Tor Project: Fake Tor App Has Been In Apple's App Store For Months 78
itwbennett (1594911) writes "For the past several months Tor developers have unsuccessfully been trying to convince Apple to remove from its iOS App Store what they believe to be a fake and potentially malicious Tor Browser application. According to subsequent messages on the bug tracker, a complaint was filed with Apple on Dec. 26 with Apple reportedly responding on Jan. 3 saying it would give a chance to the app's developer to defend it. More than two months later, the Tor Browser app created by a developer named Ronen is available still in the App Store. The issue came into the public spotlight Wednesday when people involved in the Tor Project took to Twitter to make their concerns heard. Apple did not respond to IDG News Service's request for comment."
Re: I don't see a problem.. (Score:0, Interesting)
I've been using a tor app In the app store and it works is it the same one, what's this one called. If it is I agree I don't see a problem.
Typical Apple idiocy (Score:5, Interesting)
Not fake... (Score:2, Interesting)
as much as "not an official release".
When you are working with something like the TOR network and you want to stay as secure and (hopefully) as safe as possible, you want everything to be officially released. If the browser bundle in the store is not official, you don't know *exactly* what is in it or if they added anything to it. That alone is scary. Especially if you know & trust the TOR project and expect the same from the app as you get from their other browser bundles.
"Fake" is definitely the wrong way to describe it ( if it actually does use TOR ), but it definitely makes a bigger impression than "unofficial".
Re:Would have liked to see more information (Score:1, Interesting)
If the app sends back a message to it's developer showing what you looked at then that is a serious security breach.
That's a reason not to trust the app for the intended use, but not a good reason to pull the app from the store. Apple's job is not to make sure that the app operates 100% as described, but that it falls within the guidelines for being on the store and lives up to the app description. The app says it "helps" you with security but that's as far as it goes, and would be true for anyone monitoring just the HTTP URL's accessed by the app (if it's really using TOR).
The thing is we have no-one saying it is in fact reporting back anything to anyone - all I can find is complaints ads make use of location! Location which the app user has to approve the app getting access to.
If you are a Russian citizen using this app because of a real need for anonymity, you would not approve it accessing location...
Re: I don't see a problem.. (Score:1, Interesting)
I've been using a tor app In the app store
If you're trying to use TOR on Apple or Microsoft OSs, you're doing it wrong.