The HN title/article is slightly misleading with its use of "root access"; the iOS Enterprise Root certs give increased data access outside of an app (e.g. decrypted SSL traffic, like what this app was doing), but not "root access" in the Unix sense.
You can play with them using mitmproxy to generate a Cert and intercept SSL traffic.