i feel that if this was done, it was done 'over the wire', more or less on the fly, and not by wholesale appstore replacement but by mitm of internet traffic streams looking for xcode binary material and replacing it, or portions of it, transparently.
wow, i bet some of the other prolific 'security researchers' are pissed they arent mentioned. On the other hand, those mentioned are probably rethinking their disclosure and OPSEC practices, and its interesting that at least one of the names on the list isnt even legitimately a researcher. This article, if true, I feel represents a by-product of the collusion between spooks and hackers at conferences, gladhanding, coin-swapping, etc. As a former fighter, I learned that out of battle its respectful etiquette to befriend an opponent, or someone once seen as an adversary. But now I think weve seen that sometimes its better to avoid the neutral ground altogether. I now feel dirty that I originally applauded when gen alexander swapped coins with Dave Kennedy (who is a great human being). I was sucking up to the new order, and I can come clean and admit it.
the engine also used OCR to parse timestamps within the rendered trustmark image, and log when the image was past a certain amount of days. it was also possible to generate spoofed trustmarks using the same method and we did that too.
Myself and Shane MacDougall spoke of trustmarks at both BSidesLV and Toorcon several years ago, introducing a tool against some industry backlash, Oizys, to troll through all the trustmark placeholders we could find, logging when detecting a change in the trustmark during subsequent runs. Typically there were several reasons why a trustmark would change: the site was no longer secure from the perspective of the vendor scan tool (modified nessus?), or maybe the vendor was no longer under contract (the bill hasnt been paid to the vendor). The easiest thing to look for was a transparent gif where previously there was a non-transparent one. This can also be done with your favorite search engine, with some thought, but i am glad to see this getting some additional attention.