Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I think I remember reading that if you're using Apple's APIs and frameworks (like their builtins for HTTPS) then you don't need to go through this rigmarole.


From the screen shot of Apple's app submission: "Select yes even if your app is only utilizing the encryption available in iOS or OSX."


In that case, simply saving a file would also count as encryption now, since iOS devices are encrypted...


I've always interpreted "(ii) your app uses, accesses, implements or incorporates encryption for authentication only" as our uses cases for using HTTPS and thus said that I am exempt.


Unless you are using HTTPS with NULL encryption algorithm, your bytes are encrypted and decrypted, so it's not "authentication only". I think that you can use NULL encryption algorithm and in this case only authentication will be performed. But I'm not sure that standard library will allow to use this algorithm.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: