Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

checkReceipt is insecure and vulnerable to middleman hack #37

Open
skensell opened this issue Oct 13, 2016 · 0 comments
Open

checkReceipt is insecure and vulnerable to middleman hack #37

skensell opened this issue Oct 13, 2016 · 0 comments

Comments

@skensell
Copy link

I've just been browsing this repo to see if it's usable, but I'm pretty sure I spotted a vulnerability:

The checkReceipt: method is using the logic from this Apple guide which states that this logic is meant for communication between your app's server and Apple's servers. You should not use this logic for communication between a user's device and Apple's servers, because as the docs state:

It is not possible to build a trusted connection between a user’s device and the App Store directly because you don’t control either end of that connection.

saturngod added a commit that referenced this issue Oct 24, 2016
…. It shouldn't use and use with your own risk
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant