<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: &#8220;Find and Call&#8221; Trojan</title>
	<atom:link href="http://mjtsai.com/blog/2012/07/05/find-and-call-trojan/feed/" rel="self" type="application/rss+xml" />
	<link>http://mjtsai.com/blog/2012/07/05/find-and-call-trojan/</link>
	<description></description>
	<lastBuildDate>Mon, 20 May 2013 21:41:48 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Michael Tsai</title>
		<link>http://mjtsai.com/blog/2012/07/05/find-and-call-trojan/comment-page-1/#comment-672520</link>
		<dc:creator>Michael Tsai</dc:creator>
		<pubDate>Sun, 29 Jul 2012 22:32:26 +0000</pubDate>
		<guid isPermaLink="false">http://mjtsai.com/blog/?p=5243#comment-672520</guid>
		<description>@Ölbaum I get the impression that it’s the older folks who complain more about the review process. I remember compiling software for the original Palm device—when it was called the Pilot. I’m actually not sure that the rules are the same for everyone.</description>
		<content:encoded><![CDATA[<p>@Ölbaum I get the impression that it’s the older folks who complain more about the review process. I remember compiling software for the original Palm device—when it was called the Pilot. I’m actually not sure that the rules are the same for everyone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ölbaum</title>
		<link>http://mjtsai.com/blog/2012/07/05/find-and-call-trojan/comment-page-1/#comment-672519</link>
		<dc:creator>Ölbaum</dc:creator>
		<pubDate>Sun, 29 Jul 2012 22:19:50 +0000</pubDate>
		<guid isPermaLink="false">http://mjtsai.com/blog/?p=5243#comment-672519</guid>
		<description>I think if the small yet very vocal portion of developers who do nothing but complain about the review process were old enough to have owned a Palm OS device, we would hear a different tune. Stop complaining, the rules are the same for everyone. Or continue to complain but start acknowledging every time you install an app and it doesn&#039;t break your phone.</description>
		<content:encoded><![CDATA[<p>I think if the small yet very vocal portion of developers who do nothing but complain about the review process were old enough to have owned a Palm OS device, we would hear a different tune. Stop complaining, the rules are the same for everyone. Or continue to complain but start acknowledging every time you install an app and it doesn't break your phone.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Tsai</title>
		<link>http://mjtsai.com/blog/2012/07/05/find-and-call-trojan/comment-page-1/#comment-667517</link>
		<dc:creator>Michael Tsai</dc:creator>
		<pubDate>Fri, 06 Jul 2012 14:18:15 +0000</pubDate>
		<guid isPermaLink="false">http://mjtsai.com/blog/?p=5243#comment-667517</guid>
		<description>@bob Their internal tools got confused, and they kept rejecting my app because they thought it used Java!</description>
		<content:encoded><![CDATA[<p>@bob Their internal tools got confused, and they kept rejecting my app because they thought it used Java!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jesper</title>
		<link>http://mjtsai.com/blog/2012/07/05/find-and-call-trojan/comment-page-1/#comment-667478</link>
		<dc:creator>Jesper</dc:creator>
		<pubDate>Fri, 06 Jul 2012 09:55:08 +0000</pubDate>
		<guid isPermaLink="false">http://mjtsai.com/blog/?p=5243#comment-667478</guid>
		<description>This is one quadrant. Here are the others:

2. Some people are making money on apps that do nothing but, say, enable Emoji keyboards. They pretend that they &quot;install SMS smileys!&quot; and Apple let their lies stand.
3. Some people are making awful, buggy apps.
4. Some people can&#039;t be making useful apps because they don&#039;t rub Apple the right way. They can&#039;t include useful features and they have to go through Apple to make money.

It&#039;s as hard as ever to justify the policy with anything else than &quot;Apple just wants to control this, okay?&quot;. What little protection you get from extra review obviously doesn&#039;t weigh up other downsides or maintain quality.</description>
		<content:encoded><![CDATA[<p>This is one quadrant. Here are the others:</p>
<p>2. Some people are making money on apps that do nothing but, say, enable Emoji keyboards. They pretend that they "install SMS smileys!" and Apple let their lies stand.<br />
3. Some people are making awful, buggy apps.<br />
4. Some people can't be making useful apps because they don't rub Apple the right way. They can't include useful features and they have to go through Apple to make money.</p>
<p>It's as hard as ever to justify the policy with anything else than "Apple just wants to control this, okay?". What little protection you get from extra review obviously doesn't weigh up other downsides or maintain quality.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: bob</title>
		<link>http://mjtsai.com/blog/2012/07/05/find-and-call-trojan/comment-page-1/#comment-667462</link>
		<dc:creator>bob</dc:creator>
		<pubDate>Fri, 06 Jul 2012 07:33:15 +0000</pubDate>
		<guid isPermaLink="false">http://mjtsai.com/blog/?p=5243#comment-667462</guid>
		<description>&quot;even then it&#039;s hard to review the code since developers don&#039;t share the source with Apple.&quot;

Well, sharing the source code with Apple is probably the next step.

Anyway, the real problem is that the review team is not technically qualified to review what an application is doing.

And, when they use Apple&#039;s internal tools to check what an application is doing during its execution, they do not understand what these tools report. Trying to explain to them, politely, that they are plain wrong is a dead-end. Because, you know, they know better than you what your application does.</description>
		<content:encoded><![CDATA[<p>"even then it's hard to review the code since developers don't share the source with Apple."</p>
<p>Well, sharing the source code with Apple is probably the next step.</p>
<p>Anyway, the real problem is that the review team is not technically qualified to review what an application is doing.</p>
<p>And, when they use Apple's internal tools to check what an application is doing during its execution, they do not understand what these tools report. Trying to explain to them, politely, that they are plain wrong is a dead-end. Because, you know, they know better than you what your application does.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michael Tsai</title>
		<link>http://mjtsai.com/blog/2012/07/05/find-and-call-trojan/comment-page-1/#comment-667429</link>
		<dc:creator>Michael Tsai</dc:creator>
		<pubDate>Fri, 06 Jul 2012 03:34:57 +0000</pubDate>
		<guid isPermaLink="false">http://mjtsai.com/blog/?p=5243#comment-667429</guid>
		<description>@Michel Exactly. That’s why some of us have been critical of the review process all along. I read about apps and updates submitted more than a month ago, important bug fixes delayed for weeks—and for what? It’s not possible for Apple to protect users.</description>
		<content:encoded><![CDATA[<p>@Michel Exactly. That’s why some of us have been critical of the review process all along. I read about apps and updates submitted more than a month ago, important bug fixes delayed for weeks—and for what? It’s not possible for Apple to protect users.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Michel Fortin</title>
		<link>http://mjtsai.com/blog/2012/07/05/find-and-call-trojan/comment-page-1/#comment-667428</link>
		<dc:creator>Michel Fortin</dc:creator>
		<pubDate>Fri, 06 Jul 2012 03:30:23 +0000</pubDate>
		<guid isPermaLink="false">http://mjtsai.com/blog/?p=5243#comment-667428</guid>
		<description>There&#039;s no way the review process will protect against malicious intent. For all we know, sending the contact list might be trigged by a flag from the developer&#039;s server, and that flag could be off until the app is effectively in the store. The reviewer would never have a chance to catch what was going on.

I&#039;m not saying this is how this app passed. But if it was, Apple certainly couldn&#039;t catch it short of doing an extensive code review, but even then it&#039;s hard to review the code since developers don&#039;t share the source with Apple.</description>
		<content:encoded><![CDATA[<p>There's no way the review process will protect against malicious intent. For all we know, sending the contact list might be trigged by a flag from the developer's server, and that flag could be off until the app is effectively in the store. The reviewer would never have a chance to catch what was going on.</p>
<p>I'm not saying this is how this app passed. But if it was, Apple certainly couldn't catch it short of doing an extensive code review, but even then it's hard to review the code since developers don't share the source with Apple.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
