Apple Now Including Unique Identifiers for In App Purchase Receipts to Combat Hack
Following last week's launch of a hack that allowed users to obtain In App Purchase content free of charge by routing their purchase requests through a server run by a Russian hacker, Apple began taking steps to thwart the method.
Context & Ripple Effects
Five days after 9to5Mac reported that a Russian hacker's proxy server was letting users unlock paid In App Purchase content without paying, Apple has shipped its first countermeasure: purchase receipts now carry unique identifiers, so App Store servers can distinguish genuine transactions from replayed ones. The pickup across eight outlets — The Verge, VentureBeat, TUAW, The Next Web and others — reflects how directly the exploit threatened developer revenue.
The fix lands in an awkward spot: back in March, TechCrunch reported Apple had begun rejecting apps that access UDIDs over privacy concerns, yet the company is now itself embedding device-level identifiers into its commerce plumbing. The move also extends a lineage dating to Apple's earliest identity-based digital rights management in iTunes — enforcement tied to who is buying, not what file they hold.
First-order effects
- Developers selling In App Purchase content get an immediate lever: receipt validation can now reject the forged or replayed requests the hack depended on, closing the free-content loophole at the transaction level rather than waiting on an OS update.
Second-order effects
- The identifier-in-receipts approach puts Apple's own privacy posture under scrutiny — developers already burned by the UDID crackdown must reconcile Apple's anti-tracking stance with Apple's new tracking-bearing receipts, and the hacker's incentive to probe the next weak point in the receipt chain only sharpens.
Third-order effects
- If the pattern holds, mobile app commerce keeps migrating from file-level copy protection toward per-transaction cryptographic verification anchored in device identity — pushing every app store operator toward heavier server-side validation and reigniting the question of where fraud prevention ends and user tracking begins.
The trend: Mobile app stores are shifting from static DRM to identity-anchored receipt verification, with each public exploit forcing Apple to tighten server-side trust checks faster than OS release cycles allow.