Apple News+ hacked already
2 min. read
Published on
Read our disclosure page to find out how can you help MSPoweruser sustain the editorial team Read more
Two days ago Apple introduced Apple News+, an addition to their Apple News app which offered access to 300 magazines and subscription newspapers like the Wall Street Journal for $9.99 per month, something Apple said was worth $8000 per year.
It turns out Apple has not exactly protected that value very well. Well-known iPhone hacker Steve Troughton-Smith has already broken the rather flimsy security around the premium content.
https://twitter.com/stroughtonsmith/status/1110347954550964225
He found the service does not protect the content with DRM, and that the content is available for anyone to download as long as you know the right URL.
In addition, the app also offers up all the URLs neatly to all Apple News users in the manifest of the app, allowing anyone to download a full magazine for free.
https://twitter.com/stroughtonsmith/status/1110348992288878593
A likely reason for the flimsy security is that the Apple News desktop app is a port of the iPhone app, where the operating system was expected to provide much of the security. Even this, however, seems poor performance for a company Apple’s size, though of course, the feature is really just a minor upgrade from Texture app which Apple purchased and clearly integrated cheaply.
Apple will presumably fix the feature, but until then intrepid hackers will enjoy reading about Iran’s Intrepid Nomads for free.
User forum
0 messages