Sunday, July 22, 2012

Apple will fix in-app purchases vulnerability in iOS 6, provides workaround for now

Apple will fix in-app purchase vulnerability in iOS 6, provides private API workaround for now

In iOS 6, coming this fall, Apple will fix a {security vulnerability in the App Store's in-app purchasing process](http://www.imore.com/stealing-app-purchases-and-what-it-could-cost-you) that allows "man-in-the-middle" style attacks, steals from developers, and potentially exposes user account data to hackers. This according to a new, publicly-available support document posted to developer.apple.com on in-app purchase receipt validation on iOS. Apple's preamble states:

A vulnerability has been discovered in iOS 5.1 and earlier related to validating in-app purchase receipts by connecting to the App Store server directly from an iOS device. An attacker can alter the DNS table to redirect these requests to a server controlled by the attacker. Using a certificate authority controlled by the attacker and installed on the device by the user, the attacker can issue a SSL certificate that fraudulently identifies the attacker?s server as an App Store server. When this fraudulent server is asked to validate an invalid receipt, it responds as if the receipt were valid.

iOS 6 will address this vulnerability. If your app follows the best practices described below then it is not affected by this attack.

Matthew Panzarino from The Next Web points out that Apple is exposing some private APIs (application program interfaces) to developers as part of the short-term fix:

Essentially, Apple has added a hash to each transaction that is calculated based on a digital certificate. That certificate must be coded into the app by each developer. This is used to determine whether the in-app purchase receipt has come from Apple directly. The data in the receipt is used to calculate that hash so that each one is unique and can?t be faked.

Apple typically scans for, and automatically rejects, any app that uses private API. The reason for this is, unlike public API which cary with them the promise of future compatibility and support, Apple can and will make changes to private API at any time, potentially breaking apps that rely on them.

Exceptions to the prohibition on private API are almost unheard of, which shows both the importance of the fix, and short period of time it's meant to cover (less than 3 months).

Since the security vulnerability was discovered and exploited, Apple has been engaged in a back-and-forth series of actions against the hacker in an attempt to prevent any theft of developer assets or user data. While the process has been successfully used to steal in-app purchases without paying for them, it's uncertain if any account information has been compromised. Even if it wasn't, and even if this hack, in this case, was aimed at developers rather than users, it doesn't mean the next one, using the same or similar exploits, won't specifically target user account data. Apple has to fix it and make the fix stick.

iOS 6 was announced at WWDC 2012, is currently in beta, and will be made publicly available this fall, likely alongside the next generation iPhone 5.

Until then, for developers who rely on in-app-purchases, it looks like there's some work to do to tighten up security in the meantime.

For users, while the prospect of free Smurfberries might sound enticing, essentially breaking open your iPhone or iPad's security and passing all your transactions through a hacker's servers, potentially exposing your iTunes account and related credit card information could end up being a much, much higher price to pay.

Source: developer.apple.com, The Next Web



Source: http://feedproxy.google.com/~r/TheIphoneBlog/~3/jzX2UyQq_7I/story01.htm

john boehner demi moore hospitalized james farentino somali pirates navy seals navy seal team 6 tim gunn

Wednesday, July 18, 2012

Afghan soldier sentenced to death for French killings

[ [ [['Connery is an experienced stuntman', 2]], 'http://yhoo.it/KeQd0p', '[Slideshow: See photos taken on the way down]', ' ', '630', ' ', ' ', ], [ [['Connery is an experienced stuntman', 7]], ' http://yhoo.it/KpUoHO', '[Slideshow: Death-defying daredevils]', ' ', '630', ' ', ' ', ], [ [['know that we have confidence in', 3]], 'http://yhoo.it/LqYjAX ', '[Related: The Secret Service guide to Cartagena]', ' ', '630', ' ', ' ', ], [ [['We picked up this other dog and', 5]], 'http://yhoo.it/JUSxvi', '[Related: 8 common dog fears, how to calm them]', ' ', '630', ' ', ' ', ], [ [['accused of running a fake hepatitis B', 5]], 'http://bit.ly/JnoJYN', '[Related: Did WH share raid details with filmmakers?]', ' ', '630', ' ', ' ', ], [ [['accused of running a fake hepatitis B', 3]], 'http://bit.ly/KoKiqJ', '[Factbox: AQAP, al-Qaeda in Yemen]', ' ', '630', ' ', ' ', ], [ [['have my contacts on or glasses', 3]], 'http://abcn.ws/KTE5AZ', '[Related: Should the murder charge be dropped?]', ' ', '630', ' ', ' ', ], [ [['have made this nation great as Sarah Palin', 5]], 'http://yhoo.it/JD7nlD', '[Related: Bristol Palin reality show debuts June 19]', ' ', '630', ' ', ' ', ], [ [['have made this nation great as Sarah Palin', 1]], 'http://bit.ly/JRPFRO', '[Related: McCain adviser who vetted Palin weighs in on VP race]', ' ', '630', ' ', ' ', ], [ [['A JetBlue flight from New York to Las Vegas', 3]], 'http://yhoo.it/GV9zpj', '[Related: View photos of the JetBlue plane in Amarillo]', ' ', '630', ' ', ' ', ], [ [['the 28-year-old neighborhood watchman who shot and killed', 15]], 'http://news.yahoo.com/photos/white-house-stays-out-of-teen-s-killing-slideshow/', 'Click image to see more photos', 'http://l.yimg.com/cv/ip/ap/default/120411/martinzimmermen.jpg', '630', ' ', 'AP', ], [ [['He was in shock and still strapped to his seat', 6]], 'http://news.yahoo.com/photos/navy-jet-crashes-in-virginia-slideshow/', 'Click image to see more photos', 'http://l.yimg.com/cv/ip/ap/default/120406/jet_ap.jpg', '630', ' ', 'AP', ], [ [['xxxxxxxxxxxx', 11]], 'http://news.yahoo.com/photos/russian-grannies-win-bid-to-sing-at-eurovision-1331223625-slideshow/', 'Click image to see more photos', 'http://l.yimg.com/a/p/us/news/editorial/1/56/156d92f2760dcd3e75bcd649a8b85fcf.jpeg', '500', ' ', 'AP', ] ]

[ [ [['did not go as far his colleague', 8]], '29438204', '0' ], [ [[' the 28-year-old neighborhood watchman who shot and killed', 4]], '28924649', '0' ], [ [['because I know God protects me', 14], ['Brian Snow was at a nearby credit union', 5]], '28811216', '0' ], [ [['The state news agency RIA-Novosti quoted Rosaviatsiya', 6]], '28805461', '0' ], [ [['measure all but certain to fail in the face of bipartisan', 4]], '28771014', '0' ], [ [['matter what you do in this case', 5]], '28759848', '0' ], [ [['presume laws are constitutional', 7]], '28747556', '0' ], [ [['has destroyed 15 to 25 houses', 7]], '28744868', '0' ], [ [['short answer is yes', 7]], '28746030', '0' ], [ [['opportunity to tell the real story', 7]], '28731764', '0' ], [ [['entirely respectable way to put off the searing constitutional controversy', 7]], '28723797', '0' ], [ [['point of my campaign is that big ideas matter', 9]], '28712293', '0' ], [ [['As the standoff dragged into a second day', 7]], '28687424', '0' ], [ [['French police stepped up the search', 17]], '28667224', '0' ], [ [['Seeking to elevate his candidacy back to a general', 8]], '28660934', '0' ], [ [['The tragic story of Trayvon Martin', 4]], '28647343', '0' ], [ [['Karzai will get a chance soon to express', 8]], '28630306', '0' ], [ [['powerful storms stretching', 8]], '28493546', '0' ], [ [['basic norm that death is private', 6]], '28413590', '0' ], [ [['songwriter also saw a surge in sales for her debut album', 6]], '28413590', '1', 'Watch music videos from Whitney Houston ', 'on Yahoo! Music', 'http://music.yahoo.com' ], [ [['keyword', 99999999999999999999999]], 'videoID', '1', 'overwrite-pre-description', 'overwrite-link-string', 'overwrite-link-url' ] ]

Source: http://news.yahoo.com/afghan-soldier-sentenced-death-french-killings-064932717.html

chris christie naacp glen campbell jerusalem artichoke bud shootout aretha franklin stevie wonder

Saturday, July 14, 2012

China makes its largest hybrid delivery port tire crane | China's Great ...

2012-07-15 ? Recently, Yichang strength Lifting Machinery Co., Ltd. of China?s largest hybrid LQD50A type 60-ton crane through the port of Tyre in Wuhan Port Machinery Quality Supervision and Testing Center of the type testing, access to special equipment type test certificate, has been delivered Yingkou Port Group Co., Ltd. to use.

It is reported that 60-ton dual-port power LQD50A type tire crane, which self-control and external AC power control system, two systems can be separately controlled to achieve the crane, a button to switch quickly and conveniently. DC electric machine inherits the traditional advantages of the port tire crane and innovation in technology, one hundred tons fuel-efficient than similar products loading and unloading fuel consumption more than 30%, in the use of an external AC operation, loading and unloading operations can reduce the cost of more than 70% and reduce maintenance costs over 50%.

Currently, the LQD50A type of hybrid energy-saving tire crane port already has four series of 16 tons, 25 tons, 30 tons, 40 tons, 50 tons, 60 tons, such as the six-level products, the major seaport, the port along the Yangtze River, widely used in railway freight yard.

Yichang Lidao Crane Machinery Co., Ltd., located in Zhijiang City, Hubei Province, is a high-tech enterprise specializing in the design and manufacturing of port tyre cranes.

Relying on the technical force in port machine, technology exchange platform with the industry peers in the world and state-level laboratories for crane machinery of the logistics faculty of Wuhan University of Technology, the company has a R&D, quality control and technical support team based on experts, professors, senior engineers and graduate students. Through market research and absorbing the mature experience in various port tyre cranes at home and abroad, the company has carried out repeated demonstration by combining the actual usage situation of cranes at port, thus has independently developed Lidao LQD50A-type four series hybrid low-energy port tyre cranes and grad hybrid port tyre cranes at seven levels including 16t, 25t, 30t, 36t, 40t, 50t and 60t. The company owns full intellectual property rights for the above mentioned series of cranes, which have an advantage over other products at the same level with an energy conservation rate of over 30%.

?Lidao? port tyre crane is not a sticker for either traditional or modern concept in design, but an integrator of both inheritance and innovation. In the philosophy of ?Safe and Reliable, Simple and Practical, Easy to Be Maintained, Low-energy Consumption and Eco-friendly?, the company delivers cost-effective and high-quality products which fully meet customers? individual needs based on customers? requirements. All the products have won high recognition for their practical function from users at ports, warehouses, stations, railway yards, etc.

The company constantly develops new markets in the business philosophy of ?Practical, Efficient, High-quality, Low-cost?, the tenet of ?Quality and Service?, and the business management concept of ?Customer Focus, Constant Progress, Constant Improvement, Constant Innovation, Constant Perfection?, so as to realize steady and sound development for the company and serve and benefit the community.

Source: http://www.chinatechgadget.com/china-makes-its-largest-hybrid-delivery-port-tire-crane.html

pro bowl pro bowl 2012 rick santorum daughter gainesville 2012 royal rumble the grey machine gun kelly

Sorens on Raico: Great minds think (mostly) alike

A review of Ralph Raico?s outstanding recent book, Classical Liberalism and the Austrian School reminds David Gordon that appeals to ?the results of human action but not of human design? are quite common among Austrian methodological individualists.

By David Gordon,?Guest blogger / July 13, 2012

A structure showing the Euro currency sign is seen in front of the European Central Bank (ECB) headquarters in Frankfurt on July 11, 2012. A very thoughtful review of Ralph Raico?s outstanding recent book, "Classical Liberalism and the Austrian School" prompted a response from our blogger, David Gordon.

Alex Domanski/Reuters

Enlarge

Jason Sorens has posted a very thoughtful review of Ralph Raico?s outstanding recent book, Classical Liberalism and the Austrian School.?

Skip to next paragraph

Recent posts

' + google_ads[0].line2 + '
' + google_ads[0].line3 + '

'; } else if (google_ads.length > 1) { ad_unit += ''; } } document.getElementById("ad_unit").innerHTML += ad_unit; google_adnum += google_ads.length; return; } var google_adnum = 0; google_ad_client = "pub-6743622525202572"; google_ad_output = 'js'; google_max_num_ads = '1'; google_feedback = "on"; google_ad_type = "text"; google_adtest = "on"; google_image_size = '230x105'; google_skip = '0'; // -->

I admire the post and learned from it, but I?d like to differ with Sorens on two points. He suggests that methodological individualism is vulnerable to criticism. ?We can know that firms try to maximize profit even if we do not have a good explanation for why each individual firm tries to maximize profit, or why individuals have chosen so to organize themselves. ? He appeals here to what Bob Nozick called a ?filtering device.? The explanation, I take it, is roughly this: to the extent that firms engage in profit maximization, they will tend to supplant firms that don?t.

But this explanation is entirely consistent with methodological individualism. This doctrine does not require that social outcomes be reducible to the motives of individuals. To the contrary, appeals to ?the results of human action but not of human design? are quite common among Austrian methodological individualists.? In thinking that use of ?filtering devices? in Nozick?s sense, irreducible to the psychological motives of individuals, conflicts with methodological individualism, Sorens has I think wrongly taken over Nozick?s unduly restrictive account of that doctrine, in his essay ?On Austrian Methodology?

Sorens also remarks:? ?However, what I have heard from contemporary Austrian economists such as Peter Leeson is that Mises himself was not opposed to hypothesis testing, even using statistical methods. He was merely opposed to Popper-style falsificationism (i.e., that every element of a theory must be falsifiable), which has in any case been superseded in mainstream philosophy of science. ?

Certainly, Mises did not oppose hypothesis testing in applying economics to historical issues; but in economic theory itself he was very much an apriorist. Mises himself is a much better guide to his views on method than ?contemporary Austrian economists?; and if one consults Mises, whether he was an apriorist is not a difficult question to answer.

The Christian Science Monitor has assembled a diverse group of the best economy-related bloggers out there. Our guest bloggers are not employed or directed by the Monitor and the views expressed are the bloggers' own, as is responsibility for the content of their blogs. To contact us about a blogger, click here. To add or view a comment on a guest blog, please go to the blogger's own site by clicking on blog.mises.org.

Source: http://rss.csmonitor.com/~r/feeds/csm/~3/83XzoKSLQfE/Sorens-on-Raico-Great-minds-think-mostly-alike

louisiana primary syracuse basketball chipper jones chipper jones dancing with the stars cast mickael pietrus heart transplant

Closing arguments set for voter ID trial

(AP) ? Closing arguments are set to begin a trial that will determine the fate of Texas' controversial voter ID law.

Lawyers for Texas, the Justice Department and intervening groups supporting the Justice Department's position will make their final cases in a federal court in Washington on Friday morning.

A three-judge panel is set to determine whether the 2011 Texas law violates the federal Voting Rights Act, passed in 1965 to protect minorities' right to vote.

The Justice Department blocked Texas' law in March, citing the Act. The Justice Department, in turn, filed a lawsuit, bringing the case to a courtroom in Washington. The judges have heard four days of testimony from witnesses, including experts on statistics and elections and state lawmakers.

Associated Press

Source: http://hosted2.ap.org/apdefault/386c25518f464186bf7a2ac026580ce7/Article_2012-07-13-Texas%20Voter%20ID%20Trial/id-12d3c9ebc3cc4c3783a43d7fcf38f024

goldman sachs brandon carr knicks coach encyclopedia britannica pi white lion mike d antoni resigns