{"id":16237,"date":"2013-07-22T09:51:46","date_gmt":"2013-07-22T16:51:46","guid":{"rendered":"http:\/\/www.intego.com\/mac-security-blog\/?p=16237"},"modified":"2016-10-06T12:18:19","modified_gmt":"2016-10-06T19:18:19","slug":"apple-developer-site-breached-researcher-takes-credit","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/","title":{"rendered":"Apple Developer Site Breached, Researcher Takes Credit"},"content":{"rendered":"<p style=\"text-align: center;\"><a href=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/07\/AppleSiteHacked.jpg\"><img loading=\"lazy\" class=\"aligncenter size-full wp-image-16249\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/07\/AppleSiteHacked.jpg\" alt=\"AppleSiteBreached\" width=\"500\" height=\"332\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/07\/AppleSiteHacked.jpg 500w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/07\/AppleSiteHacked-150x99.jpg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/07\/AppleSiteHacked-300x199.jpg 300w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/><\/a><\/p>\n<p>It&#8217;s looking like a rough morning for both Apple and a researcher that reportedly breached Apple&#8217;s developer site late last week.<\/p>\n<p>Apple announced this morning that the developer site had been breached on Thursday (whoops), saying an &#8220;intruder&#8221; had potentially accessed developers\u2019 names, mailing addresses, and\/or email addresses. It would seem that the researcher responsible for the breach got nervous at the thought that he was being categorized as a digital burglar. In a video defending his actions, the researcher <a href=\"http:\/\/news.cnet.com\/8301-13579_3-57594804-37\/researcher-apple-developer-site-hack-i-meant-no-harm\/\" target=\"_blank\">Ibrahim Balic said that he had reported 13 bugs<\/a> on the developer site to Apple, which gave him access to developers&#8217; information. Unfortunately, his video also includes some of those developers&#8217; details (ouch).<\/p>\n<p>This story is full of missteps on both sides: Apple did take their site down within a few hours of the report of the breach, but they waited several days to announce it to developers. Balic may have quietly, responsibly disclosed the vulnerabilities to Apple, but then he effectively <a href=\"http:\/\/www.urbandictionary.com\/define.php?term=doxed\" target=\"_blank\">doxed<\/a> the developers whose information he stumbled upon.<\/p>\n<p>If the details of the story as we now know it are accurate, this might have been a win for all concerned. Balic was ostensibly testing Apple\u2019s site to help improve their security, even if it was an un-requested test. If Apple had more quickly and more neutrally reported the event, this could have been a quick blip on the media radar that resulted in better security for all. Instead, Apple delayed reporting and used inflammatory words to describe the event. Then Balic got twitchy and released information of Apple developers that likely had nothing to do with this decision. Egg on face, all around!<\/p>\n<p>At any rate, it&#8217;s worth reiterating that this breach only pertains to the developer site, not to other Apple sites. The information that was accessed was not app code or data, nor was it credit card information. The breached site is down for now, and Apple is working to secure it before bringing it back up.<\/p>\n<p><span style=\"font-size: x-small;\">photo credit: <a href=\"http:\/\/www.flickr.com\/photos\/90982314@N00\/4325797829\/\">Tim . Simpson<\/a> via <a href=\"http:\/\/photopin.com\">photopin<\/a> <a href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/2.0\/\">cc<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s looking like a rough morning for both Apple and a researcher that reportedly breached Apple&#8217;s developer site late last week. Apple announced this morning that the developer site had been breached on Thursday (whoops), saying an &#8220;intruder&#8221; had potentially accessed developers\u2019 names, mailing addresses, and\/or email addresses. It would seem that the researcher responsible [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":16253,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[7,5],"tags":[543,319],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"It&#039;s looking like a rough morning for both Apple and a researcher that reportedly breached Apple&#039;s developer site late last week. Apple announced this\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Apple Developer Site Breached, Researcher Takes Credit - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"It&#039;s looking like a rough morning for both Apple and a researcher that reportedly breached Apple&#039;s developer site late last week. Apple announced this\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:published_time\" content=\"2013-07-22T16:51:46+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2016-10-06T19:18:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/07\/AppleSiteHacked_FT.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"266\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Lysa Myers\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/07\/AppleSiteHacked_FT.jpg\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/07\/AppleSiteHacked_FT.jpg\",\"width\":400,\"height\":266},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/\",\"name\":\"Apple Developer Site Breached, Researcher Takes Credit - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#primaryimage\"},\"datePublished\":\"2013-07-22T16:51:46+00:00\",\"dateModified\":\"2016-10-06T19:18:19+00:00\",\"description\":\"It's looking like a rough morning for both Apple and a researcher that reportedly breached Apple's developer site late last week. Apple announced this\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Apple Developer Site Breached, Researcher Takes Credit\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a\"},\"headline\":\"Apple Developer Site Breached, Researcher Takes Credit\",\"datePublished\":\"2013-07-22T16:51:46+00:00\",\"dateModified\":\"2016-10-06T19:18:19+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#webpage\"},\"wordCount\":346,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/07\/AppleSiteHacked_FT.jpg\",\"keywords\":[\"breached\",\"Security\"],\"articleSection\":[\"Apple\",\"Security News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a\",\"name\":\"Lysa Myers\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g\",\"caption\":\"Lysa Myers\"},\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"It's looking like a rough morning for both Apple and a researcher that reportedly breached Apple's developer site late last week. Apple announced this","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/","og_locale":"en_US","og_type":"article","og_title":"Apple Developer Site Breached, Researcher Takes Credit - The Mac Security Blog","og_description":"It's looking like a rough morning for both Apple and a researcher that reportedly breached Apple's developer site late last week. Apple announced this","og_url":"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/","og_site_name":"The Mac Security Blog","article_published_time":"2013-07-22T16:51:46+00:00","article_modified_time":"2016-10-06T19:18:19+00:00","og_image":[{"width":400,"height":266,"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/07\/AppleSiteHacked_FT.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Written by":"Lysa Myers","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/07\/AppleSiteHacked_FT.jpg","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/07\/AppleSiteHacked_FT.jpg","width":400,"height":266},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/","name":"Apple Developer Site Breached, Researcher Takes Credit - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#primaryimage"},"datePublished":"2013-07-22T16:51:46+00:00","dateModified":"2016-10-06T19:18:19+00:00","description":"It's looking like a rough morning for both Apple and a researcher that reportedly breached Apple's developer site late last week. Apple announced this","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Apple Developer Site Breached, Researcher Takes Credit"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a"},"headline":"Apple Developer Site Breached, Researcher Takes Credit","datePublished":"2013-07-22T16:51:46+00:00","dateModified":"2016-10-06T19:18:19+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#webpage"},"wordCount":346,"commentCount":0,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/07\/AppleSiteHacked_FT.jpg","keywords":["breached","Security"],"articleSection":["Apple","Security News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/apple-developer-site-breached-researcher-takes-credit\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/12b11624d5a648c576d8dce6f93b230a","name":"Lysa Myers","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/783af524dca7753ceb3cd9a576398a0e?s=96&d=mm&r=g","caption":"Lysa Myers"},"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/lysam\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2013\/07\/AppleSiteHacked_FT.jpg","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-4dT","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/16237"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=16237"}],"version-history":[{"count":16,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/16237\/revisions"}],"predecessor-version":[{"id":58006,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/16237\/revisions\/58006"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/16253"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=16237"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=16237"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=16237"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}