Apple Developer Website Hacked: Developer Names, Addresses May Have Been Taken

developerIn an email to developers today, Apple revealed that its Developer Center website was breached by unknown hackers and was taken offline last Thursday as a precaution.

The company notes that sensitive personal information was "encrypted and cannot be accessed" but that Apple's engineers "could not rule out the possibility" that developer names, mailing addresses and email addresses may have been accessed.

Apple says it is overhauling its developer systems, updating software and rebuilding the entire developer database. There is no indication of when the site will be back up, other than the company saying it expects to have it up again soon.

Apple Developer Website Update

Last Thursday, an intruder attempted to secure personal information of our registered developers from our developer website. Sensitive personal information was encrypted and cannot be accessed, however, we have not been able to rule out the possibility that some developers’ names, mailing addresses, and/or email addresses may have been accessed. In the spirit of transparency, we want to inform you of the issue. We took the site down immediately on Thursday and have been working around the clock since then.

In order to prevent a security threat like this from happening again, we’re completely overhauling our developer systems, updating our server software, and rebuilding our entire database. We apologize for the significant inconvenience that our downtime has caused you and we expect to have the developer website up again soon.

Apple told Macworld that the breached server was not associated with any customer information and that all personal information is encrypted -- additionally, the attackers did not get access to any app code or to any servers where app information is stored.

Top Rated Comments

WolfSnap Avatar
111 months ago
News reporting would go something like this...

Of the Apple hacking, which didn't really affect much, and is actively being resolved:
Apple completely compromised!

Of the Android master key exploit which exposes 900 million phones to malware/viruses and more, and has no chance of ever being resolved:
<chirp><chirp><chirp>
Score: 43 Votes (Like | Disagree)
Snowshiro Avatar
111 months ago
I'm not normally one to step up and defend Apple, but in this case, sadly this is how things are now.

Facebook has been hacked, Twitter has been hacked, Sony has been hacked, Zendesk has been hacked, Microsoft has been hacked, Ubuntu has been hacked, numerous government websites have been hacked etc. etc.

It's simply next to impossible these days to guarantee security in the millions of lines of code that constitute modern Operating Systems and the dozens of processes that run on them. Someone will find a vulnerability sooner or later and exploit it. The only thing you can do is make it as hard as possible for them, and store your data in as safe a manner as possible with strong encryption (and hashing for passwords).

This was going to happen sooner or later, and while it looks bad for Apple, it's a fact of life that there are people out there for whom hacking is their job and how they earn their money. The only way to secure your data from hacking, is not to put it on the internet. End of story.
Score: 26 Votes (Like | Disagree)
TheFithBeatle Avatar
111 months ago
oh dam

this will hit news stations like a frenzy, android users are gonna gloat
Score: 18 Votes (Like | Disagree)
WhackyNinja Avatar
111 months ago
Travel back in Time and stop this NOW!

Fixed point in time it cant be changed! ITS ALL JUST WIBBLY WOBBLY TIMEY WIMEY
Score: 11 Votes (Like | Disagree)
Zaqfalcon Avatar
111 months ago
Do developer names, mailing addresses and email addresses, not constitute sensitive?
Score: 10 Votes (Like | Disagree)
gnasher729 Avatar
111 months ago
Why didn't you do this as routine maintenance to prevent anything like this from happening to this severity? Sure you can't make it 100% immune from attacks, but you could make the data 98% safe.
It seems you don't have much experience building secure websites. What you do is building security in depth. You make sure nobody can get in, and you make sure there's nothing to see if somebody gets in. You always assume that someone _might_ figure out how to get around one defense, and have a second defense in place. That's what Apple did, and it worked. Most likely the attacker didn't get access to anything, and what there was to access was encrypted.

If you knew of ways to get past one of the defences, you would of course fix it. Somebody got in, which means they used a method that wasn't anticipated and couldn't have been fixed. Because of "security in depth", that breach didn't gain the attacker anything, but now Apple knows what they did and makes the necessary changes. It is quite possible that Apple's security developers have from time to time found possible attacks and quietly fixed them; you wouldn't notice it.

----------

Why didn't these hackers go after the NSA? They already have all Apple Dev Center data and lots more..
That's of course nonsense, and you know that. And if it was true, you wouldn't go after the NSA. You go after someone who can't lock you away for the rest of your sad life without a court case.


this shows that apple is no longer reliable and it may affect stocks greatly.
There goes the public trust...Apple....
Nonsense. There's security in depth in place. Someone got past one defense, was promptly detected, and other defenses stopped him. Exactly how it is supposed to work. Public trust is also based on how a company handles problems: Apple handled it by immediately shutting down the site, which is inconvenient, but the absolutely safe thing to do, and they promptly informed the affected people about what was going on. Others companies would have kept the site running, hoping that nothing else happens. That's the companies you can't trust.
Score: 9 Votes (Like | Disagree)

Popular Stories

maxresdefault

Review: M1 Max MacBook Pro After Three Months

Wednesday January 19, 2022 11:30 am PST by
It's now been a few months since the M1 Pro and M1 Max MacBook Pro models launched in October, and MacRumors video editor Dan Barbera has been using one of the new machines since they debuted. Over on the MacRumors YouTube channel, Dan has shared a three month review of his MacBook Pro to see how it has held up over time and how it's changed his workflow. Subscribe to the MacRumors YouTube ...
airpodsinear 1

AirPods Save Woman's Life With Feature Everyone Should Know

Friday January 21, 2022 2:13 am PST by
Apple's AirPods have been credited with saving a woman's life after a potentially fatal fall, People reports. When a 60-year-old florist in New Jersey tripped and hit her head in her studio, she lost consciousness and awoke heavily bleeding. With nobody around to call for help, she realized she had her AirPods in, and used a "Hey Siri" command to call 911. An operator was able to stay on the ...
iphone se 2020 top

New iPhone SE Likely to Launch in April Based on Production Timeframe

Wednesday January 19, 2022 6:44 am PST by
Apple suppliers will begin producing display panels for the third-generation iPhone SE this month, with final assembly of the device likely to start in March, according to information shared by display industry consultant Ross Young. Based on this production timeframe, Young believes the third-generation iPhone SE is likely to launch in the second half of April, or perhaps in early May at...
iphone 13 earpods

Apple to Stop Including EarPods With Every iPhone Sold in France From Next Week

Friday January 21, 2022 3:21 am PST by
Apple will no longer include EarPods with every iPhone sold in France, starting on January 24, according to a notice posted by a French carrier (via iGeneration). Apple was previously required to include EarPods in the box with the iPhone due to a French law that required every smartphone sold in the country to come with a "handsfree kit," but the law has now been changed in favor of reducing the ...
Spring 2022 Apple Products Feature

New iPad Air, Macs, and iPhone SE With 5G Likely to Be Announced at Apple Event This Spring

Thursday January 20, 2022 8:32 am PST by
Earlier this week, Bloomberg's Mark Gurman tweeted that Apple "will be holding a spring event" to announce a new iPhone SE and other hardware. In a recent edition of his newsletter, Gurman said the event is likely to occur in March or April. Gurman did not elaborate on what "other hardware" will be announced at Apple's purported spring event, but rumors suggest at least four products are...
appleeducation

Apple's US Education Store Now Requires Institution Verification to Buy Discounted Products

Wednesday January 19, 2022 2:22 am PST by
Apple is now requiring that customers in the United States verify that they're active students, teachers, or staff members at an educational institution in order to access education discounts on products. Previously, little verification was needed for customers to purchase products through Apple's education store in the United States. Apple's education stores offer models of the iPad and Mac ...
AirPods 3 New Firmware Feature

Apple Updates AirPods 3 Firmware to Version 4C170

Tuesday January 18, 2022 11:46 am PST by
Apple today released a new 4C170 firmware update for the AirPods 3, an update from the prior 4C165 that was made available in December. Apple does not offer details on what's included in new firmware updates for the AirPods‌, so we don't know what improvements or bug fixes the new firmware brings. There is no standard way to upgrade the ‌AirPods‌‌ software, but firmware is...
appleprivacyad cleaned

iOS 15 Patched Security Hole That Potentially Exposed Users' Private Apple ID Information to Third-Party Apps

Thursday January 20, 2022 3:32 am PST by
Apple patched two significant security vulnerabilities when it released iOS 15 that could have potentially exposed users' private Apple ID information and in-app search history to malicious third-party apps and allowed apps to override user Privacy preferences, Apple has revealed in a recent support document update. With most iOS, macOS, tvOS, and watchOS updates, Apple provides a list of...
apple watch series 7 aluminum colors yellowbg

Apple Watch Charging Bug Fixed in watchOS 8.4 Release Candidate

Thursday January 20, 2022 4:01 pm PST by
The watchOS 8.4 release candidate that was seeded to developers and beta testers this morning addresses an ongoing bug that could cause some Apple Watch chargers not to work properly with the Apple Watch. Back in December, we reported on a growing number of charging issues that Apple Watch Series 7 owners were facing. Since watchOS 8.3, there have been a number of complaints about...