Dash developer's response to Apple's response
blog.kapeli.com
blog.kapeli.com
End of.
Kind of.
Seems like Apple is working off the assumption that linked accounts are acutely aware of what each other are doing, and thus are all equally responsible for each others actions. Clearly this assumption is not valid.
Having listened to the entire call, I think both parties conducted themselves with respect and good faith. The only question unanswered in the call is “why didn't Apple notify both accounts?”.
Apple is in a position of disproportionate power here. They created the platform, they make the rules, everybody either plays by them or doesn't play at all. I really hope Apple will just be honest and admit that they did, in fact, have an inadequate process for dealing with this kind of corner case. They did make a mistake. They closed someone's account when it shouldn't have been closed.
If Apple is adamant that they made no mistake, they only reinforce the feeling that Apple has become an inhuman giant, a profit-hunting corporate entity, that doesn't really care about human values — the antithesis of what Apple used to be.
Both were faulty and they obviously didn't come to an agreement. Apple phone offer would have gave both of them a clean exit and it might always remain shady why this agrement wasn't actually implemented...
After carefully listening to the phone call I still don't understand why the developers was arguing at all. He could have been back in buisness in a breeze with no harm at all.
Apple, being a big corporation, is inhuman if they do not admit their mistakes.
The developer, being a human, is a prick if he doesn't admit his mistakes.
I don't know how you arrived at that conclusion. The developer offered to publish a blog post saying that the app was removed due to fraudulent activity on a linked account he was not aware of. Apple accepted and then went ahead and published a statement accusing him of engaging in fraudulent behaviour anyway, claiming they gave plenty of warning, but not mentioning that the activity was limited to the non-Dash account, that the developer claims to have been unaware of the connection, and that they did not inform him of the connection or give any warning on this account. That's just dishonest.
So again this might well remain unsolved because probably no one appart from the arguing parties can't tell why the agreement on the blog post in exchange for dev program re-enrollment wasn't fulfilled by either parties...
From the blog post:
> Update: Just to make it clear, I have complied with Apple’s request and have sent a blog post draft approximately 30 minutes after this phone call ended. I have since not received any contact from Apple in any way, and they did not respond to my calls. Their recent statements come as a shock as I thought we were working together to resolve this issue.
Given that Apple's statement left out several important facts (arguably, to paint a rosy picture of their behavior), I'm inclined to believe the developer here.
I choose to focus more on the actual phone recording than to the dev post because at least you can hear both positions.
Indeed something had gone wrong in the process they agreed on phone. But it's words against words. So I really think it's better not to chose to believe in one over another, because that would always be tainted by our own personal predisposition (which of course may differ).
Is everyone here taking the developer's word at face value? Despite him giving no reason to do so?
Apple didn't notify both accounts because they're under no obligation to notify someone that they're committing fraud and ask them politely to stop.
Why would you take the word of a developer dumb enough to post this audio clip and publicly shame Apple in blog posts as someone honest and working in good faith with them? Here's a much more likely story: he's not telling the truth and he's in over his head. His cousin didn't leave fraudulent reviews from his test devices on his and competitors' apps for no apparent reason.
Apple is under no obligation to do anything, they can do as they please. But just because an entity is “under no obligation” to do something, or something is “completely legal”, doesn't make it right.
In this case, I'm siding with the developer for a few reasons.
First of all, his app is good, the reviews are genuine, and even Apple thinks so.
Second, I can relate to him, as I've given away test hardware to others, and I was not aware that I should vouch for whatever they do with the hardware.
Finally, Apple is the big player here with all the muscle. When in doubt, I try to side with the party that didn't come up with the rules.
So this guy has a lot of suspicious activity on accounts linked to him. Apple have done what they believe is the right thing to protect the integrity of the app store, in line with there own terms and conditions which the developer has agreed too.
Said developer has published blog posts online that give Apple very bad publicity over this, making them look like the bad guy for trying to protect users and maintain quality (What does apple have to gain by randomly disabling this guys account?)
Apple have reached out to him and offered to sort the issue out as long as he posts the facts in a blog post, which is fair after his previous posts have outright caused Apple PR issues for something that is his own fault.
Apple have also got top execs dealing with this issue, trying to make things right. Developer doesn't release said blog post, so Apple releases statement with said facts to protect themselves for further incorrect accusations.
Developer then gets but hurt and releases the conversation that does nothing to help there situation.
What is the developer trying to achieve here exactly? Sounds like the developer is guilty as sin for this fraud and is more interested in accusing apple and covering themselves.
1. That it's his fault isn't so clear. The developer claims he was not notified that there was a linked account until two days after a ban. If you listen to the recording, he asks why he was not notified, and the representative does not give a good answer.
> Developer doesn't release said blog post, so Apple releases statement with said facts to protect themselves for further incorrect accusations.
2. If we are to believe the developer, then he actually sent a draft of the blog post to Apple, then Apple doesn't respond and instead posts a public statement.
> What is the developer trying to achieve here exactly?
3. Telling his side of the story and what happened. If we just heard the Apple side of the story and that was it, then we would assume, as many did, that the developer did do review manipulation. If we didn't hear about his side, we would have had no idea that Apple discovered the fraud on a linked account and wanted a blog post explanation to reinstate the account. Apple's statement was incomplete given everything they knew; there was no talk of "linked" accounts or anything of that sort.
> Sounds like the developer is guilty as sin for this fraud
4. Again, if we are to believe the developer, there was no intent to defraud anyone, so I think it's a stretch to say that he's "guilty as sin" for it. The only fraud would be his cousin's fraud that his account is connected to, which Apple failed to notify the developer about until two days after closing his account and after the blog post.
And if he didn't commit fraud, why is Apple enforcing him to write a PR blog post in favor of Apple as a condition to get back into the program?
Apple wants him to write fake review. Oh the irony.
Apple says his account was linked to the fraudulent account. They define "linked" as sharing test devices, and having been enrolled under the same credit card number. The accounts were linked.
They say to the developer that if he explains exactly the above then his account will be re-instated. It's not a "fake review" if it's stating the facts.
The part where we can assign blame to Apple is where they failed to notify all "linked accounts" when one of the accounts was engaged in fraudulent activity. They only notified the account engaged in the fraudulent activity, but went on to shut down that account and all linked accounts.
If they had notified all linked accounts then the developer claims he could have taken steps to resolve this much sooner. (But to argue for Apple's side here: Apple views all linked accounts as a singular "legal entity," and so assumed notifying one was the same as notifying them all.)
Regardless of which side of the argument you lean towards, they can both legitimately believe they are 100% in the right.
- Developer used his credit card to enrol in multiple accounts
- Developer had same test devices on both accounts
- One account engaged in fraud
- One account was notified of fraud
Apple's request is that the developer make these facts known and have his account reinstated. Because Apple doesn't want to be seen as arbitrarily shutting down developer accounts — they have reason in this case and want it known.
It seems like Apple was sympathetic to the claim that the developer lost control of / forgot about the account which had the fraudulent activity. But also wanted to be seen as having a reason for pulling Dash in the first place.
They weren't asking the dev to admit to fraud. They were asking him to admit to opening multiple developer accounts and losing control of one. Which both sides acknowledge he did. I'm not sure I understand why the developer thinks this would be an admission of wrongdoing on his part (unless the wrongdoing was opening multiple accounts and giving them to untrustworthy people, which he did).
Just to be clear, the developer would've been happy to do exactly that:
> On Saturday they told me that they are fine with me writing the truth about what happened, and that if I did that, my account would be restored. Saturday night I sent a blog post draft to Apple and have since waited for their approval.
However ...
> Tonight Apple decided to accuse me of manipulating the App Store in public via a spokesperson.
Apple's press release does not make any mention of the fact that the fraudulent reviews were for apps from a different (linked) developer account. They also say that they gave multiple warnings prior to removing the app. The developer's blog post and his recording shows this only to be true for the linked account, not his. At the very least, Apple is guilty of lying by omission.
All in all, I think this is very bad form from Apple. They could've simply admitted that their notification system does not present a full picture to developers and fix that, rather than do some weird "we want to make clear we did nothing wrong" dance, and then go out and make misleading statements.
They also likely have additional information, like the IP addresses and timestamps in use when the reports were made. Keep in mind that Apple doesn't make money (directly) from taking the guy's app down, and even the guy's story doesn't really make sense.
It hinges on the idea that he bought the developer program for a relative, who then used a bunch of his devices years later to leave a bunch of fraudulent positive reviews for his apps and negative ones for competitors. Really?
It sounds to me like Apple had him dead to rights and gave him an out, despite having no need to do so. He knows he screwed up AND publicized this with his blog, so he can fix it with his blog or he can lie in the bed he made. He stuck with his made-up story to save face (at the expense of Apple) so they're sticking with the original decision.
>It's not like Apple does this kind of thing every day
1. Just because you don't hear about it doesn't mean it doesn't happen all the time to less known developers with no public voice.
2. What's his incentive not to take the out Apple offered him? If he was guilty & had no problem lying, why the heck wouldn't he grab the opportunity to be reinstated?
The only rational incentive to hold his ground is if he actually believes he is in the right. Which indicates that his story is likely true.
I agree that he could just as easily be lying, but the series of events and decisions fit much better with a guy who feels hurt and in the right, versus a guy who has no problem lying and being dishonest publicly.
Edit: spelling correction
* They did make a mistake in not verifying whether the second account activity was actually done by Kapeli, yet they want him to claim they made no mistake, otherwise they won't reinstate Dash.
A second developer account, which is the account linked to fraudulent reviews, was opened using the same credit card, same bank account, and same test devices as the main Kapeli account. So it's reasonable that they would assume the same person was in control of both accounts.
The developer claims this is not the case, however. Apple seems willing to accept that. All they are asking is for him to write a blog post stating these facts.
- Apple assumed, and let these assumptions stay untested, and particularly failed to reach out to the different contact details on all involved accounts.
- Apple admits they terminated his account in error, yet blackmail him in refusing to reinstate unless he makes a blog post. (Actual contents of the post irrelevant to the point at hand.)
> We don't believe that there was a mistake here, right. We don't think that we made a mistake.
So no, Apple is very explicitly saying they were not in error.
Yes, and it boils down to one thing:
Either the termination of his account was correct, and should be upheld; or it was wrong, and should be rescinded.
There are many times in life when things are in a range of grey between black and white, but this case is entirely black and white. Either they made an error with the termination or they didn't. If they made an error the account should be reinstated without question, delay or condition. If they did not make an error it needs to remain closed.
By the very fact that they are willing to reinstate it, they admit to the fact that the termination was in error, regardless of what they believe of say they believe.
Doublethink is real.
And the fact that Apple's willing to work with Bogdan to unlink and reinstate his account also does not mean Apple did anything wrong. If you actually listen to the phone call the Apple rep makes it very clear that Apple believes they were correct, but that Apple is willing to offer Bogdan a way to fix things.
Well, we'll have to disagree. And i think Apple's actions, in giving the option of reinstatement, disagree as well, even though they claim to believe otherwise.
Edit: Oh, and even if something were to appear reasonable to do, but turned out in hindsight to be wrong, then it would still be an error.
And this is quite a similar to what you might experience if you ever go to a Genius Bar when you are somewhere in a range of grey as I once was.
That's what's really wrong here.
His account was linked to one involved in fraudulent activity.
He's working with Apple to get his account unlinked from the fraudulent one.
That's it! He doesn't have to admit wrongdoing and Apple (despite being very confident they didn't make a mistake) gives him the benefit of the doubt and unlinks the account. Instead, he decided to dig his own App Store grave.
Do they make people aware that the accounts are linked?
>Apple representative states there was no wrongdoing on Kapeli's side.
which is a misrepresentation of what the Apple rep said on the call.
If they thought there were any wrongdoing they wouldn't even be talking to him, much less make him that offer.
The wrongdoing here is that he opened multiple accounts that could legally be linked to him and allowed one of them to be used to defraud the App Store. Apple could see that as wrongdoing while being sympathetic to his story that he forgot about it / lost control of it and so allow him to reinstate his account.
You got your facts wrong. He did not do that.
But in either case, Apple may have viewed this as the wrongdoing.
So the same question applies to you: why are you equating Apple's willingness to reinstate his account with an admission that there was no wrongdoing?
It is expressly permitted by their guide lines to use another person's credit card to start one's own account as long as one provides govt id: https://developer.apple.com/support/purchase-activation/ Please get your facts straight before trying to get into an argument.
As to your question: If there was any wrongdoing, which Apple at first staunchly insisted there was, Apple would not even bother to talk to him, much less offer any redress.
I'm suggesting that if the account goes on to commit fraud then Apple may view that as wrongdoing. That is, the developer loaning out their credit card should be more responsible. Can you not see that this is a possibility?
And if this is a possibility then you might also see how Apple could allow the developer to reinstate their account because they are sympathetic to the reasons behind it happening. It doesn't have to mean that no wrongdoing took place.
It simply means: "We understand there was no intent to commit fraud, but it still happened, so we'll let you have your account back as long as you clear up how and why this happened on your blog."
Edit: Why would Apple not talk to him if there was any wrongdoing? I have been in a position where Apple has talked to me after assuming I was involved in wrongdoing. I was able to clear it up because they talked to me about it.
No, that is absolutely dificulous to me, and if it were the case, then the guidelines must state that, which they don't.
> Why would Apple not talk to him
Because they already told him they would not when they thought there was nothing in question.
Why must they state that? It's a fairly obscure edge case that they probably didn't predict. There aren't going to be guidelines for every conceivable possibility of how a cluster of Apple developer accounts can be (mis)used.
> Because they already told him they would not when they thought there was nothing in question.
Your claim is that if Apple even talks to the developer, then there must be no wrongdoing. I disagree with that in this case and from personal experience. Apple's developer relations people are generally able to understand and sympathise with extraordinary circumstances. Such as they did in this case.
If Apple is ready to bring him back it's because he didn't commit fraud.
And if he didn't commit fraud he shouldn't need to write a blog post as a condition to get back. Quite contrary, Apple owes him an apology.
If you open developer accounts that eventually engage in fraudulent activity you're not "owed" an apology. You should be on top of the things you open in your name and with your bank details.
Apple should have taken steps to notify all linked accounts. That's their mistake. But it was the developer's mistake to open an account for someone who would engage in fraud in the first place.
Morally it absolutely does remain blackmail.
Apple's warranty policy that users 'agree with' has been over turned in many many countries.
He then today refreshes Loop Insight / iMore and reads "According to Apple, all attempts to work with the developer have failed".
Was the press release really Apple's answer to the blog draft? Was it meant to torpedo the ongoing "blog negotiation", or independent of it?
But the Dash developer clearly read the press releases as responses to the ongoing communication, rejections of his draft blog post. In his view they made a new decision and went to the press with it. Account ban final. He has nothing to lose by posting his telling of the events and the audio.
> Tonight Apple decided to accuse me of manipulating the App Store in public via a spokesperson.
It's really unfortunate for both sides if this drama is the result of bad timing and/or siloed organizational departments.
There was no other communication with Kapeli.
There was no reason for them to know that this developer purchased an account for someone else and gave them his test devices (which sounds like an excuse anyone accused of anything gives when they're caught).
He got caught and didn't realize they would make the connection, so he's blaming someone else.
It's the same tactic that makes Facebook advertising so useless. You have millions of fake people posting regular fake "updates" complete with fake GPS locations just so that some of them can provide fake traffic for pages when someone pays.
I want to see the proof that the reviews were fake in the first place and I want to see all the reviews posted by these supposedly fake users.
It probably won't happen but here's to hoping. Maybe some public visibility into these sorts of things will breed sympathy for Apple's position because it's a real problem and it's very difficult to solve.
Sounds like bullshit to me.
How would you feel if someone swiped a copy of your cc, started an apple developer account, did a bunch of review freud and then got you kicked out of the app store.
I think there are some serious issues around due process with account termination. If something like this was sent originally this would be a non issue.
> We detected freud from account X that is linked using your credit card number to account Y. ... bla bla bla freud is bad ... respond within N hours or have your account terminated.
- Apple considers Developer Program memberships "linked to the same entity" if they are paid for by the same credit card.
- If one of these accounts violates rules, all accounts of this entity are being closed.
- As always, it's difficult to get any useful information from Apple.
- Apple will listen and try to find a reasonable solution – at least if the public backlash is big enough.
In my opinion, Apple should communicate this more clearly and, upon closing an account, provide all relevant information to the membership holders as well as providing a means of appeal. Mistakes do happen.I welcome Apple's crackdown on fradulent activity. However, as an iOS developer, stories like these are the reason why I don't want to bet my livelihood on distributing apps through the App Store. While the risk of having my app rejected or account closed for no particular reason is small, it's still there. Are developer's voices being heard, even if they don't have a blog and a twitter account? My experience with Apple's Bug Reporter says no.
Suddenly UDIDs need to be kept confidential, or a fraudster might add a high profile developer's UDID to their own developer account and then drive it into the ground.
Doing iOS consultancy work for other people's dev accounts could also be more risky than expected now if you use your personal test devices there.
Remember also that there are probably thousands of third party databases out there linking millions of UDIDs with real world identities, as it is only in the last few iOS versions that the device uniqueIdentifier API started returning blanks. Earlier, many apps and adtracking libraries almost certainly would include the UDID in server calls during login etc.
I don't think so. The fact that you have your device registered on two different accounts is unlikely to be sufficient to link the two accounts. It's merely one of the ways in which the accounts were linked. Using the same CC and/or bank details is another. And there's probably other links too that Apple didn't disclose (because they're only effective at combating fraud if fraudsters don't know about them).
That's not the case here. They reiterated many times on that phone call that they're sure they didn't make a mistake and they have no financial interest in banning his account. They gave him an "out" by letting him post a carefully worded post without even admitting wrongdoing and he instead recorded their phone call and posted part (!) of it on his blog.
How people are seeing Apple as in the wrong here is mindblowing.
The relative was acting only on their own and likely not even aware that what they were doing could hurt Kapeli, and vice versa.
And Apple knee-jerked without questioning their assumptions.
Apple should be contacting the App's official developer account link to the App Developer, or all accounts linked to the App's Developer, not just the discovered linked Account. After all, isn;t the official account the one bound by the license and terms of use for the developer's app?
If Apple chooses not to notify the App developer's via his official account, but the discovered account. Well, then only the discovered account should be deactivated (and not impact the App).
Would apple send a password reset to the discovered linked account or the official account contact? We could insert a few jokes here, but obviously the answer here is the official account email.
That doesn't make sense. We're talking about anti-fraud measures here. If they contacted the other account and said "hey are you the same person as this first account?" a fraudster would always say no even if the same person controls both accounts!
A linked account was involved in fraudulent activity. Its easy for anyone to say 'Oh, i just paid for that and gave my hardware but thats not mine'. Still doesn't change the reasons for suspicion.
It does suck since I really like Dash. One reason why you should not share/use your work CC/bank accounts and Hardware for non-work reasons.
Telephone companies are one such an example.
If you paid the bill of your friends phone one month, and later the phone company got into a dispute with them and cut off the phone that you do business on out of your home office -- and then refused to reinstate your phone line unless you publicly apologized to them, I suspect the FCC would not approve of their actions.
Apple has way more power in this situation and is much more of a monopoly over many software developers lives, but is operating by rules that it makes up itself.
That's pretty much the same thing they claimed was the basis of the account suspension, if you think about it. Guess it's a "good for me, but not for thee" kind of thing.
https://en.m.wikipedia.org/wiki/Telephone_recording_laws#Uni...
Spend $5000 at Fiverr or similar on bogus reviews.
.. There are no more steps.
This also works with SEO. You can spend under $100 at Fiverr for thousands of backlinks, get your website flagged by Google and the website needs to manually remove those backlinks in their console (which takes days, if not weeks to track down the flagged links).
Rinse and repeat on your competitor once a month to ruin their online presence.
(In case my oblique comment isn't clear enough: Time for someone with real authority to cut through the crap on Apple's end.)
I think Apple did fine here, actually.
Dumb move. Most people will forget about this in a week and his business will be affected for months (in the shortest possible time frame) and probably permanently.
This is a dangerous bluff to make.
Dash is mostly a desktop app and he can keep on selling it outside the MAS.
I suspect that his recording and posting audio of that call is going to blow up in his face. Especially if he broke any laws by doing it.
http://www.dmlp.org/legal-guide/recording-phone-calls-and-co...
Federal law is "one party" as well.
Edit: Romania.
Sounds a little fishy to me. I'm not saying that he was aware of or involved in review manipulation that was coming from his "relative's" Apple Developer account that he happened to pay for.
But I wouldn't bet money that he wasn't.
And the fact that he feels the need to mention giving said relative "test hardware that I no longer needed" suggests that said hardware might have been involved in the alleged review fraud.
I don't think this will end well for this guy.
> on FRIDAY they told me they’d reactivate my account if I’d make a blog post admitting some wrongdoing. I told them I can’t do that, because I did nothing wrong.
> On SATURDAY they told me that they are fine with me writing the truth about what happened. [this is the call that was recorded]