Forgot your password?
typodupeerror
Desktops (Apple)

The Mac App Flea Market 40

A search for "AI chat" in the Mac App Store returns dozens of applications sporting black-and-white icons nearly identical to ChatGPT's official logo. OpenAI's ChatGPT desktop application isn't available through the Mac App Store and can only be downloaded from the company's website. The copycat applications use various combinations of "AI," "Chat," and "Bot" in their names, including "AI Chat Bot : Ask Assistant," "AI Chatbot: Chat Ask Assistant," and dozens of similar variations. One application named itself "Al Chatbot" using a lowercase L instead of a capital I in "AI." Additional lookalike icons mimicking Claude, Grok, and Gemini applications also appear in search results.
This discussion has been archived. No new comments can be posted.

The Mac App Flea Market

Comments Filter:
  • by LodCrappo ( 705968 ) on Tuesday September 16, 2025 @10:43AM (#65663100)

    My IT team regularly has to help iPhone users install the Microsoft authenticator app for MFA as part of adding them to our email system. It is very difficult to walk someone through this over the phone as there are so many fake authenticator apps with very similar icons. They even work, they just charge a $10/month subscription for something the official MS app does for free.

    • Have you tried just sending them a link to the app in the store? I think this [apple.com] is the one you mean.
    • My IT team regularly has to help iPhone users install the Microsoft authenticator app for MFA as part of adding them to our email system. It is very difficult to walk someone through this over the phone as there are so many fake authenticator apps with very similar icons.

      I ask them to visit the app store, search for Microsoft Authenticator, then I ask them things like "how many ratings does it have?" It's very difficult to match the real Microsoft Authenticator app for the number of ratings.

      • yes this is the best technique we've found so far, but some users still rush to install a fake one or seem to struggle with basic reading comprehension.

        the point is that this problem shouldn't exist in the first place

    • My IT team regularly has to help iPhone users install the Microsoft authenticator app for MFA as part of adding them to our email system.

      Stop doing BYOD, preload apps on the phones issued to users, and you won't have this problem.

      No fucking way I'm allowing my employer access to my personal phone. Luckily mine is smart enough to issue phones.

      • we allow users to use their personal devices for MFA as a convenience, and we provide physical Yubikeys to users that prefer not to use their personal device for MFA. we do not provide phones or require anyone to use their own for anything. the vast majority of users opt to use their own device rather than carry the yubikey

      • Instead, you have the problem of having to pay for a few hundred phones.

        And you don't actually think that having an authenticator on your phone gives your employer access to it, do you?

        • And you don't actually think that having an authenticator on your phone gives your employer access to it, do you?

          If you're using your phone for something that winds up being the subject of an investigation, then your phone can be subpoena'd. Even if everything is on the up and up, and everything on your device is ducky, you can still be inconveniently deprived of your device for a time. Therefore you should never use your device for work in any way other than calling in to it, which doesn't leave any traces on your device that it doesn't also leave on the network.

          • in what legal way would a phone call be any different than an MFA challenge as far as impacting whether a phone could be subpoenaed? both involve another side with exhaustive logging. neither provide your employer with any access to your device. if you use your phone to place a call, you've exposed it just as much as using it to do MFA imho

          • I see the value in separate work and personal phones, what I don't see is any potential issue with having an authenticator installed.

            What if you already had one on your personal phone? Would you have an issue with adding a work account to your existing authenticator? What if it's pure TOTP? In that case there's no communication between your device and your job at all, let alone anything to subpoena.

      • it doesn't support "phish resistant" MFA with push notifications

      • The problem with the IOS (and Mac) MFA apps is they are strictly apple only affairs. In my own home, I've got an iPhone, a mac, a windows machine a linux machine and assorted black boxes (samsung tv, etc). I can get 1password running on all of them except the TV. The apple one only runs on the mac and iphone.

  • What do they connect to on the back end?
    No mention of that in TFS.
    Poor reporting...

    • Worth knowing, but I can see how it might be difficult for a reporter with a deadline to download each one and sniff its traffic.

      Besides, do we really need to guess, or can we just safely assume DeepSeek?

  • by russotto ( 537200 ) on Tuesday September 16, 2025 @11:12AM (#65663196) Journal

    "Chat" is generic. So is "AI". The logos are deceptive, but OpenAI has no claim on "chat", "chatbot"or "AI chatbot", and no one should expect that those terms mean "ChatGPT"

  • I've got one here. [nocookie.net]

  • Recently got a work email saying that the Apple app store is carrying a fraudulent version of our app which costs money including having a subscription fee while ours is free. I would assume the scam app also steals PII. Apple isn't responding to requests to remove it though it's clearly fraudulent (it's even using a version of the same name) which can only be because they get a cut of the fees.

    • Apple isn't responding to requests to remove it though it's clearly fraudulent (it's even using a version of the same name) which can only be because they get a cut of the fees.

      I can think of other possible explanations.

      - If they are unfamiliar with your application, it's not trivial for them to definitively determine that yours is the real one.
      - The app store is huge and they don't adequately staff the group responsible for investigating these sorts of claims.
      - Some combination of the above explanations (including yours).

      • Our app is used by many thousands of people, so I know it's not a lack of familiarity.

        Apple has more money than God, so if they are not staffing enough to handle reports of fraud pertaining to extremely highly used apps, there can be only one reason, and it is enjoying the profits related to allowing that fraud.

    • by davidwr ( 791652 )

      It won't be cheap for you, but you can file a trademark suit against the fake company then subpoena apple for the company's contact info and enough additional information that it costs Apple enough time and money to be annoying.

      When the other company doesn't respond to the suit, or if they are out of the country, get a default judgement and an injunction to force Apple to remove the fake listing, at least in the country you are filing suit in.

      If enough victims did this, Apple would find it very annoying fin

      • I think you've hit on the only real solution - filing an infringement suit. Apple is not capable of enforcing copyrights or trademarks, and they would be fools to try. The legal liability would be insane, and there are established legal avenues to resolve those issues. Is that ideal? I don't know.
  • by JustNiz ( 692889 ) on Tuesday September 16, 2025 @12:18PM (#65663400)

    So Apple store is actually no higher quality than Google Play store, so it turns out the whole "walled garden" thing is only for Apple's benefit and not their customers.
    Another Apple marketing lie busted then.

There's no future in time travel.

Working...