Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

MacRumors

macrumors bot
Original poster
Apr 12, 2001
63,625
31,011



developer.png
In an email to developers today, Apple revealed that its Developer Center website was breached by unknown hackers and was taken offline last Thursday as a precaution.

The company notes that sensitive personal information was "encrypted and cannot be accessed" but that Apple's engineers "could not rule out the possibility" that developer names, mailing addresses and email addresses may have been accessed.

Apple says it is overhauling its developer systems, updating software and rebuilding the entire developer database. There is no indication of when the site will be back up, other than the company saying it expects to have it up again soon.
Apple Developer Website Update

Last Thursday, an intruder attempted to secure personal information of our registered developers from our developer website. Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers' names, mailing addresses, and/or email addresses may have been accessed. In the spirit of transparency, we want to inform you of the issue. We took the site down immediately on Thursday and have been working around the clock since then.

In order to prevent a security threat like this from happening again, we're completely overhauling our developer systems, updating our server software, and rebuilding our entire database. We apologize for the significant inconvenience that our downtime has caused you and we expect to have the developer website up again soon.
Apple told Macworld that the breached server was not associated with any customer information and that all personal information is encrypted -- additionally, the attackers did not get access to any app code or to any servers where app information is stored.

Article Link: Apple Developer Website Hacked: Developer Names, Addresses May Have Been Taken
 

gmanist1000

macrumors 68030
Sep 22, 2009
2,833
824
Out of curiosity, does Apple use 128 or 256 bit encryption on their developer site?
 

ct2k7

macrumors G3
Aug 29, 2008
8,362
3,435
London
Someone says that they are required to inform us within a timely manner about this?
 

WolfSnap

macrumors 65816
Sep 18, 2012
1,071
911
SoCal
News reporting would go something like this...

Of the Apple hacking, which didn't really affect much, and is actively being resolved:
Apple completely compromised!

Of the Android master key exploit which exposes 900 million phones to malware/viruses and more, and has no chance of ever being resolved:
<chirp><chirp><chirp>
 

Tankmaze

macrumors 68000
Mar 7, 2012
1,707
351
Oo wow, didn't see that coming.
by getting the email address, a hacker can brute force the password to access the developer section. But thankfully any changes in developer area takes time and email confirmation, so yeah hopefully not a big deal.
 

redsoxunixgeek

macrumors regular
Dec 1, 2006
115
21
Salt Lake City YOOTah
Oo wow, didn't see that coming.
by getting the email address, a hacker can brute force the password to access the developer section. But thankfully any changes in developer area takes time and email confirmation, so yeah hopefully not a big deal.

This explains why I have had the four alerts pop up on my iPad/iPhone (2x each) of someone trying to reset my apple account password. If You guys haven't set this up yet, May I be the one to recommend it?
 

Unggoy Murderer

macrumors 65816
Jan 28, 2011
1,152
4,013
Edinburgh, UK
To be honest, I did suspect something like this had happened, but I hoped it wasn't the case. It's good they actually encrypted some of the information, but it's a shame that some information may have been accessed.

Hope Apple are able to clear it up without too much trouble.

Although, I'll bet the Fandroid bandwagon will be arriving shortly. Like flies to a pile of, you know...
 

drewyboy

macrumors 65816
Jan 27, 2005
1,385
1,467
News reporting would go something like this...

Of the Android master key exploit which exposes 900 million phones to malware/viruses and more, and has no chance of ever being resolved:

How DARE you bring REASON to this discussion. It's about jumping on the hating Apple bandwagon and bringing its stock to it's knees! /s

But yes, I'm sure we'll hear about it in the news and the android exploit goes unnoticed.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.