from knowing the name of their app.
- CoryG89 13y agoName and e-mail, I'm kinda with you. Everyone who uses my app knowing my current mailing address I look at a little bit different.
- ojbyrne 13y agoIf by "reality distortion field," you mean the legal community, then yes. Having been through something similar recently, the lawyers will likely be making sure everyone involved understands the concept of PII: https://en.wikipedia.org/wiki/Personally_identifiable_information https://en.wikipedia.org/wiki/Personally_identifiable_inform...
- VeryVito 13y agoOne of the understood requirements of publishing an app on the App Store is that developers must provide some means for customers to contact them directly (support page, email address, etc). If you're selling apps on the app store, people can already peddle their wares to your email account. So yeah, developer's names, addresses and emails are not secrets by any means. Why would anyone buy an app from someone they had no means of identifying?
- gurkendoktor 13y agoiOS developers != App Store vendors. There are plenty of developers who work on other people's apps for a living.
- kristofferR 13y agoBy "sensitive personal information" they probably just mean passwords and credit card information, not names, email addresses and mailing addresses.
- _delirium 13y agoPasswords could be hashed, but credit-cards are the big one you have to keep in plaintext. If you want to bill the card without asking for the number to be reentered, there's no way to avoid storing the number and expiration date. PCI does mandate that you keep less than necessary to initiate a new charge, though: you are not allowed to store the 3-digit verification code from the back of the card. Future charges from the same vendor can go through based on the stored information (without re-sending the verification code), but charges from a new vendor would need the code, so this is intended to make it harder for someone who stole the saved information to initiate a new charge. A loophole is that in-person charges do not use the verification code, so someone could use the saved information to fabricate physical cards, and try to use them at stores (the U.S. doesn't typically use either chipped or PIN-protected credit cards, so cloning a card from the number is relatively easy, prevented more or less only by the heuristic fraud-detection algorithms).
- kybernetyk 13y agoPurchases of developer memberships are handled through Apple's online store. And that is still up.
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- clarky07 13y agonames, email adresses, and mailing addresses aren't particularly sensitive. These are all pretty easy to get for most people without hacking anything.
- _sabe_ 13y ago"The intruder had good intent with trying to "secure" our personal information. But despite nothing being hacked, as it was only a 'threat', we still need to tear down and build up the system from scratch again. In the spirit of transparency we've waited 72 hours before giving you this nonsense bullshit. Please note that some (that is all) of you will from now on get regular viagra offerings in cyrillic. Good for you!"
- rimantas 13y agosecure verb [ with obj. ] 2 succeed in obtaining (something), especially with difficulty
- llamataboot 13y ago"First of all, this does not affect iTunes customer accounts—this is a different system and all iTunes customer information is completely safe, Apple told me. It’s also important to note that the hacker did not get access to any app code or even the servers where the app information was stored. The hacker also did not get access to any credit card information. The only thing that the hacker could have gotten access to was the names, email addresses and mailing addresses of the developers. At this point, Apple doesn’t know if the hacker even managed to see that information. Worst case, that is all the information they would have seen, according to Apple." http://www.loopinsight.com/2013/07/21/apple-comments-on-developer-site-hack/ http://www.loopinsight.com/2013/07/21/apple-comments-on-deve...
- jpttsn 13y agoApple apparently doesn't agree that, in context of the data they have on you, your name, mailing address or email address qualifies as sensitive.