Researcher Takes Credit for Security Breach of Apple's Developer Center

The Next Web points to a comment on a TechCrunch article taking credit for last week's unauthorized access of Apple's Developer Center last week. The comment comes from independent security researcher Ibrahim Balic, who claims that his effort was not intended to be malicious and that he reported his findings to Apple just hours before the developer site was taken down by the company.

In total I have found 13 bugs and have reported through http://bugreport.apple.com. The bugs are all reported one by one and Apple was informed. I gave details to Apple as much as I can and I’ve also added screenshots.

One of those bugs have provided me access to users details etc. I immediately reported this to Apple. I have taken 73 users details (all apple inc workers only) and prove them as an example.

apple_dev_site_back_soon_hack
Balic claims to have accessed details on over 100,000 users, but only released to Apple details on 73 of its own employees in order to prove the seriousness of the issue.

I have emailed and asked if I am putting them in any difficulty so that I can give a break to my research. I have not gotten any respond to this… I have been waiting since then for them to contact me, and today I’m reading news saying that they have been attacked and hacked. In some of the media news I watch/read that whether legal authorities were involved in its investigation of the hack. I’m not feeling very happy with what I read and a bit irritated, as I did not done this research to harm or damage. I didn’t attempt to publish or have not shared this situation with anybody else.

Balic's tactics and motives have, however, been questioned by some, with scattered reports suggesting an unusually high level of password reset requests on Apple developers' accounts over the past few days.

Apple's Developer Center remains down today, some four days after the company took it down in order to investigate the breach, update its software, and rebuild its developer database.

Top Rated Comments

Konrad9 Avatar
141 months ago
And why exactly did it "need" to happen?

Because Apple is clearly not keeping it's security systems up to par, and it's better for someone to do this and make it public, than for someone to do this and steal and sell as much information as he could.
Score: 44 Votes (Like | Disagree)
napabar Avatar
141 months ago
Well if it didn't happen Apple wouldn't have taken measures to improve security. Pretty straightforward.
OK. No problem then. I'll be over tonight to break into your house. I'm not a thief. I just want to make sure your dwelling is secure.
Score: 43 Votes (Like | Disagree)
Reason077 Avatar
141 months ago
The most amazing revelation with this story that is suggests someone at Apple actually reads bug reports submitted through bugreport.apple.com!

This seems completely contrary to my own experience - perhaps it's actually worth reporting bugs to Apple after all.
Score: 31 Votes (Like | Disagree)
Michaelgtrusa Avatar
141 months ago
This needed to happen.
Score: 30 Votes (Like | Disagree)
millarj Avatar
141 months ago
"Security researcher" Yeah, that's it. Is the guy "testing" my front door with a crowbar also a security researcher?

It is nice that he gave apple a couple of hours to respond. Classy of 'im.
Score: 27 Votes (Like | Disagree)
recklesslife85 Avatar
141 months ago
Couldnt he have done this after Beta 4 release - DAMN HIM! ;)
Score: 26 Votes (Like | Disagree)

Popular Stories

Beyond iPhone 13 Better Blue Face ID Single Camera Hole

10 Reasons to Wait for Next Year's iPhone 17

Thursday May 9, 2024 9:00 am PDT by
Apple's iPhone development roadmap runs several years into the future and the company is continually working with suppliers on several successive iPhone models concurrently, which is why we sometimes get rumored feature leaks so far ahead of launch. The iPhone 17 series is no different, and already we have some idea of what to expect from Apple's 2025 smartphone lineup. If you plan to skip...
maxresdefault

Everything Announced at Today's Apple Event

Tuesday May 7, 2024 1:06 pm PDT by
Apple today held the first event of 2024, debuting new iPad Air and iPad Pro models and accompanying accessories. While the event was faster than normal and took 40 minutes, we've condensed it down even further for those who want a quick overview of everything that was announced. Subscribe to the MacRumors YouTube channel for more videos. We've also got a full recap of all of the coverage...
iOS 17 All New Features Thumb

Apple Says iOS 17.5 Coming 'Soon' With These New Features for iPhones

Monday May 6, 2024 7:33 am PDT by
Apple today announced that iOS 17.5 will be released to the public "soon," following over a month of beta testing. While the software update is relatively minor, it does have a few new features and changes, as outlined in the list below. "The new Pride Radiance watch face and iPhone and iPad wallpapers will be available soon with watchOS 10.5, iOS 17.5, and iPadOS 17.5," said Apple, in its...