Show HN: The Provisionator – Apple push notification certificate wizard(gamethrive.com)
gamethrive.com
Show HN: The Provisionator – Apple push notification certificate wizard
https://gamethrive.com/provisionator
3 comments
Hi mbesto, author of this tool here. I definitely understand your concern. I would encourage people to change their password before/after using the tool if they want to play it safe -- but you do have my word that we don't store the credentials at all (not in our logs either).
Initially I started working on this to be used just by our customers. After chatting with other iOS devs, we saw that messing up Push Certificates was such a common problem that we decided to make it open to everyone.
Initially I started working on this to be used just by our customers. After chatting with other iOS devs, we saw that messing up Push Certificates was such a common problem that we decided to make it open to everyone.
As everyone else is probably just going to be irritatingly negative (just snipping at you for doing it or accusing you of being malicious), I am instead going to try to be a little positive and point out what I bet is the different variable: your customers already are putting a lot of other trust in you, so what will work for your customers doesn't always work for the public at large. I appreciate the idea, and I see how it happened that you released it, and I even think I could see the value myself in using it, and yet even if I don't think you are a scam (and I really don't think you are: there are so many better ways of phishing than this), trusting your software to not have some information disclosure flaw or to not be compromised is different entirely.
I have no doubt as a fellow HN'r that your intentions are anything but ill-willed. I appreciate that you're genuinely trying to solve a problem that is recurring for many people, but this is definitely not the way to do it.
There are so many things that could go wrong here that I don't know where to start. For your own sake, shut this functionality down.
There are so many things that could go wrong here that I don't know where to start. For your own sake, shut this functionality down.
Hey,
I know you are genuinely trying to solve a problem.. But look at the comments: Three comments with the exact same reaction.
Only Hodor would get to Step 2.
Something similar to OAuth 2.0 would be better.
I know you are genuinely trying to solve a problem.. But look at the comments: Three comments with the exact same reaction.
Only Hodor would get to Step 2.
Something similar to OAuth 2.0 would be better.
Thanks Jugurtha. If Apple supported OAuth login (or anything else really) we'd definitely use it.
As things are, there's not really much that can be done unfortunately. We do plan to open source this in the near future however, which should make us seem a bit more trustworthy at least.
For now I added a note encouraging people to change their password after using the tool.
Ultimately the solution is probably for Apple to improve the process of creating certificates. Right now almost all instructions on how to do so require you to use Keychain Access (So you must be on a Mac), followed by typing commands into openssl on the command line. There's a lot of room for error and StackOverflow is filled with people running into problems during the process, so hopefully this tool saves some people time.
As things are, there's not really much that can be done unfortunately. We do plan to open source this in the near future however, which should make us seem a bit more trustworthy at least.
For now I added a note encouraging people to change their password after using the tool.
Ultimately the solution is probably for Apple to improve the process of creating certificates. Right now almost all instructions on how to do so require you to use Keychain Access (So you must be on a Mac), followed by typing commands into openssl on the command line. There's a lot of room for error and StackOverflow is filled with people running into problems during the process, so hopefully this tool saves some people time.
"Step 1: Enter your Apple credentials.."
Chuckles, closes tab, returns to Thunderbird to get HN link and write this.
Chuckles, closes tab, returns to Thunderbird to get HN link and write this.
> Step 1: Enter your Apple credentials
Oh my gosh, please nobody use this.
Oh my gosh, please nobody use this.
Yaaaaa.....no. This is extremely dangerous and without knowing anything about your source code, there is no way in hell I'm putting my credentials in there. In fact, this is borderline phishing.