Apple Responds to Dash Controversy
loopinsight.com
loopinsight.com
A much more accurate headline might be "Apple responds to Dash controversy by insisting they were right all along and refusing to provide proof."
Edit: The tone of the entire article rubs me the wrong way; it reads like a press release that nobody could be bothered to re-write.
> The integrity of the App Store is as important to Apple as it is to consumers.
Citation needed? Plus it immediately follows an unsubstantiated claim that Apple has been ignoring evidence of review manipulation for two years, so even if we take the article at face value...that doesn't sound like they think it's important?
> This is part of the reason we trust Apple and the App Store.
That's the most circular argument. "We trust Apple because they claim they're trustworthy!"
So I am not surprised they gave a lot of leeway to the developer.
Edit: Compare the tone of the Loop article to Daring Fireballs:
http://daringfireball.net/2016/10/apple_dash_controversy
Gruber takes a much more unbiased approach, supported well. The Loop article reads like a statement from the Principal read by your teacher.
I have little reason to doubt that Dash really posted lots of fake reviews. It's not like Apple goes and accuses people of that all the time...
So what if he does? I believe it. That doesn't mean that Apple has provided any actual proof, and only a blinkered shill would claim they had.
https://blog.kapeli.com/dash-and-apple-my-side-of-the-story
!!! it includes a recording of a phone call with Apple !!!
Edit: After listening to the first 2 minutes of the call, i can say with absolute confidence that Apple is straight-up blackmailing him. I would love to hear opinions on whether this is something that could be taken to court.
Here's the HN submission of the link: https://news.ycombinator.com/item?id=12680597
Which after reading the post and listening to the recording on why Apple hit the account it seems fair after all this has gone public. (Kapeli set up an account for a relative using his CC, gave them some of his old hardware and it's that account that was caught in the review fraud. So in Apples system the two accounts were linked so when they nuked one account, the other went along with it.)
A Blog posting from Kapeli explaining the cause of the account ban and that he has worked with Apple to unlink the two accounts and resolve the situation.
> What Apple has done: on Friday they told me they’d reactivate my account if I’d make a blog post admitting some wrongdoing.
I didn't get from the call that he would have to admit and wrong doing, just explain what had happened and he got hit in the crossfire. Heck if I was in his boat I would end the blog post with "I would like to thank Apple and Phil for working with me to get this sorted and thanks to the community at large for helping to get this resolved." Not that they asked for a thank you but because I can see it from Apple's POV from Kapeli's recent Blog post.
> What Apple has done: on Friday they told me they’d reactivate my account if I’d make a blog post admitting some wrongdoing.
The "if" is the problem here. Had Apple said "we'll reinstate your account AND please make a blog post stating xyz" everything would be fine. Making it conditional on the post despite being their mistake is just reprehensible.
If Apple didn't want to avoid the bad PR, they could just terminate their business relationship permanently, and they'd be in the right, even morally, since it was Kapeli who violated the trust.
"You can choose from the payment methods presented during your membership purchase. If you are paying by credit card and enrolling as an individual, you must use your own credit card to complete your purchase. If you do not, your enrollment will be delayed and you will be asked for a copy of your government-issued photo identification."
Again, it's unclear under whose name the account really was registered, but if he went through the trouble of sending in photo ID, Kapeli would probably mention that as to further exonerate him of any mistakes.
He has registered an account using his credentials, the account was involved in fraudulent activity, that makes him responsible, as an individual. Why is Apple supposed to even care that he doesn't control the other account anymore? He's supposed to control the account, according to the terms of service he agreed to. If he doesn't control it and he doesn't want to be responsible, he has to close it.
Apple is giving him the opportunity to get back to having a business relationship, but he doesn't understand the problem. Apparently, neither do many of the other users on here. Apple has every right to terminate their business relationship,so how is it blackmail? It's more like a plea bargain...
That's why I'm suspicious as to which name he actually entered.
At least this was the case with the cards issued for authorized users I added to my Citi Double credit card account.
So you could have a single card number with multiple valid names/users.
In this case, it seems the two accounts used different names otherwise they would mentioned it already because it's huge evidence that the accounts are linked.
For example, Mithaldu, if an anonymous outsourcing party rendered you a service, than rather than wire them money or pay via paypal, would you be okay with paying for an apple account with them, with no further relationship, and you don't even know who they are? Probably not.
I think we can all agree that yes, he "should have" thought about this implication of trust.
[edit: given the down votes, I guess the HN crowd has rich friends or doesn't do mentoring. Sometimes the people you sponsor don't get it right]
A developer account + some old test devices sounds like a great birthday or christmas present!
It was a relative, so I don't get your question's relevance to the situation.
You might want to read the rest, the relative was boosting their own apps. Dash was not part of scenario just affected by the end result.
Kapeli is in Romania where credit card ownership is less common, and the "legal entity link" we're talking about is just a nominal $99/fee and some older devices. Moreover, Apple is admitting they they see them as distinct accounts, only notified one of them, and completely ignored the fact that Kapeli's side of the linked accounts had high credibility.
It sounds like Apple is desperately trying to justify the not-very-smart algorithm of an automated "booter" program rather than giving Kapeli the respect and due diligence that he deserves as a top developer.
This was made abundantly clear when I signed up.
Sorry, not buying it.
This does not completely absolve Kapeli, but the bigger problem here is that Kapeli is (was) a top developer on Apple's platform and had oodles of credibility. He deserved a better investigation than Apple gave him, and to at least have his own ("linked") account notified of the problem before getting banned.
[1] http://ec.europa.eu/public_opinion/archives/ebs/ebs_373_en.p...
If I bring my cousin with me to a party at a friend's house and he trashes the place and gets into fights, you can sure bet I'm going to be apologizing like heck to the host, cleaning the place up, and trying to make things right. Would all people do that? Maybe not ... but don't go complaining that the host never invited you back if you didn't.
A better analogy would be: You loaned your underage friend your ID 4 years ago and forgot about it. They proceeded to behave badly at a bar over a period of years without your knowledge. Then the bar owner confuses your identity based solely on that ID, despite your picture looking nothing like them and you being a well known and respected regular, and bans you without notice. Then they admit it wasn't you that trashed the place, but won't let you in until you state that the bar made no mistake in confusing you for that person.
Where are you getting that? In his blog posts, he only mentioned the common thing between the accounts were his credit card and old test devices he handed off - how do those qualify as "his credentials"? He explicitly mentioned he wasn't aware that his account and his alleged relatives account were linked until after his account was blocked.
You are right - he doesn't understand the problem - and neither do I. With the information that I have so far, it seems that Apple has set the bar for guilt too low, and the whole process is extremely opaque.
In short, Kapeli helped a relative open an account years ago but has otherwise been unassociated with that account. He technically shouldn't have used his credit card to help his relative, but this is Romania and it's just a nominal $99 fee, so he probably didn't think much of it. Apple's stance is they now look at them as "linked" accounts due to the use of his credit card and old devices, so they were justified in shutting down his account for fraudulent activity on the other one.
Problem is Apple never contacted Kapeli's account before shutting both of them down. They didn't do any extra due diligence for a top developer. Their notices only went to the other account, apparently, and Kapeli never had a chance to see them. He just woke up one day and his account was banned.
Now, that's just dumb. If the accounts are linked, why not notify both accounts?
Kapeli's an extremely well-respected app and has oodles of credibility. That alone should have triggered a deeper investigation before shutting him down. That fact that they know what happened here and still refuse to reinstate the account is shameful.
That's what Kapeli claims. How exactly do you know that the above is true? As opposed to, you know, himself creating two accounts.
I have no idea if Popescu was really involved in the fraudulent activity or not. But dismissing it as too dumb to be possible is no better than dismissing the possibility of Apple making a detection mistake as too dumb to be possible.
This claim is untrue. Per Popescu's blog, he didn't know using the same bank/CC info would link the accounts. So no, he likely wouldn't have used a different card. So the implication that because he didn't use a different card, he therefore wasn't trying to commit fraud is invalid.
The reference to Apple being dumb was merely for comparison.
It's clearly not obvious to Popescu per his own statement on the matter. Asserting repeatedly that it's obvious doesn't make it so.
> Ergo, by "linking" what he is referring to is being personally responsible for the behavior of the other person
This is a distinction without a difference. "Linking" the accounts is pointless unless it creates a meaningful relationship between them. The only reason to link accounts is to establish that they be somehow treated as a unit.
Your evidence is his statement, which refers to a more specific technical use of the term "linking", namely responsibility for fraud as a combined "legal entity", the phrase that is used in the cited phone call. I will let the downvotes on your comment speak for themselves here.
Your appeal to downvotes as some form of proof that your interpretation is correct is also absurd, partly because downvotes don't mean that much in general, but mostly because I have exactly one in total. So as with the rest of the thread your self-satisfaction seems rather unjustified.
I was not aware my account was linked to another until Apple contacted me Friday, 2 days after closing my account. I was never notified of any kind of wrongdoing before my account was terminated.
In cases where Apple is this certain (or seemingly certain) they usually have a smoking gun. That is, they have some kind of heuristic or action/event that is unquestionably tied to the developer. Perhaps a bunch of the positive reviews came from installs that used a developer freebie code, something only the developer could give out.
Also, smoking guns, when you're dealing with fraud and systems that people can manipulate, are the kind of thing you don't share with others.
I expect that Apple has seen _a lot_ of competitors trying to screw over other apps, and they would have exhausted that possibility before banning a popular app.
My knee jerk reaction to this article, is that if I were nefarious and I wanted to get a competitor off the appstore, than I would game the review system on their behalf. I didn't look at it too closely, but I think part of it they said was also creating negative reviews for competitors.
Like you said, it depends on the smoking gun or the strength of evidence, but without knowing what criteria Apple uses I think it's difficult to say how prudent they might be.
I of course have no indication that another party is involved in this case, I just imagine that it could, along with any number of other scenarios. Without knowing what evidence or criteria apple uses to make this determination, it's impossible to say as an external observer.
It's likely better to take no action than to take action, so when you take action, it is only when there is a very strong positive signal.
Again, I'm making assumptions because this is how the work I did went. There are a lot of things that can be done before dropping an app from the store entirely, and Apple is incentivized to keep the apps in the store – they get paid when people buy them, so removing them is a last straw.
"Because we see them as the same entity. If we have accounts that are enrolled in our programme using the same credit card, they are the SAME legal entity. They ARE the same..."
Yikes, because I often put contractor developer subscriptions and other incidental expenses on my company credit card to facilitate turnaround. Now it looks like I can get black banned if one of my contractors on the other side of the world goes rogue?!?
I would refrain from using your credit card for others' accounts without serious consideration. I definitely wouldn't do this frivolously or for people you don't have a real trust relationship with.
Maybe I'm missing something, but it seems practically impossible to distinguish between the two unless there was a royal screw up somewhere along the line.
It would be a big risk, but one could potentially buy 'false flag' reviews - throw some negative reviews on your own product, and positive reviews on your biggest competitor - It would hurt yourself in the short-term, but could pay off if you can get the competitor banned. Again, super risky, probably stupid strategy... But with the state of the 'app' market, I wouldn't be surprised if people would try it.
You just go on fiverr.com and pay someone in Indonesia $5 for the hit.
I think apple acted pretty responsibly here.
Edit: To other commenters, why would Apple accuse the dev of faking reviews if it wasn't true? I don't see Apple getting anything out of it.
> I don't see Apple getting anything out of it.
Refusing to admit innocent error is a very understandable course of action. If, of course, that's what they're doing. From where I stand the entire situation is completely muddy, and I don't think the linked article clarifies anything.
Usually they just apologise and put it back up. It would be very uncharacteristic to stubbornly refuse to acknowledge and rectify the mistake.
They'll never provide proof for the same reason that Google won't publicize the exact parameters behind search; it would provide bad actors with information on how to game their system.
Because few people care to check it out / buy it?
Being the "best of its kind", belonging to a popular app genre, and actually selling are three distinct things.
[1]: http://daringfireball.net/2016/10/apple_dash_controversy
While I'd like to give him the benefit of the doubt, the overwhelming most likely case is he was doing exactly what Apple thought he was doing. At the very least, he should take some responsibility for the fact he's paying for someones account who is actively trying to harm his competitors.
Apple probably could've avoided a lot of this mess by not overtly banning his account, but doing the except opposite of what his manipulations intended and make the app almost impossible to find.
They both agree in principle that DASH should be reinstated, and clearly it being reinstated is in both sides best interests.
Why Does Apple NEED an acknowledgment that they didn't do anything wrong? What difference would it make?
Why can't Kapeli just acknowledge that he was associated with a bad actor in Apple's system.
I get the idea of integrity, but I get the idea of self-preservation a little more...Especially when reality is subjective and your perspective might not be the only sincerely held belief.
I will never understand the people too principled to just SAY SORRY even if you believe you are in the right. Are you so principled that you can't even acknowledge the existence of a potential conflicting view point, at least enough to admit you might be wrong, when its clearly in your best interest to just own up, and move on...even if you aren't sincere in your apology!
Edit: I can maybe understand a prisoner refusing to admit to a crime they didn't commit to a parole board despite contrition being a key to getting released...but at some point of serving a life sentence, you have to kick into self preservation mode and just admit to wrongdoing, and spend your free years atoning for your lie.
I get what you're saying, but if Apples gets hammered with bad publicity every time their anti-fraud team does the right thing, they're going to stop doing the right thing.
Especially as this case is going to be cited for years to come, it's important apple has something to point to and say: "We didn't just arbitrarily ban the account, it was involved in manipulating our reviews"
>anti-fraud team does the right thing
That's not what happened though. What happened is that Apple has their internal tools to link fraudulent accounts, to keep out bad actors, and this "good" account got caught in that web. You can just as easily argue that he didn't actually do anything wrong. After all, if he did Apple wouldn't even consider reinstating him. The fact that Apple linked the accounts internally doesn't actually point to any guilt or wrongdoing...It could even be pointed to Apple's policies arbitrarily hurting the little guy.
I can see both sides very clearly and I can see a middle ground very clearly. The only thing stopping this from being resolved is "bruised egos" on both sides.
Edit: Added in second quote
From the call, it appears that Apple only wanted a clarification in that direction, i. e. "I should not have given my drunk little brother the car keys".
They're not reacting from a "bruised ego", since a professional PR team doesn't get emotional in that sense.
They feel that the initial accusations have created actual damage for Apple's image, and they want him to stop the pitchfork-wielding mob.
I bet the PR costs exceed the actual damage in this case. If they were really afraid of damage, they wouldnt come out swinging, they would simply apologize for banning the account and the public would forgive them instantly.
Both sides are acting against their own interests IMO.
1. Opened up a developer account for a relative 4 years ago. Relative. Yeah, ok. And 4 years ago... don't credit cards usually expire before then?
2. The same devices were being used on both accounts. While the info isn't available, I'm sure Apple can know if these same devices were still in active use by both accounts.
3. Dash isn't the problem. Too many people seem fixated on the notion of why the developer needed to do review manipulation on Dash when that's not at all the problem. It's the other apps on the other account that were the subject of App Store review manipulation. These apps contained descriptions that contained the developer's own email address in it: http://appshopper.com/search/?searchdev=603546869&sort=name&...
Also, if he really was guilty, why would he poke the bear after apple agreed to reinstate him...why not apologize and get off scott free.
It appears to me like both sides agreed to a set of facts and now its just a matter of setting the record straight. No one seems to want to admit fault and they are being childish about that since its in both of their interests to do so.
Imagine a family account at the bank. Husband is committing fraud, bank closes the account to stop fraud and 'good' wife cannot use her credit card anymore.
EDIT: afaik, other account also used the same identifier for their apps. Apple sees that there is a person/company who has fraudulent activity in one of it's accounts and bans that person/company. Simple as that.
They only wanted this because he chose to get everyone riled up about the perceived injustice, and it's causing Apple a PR headache. It could have been avoided if he had chosen to resolve this in private, or at least went with a bit more ambiguity instead of indignation.
...But I really don't get why this didn't end with the phone call. Write a post, be done with it. Instead, he's trying to escalate it further, breaking California law by publishing the phone call and making it basically impossible for Apple to accommodate him. Considering this is his livelihood, this post is a tragic mistake.
Funny thing is that everyone seems to have agreed on a story... "My cousin did it". It seems quite natural that when that account is used for spam, it comes back to him. considering his credit card was the only ID that had been verified.
Leaving aside whatever inferences might be drawn from the fact that the developer saw fit to record and publish the recording in the first place, here's a brief summary of what was said:
- There was at least one other developer account "linked" to the Dash developer account. In this context, "linked" means that the accounts "shared the same details": they were enrolled in the Apple Developer Program "with the same credit card number", and "used the same test devices".
- Apple says that at least one of those other developer accounts "definitely had fraudulent activity": "It was not your direct account but it was a linked account." Warnings about fraudulent activity were sent to the linked account. No warnings were sent to the Dash account.
- The Dash developer asked: "Why didn't you notify me beforehand though, and let me know that an account that's linked to mine is doing fraudulent activity, so I can do something about it?" The answer is "because they were linked"; "we see them as the same entity". "If we have accounts that have enrolled in our program using the same credit card, they are the same legal entity; they are the same." So Apple believed they had notified the Dash developer because Apple believed the same person was behind the linked accounts. (Prudence would dictate notifying all accounts at risk of termination; we'll see what happens in future.)
- Apple's position is that no mistakes were made. The Dash developer account was linked to an account with fraudulent activity based on the facts known to Apple.
- The Dash developer says (in his blog post) that he "helped a relative get started by paying for her Apple's Developer Program Membership using my credit card" and "handed her test hardware that I no longer needed".
- Apple says they are "working with" the Dash developer to "unlink the accounts", which (I speculate) may involve some attempt to verify the Dash developer's claim that the linked account was used only by a relative and not by him. If the accounts are unlinked, there would be no reason for the Dash account to remain closed.
[1] https://blog.kapeli.com/dash-and-apple-my-side-of-the-story
Also The apple guy said it uses same test devices. As usual the devil is in details, it's important if they still uses the same devices and in what extent.
You're assuming that Apple has no process to distinguish between intentional fraudulent reviews coming from the developer in question, and random fraudulent reviews from others. But that assumption is not supported by any facts.
I would think its pretty easy to hire a click farm to blatantly post fake reviews to the app store. The worse the click farm is at covering their tracks the better if you're trying to get a competitor banned by Apple.
Dash was a popular app among developers who use Apple products I doubt the fake reviews would be needed. I wouldn't be surprised at all if this was caused by a third party.
Although I have no idea how you'd create dozens of accounts with independent payment methods without it becoming suspicious. I guess you can use gift cards anonymously but that's almost certain to trigger even the most basic anomaly detection.
Apple should have just told us that the account was linked to a fraudulent account so they were correct to pull the plug quickly to prevent add'l harm, and that on further review it was clear that the relationship between the accounts was not as close as the facts initially suggested. That would seem entirely reasonable to me.
That said, by not notifying both accounts it seems that problems like this are totally foreseeable. It also suggests that if a malicious actor was able to get a developer's credit card he would have a fair shot at getting an app delisted.
For people saying this was already in top of app store, well, there was rating manipulation. That's why it was on the top (?)
[1]: https://blog.kapeli.com/dash-and-apple-my-side-of-the-story
What's worse, by coming out, the Dash developer has forced Apple into a defensive position, ensuring that Dash will never appear on iOS again. Dash has now lost revenue and exposure opportunities, and Apple's consumers are reminded once again that they don't have the right to control their devices.
Both sides want to come out of this looking good, and right now neither side does.
Dash developer caught up in an errant fraud check? Eh, it happens. At least this is Apple; were it Google, the developer would be right proper fucked (then again, his post made it to HN, so he might have gotten some special attention).
However, making that resolution conditional on the developer making Apple look good in a blog post? That feels pretty scummy here again to me.
The error seems innocent enough to me (though the party line of "we can't tell you why you were shut down" is the worst way to interact with your developers), but the conditional resolution is not making Apple look good.
It might not be fair, but it's logical.
Unfortunately, it does create a frustrating situation when you're on the other end of a complaint.
I would strenuously avoid making the HN community feel more entitled than it already does to all the technical details so it can be endlessly armchair litigated.
Take this app for example: https://itunes.apple.com/us/app/disk-drill-media-recovery/id...
(click on "All versions"). You'll see there's HUNDREDS of fake reviews, all giving it 5 stars, and in all cases it is the only review that account has ever made.
I mean, we are talking about the same company that just a few years back subjected all iPhone developers to such a strict NDA that they were technically not allowed to discuss a WWDC panel they were watching with the person sitting next to them.
Edit: Seriously, what question can I ask? This sounds like a fun brainteaser, like the one where half of the people on an island are liars and half are truth-tellers, and the explorer has to figure out which fork in the road leads to the village. If there's an answer, I'd genuinely like to hear it. Downvoting me is just a way to shrug your shoulders and admit your bluff has been called.
The account that the fraud happened on, and all the other accounts that appear 'linked' will be closed.
The issue was with the account he gave to his relative, which Apple probably assumed was his account because it used the same credit card and test devices registered to both accounts.
implying that this is the only way Apple would consider fraudulent positive reviews to be developer's fault? Unlikely.
If it's not, it'd be quite a blow to the dev's credibility. (and a felony).
[1]: https://en.wikipedia.org/wiki/Telephone_recording_laws#Roman...
But it does make it less relevant at least practically.
On another note, I tried to find out where he lives, but it's nowhere to be found on the website. I really prefer business websites that give me at least a full name and a city. I don't even know why – I'm not planning to write/stop by/sue – it just feels shady.
(whois data is similarly anonymous – I'm starting to see Apple's point of view)
Romania doesn't care either, considering how it is not subject to US law.
In addition to Dash (which I'm not able to locate in my Purchases tab), I've noticed this to be the case with apps that violate Apple's rules, like those hidden proxies or emulators that have sprung up over the years and were later removed by Apple.
What Apple has done: on Friday they told me they’d reactivate my account if I’d make a blog post admitting some wrongdoing. I told them I can’t do that, because I did nothing wrong. On Saturday they told me that they are fine with me writing the truth about what happened, and that if I did that, my account would be restored. Saturday night I sent a blog post draft to Apple and have since waited for their approval.
Tonight Apple decided to accuse me of manipulating the App Store in public via a spokesperson.
That makes me wonder about what the heck happened?
† I remember it happening for the game Edge when it was taken down due to trademark trolling. It was later reinstated.
Sounds damning. Was this a paid app? How many downloads did it have?
This is more a middle ground, for people caught in the cross hairs to present their case. Maybe like WIPO arbitration for trademark domains.
If there was somebody - anybody - in Apple who spoke with a voice developers trusted, right now they could be explaining what in hell's going on. Having Apple Marketing leak something to somebody who leaks it to Gruber, who then reports it as hearsay, is a damned shoddy substitute.