Skip the navigation
)
News

Apple approves fake iPhone app for App Store

Security experts can't tell whether bogus Camera+ was malicious

January 23, 2012 12:04 PM ET

Computerworld - Apple let a fake app slip through its approval process for the iOS App Store, the makers of the popular Camera+ program said over the weekend.

Security researchers who noted the slip-up did not know whether the bogus app contained malware because they had been unable to grab a copy before Apple yanked it from the App Store.

On Saturday, the iPhoneography blog announced that a new App Store entry was fake.

The App Store listing touted Camera+ version 4.0, and listed the price at $0.99.

Although the real Camera+ -- created by Tap Tap Tap -- is sold for the same price, it's only at version 2.4.

iPhoneography's Glyn Evans contacted Tap Tap Tap, who confirmed that Camera+ 4.0 was phony.

"Oh, Apple and your all too often disappointing approval process," said Tap Tap Tap on Twitter Saturday.

Tap Tap Tap has butted heads with Apple before: In 2010, Apple yanked Camera+ from the App Store in a dispute over a violation of Apple's developer agreements.

Apple later restored Camera+ to its app distribution channel.

U.K. security company Sophos noted the fake Camera+, but said it couldn't tell whether the app had a malicious purpose.

"We haven't been able to get our hands on a copy of the bogus app, so we cannot confirm if it contained any malicious functionality," said Graham Cluley, a Sophos senior security consultant, in a blog Monday. In a follow-up email, a Sophos spokeswoman said the company believed it was probably created to siphon money from Tap Tap Tap's sales.

The fake Camera+ used graphics identical to the real deal to promote the program on the App Store.

According to that entry -- which was still available Monday via Google's search cache -- the bogus Camera+ was released on Saturday, Jan. 21 by a Hiep Nguyen of a company called Pursuit Special.

Later that day, Apple pulled the illicit Camera+ from the App Store, Tap Tap Tap confirmed on Twitter.

Apple's gaffe was notable since most security experts consider the iPhone platform more secure from hacker misuse because Apple vets each app before allowing it into the App Store, unlike Google.

Google's Android Market has been plagued with bogus apps, many of which contain some kind of malicious functionality. Last month, for example, Google scrubbed 22 malware-infected apps from its official e-store.

Cluley wondered how Apple could have screwed up.

"But questions still remain as to what went wrong with Apple's approval process," Cluley said. "After all, Camera+ is currently the 14th best-selling app in the App Store -- Apple should surely recognize if someone other than Tap Tap Tap tries to submit it to the store."

As of mid-day Monday, Camera+ was actually No. 7 on Apple's bestseller list of paid iPhone apps.

Apple did not immediately reply to questions Monday.

Fake app
A fake Camera+ app slipped by Apple's approval process for the App Store.

covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at Twitter @gkeizer, on Google+ or subscribe to Gregg's RSS feed Keizer RSS. His e-mail address is gkeizer@computerworld.com.

See .

Read more about Mobile Apps and Services in Computerworld's Mobile Apps and Services Topic Center.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Mobile Apps and Services White Papers
Mobile Middleware Strategies
Learn why a mobile development platform is critical to be able to support today's complex enterprise mobility strategies. Learn what to look for...
The Evolution of Enterprise Mobile App Development
Driven by explosive growth in smartphone and tablet sales, enterprise mobility has become an essential part of business. Organizations across industries are developing...
Native & HTML5 Mobile Apps: Not an either or, but a where and when
Learn how developers are using HTML5 and native development methods to build mobile apps. Get practical insights on how these tools are being...
Bank Improves Crisis Management Communications with Help from BlackBerry Solution
With a staff of more than 60,000 people dispersed across the United States, U.S. Bank needed a robust and intuitive program that would...
Why Centralized Cloud Identity Management is Crucial for the Enterprise
Now that employees are leaving the relative safety of the firewall to use online SaaS applications, enterprises need to adjust the way they...
All Mobile Apps and Services White Papers
Mobile Apps and Services Webcasts
BlackBerry NFC Security Overview
The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
Apps that add business value
BlackBerry® has all that you need to leverage mobile applications for BlackBerry® smartphones and BlackBerry® PlayBook™ tablets. You will see some simple applications...
Distributed Database Security with Real-time Monitoring
View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
InfoSphere Warehouse Packs Demo
These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
Delivery Management -- Extending Lifecycle Management
Date: Wednesday, June 20, 2012, 1:00 PM EDT

Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
All Mobile Apps and Services Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs