Skip to content

Comment on Puff Puff… Pass

Comments

I'm not too impressed with the blog's author either. He documents breaking into another website in a previous blog post: http://faptrackr.org/blog/?p=45

That website hosted pirated copies of iOS apps, so it's not as bad as it seems.

It seems OP is in similar business.

https://github.com/KJCracks/Clutch

Piracy is not the only reason why you would decrypt an app.

Exactly. A lot of people don't know that you can easily crack a .ipa binary and see things like method names and string constants with about 5 minutes of work. You can do the same with Android .apk files. Seriously, if you're doing security intensive software, try to crack your own binary and see what information you can get. You'll probably see way more than you thought you would.

As did a site the author was running, by my read. Responsible disclosure is one thing, but I won't support defacing of websites.

Don't throw the baby out with the bathwater, as they say.

Agreed, but it makes me wonder if we can trust the author's description of his disclosure efforts. Not that that gives a free pass to the app developer(s), of course.

You're right, it is silly, it was a dumb thing to do - but most_unique was actively commiting credit card fraud of innocent people to run his site and wasn't going to stop anytime soon.

It was the content of the article, and not the title of the blog that left the bad impression?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.