03:32 PM
Connect Directly
Repost This

Apple Ends In-App Purchase Grace Period

To placate parents and lawmakers, password authorization is now required for every item purchased in an iOS app.

Apple and iOS developers love in-app purchase (IAP), the payment system that Apple makes available to developers inside apps. They love it because it allows apps to be offered for free without foregoing the possibility of revenue or forcing the developer to adopt an ad-based business model. They love it because it provides for the possibility of a recurring revenue stream and because it mitigates the impact of unauthorized copying.

With the current average price for games at $1.06, single-download sales are nowhere near as appealing as selling in-game items, level packs, and maps that may bring ten times that or more. Flurry, a mobile metrics and marketing company, estimated last year that in-app purchasing brings in $14.66 per user annually. And research firm Juniper predicts that in-app purchasing revenue will eclipse single-download revenue in 2013.

In-app purchasing works. The problem is that it works too well. Parents have been complaining about huge bills racked up by children who ostensibly didn't realize that buying virtual goods results in real charges.

In December, Paula Selis, senior counsel for the office of Rob McKenna, Attorney General for the State of Washington, took notice and sent a letter to Apple in which she explained the problems posed by the $99 barrels of Smurfberries available to players of Capcom's Smurfs' Village mobile game.

In the wake of reports published by The Washington Post and The Associated Press, Congressman Edward Markey (D-Mass.) asked the Federal Trade Commission to look into the issue. In response, the FTC said it would review industry practices.

Apple already had parental controls in place to disable in-app purchasing. But facing antitrust scrutiny over its recently introduced subscription purchase rules, Apple decided to add additional safeguards to prevent unauthorized in-app shopping sprees.

With the launch of iOS 4.3 this week, Apple has eliminated the grace period for in-app purchasing. Now, every purchase must be authorized by a password. Previously, once the user had made an in-app purchase, he or she could make subsequent purchases without authorization for 15 minutes.

Parents who had a problem with in-app purchasing may welcome the change, but for developers, the introduction of additional friction to the purchase process is likely to decrease revenue, even for goods that aren't cynically priced $99 barrels of Smurfberries.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Latest Comment: LOL.
Current Issue
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2014-04-17
DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:, 1:0.134.x before 1:, 1:0.142.x before 1:, 1:0.150.x before 1:, and 1:0.152.x before 1: does not properly create temporary files, which allows local users to obtain the XAUTHORITY file conte...

Published: 2014-04-17
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to gain privileges by setting a user account to an administrator account.

Published: 2014-04-17
The rbovirt gem before 0.0.24 for Ruby uses the rest-client gem with SSL verification disabled, which allows remote attackers to conduct man-in-the-middle attacks via unspecified vectors.

Published: 2014-04-17
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External ...

Published: 2014-04-17
PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.

Best of the Web