Risk
3/11/2011
03:32 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%
Repost This

Apple Ends In-App Purchase Grace Period

To placate parents and lawmakers, password authorization is now required for every item purchased in an iOS app.

Apple and iOS developers love in-app purchase (IAP), the payment system that Apple makes available to developers inside apps. They love it because it allows apps to be offered for free without foregoing the possibility of revenue or forcing the developer to adopt an ad-based business model. They love it because it provides for the possibility of a recurring revenue stream and because it mitigates the impact of unauthorized copying.

With the current average price for games at $1.06, single-download sales are nowhere near as appealing as selling in-game items, level packs, and maps that may bring ten times that or more. Flurry, a mobile metrics and marketing company, estimated last year that in-app purchasing brings in $14.66 per user annually. And research firm Juniper predicts that in-app purchasing revenue will eclipse single-download revenue in 2013.

In-app purchasing works. The problem is that it works too well. Parents have been complaining about huge bills racked up by children who ostensibly didn't realize that buying virtual goods results in real charges.

In December, Paula Selis, senior counsel for the office of Rob McKenna, Attorney General for the State of Washington, took notice and sent a letter to Apple in which she explained the problems posed by the $99 barrels of Smurfberries available to players of Capcom's Smurfs' Village mobile game.

In the wake of reports published by The Washington Post and The Associated Press, Congressman Edward Markey (D-Mass.) asked the Federal Trade Commission to look into the issue. In response, the FTC said it would review industry practices.

Apple already had parental controls in place to disable in-app purchasing. But facing antitrust scrutiny over its recently introduced subscription purchase rules, Apple decided to add additional safeguards to prevent unauthorized in-app shopping sprees.

With the launch of iOS 4.3 this week, Apple has eliminated the grace period for in-app purchasing. Now, every purchase must be authorized by a password. Previously, once the user had made an in-app purchase, he or she could make subsequent purchases without authorization for 15 minutes.

Parents who had a problem with in-app purchasing may welcome the change, but for developers, the introduction of additional friction to the purchase process is likely to decrease revenue, even for goods that aren't cynically priced $99 barrels of Smurfberries.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-1421
Published: 2014-04-22
Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar before 1.2.5, 1.2.6, and other versions before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the Category Name field to category.php.

CVE-2013-2105
Published: 2014-04-22
The Show In Browser (show_in_browser) gem 0.0.3 for Ruby allows local users to inject arbitrary web script or HTML via a symlink attack on /tmp/browser.html.

CVE-2013-2187
Published: 2014-04-22
Cross-site scripting (XSS) vulnerability in Apache Archiva 1.2 through 1.2.2 and 1.3 before 1.3.8 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, related to the home page.

CVE-2013-4116
Published: 2014-04-22
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

CVE-2013-4472
Published: 2014-04-22
The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

Best of the Web