@tapbot_paul thanks for the heads uppic.twitter.com/z7PRH6GsYL
When you tweet with a location, Twitter stores that location. You can switch location on/off before each Tweet and always have the option to delete your location history. Learn more
@tapbot_paul Wish the creation date field had been documented from the start, we could have avoided the whole thing. https://developer.apple.com/library/mac/releasenotes/General/ValidateAppStoreReceipt/Chapters/ReceiptFields.html#//apple_ref/doc/uid/TP40010573-CH106-DontLinkElementID_1 …
@mattstevens @tapbot_paul Does that apply to the Mac App Store? It's not mentioned in Apple's sample code.
@mjtsai @mattstevens two totally diff dates.
@tapbot_paul @mjtsai It’s like a code signing timestamp. If the signing certificate is trusted, you check if it was valid at signing time.
@mattstevens So if you don't check it, it won't falsely cause validation to fail?
@mjtsai You check the creation date (when the cert was used) against the certificate’s validity period, vs checking the current time.
@mjtsai So if the certificate is trusted and was valid at the time it was used you don’t care if it is expired.
@mattstevens Right. My question is, does Apple's sample code implicitly use the current date? (Guess: No. So this wouldn't be a problem.)
@tapbot_paul this is the leaf cert. Just got a new receipt with this cert but the middle cert expires Feb.14, 2016.pic.twitter.com/KrwAK3z1ML
@rbrockerhoff yeah I noticed that will be interesting to see what happens.
@tapbot_paul isn’t SHA1 on the edge of being deprecated in crypto?
@DrewFitz yeah, but really for these receipts not a big deal for the most part.
@tapbot_paul This is great news. Didn’t want to put my “removed from sale” app back on the store just to release a receipt validation update
@fafner well I hope it fixes the problem we’re having, no idea though, won’t know for a while.
@tapbot_paul what version of OSX produced this receipt? New receipts on 10.8.5 are signed with a cert that expires 2017.10.24
@tapbot_paul "Siri, set a reminder for February 6, 2023."
@tapbot_paul isn't SHA1 considered insecure along with MD5?
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.