Archive for August 7, 2026

Friday, August 7, 2026

Dark Hours Rejected From the App Store

[Update: See the retraction below.]

Terry Godier:

On the web, if I build something that works within the standards, it works. Whether people use it is up to them. On iOS, there is another question entirely: whether Apple decides it should exist.

[…]

In the past couple of years I’ve built three apps that were rejected from the App Store on various grounds.

[…]

A while ago I tried to submit an iOS app for Dark Hours, my astronomy website for normal people. It was rejected on the grounds that it was astrology.

[…]

I see countless ChatGPT wrappers with nearly identical icons and eye-watering subscriptions. I see astronomy apps requesting permissions that have nothing to do with looking at the night sky. My kids download games that interrupt play every few minutes to advertise the developer’s other subscription apps, each with their own $20–50 yearly plans.

Via John Gruber (Mastodon, Hacker News):

But if you actually look at Godier’s Dark Hours, for even just a few seconds, it is instantly obvious that it pertains to the science of astronomy and has absolutely nothing — zero, zilch, nada — to do with astrology.

[…]

Godier proceeded through a series of escalations up to the App Review Board and the Review Board responded that they determined the original rejection was valid because, I shit you not, “We understand that the app includes a live tarot reading feature.” Which isn’t even about astrology. It’s straight out of Kafka.

[…]

This isn’t just contrary to the benefit of developers, like Godier. It’s obviously contrary to the benefit of Apple itself, which should not just accept an app like Dark Hours, but celebrate it as an exemplar of the platform.

Mistakes happen. But in a functioning system mistakes get corrected, and mistakes as obvious as this one get corrected almost instantly and include a quick apology for the conflation. The App Store is not a functioning system.

Previously:

Update (2026-08-10): John Gruber:

To the best of my recollection, this is the first post I’ve retracted in the 24 years I’ve been writing Daring Fireball. I hope it’s the last. I was misled, both overtly and through omissions[…]

[…]

The truth is, the app, as originally submitted by Godier to the App Store (under the name “Asterly”, not “Dark Hours”), was entirely dedicated to astrology, not astronomy, and did in fact include a “Tarot card of the day” feature amongst other occultist horseshit.

[…]

I wrongly took Godier at his word, both in his public blog post and in private iMessage correspondence yesterday, that the rejection wasn’t just merely debatable, but completely and rather preposterously ungrounded. Whether Godier ever submitted a build of “Asterly” to the App Store that contained no occult horseshit and only the hard-science astronomy features that were present in his “Dark Hours” website that was available for the last week, I don’t know. But I have no reason to believe that he did.

[…]

In an uncomfortable exchange between Beher and Godier on Bluesky, Beher pointed out that Godier’s Dark Hours had the same bug as Beher’s that routed people to “random fields in Mexico”. Earlier today, Godier took his web app down and redirected his darkhours.io domain to Beher’s darkhours.app.

I’m really unhappy about this, both for my role in spreading a false story and because I think it will hurt the cause of reforming App Review. I know there are many crazy rejections and have experienced some first-hand. This story was believable because of that well-known history and because Godier didn’t seem like a nobody trying to get attention—he was the developer of another highly regarded app. But now people are going to point to true developer stories and accuse them of being fakes, too.

Jeff Johnson:

Terry Godier has just published a so-called “Mea Culpa” blaming Claude for cloning an open source app and denying foreknowledge.

There’s no mention of or apology for how Godier deceived Gruber and the world about the astronomy/astrology App Store submission/rejection.

The blog post essentially confirms that this person cannot be trusted.

Update (2026-08-11): Colin Cornaby:

BOTH projects were generated using Claude. So you have two people - both generating the same app from the same training data - having a public throw down over who copied who.

[…]

The “original” developer does claim to know how to code - which wasn’t clear from my research. That still doesn’t necessarily mean the original app was the source of the training data. They both may be a result of the same training data.

Nick Lockwood:

Holy shit, so the “Claude plagiarised an app” story is actually “Claude produced the same app twice when prompted to do so by two separate developers” 😅

It’s not clear to me exactly how much each developer relied on Claude or which training data was used, but I wanted to note this angle of the story.

Update (2026-08-14): Rosyna Keller:

With all this talk of an astrology app being rejected by App Store review I’m reminded there’s still a flat Earth/astrology app on the App Store that actively leaks the location of all of its users.

macOS 26.6.1

Juli Clover (release notes, security, no enterprise, no developer, full installer, IPSW):

macOS Tahoe 26.6.1 fixes a vulnerability that could allow an attacker to authenticate to Screen Sharing without valid credentials.

See also: Adam Engst and Mr. Macintosh.

Previously:

Update (2026-08-14): Bill Toulas:

In an update to the initial advisory, the Dutch agency said it received a report indicating that the vulnerability is being exploited in the wild in attacks where port 5900 is exposed to the internet.

According to the NCSC, the attacker obtained root access to the system and deployed a Monero cryptocurrency miner.

Update (2026-08-20): Edovia (tweet, MacRumors):

The vulnerability, identified as CVE-2026-65400, could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. Reports now indicate that the vulnerability has been actively exploited on Macs where Screen Sharing was accessible from the Internet.

[…]

[We] strongly recommend that all Screens users install the latest macOS updates as soon as possible.

[…]

For users who want to further restrict access to Screen Sharing, Screens can connect to a Mac through an SSH tunnel instead of exposing the Screen Sharing service directly.

macOS 15.7.9 and 14.8.9

macOS 15.7.9 (security, full installer):

This update provides important security fixes and is recommended for all users.

macOS 14.8.9 (security, full installer):

This update provides important security fixes and is recommended for all users.

These seem to fix the same screen sharing bug as the macOS 26.6.1 update.

See also: Howard Oakley.

Previously: