Tuesday, May 14, 2013

Routing Around Apple's Restrictions, AppCertain & Others Bring Enterprise-Level Control To Consumers In The Interest Of Child Safety

appcertainIn the interest of protecting children, a new iOS application called AppCertain has debuted a monitoring application aimed at parents. The app, whose goal is to alert parents about the nature of the applications their kids are downloading, involves the use of a “configuration profile” – special software Apple originally intended for enterprise use, not consumer-facing apps sold through its App Store marketplace. But Apple reviewed the application – for longer than most, founder and CEO Spencer Whitman tells us – and subsequently approved it. For how long that will remain the case, however, is unknown. “We?think we are on a gray line with respect to Apple, but we don’t really know,” Whitman admits. Configuration profiles, for those unfamiliar, were designed for the enterprise environment, allowing I.T. departments to manage the iPhones and iPads used by a company’s employees. They’re typically employed by Mobile Device Management solutions which use the software to configure, track and/or restrict a number of system-level settings like Wi-Fi, VPNs, app settings, permissions, and more. But more recently, a handful of startups have started using these same profiles to work around Apple’s App Store’s restrictions in order to accomplish tasks which wouldn’t otherwise be possible. Apple is aware this is happening, and seems to be handling each app submission on a one-off basis for now. We’ve seen mobile data compression utilities like Onavo and Snappli take advantage of the technology to intercept, re-route, and compress web data in order to save users’ bandwidth, for instance. Social search engine Wajam also uses a configuration profile to inject its own search results into Safari, though this is done outside of the Apple App Store. Onavo is still live on the Apple App Store today, though Snappli has since disappeared. (We reached out to the company for details, but have yet to hear back. It’s possible that Apple simply didn’t care for the fact that Snappli had publicly shared data showing how iOS users were dumping the then newly-launched Apple Maps application.) But frankly, it seems odd that Apple would knowingly ever let these types of applications into its consumer-facing app store in the first place, given the security risks they could pose. If used unscrupulously, a malicious configuration profile could remote control a user’s device, manipulate user activity, and hijack their sessions, or so explained?security researchers at Skycure?back in March. AppCertain isn’t a malicious developer, though, and its

Source: http://feedproxy.google.com/~r/Techcrunch/~3/iMxaD9pzMZg/

Belk Led Zeppelin Ned Rocknroll Norman Schwarzkopf Avery Johnson kennedy center honors boxing day

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.