Apple blocks Google from running its internal iOS apps
theverge.com
theverge.com
Google and Facebook both knew the terms. They both knew that the Enterprise Distribution Program was for internal use only. They still put ads out in the wild to recruit regular consumers to use internal apps which is beyond the scope of the program. Why would the certificates not be revoked?
I don’t understand people who are acting offended that Apple is enforcing the clear terms of service it laid out.
It's useful to discuss the philosophical implications of any tech company having too much power. To add the most to that discussion, it's helpful to understand that these actions are not directly affecting customers (aside from those who were using these enterprise apps outside their intended scope).
Clearly that's not a terribly big deal, and you'd imagine that Google has a lower proportion of iPhone users than many companies, but it's not nothing.
They are not personally affected as they still have access to public versions of the apps like every other person in America.
When you are paid to take a survey, do you magically become an employee of the company conducting the survey?
This is generally false. Minors generally can make valid contracts, though such contracts are usually voidable by the minor prior to execution. [0]
[0] without otherwise endorsing the site as an authority, the discussion here provides a good general coverage of the issue: https://contracts.uslegal.com/contract-by-a-minor/
It is an interesting salvo in what I've started thinking of as the "data war." All three companies have a huge asset in data collection capability, and preventing the others from exploiting it is only the first skirmish among them.
It will be interesting to see if Google offers to pay additional monies to Apple in order to "restore" this pipeline, and whether or not Apple will agree. In one sense, Apple already gives up a data feed by sending search queries to Google.
Apple does this under protest. Their top search queries are served through siri lately, and the hope is siri will replace all search so they won't need to utilize google anymore.
Bing, I thought?
But I think that DuckDuckGo uses multiple sources. Although it's easy to restrict that to Google.
There was a time when the Siri folks approached Blekko (which was an actual search engine with its own index, crawler, and ranking Etc. to discuss partnering with Apple (personally I think they should have bought us :-)) But, according to people who should know, there was a cultural mental block at Apple about providing web services at the time. The biggest thing like that they had done was Apple Maps and it was a 'mixed' success. Apple didn't see itself as being a search company.
I used to point out that Microsoft had a phone (Nokia), an operating system (Windows Phone), and a search engine. Google had a phone (Nexus), an operating system (Android), and a search engine. Apple had a phone (iPhone) and an operating system (iOS).
Since that time Microsoft dropped the OS and phone, and Apple never did build a real search engine.
[1] More precisely it is a front end to a simple knowledge base, a local index of things on your device, and when those things are exhausted an internet search engine.
I've noticed several times now where Google assistant has been able to answer questions about things in almost real time all thanks to Google's crawlers.
My friend asked it earlier whether USPS delivers mail during a polar vortex and Google assistant told them they didn't yesterday, at least in Chicago.
I mean, when I think about Apple, I think of a company that designs the look, the internals, the case, the glass, the board layout, and even some of the chips. (Sure, they contract the manufacture out, but Apple is deeply involved with designing components on a low level -- not merely farming it all out to some device maker in Taiwan or China.)
But for Nexus/Pixel: how much is Google and how much is LG or Samsung or HTC (yes, I know they bought HTC). I mean, how deep do Google personnel in Mountain View really go? How much do they just hand off to outsiders? Is it comparable to what Apple does? Maybe so. I just can't quite see into it.
Google's biggest challenge was customer support, they just didn't do the whole "someone to pick up the phone and talk to you" thing.
So I'd say, they have a core capability to do handset design (perhaps some of it residual) and they likely strongly influence the hardware they sell. Is their bench as deep as Apples? No.
What are you basing that on, exactly? Apple doesn't exist in a market simply to "be" in that market. That's why they jettisoned things like their Airport routers
Do this. Create a fake company and say you wrote a spider to index Facebook public profile data and that you have like say 100GB ....
Watch how fast you get sued by Facebook.
Mind you this is public data that EVERYONE can see...
"It's a bold strategy, Cotton, let's see if it pays off for him"
The entire concept of law is based on the premise that not everything that is physically possible should be permitted.
Yeah nah, that's where the concept of agreements comes in. You walk up to Fes Boock and say:
― I want to have business with Fes Boock.
― Fes Boock will have business with you if you promise to not stab Fes Boock in the back.
― I give my word to not stab Fes Boock in the back.
Turns out, this thing is so valuable, it's supported by law everywhere that I know of, in multiple forms, including rather implicit ones such as “ToS.” Which is what allows Fes to sue the stabbing bastard.
Since a web server, by its primary mode of operation, does indeed more or less indiscriminately send replies to whomever makes a request, it follows that the duty of choice lies with the client. The person operating the client has to apply their reason and follow the inter-party conduct.
Sorry, why isn't it the duty of choice the server owner, who chooses to put the server online in the first place? What exactly are these rules you think exist? This is the first time I've ever heard of them.
> Since a web server, by its primary mode of operation, does indeed more or less indiscriminately send replies to whomever makes a request,
This is completely false. The server owner can authenticate GET requests and return an unauthorized response if the client is not permitted to access the document. We are not talking about a situation where a hacker attempts to brute force a password or gain unauthorized access to a server. If the server is on the internet serving anonymous GET requests with no authentication the reasonable assumption is that anyone is permitted to access the data.
It appears that the rest of the web gets by pretty well using the legal framework I've described. Because, you know, they tend to choose things to be pragmatical instead of those that “can be done.”
A better real world analogy is a bulletin board on campus or a wooden power pole.
Lets suppose that it is super common that people staple flyers to power poles, with the expectation that people will read them as they pass by. Your analogy would claim that if I staple a letter to the power pole, expecting that only my friend that I told about the letter should read it, that passers-by are doing something unseemly by reading it, while being surrounded by want ads and for sale flyers that people do want read.
Websites are nothing like mailboxes. The vast majority of websites would prefer that as many people as possible read their contents as much as possible. Email would be a better analogy.
This is not the case for HTTP. A network protocol is an agreement about the meaning of certain clusters of bytes sent over a network. When someone operates an HTTP server, a reasonable person could conclude that they take HTTP messages to mean what HTTP says they mean. A lot of cases get more interesting because there is also something generally understood to mean, "Please don't access the following resources by automated scraping, independently of whether my server decides to grant those requests."
I don't understand why they were so happy when this happened to Facebook but now they are offended because it happened to Google.
Oh wait, yes I do understand why. o:-)
[1] https://www.dailymail.co.uk/news/article-4438800/Uber-s-CEO-...
Seeing what's going on with Facebook and Google I guess Apple didn't pay much attention to this.
The whole point of enterprise certificates was to allow creation of internal apps that even Apple shouldn't know about.
I think most/all of the companies in the program would say it's about controlling the distribution of their apps, since putting them on the App Store would expose them to the public, and less about hiding from Apple...
I mean, the program exists for a reason.
In both Google and Facebook's cases, they were using it to distribute apps to the public at large (i.e., users with whom they have no business relationship) simply because they couldn't get the apps into the app store to begin with because they would otherwise violate Apple's rules. So not only were they flagrantly disregarding the ToS of their enterprise certs, they were doing so in order to violate Apple's rules for app distribution. Less than great.
(also, what Apple allows you to run on your own device is actually a different story, not related to this news)
XX% of Google employees are non-technical
XX% of Google employees don't use Mac as their laptop platform
XX% of Google employees have a locked-down Mac that isn't allowed to run XCode or locally-compiled binaries because their job role isn't in Engineering
Or stop abusing the terms of the enterprise certificates.
And know that Apple has your back when it comes to holding developers of the apps you use to their commitments.
There’s a clear benefit to the reputation of a vendor being on the line for the security and quality of their product and the services offered on it.
I mean, yes, we shouldn't buy iOS devices. But we should accept that things have ad hoc vendor-controlled "rules" just because someone baked them into the things, either.
> what Apple allows you to run on your own device is actually a different story, not related to this news
How so? It's not like Facebook and Google were hacking their way in here. They asked users "please run this software" and users had the option to do so. Seriously how is that any different than "please run my great jailbreak environment" or "here's a new OS for your iPhone"?
It was the behavior and marketing of these spyware things that we shouldn't like, not their mechanism.
Technically correct. But software running on "things" has terms. It's called a license. When you buy a movie, you don't own the film. You own the right to use that film in accordance with the license.
The question you're sidestepping is whether a license can say "you can't run your own software on your own thing". Obviously it can be implemented to do so given the way computers work, but it's not at all clear why that should be so.
BTW. I ignore that and even many large, respectable companies ignore that, but it's there ;)
IBM has had contracts for decades that govern use of your software on the hardware you bought from them. You buy CPU hours or the right to use a certain amount of the computer for a specific timeframe. One place I worked at had a mainframe that they could not use for production workloads unless a disaster declaration was made.
They’ve been litigated and are valid.
True, but you entered in a contract with the app developer and they are bound by one with Apple.
Apple’s right to act on iOS devices is in virtue of them being a service provider to google more than the company that sold you your phone
... wat? No, I didn't. It's easy to imagine I "must have", but in fact there's no signature, no negotiation nor in many cases any consideration.
Ah, but you say: I must have signed a contract to use the app store that I downloaded the app from, and that must constrain me to honor the terms of the app that I downloaded, which is constrained by Apple's contract with the developer.
Except, no, I didn't do that either. The whole thing is a house of cards. There is absolutely no principle behind this regime, it's just something we've all come to accept because it's technically possible and because "usually" the power granted to hardware vendors hasn't been abused.
But it has bad side effects too, and it's really important that we as a community not lose sight of the fact that locked down devices are really, really bad.
Do you have an Apple ID? You need an Apple ID to download apps from the App Store, and when you create the Apple ID, you accept their ToS. So, yeah, I think you did.
Though that ToS has absolutely nothing to do with anything we're discussing -- the ToS that matters here is the one between Apple and Google/Facebook.
> ...and that must constrain me to honor the terms of the app that I downloaded...
I don't think Apple's ToS with you constrains you to honors the terms of the app you downloaded. That seems strangely indirect. I think the app may or may not have their own ToS that they make you agree to at some point before permitting you to use their services.
Facebook and Google did sign it and distributed their software based on it.
> It's not like Facebook and Google were hacking their way in here.
They literally did (in the legal sense).
But of course, it's a battle of two evils here. Both sides can just nuke each other if you ask me, I won't miss them ;)
I think we're talking past each other here. I'm not talking about how Facebook and Google's spy kits were licensed to the end users or about their compliance with Apple's own vendor license.
I was pointing out that the principle here is that I (and Facebook and Google) should have the ability to write and distribute software for you (and me, and Facebook and Google and even Apple) to use on your iPhone. And that the fact we don't have that ability is bad.
And more to the point the fact that Apple's control over their platform was used to benefit the public by disallowing spy kits still does not make that control a good thing.
Free speech doesn’t allow libel and slander. Free assembly doesn’t allow riots. Without a framework for meaningful justice, the high minded principle is just a race to the bottom.
I should be able to have the freedom to choose a platform where I have some protection against the various bad actors out there. Without Apple, the only options we have is non-participation, believing the lies, and arbritration.
What? Very absolutely it does. It just doesn't protect from the consequences.
Sure they do. You want a gun? That comes with certain restrictions on what you can do with it. You want a car? There are certain restrictions on what you can do with it. Jet? Restrictions. Schedule 1 drugs? Restrictions. Knives? Restrictions. Fireworks? Restrictions. Cameras? Restrictions. Hell, even when it comes to a 2x4, there are rules about what you can and can't do with it -- you can't hit someone with it, or you'll suffer consequences.
It's the golden cage that allowed them to do of course good things this time. This argument is the old one against a walled garden and it still stands.
that's the problem - why should this service exist in the first place? It's extortion to have to pay to distribute apps to people who want them, on devices they own themselves.
Except if they force Apple to nuke all of their apps, which would put Apple in a difficult position. But perhaps Apple could sandbox apps, and prevent them from doing stuff that violates ToS.
That's what Apple is doing here. Pushing iPhone as a commodity, not a replacement for your macbook. This way they get the benefits of controlling the experience as much as they want. (I am not saying it is right or wrong, just that many people are fine with commodity phones and don't care for the loss of configurability).
Now, _will_ I do that? Probably not, but my opinion is that as the owner of the device, I should have the ability to do so if I so choose.
And what about the manufacturer? Why should it be their legal responsibility to satisfy your whims for programmable interfaces?
Not to mention what you're mentioning that what you're suggesting will make the iPhone incredibly insecure.
Regarding security, that very much depends on your threat model and definition of "secure". Indeed, I see this general trend of decreasing user control over increasingly complex and connected hardware as a massive security threat where I am forced to trust multiple 3rd parties who may arbitrarily disrupt my life anytime new "features" or "policies" get pushed out.
It is perfectly possible to securely implement a tamper-evident "I know what I'm doing" switch/fuse that enables advanced control by device owners. However, I'm well aware that I'm in the minority on this topic, so I'm not holding my breath for such features to be implemented.
Yes. It is within my full legal right to install whatever programs I want on my washing machine.
Apple lost a bunch of lawsuits, when it tried to sue people for doing this. The courts proved that yes, you do have a legal right to do whatever you want with hardware that you own.
That said, I doubt washing machine microcontrollers use signed code. It's easier to modify them than your phone which is completely backwards.
But that's not what this is about. Apple has been enforcing these rules for years. F.lux tried to get around the App Store by reaching users how to sideload via Xcode. Apple killed it.
The big players should be subject to the same rules. If they want to run their own code, they can't just flagrantly ignore Apple's TOS.
I'm also onboard with the Nielsen metaphor but not for kids. And both were scummy in targeting kids (though FB was definitely worse judging from marketing materials).
Specifically, Apple killed it because f.lux decided to distribute their app in a really sketchy manner where they essentially pushed an opaque binary blob to the phone rather than compiling the app from source and installing the build product from that.
How do you protect against that backdoor being used by hostiles?
I say this with an unlocked and de-googled android phone next to me, and several hacked arm devices at home. I OWN THEM, with no doubt, so I agree with you in a different world.
But the terms of this license are by no means "protecting" users who voluntarily chose to install these apps for payment. A license can have multiple legitimate purposes, including protecting the business interests of the licenser. There's no need to pretend that Apple is protecting users in order to defend their actions here.
Apple found themselves in a position were doing "the good thing" aligned with business.
Do you?
And atm, you couldn't on a locked down device.
FTFY
There are quite a few Apple users who like the hardware, the operating system, apps which are iOS-only, and the integration with other Apple devices - some of whom also want to run their own choice of software as well.
There's no alternative which has equivalent benefits, if that's what you're looking for.
(NB, I don't use an Apple phone personally).
I sideload stuff on my phone quite frequently.
Xcode 7 and iOS 9, and yes, you can still do this.
They are anti consumer and anti developer, buying from them is bad capitalism.
There will always be the possibility that some company will ask users to their absolute freedom ability to give them absolute freedom. Which is basically exactly what happened in this case. The only difference is, in this case, Apple built in a mechanism where they can stop individual actors.
And, to protect their users, they used it.
I think an interesting question is: What is Apple's best move from here?
I would suggest that Apple should leave Google/ FB blocked for ~1-2 weeks, to remind them who's boss on the iOS platform. However, I would argue it'd be smart for them to switch them back on after that- there's a chance that this looks anticompetitive to regulators at some point, which isn't something Apple wants to mess around with.
The reality, though, is that this sort of behavior in VERY large, VERY influential companies is going to draw way more scrutiny than a small company getting crushed by one of the big guys.
In general, Apple, Google, and Facebook are 3 of the largest technology companies in the world. In general, they have areas where their interests overlap (messaging as one good example of this).
Hindering the ability of Google/ FB to develop on iOS could absolutely be seen as an anticompetitive measure by Apple.
- Utilities that are only useful to employees of those companies (cafeteria menus, shuttle schedules, resources for salespeople on the go, etc.).
- Pre-release/testing (aka dogfood) versions of the apps they distribute to the public, for employees to use and find bugs on before they make it out to normal users.
Neither of those are pools that Apple wants to play in.
...and I guess there's a third category:
- Apps used gain "competitive intelligence" and spy on users.
I wouldn’t even look at it from an anticompetitive angle or anything like that. This is a matter of what’s best for apple and its users. They should absolutely do what’s needed to ensure that their terms are obeyed. But permanently banning google is not “what’s needed.” What’s needed is merely to demonstrate that the behavior will not be tolerated going forward. I imagine discussions between corporate lawyers and perhaps a reasonably sized bond would be sufficient to demonstrate google’s sincerity in not repeating the error.
By making this problem last long they aren't doing anything useful either.
- Bad case, they never restore certificates to G/FB and they end up losing all their employees to Android, with likely ripple effects in their tech sphere of influence.
- Worst case, G/FB retaliate by removing their apps from iOS and it's all out war with everyone losing.
- Best case, they restore them tomorrow with some fanfare and handshakes, but thousands of smaller companies now have been reminded Apple may actually shut them down if they misbehave.
This sounds counterproductive, as opposed to enforcing rules consistently.
There's no actual legal requirement that your company offers the same service that you use your market control to prevent your competitors from offering.
This is especially relevant in the markets where Apple has a significant market share (USA).
A convenient and inexpensive mechanism for installing apps to lots of other people’s devices has, however, been revoked.
You can create devices and sell them and not make them compatible with other companies products if you want. It’s true from printer ink to PlayStations.
The only issue would be market share and monopoly problems, which given that Google’s alternative platform has 54% of the market is totally irrelevant here.
One sort of "rubbing their nose in it" term could be something like a large donation to some sort of privacy advocacy group or similar.
You mean like the terms of the Enterprise agreement? The terms that were already agreed to?
Perhaps Google should shut down ever one of the servers that Apple is renting from them, for a couple weeks?
Or just block everyone on apple's campus/IP addresses from having access to any google services, search engines, ect?
The 2nd one probably wouldn't violate any contracts, so I don't see a problem with it.
The fact that you cant reach a human if you are a "user" tells a lot about values at Google.
This would sure save a lot of unnecessary network usage and bandwidth charges, not to mention it would be useful when you do not have network connectivity.
What is the reason if any why users should be prohibited from doing this?
The question is why every time the user wants to look at a map she needs to let Google know, using computer network access for which the user must pay.
Paper maps or maps stored on physical media do not have this requirement. The map company may "own the map" but the purchaser can look at the map anytime she wants, without any ongoing expense to keep the map company abreast of her travel plans.
I do not not use an "account" or "log in" to view free maps, so I just take screenshots as a quick workaround.
If you take a picture of Google Maps and then host it on your website without approval/paying Google and get caught you'll be hearing from their copyright lawyer.
I could take a picture of a map and share it on my LAN via httpd so all my computers can access it. I am the only user on the LAN.
It is not the "website" aspect that would implicate copyright, it is the redistribution, e.g., via a website on the public internet.
My original question is being misunderstood. It is not about copyright or what rights Google has in maps. It is a question about why Google attempts to force users to contact them every time the user looks at a map.
Details matter. Don’t leave them out.
It's not just apple either. Using facebook, gmail, anything in the cloud and/or anything hosted, basically anything not under your control exposes you to the same risk. Most people don't care until it becomes a problem for them and by then it's too late.
And let's not forget that google weren't working with apple, they were working around them.
This isn't a single person choosing differently. Employees and consumers buy and use iphones and Google has no choice in avoiding them. Doing so will only hurt their business, and they don't exactly have the leverage to demand whatever APIs and access they want.
This change did nothing to individual phones.
This simply prevents two organizations from deploying applications to phones with specific certificates. That's all.
Apple can't physically confiscate the phone or the data that you put onto it's hard drive (not talking about iCloud). It's yours. You can put linux on your iPhone if you want and there is nothing Apple can do about it.
They can control which apps can and cannot run as long as those apps are intended for internal use by enterprises. That seems reasonable imo, given that these apps are also not subject to any approval process.
Because there should be no 'terms' as to what software you can install on your devices.
BMW can make 'terms' so that if you mess with your audio system, it's not under warranty, but otherwise it's your car.
Also - 'the terms' are never very clear, and they can change on a dime.
Apple feeling some competitive heat? 'Just change the terms'!
Consider the collusion opportunities:
You want to use an Android - you have to give everything to Google. Don't like the terms? Apple colludes and does the same!
All of this is starting to get very close to anti-competitive kind of stuff, both between the big powers - and among consumers.
Things are obviously getting a bit ridiculous. Part of me thinks that something awful is going to have to happen before society stops these companies from pursuing everything they feel they need to.
Hopefully it won't be too late when that realisation becomes crystal clear to the majority.
I am hoping for a massive leak/scandal/Snowden moment when they finally cross the line and something happens that the lobotomized masses actually care about and cannot ignore.
Hopefully we end up with some sane legislation about how much mass surveillance of citizens by private companies is ok.
IMO, it is very, very wrong that Apple is judge, jury, and executioner in this case.
Also, in today’s world, this potentially could be disastrous, not only for the company affected, but also for the world at large, for example if Google depends on internal apps for informing employees about emergencies such as “hacking like activity on our servers or even “data center on fire”.
If Google depends on internal apps then they shouldn't have violated the terms of internal apps.
This is not true for major consumers of the API. They will call you and work it out. I know this from personal experience.
Because of two related points:
1) The apps in question would not be allowed into the app store by Apple in the first place.
2) People believe that Apple abuses its dictatorial power over the app store and that it should be a more open platform.
For my thesis, I was trying to load two Street View photos side by side in a browser to compare people's perceptions side-by-side. Google maps at the time required you to load a javascript viewer for each image you requested. Think Hot-or-Not for cities.
The experience needed to instantly load a new image after the user voted because I knew they were only going to be on the site for maybe 30 seconds before they got bored and went back to reddit. I needed to collect as many votes as possible within that time period.
So I knowingly broke Google's ToS and prefetched the images on my server so I could provide the user experience I wanted. "I'm a small operation. Surely they won't know." I wrote a server side screen scraper to load the Street View images and exposed the scraped images with an API.
Now my site was faaaast. I could load Street View images instantly and in the end got over a million data points doing this.
But then one day soon after it stopped working. Then I got a cease and desist email from someone at google legal. They didn't respond to any requests for turning it back on or even to discuss. Radio silence. That was terrifying.
Since this was my thesis, I needed help getting my keys turned back on. Google in the end was very accommodating, but only after I used my nuclear option: asking lab director Joi Ito to bug Megan Smith while she was still at Google to help.
I was connected to some engineer and told them what I was doing and why. They said stop. But then a week or so later, they sent me a beta invite to their new Street View images api, where you can feed in a lat, lng, header to a query string and they'll just serve the image now. Pretty cool.
Offending site for the interested: http://pulse.media.mit.edu/
I find the trick, when you're worried about this, is to use the regular API normally, but save the data that comes in from the normal usage of the API. i.e. Use the Google maps viewer and after the image is loaded, grab it however you have to, and post it to another API you've created that allows you to save the image. You're scraping their site, but you're not doing it in an automated way, and it should be undetectable.
After a while, you've got a good library of images from normal use. So you code up a switch that you can toggle that changes it from loading from the Google maps viewer to using your API to get images.
If you want to grow your image library, randomly assign some percentage of people to using the Google viewer (and save them they download), and the rest to your library of images you've accumulated. Or use a cookie or JS localStorage variable to track whether they are a returning person, and the first time always give them the quick library version, and if they return give them the Google maps viewer version (or just switch the percentages from 90/10 to 10/90, etc).
If they're willing to give you the data free within their ToS, there's very little technologically they can do to stop you from easily (or moderately easily, in the harder cases) storing the data. Worst case for someone looking to save it would be if they generate an image for the content and just serve the image, and that's not that hard to work around either, if the data is structured.
And while that’s not conclusive, they can just look at how your application functions to see what’s going on.
Oh, I'm not making any claim that it's legal. I'm just noting that if you've decided you want to scrape and are disregarding the ToS, there are ways to make it less likely to get you blocked.
> That said, this kind of thing is detectable. If users of an application are far less likely to download common data it quickly looks odd.
In the approach I outlined, you either load the Google JS payload and use it entirely as normal (and just do something extra with the data it provides), or you don't load it at all and run entirely locally. There are things they can do, such as embed analytical code in their payload to test for certain things, but it's just a cat and mouse game at that point.
> And while that’s not conclusive, they can just look at how your application functions to see what’s going on.
Assuming it's a public application (in this case it is), and that they have reason to look at it. If it's just spiky load, where sometimes there is load and other times there isn't or it's less, that's not really indicative of something odd going on, especially if you're relatively small.
Once the reasoning boils down to offense I know I am dealing with either intentional hostility or stupidity. Regardless of which of those is the problem I stop wasting energy thinking about it.
For people confused or further offended by this sentiment I suggest reading Principles by Ray Dalio.
This isn't some grey area where the details are difficult to ascertain. Everything is pretty clear; the enterprise app distribution service is most assuredly not for distributing apps that break the App Store rules to customers. This isn't difficult to understand, so I'm struggling to see where people are trying to find some sort of detail to exonerate two well-known, repeated rule breakers, violators of personal privacy, and altogether companies who think their size puts them above reproach.
I mean, when Apple makes a big screw up, everybody leaps on it, even when it's just based on unconfirmed (and sometimes fabricated, like the journalist reporting on conditions in the Foxconn factories) reports; but if it's Facebook or Google, somehow they're underdogs with clean records, deserving of the benefit of the doubt? I don't swallow it.
How about we all just pass judgement equally upon the big companies, Apple included, for their foibles? But let's also take into account when these companies have been caught red-handed before, and if the best punishment we could muster was a slap with a wet bus ticket, let's not umm and ahh about why they think they can get away with their behaviour, and not be at all surprised when finally someone takes a stand on their own territory.
They're outraged because they have no recourse. What they usually do to users or partners, dictate take-it-or-leave-it terms, is being done to them. They can't even complain to antitrust regulators because Apple is only lord of its own kingdom (which doesn't have market dominance).
Do you think Facebook's right wing oppo research firm would balk about leaking a story that a competitor's phone is vulnerable? Absolutely not.
The point being made is that the blackmail is unsaid and implicit.
I think our support that we get is probably quite different than the support Apple gives to the developers of Google and Facebook, who make most of the top 10 apps downloaded from the App Store.
I have since left the startup, but as far as I’m aware they are still continuing with this practice.
>A Google spokesperson told The Verge, “The Screenwise Meter iOS app should not have operated under Apple’s developer enterprise program — this was a mistake, and we apologize.
https://www.theverge.com/2019/1/30/18204064/apple-google-mon...
It's hard to tell exactly how long the iOS app has been available, but I found version 7.x of the Android app all the way back in 2015 on APKmirror (it's archive only goes back so far). So presumably the mobile app strategy has been around a long time.
As mentioned in a separate Verge article-
"One giant platform declared another giant platform’s market research program inappropriate, then disappeared it with a Thanos-style finger snap"
also from same article, attributed to Nilay Patel
"Hi, I’m the nagging voice in the back of your head pointing out that it’s pretty intense that Apple can simply decide to prevent people from running code on their phones."
Edited for punctuation
Google can make the terms of use "None of our services and any kind of services deployed on Google Cloud may ever be displayed on an Apple device" and it will have the same legitimancy.
I don't know why there's so many people who think putting something in a bullet point as a policy/law just makes it somehow different.
The difference is that Facebook and Google agreed to and were fully aware of the terms beforehand.
Remember those cyberpunk stories where not the elected governments but rivaling multinational companies are the law? This is how we get there.
Heh. They already have, to Amazon though. See all the petty fights Google and Amazon have engaged in over youtube, chromecast etc. This is a good PR move by Apple though, especially when game studios are clawing out of the 30% cut and people are beginning to ask for the right to repair or the ability to side load apps. Apple saves the day yet again by providing value through the app store.
The terms are very clear. Apple wants to control distribution of apps, the enterprise program is only supposed to be for employees or for end users using under the direct personal supervision of an employee as part of an in office test. The conditions are clearly defined.
Given that the users of the app in question were being paid by Google, one could argue they are employed... or at least are contractors.
On the other hand, given the users did not have the rights generally associated with being an employee or a contractor... and they were not even getting minimum wage...
But at that point IANAL and courts would need to decide
Google or FB isn't going to touch that with a 10 foot pole, and no there is no need for courts to decide, they don't want these users considered employees or contractors in any way. Also monetary compensation is very common in some research industries without said people being contractors or employees. Simply put Google and FB F*up big time in violating the TOS.
"Your company, organization or educational institution would like to use the Apple Software (as defined below) to develop one or more Internal Use Applications (as defined below) for Apple- branded products running iOS, watchOS, tvOS, and/or macOS, and to deploy these Applications only for internal use within Your company, organization or educational institution or for limited use as expressly set forth herein."
https://developer.apple.com/terms/ → Apple Developer Enterprise Program License Agreement
You are a "contractor" if you are providing services under a contract. A contract exists whenever there is a definitive agreement to exchange valuable considerations – even in the absence of a written, signed contract.
But the sign-up for these apps might have included an explicit "signing" phase! (It's even possible that FB/Google asked for participants' SSNs, just in case any payments went over $600.)
(And if they’re under any sort of confidentiality agreement or other conditions on their app usage, they fit under the Apple terms’ concepts of “Permitted Users” and “Internal Use” even better.)
Further, some stories have reported that Facebook says they acquired such parental permission for the minor participants.
Additionally, the minimum age for non-agricultural workers is 14 anyway, so even then they're in the wrong and can't legally hire 13-year olds as contractors or employees. There's also several other rules in the FLSA pertaining to workers under 18 including minimum wage. I have a sneaky suspicion $20 per whatever period it is (unless said period is a few hours) is going to be under that wage.
Not to mention there's a whole lot more can of worms being opened specifically around minimum wage and recording hours that I highly doubt either Facebook or Google were actively managing.
I've never seen that relationship result in anyone being called a contractor and I've signed too many film contracts. I don't know where OP is getting this notion.
Here you can see a VentureBeat reporter – and one who is actually a member of the California State Bar of Attorneys – raise some of the same questions as I have:
https://venturebeat.com/2019/01/31/the-odd-reason-apple-kill...
Late in this article, you can see Facebook's statement that all minors who participated did so with signed parental consent forms:
https://gizmodo.com/facebook-is-paying-teens-to-install-a-re...
Facebook's statement: "Key facts about this market research program are being ignored. Despite early reports, there was nothing ‘secret’ about this; it was literally called the Facebook Research App. It wasn’t ‘spying’ as all of the people who signed up to participate went through a clear on-boarding process asking for their permission and were paid to participate. Finally, less than 5 percent of the people who chose to participate in this market research program were teens. All of them with signed parental consent forms."
It’s behind the developer wall but the whole thing is here. https://download.developer.apple.com/Documentation/License_A...
Compensated members of these apps' research panels are quite literally "contractors" of FB/Google, and possibly even under written contracts that explicitly limit the apps' use as Apple requires. So what you've quoted doesn't demonstrate a violation.
The only provision I see that's close to what you're talking about is the definitions section, which provides that Permitted Users include "contractors . . . who have written and binding agreements with You . . . to protect Your Internal Use Application from unauthorized use"
It's quite the stretch to say that this language, which by its text limits contractors to authorized uses, somehow expands the scope of authorized use. Even if you could get to that conclusion, it would not be "expressly set forth."
"Internal Use Applications or Passes developed using the Apple Software may only be deployed to and used by Your Employees or Permitted Users for internal use purposes or for limited use by Customers on Deployment Devices on Your (or Your Permitted Entity’s) physical premises or in other locations when the use is under Your (or Your Permitted Entity’s) direct supervision and physical control as set forth in Section 2.1(f)."
Is it being used by "Permitted Users", which is elsewhere defined as including "contractors"? Yes.
Is it for "internal use purposes"? An internal customer research program, which is a cost-center and involves compensated research subjects, where the data is kept internal-confidential – and where perhaps even the research-subjects are under various kinds of NDA – is pretty "internal use" from my perspective. So, yes.
There's the "express authorization" that the following sentence doesn't revoke.
(Even the 2.1(f) allowance for customer use might be satisfied if the app has a central monitoring/disabling switch that counts as "direct supervision and physical control". But that's a little murkier, and the 2.1(f) allowance isn't strictly necessary for this use by compensated research subjects.)
It is not defined elsewhere as including contractors. It is defined elsewhere as including contractors who use it for authorized purposes. The bootstrapping you're attempting here is circular reasoning.
“Permitted Users” means employees and contractors of Your Permitted Entity who have written and binding agreements with You or Your Permitted Entity to protect Your Internal Use Application from unauthorized use in accordance with the terms of this Agreement.
If the research panel subjects were under a written agreement to only use the app in the manner it was intended – such as keeping aspects of its use confidential, or disabling it when other non-compensated others were using their devices – doesn't that match the definition? Or are you claiming some other "circular" bootstrapping of extra fuzzy limitations on what "Permitted Users" are?
I'm not sure how it could be much clearer that this is not intended to be used to distribute apps to customers.
> "Internal Use Application" means a software program (including extensions, media, and Libraries that are enclosed in a single software bundle) that is developed by You on a custom basis for Your own business purposes (e.g., an inventory app specific to Your business) for specific use with an Apple-branded product running iOS, watchOS, tvOS, and/or macOS, as applicable, and solely for internal use by Your Employees or Permitted Users, or as otherwise expressly permitted in Section 2.1(f). Except as otherwise expressly permitted herein, specifically excluded from Internal Use Applications are any programs or applications that may be used, distributed, or otherwise made available to other companies, contractors (except for contractors who are developing the Internal Use Application for You on a custom basis and therefore need to use or have access to such Application), distributors, vendors, resellers, endusers or members of the general public. For the sake of clarity, Internal Use Applications do not include third-party applications even if some customization has been done.
There's other damning bits later in the license agreement, including:
> You must provide clear and complete information to users regarding Your collection, use and disclosure of user or device data, e.g., a description of Your use of user and device data in the Your Internal Use Application.
and
> Notwithstanding anything to the contrary in Section 3.3.9, You and Your Internal Use Application may not use the Network Extension Framework, or any data or information obtained through the Network Extension Framework, for any purpose other than providing networking capabilities in connection with Your Internal Use Application (e.g., not for using an end-user's Internet traffic to serve advertising or to otherwise build user profiles for advertising).
I don't see the definition of "Internal Use Application" as clearly prohibiting app usage by these research panels – paid contractors of FB/Google. And, the disclosures to panel members may have met the "clear and complete information" clause.
But the limits on the "Network Extension Framework" usage might be a violation. I suspect FB/Google were effectively building "user profiles for advertising" with this data... though perhaps they could make a case that these specific networking hooks were walled away to a separate, non-prohibited purpose.
Even if you make the argument that the users of this app are paid contractors of FB/Google, they are not contractors who are "developing the Internal Use Application for You on a custom basis and therefore need to use or have access to such Application", so it still seems pretty clear cut.
And, other sections of the terms (just before that) expressly enable "a software program… for Your own business purposes… and solely for internal use by Your Employees or Permitted Users" – where, as noted, "Permitted Users" also was defined to include "contractors".
They're being paid for a product (their data). By what I'm gathering, I could define Netflix as my contractor for delivering my team streamed movies for $n per month... which isn't true unless a more specific relationship e.g. a c2c is put in place.
(Yes, when Netflix agrees to provide you with something in return for your payment, you've entered a contract with them, and they are your contractor. If somehow you were an US entity with 50+ netflix subscriptions for different offices, and thus paid them more than $600/year, you technically might be on the hook to file a 1099.)
Source. Now. Because I highly doubt this is accurate. I have never heard of someone having to file a 1099 for purchasing services, of any kind. Hell, half of everyone's time would be spent filing 1099s because as a society we spend far more than 600 dollars with any one company over the course of a year literally all the time.
You're using what is known as a "cute trick".
Judges are rarely amused by "cute tricks". Like a Sovereign Citizen believer you can keep claiming to be correct all the way to a loss in court, followed by denied appeal after denied appeal.
There’s no trickery here: that’s the ordinary legal meaning, and it is those who insist on only the far narrower regulatory/tax ‘contractor’ category who are playing semantic tricks.
It doesn't matter how many people "explain" falsehoods, like the idea that minors can't enter contracts (even with parental permissiion), or that a person being paid by a company under the terms of a contract is not a 'contractor'. They're wrong despite their multitudes.
Compare this account from a reporter at VentureBeat – who also happens to be a member of the California State Bar – who makes similar points as I have, about how compensated panelists are “arguably limited purpose ‘contractors’ providing data solely for the developer’s research purposes “:
https://venturebeat.com/2019/01/31/the-odd-reason-apple-kill...
Not since 2007 - http://members.calbar.ca.gov/fal/Licensee/Detail/215049
And his CV suggests he only practiced any law at all between 2001 and 2004 - http://www.jhorwitz.com/jhresume.pdf
Disingenuous of both him and you to claim he has any authority to speak from a legal point of view on this, really, no?
But still, a legal degree, one-time certification, and some legal practice are kind of relevant, compared to anonymous commenters who are just insisting by repetition "but that's not a 'contractor'!"
Is it your reasoned argument that an individual receiving payment for services rendered to a corporation, under the terms of a mutually-agreed contract, is not a "contractor" in the eyes of the law?
Ok, I'll remove you from the disingenuous. He stays though because he should definitely mention it on his CV.
> a legal degree, one-time certification, and some legal practice are kind of relevant
Yep, he's definitely probably got more standing than anonymous commenters. But that's a low bar. He didn't practice contract law (it was transactional IP) and it was 14 years ago - it's an almost certainty he isn't au fait with current contract or employment law.
> Is it your reasoned argument
I don't have one knowing nothing about US contract or employment law. My layperson viewpoint is that it's quite clear they weren't Facebook contractors in the terms of the Apple agreement.
IANAL, but I know the rough outlines of US contract and employment law as a frequent party to contracts, occasionally to disputes, and as a US person who has both contracted others and been a contract worker.
If you have a contract (which doesn't even have to be written), you're a contractor. Full stop. And, an agreement to provide payment in return for performing certain actions (like installing an app, leaving it running, answering questionnaires, maintaining confidentiality, etc) is a contract, even if it's a clickthrough agreement. Ergo, compensated research panelists are 'contractors' in the eyes of the law.
Yes, and I explicitly said I didn't have an argument but only my "layperson viewpoint".
> IANAL, but I know the rough outlines of US contract
Great. I don't care. Argue with other people about that. All I wanted to do was correct the perception that the journalist was a member of the bar and had some kind of legal standing.
> ...though perhaps they could make a case that these specific networking hooks were walled away to a separate, non-prohibited purpose.
They could not. The primary purpose of the Facebook and Google research apps was not to provide a VPN service; as such, using VPN services was a violation of the program terms. The use cases mentioned -- "to serve advertising or to otherwise build user profiles for advertising" -- are examples of prohibited use cases, not the full extent of the prohibitions.
You're looking for the "Apple Developer Enterprise Program License Agreement" — I found it in ten seconds. The only production applications allowed on the cert are internal applications ("Internal Use Applications developed for macOS can be distributed under this Agreement using an Apple Certificate or may be separately distributed.") Or applications under development (2.1 Permitted Uses and Restrictions, Program Services). Also outlined are explicit unpermitted uses and a general declaration that anything outside of 2.1 won't fly (2.6 No Other Permitted Uses, specifically "You may not use the Apple Software, Apple Certificates, or any Services provided hereunder for any purpose not expressly permitted by this Agreement,").
You'll need to sign in with your Apple ID to open this: https://developer.apple.com/services-account/download?path=/...
Hope this helps.
---
Edit: for anyone who wants to spare themselves the chain, OP is missing the distinction between vendors, contractors, and other service providers and is interpreting the presence of any contract as rendering a person as a contractor. In this case, it's likely (IANAL) that each individual user of the service would be described as a vendor selling access to their data. The data itself is not created for Google's (or Facebook's in that previous case) consumption.
https://www.quora.com/What-is-the-difference-between-a-vendo...
https://english.stackexchange.com/questions/248665/contracto...
--
Added in response to edit: The links to Quora/StackExchange, however, miss the point. Anyone who's entered a contract to provide a service in return for compensation is a 'contractor', both in legal terms, and in layman's terms. Facebook's description of their on-boarding, especially, suggests there was sufficient "meeting of the minds", mutual agreement, and exchange-of-valuable-considerations as required for a contract to exist:
Facebook statement via <https://gizmodo.com/facebook-is-paying-teens-to-install-a-re...:
"Key facts about this market research program are being ignored. Despite early reports, there was nothing ‘secret’ about this; it was literally called the Facebook Research App. It wasn’t ‘spying’ as all of the people who signed up to participate went through a clear on-boarding process asking for their permission and were paid to participate. Finally, less than 5 percent of the people who chose to participate in this market research program were teens. All of them with signed parental consent forms."
> Google’s private app was designed to monitor how people use their iPhones, similar to Facebook’s research app.
Googling this, I don't see references to 1099, W2, or Corp to Corp contracts which might help anyone say it's "internal." Paying someone for a service does not make them a part of internal operations of a company.
It's this Screenwise Meter app which got the certificate nixed, and with it, any other apps on that cert were shattered. The aforementioned app was a non-internal app used in a production capacity, which falls out of the bounds of test/dev/internal apps enforced by the contract.
Tl;Dr: Google had in service a production application using a developer/internal cert. This caused the cert to fall in scope for revocation.
If the mechanism for bringing participants into "Screenwise Meter" involved a contracted payment, it plausibly matches some of the expressly permitted uses, in the Apple Enterprise terms. (If it included an express written contract that limited the participants' use of the app, it further matches certain explicit requirements of the Apple terms.)
(There's another clause about using a specific "Network Extension Framework" that seems like a bigger problem for Facebook/Google, depending on what they likely did with that API and the info retrieved. But these clauses, about "internal use" and "permitted users", seem fully compatible with an internal-research-program using a panel of compensated research-subjects.)
They can't sign a contract. They can't become contractors.
Why do you keep fighting this? It doesn't even seem like devil's advocate anymore. :/
---
it's anyone "under contract".
It's not. I'm not an employment lawyer, but that's definitely not true. At all. Under any circumstances.
If you need help with it, check this: https://www.quora.com/What-is-the-difference-between-a-vendo...
But further, even if it was a violation if minors were involved, that'd leave open the question of whether use by contracted adults was compliant under the terms. (And supposedly the Google app wasn't offered to minors.)
And, paid research subjects meet the legal definition of contractor, as outlined here or elsewhere:
https://dictionary.law.com/Default.aspx?selected=939
Simply insisting "definitely not true" is not convincing.
In this case, it's likely (IANAL, nor are you) that each individual user of the service would be described as a vendor selling access to their data. The data itself is not created for Google's (or Facebook's in that previous case) consumption. The users of the service were selling rights and were not producing anything for hire.
https://www.quora.com/What-is-the-difference-between-a-vendo...
https://english.stackexchange.com/questions/248665/contracto...
---
This is becoming tedious. I'm out.
Inacceptable. Such a company should not be allowed to do business in EU. Much worse than what happened with Microsoft in the 90ties.
Your comment might make sense of Apple were some sort of government entity, but it isn't; it was completely Facebook and Google's decision to abide by Apple's terms and conditions, something that will have been pored over by legal team upon legal team. This is not something Facebook or Google will have entered into lightly, and yet they explicitly chose to break the terms and conditions.
If I run a restaurant and one of the house rules is that you're not allowed to harass my staff and make the dining experience unpleasant for other customers, and you do that, of course I'm well within my rights to throw you out.
Because they became too big. It's the right of e.g. the EU to allow them to operate. Or better said, the law could be changed to disallow operation if certainy conditions are not met. Apple then has the choice to either adapt or leave the EU market.
You're talking like the EU has one set of rules for companies from its members and another for others, but that isn't the case. The EU treats all monopolies equally; Apple isn't close to a monopoly.
Of the actors involved here, Google is the one that the EU is most concerned about.
Apple is only acting on their own turf, their services. Their reach is not far spread outside of the iOS landscape, heavily dwarfed by Google's Android at something like 85% share.
The problem isn't that Apple are allowed to throw Google out of the enterprise program; the problem is that Apple users aren't allowed to install Google's apps without Apple's permission.
It's fair enough to say that Google can't complain because they knew the terms of the enterprise agreement. But I'm not sure it's fair to say that Apple phone purchasers are clearly told when they buy a phone that Apple can disable their employer's internal apps.
Maybe, except that the enterprise app distribution system is a service provided by Apple. It has associated terms and conditions.
I'm not saying you're wrong, but I don't think it's the argument to be making right now; if the topic were jailbreaking, sure. As it is, it's about abusing a service. The enterprise app distribution system is not sideloading in the same sense as it is on Android; it is a service for a specific purpose.
> But I'm not sure it's fair to say that Apple phone purchasers are clearly told when they buy a phone that Apple can disable their employer's internal apps
For the individual employees, no, they probably don't know this. However, they have no real need to know; this is an implementation detail on the employer's end.
The employers 100% know about this, or else they wouldn't agree to the terms and conditions of the enterprise app distribution system. Legal teams will have pored over this. Nobody is ignorant of the implications of their actions; it just happened to be that two high-profile companies made the mistake of thinking they were immune to punishment.
But no, any company involved in the enterprise app distribution system knows 100% what getting that certificate revoked means. Especially a tech company!
Apple is not a state-owned company. They can do whatever they like, and you can choose to support them by purchasing their stock and/or their products. You can choose not to support them by purchasing neither their stock or their products.
There are several federal and state laws that define what they "can not do", and this isn't one of them. Why should a business owner(s) "not have the right" to run their business any way they see fit, so long as they do not violate the law?
Your analogy to MS doesn't hold water - MS was told not to do something by a governing authority, and they did it anyway. The governing authority stepped in and enforced their rules - nothing out of the ordinary there.
We limit what business owners can do for 'greater good' in quite some areas. I think it is necessary here too. Apple: enforce access, Android: limit data snooping.
Thats not really true. There are a multitude of anti monopoly laws and consumer protections that may apply to Apple's actions.
> Why should a business owner(s) "not have the right" to run their business any way they see fit
Because one company having too much market power, and being in an oligopoly type situation is bad.
Because we have consumer protection laws for a reason.
Because when a consumer buys a device, they have the legal right to do whatever the heck they want with it, and Apple tried, and failed, to sue consumers for doing things to devices that the consumer owns.
The courts have sided quite a few times in favor of consumers, regarding how they have the legal right to do what they want with devices that they own.
And if the current laws don't 100% cover this situation that we are in right now, then hopefully the law will be reinterpreted to apply to it.
But even beyond that, it makes perfect sense to criticize, and retaliate against, companies that hurt consumers, and try to take away their rights.
Apple is a chief offending, in just how many bad things that they have done, to try to take away consumer's legal rights to doing what they want with devices that the consumer owns. They tried, and failed, to sue people. This deserves to be criticized, and retailiated against.
If some app decides to include a crypto-miner, that burns up your battery, your sure going to want apple to yank that from all the phones, as quick as possible, not sit there an hope your pocket doesn't melt before you can figure out which app to uninstall.
It's my device, if I am fully informed and decide to run a crypto-miner application I should be able to do so. If I want to run 'In A Permanent Save State' [1], Apple shouldn't be allowed to censor this (not that I would agree with the subsumptions in that app, but that is not relevant here).
[1] https://www.forbes.com/sites/timworstall/2012/11/13/the-very...
no - you are free to run any code on YOUR phones with the enterprise program - you are clearly not free to run any code on OTHERS phones using this program..
As a user, I can not choose what code to run on my iPhone.
The only way to run a non-official app would be if the app was open source: put it in testflight for your personal use.
This is the main reason I have sworn off all Apple devices.
If someone won’t give you the code, but instead will only supply it via Apple’s store, that’s between you and the supplier.
That is a very limited subset of iPhone users.
The only reason Fortnite used Apple's app store is because Apple has made it practically impossible to side load apps.
What’s difficult is to distribute commercially, or maliciously without going through Apple.
https://www.theinquirer.net/inquirer/news/3063669/google-is-...
If, as you admit yourself, Apple is far better in terms of privacy, would it not be helpful, even if they are not perfect, to praise their (relative) sainthood and bury them with money?
That way, they would be reward for their strategy, might double-down on it (maybe even achieving perfection in your very smart and perpetually critical eyes), and inspire others to follow their lead.
In my mind, a reasonable settlement includes not installing spyware on users' iPhones through the enterprise development program, so it looks like they're doing precisely that.
I think a mistake to make here is thinking that Apple gives a toss.
I would say rather to avoid laws it's to avoid appearing as a commodity and losing its "fashion" or "hip" status. If everyone has an iPhone suddenly it is less desirable to own an iPhone.
Apple’s business model is selling high margin products. More share requires lower costs, which increases operational risk and reduces profitability. That’s why Apple stock is cheap compared to other big tech companies... a problem with execution today has a bigger impact than a company like Google that has a stream of revenue from ads on every platform.
You’re going to see changes in the model as they are hitting a growth ceiling, but they’ll probably take a different services path than Google.
I think that in this particular case, Google overreached, it's an inconvenience to them, and they'll roll it back. In the general case, though, Google's got way more power than Apple (and more than most nation-states) and they just haven't been called on it yet.
Does that count ad revenue from ads running on smartphones?
Apple’s market aligns with the most profitable markets for Google.
[1] https://deviceatlas.com/blog/android-v-ios-market-share#us
From "The State of Mozilla 2017" https://blog.mozilla.org/blog/2018/11/27/state-of-mozilla-20...
Today, the majority of Mozilla Corporation revenue is generated from global browser search partnerships, including the deal negotiated with Google in 2017 following Mozilla’s termination of its search agreement with Yahoo/Oath which required ongoing payments to Mozilla that remain the subject of litigation.
Not really. If any lone developer/small company did this, Apple would have banned the whole developer account.
Sounds like you just confessed to violating Apple's terms.
The argument is somewhat moot, anyway. Apple has simply decided that privacy is a tenet of their value proposition, that value is reflected in their contacts granting in-house certificates, and these companies broke the terms of these contracts.
Yeah, that's just marketing. If they really cared, they wouldn't accept a 9 billion dollar payout per year to make Google the default search engine for IOS.
Apple is likely shooting themselves in the foot here. These companies' IT departments will no longer be able to support iOS devices for accessing intranet resources, which means no engineers will be using iOS devices as daily drivers, which means their iOS apps will fall further behind their Android apps in quality.
Apple's platform, their rules.
I'd rather Facebook feel the hurt for its audacity than Apple be forced to backtrack because they made too many enemies.
In what way does Apple have anything to fear from FB or Google, or even depend on either of them at all? Where is the "force" going to come from, their users threatening to switch to Android? I don't think these incidents would be enough to lend that eventuality any weight.
That's your only two options? Sounds like you've already made your decision.
At the end of the day, you can compile and run anything on your machine. This is just regulating distribution. Given the specific breaches at hand by Facebook and Google, a balance seems to have been found (acceptable to most users) between freedom and security.
It's free to get one though, but it only lasts for a week or so. You can pay to become a developer and I think you get one that lasts a year instead.
I agree that Google Play Services is not competition friendly, but that is a different topic.
The installer is a piece of software made by Apple, to install things that meet certain criteria(ie signed packages). It's not that you can't technically "install" other things, but there doesn't exist a mechanism to do so.
Not really. You have to pay the ransom^W^W$100 for a developer account every year.
Iff you have a Mac. And even then, you need to recompile it every week.
I'd prefer something else for my personal toy applications so I don't even need to bother with this, but it's not a huge deal to me.
The advantage of the Free Profile is that (afaik) it can't be revoked or censored. Disadvantage is 7 day lifespan.
So far they have used the power sparingly, at the end of the day it could have been a cute cat app and did nothing wrong but it still broke Apple's terms that these companies agreed to and Apple acted accordingly.
It will cost $500 to ditch Apple and replace them; there’s a 10% chance I will have to switch before I’d make my next purchase anyway; and Apple has to date saved me over $50 in frustration via their control of the ecosystem.
So I’m willing to ride it out and see what happens.
With the above said, we can certainly discuss if Apple should use/have this ability at all. But, IMO it is a different discussion.
This kind of behavior from executives[0] is precisely why I invested in Apple products in the first place — why I took the risk at all.
I meant that I don’t see this as any reason to get out, from a pure “well, what if they abuse their power?” perspective: the risk is low, given the way they’ve acted until now, and the total possible cost is reasonably bounded — I’ve already had enough upside to eclipse the risk weighted cost, this was a good investment.
So why would I even worry about it until something bad did happen? The homo economis answer is to let your bet ride, until the point you were going to re-evaluate anyway, when buying a new phone.
[0] There is approximately 0% chance Google and Facebook were kicked out of dev programs without running it by senior executives.
If you don't, we end up going back to the Blaster worm days of 2003, where software gets installed and regular people don't know how to get rid of it.
I'll do it for you: both Facebook and Google were crystal clear violations. Like, not anywhere close to the intended use case for Enterprise distribution
This is basically what I want, most of the time, and it's hard to achieve it outside the App Store.
IIRC Chrome even asks you if you want to enable that setting once you download an APK file.
And why this extreme generalization, exactly? Don't you suppose you could have privacy, security, and perhaps even simplicity and ease-of-use with a totally free and open phone that grants control to the user? You really don't explain how "a totally open platform" is mutually exclusive, nor how your own personal needs require the inverse of freedom. Further, the distinction between computer and mobile device are irrelevant given so many people depend on the later as their main computing device. They should be offered the same degree of control as someone with a computer has.
Ultimately, you cannot have privacy and security in a closed-source restricted platform, even if it's backed by good intentions. You're at the mercy of a few companies and as soon as they abandon the device, or make a mistake, you're exposed. And as a consumer, you're forced to buy into their ecosystem instead of having the choice to provide your own solutions. This is already true for the hardware, such as the black-box baseband required to connect to cellular networks.
While this kind of support doesn't technically preclude open-source code, it's hard to find both in one. Red Hat is one rare exception to this - providing a comprehensive, supported solution that also happens to be open-source. But the economics tend to push it to be one or the other. In this case, I'm perfectly fine making that trade.
Phones are more then likely the workstations of the future (when we figure out how to use them more effectively then the workstations).
The problem with that is that the nature of the issue is that it doesn't matter to you ... until it does. Like freedom of speech - you will never notice that your government is censoring you until you have a controversial viewpoint. And then it will matter. But all the people without those viewpoints will still wander around saying they can't see what all the fuss is about freedom of speech. This is intrinsically a problem you have to care about in advance of when you need it.
>Workstations need to be totally user-controlled,
I believe chromeOS is a good example of a stripped down less tunable OS that works great and is perfect for inexpensive Atom based machines that still have good build quality, battery life, and displays while being simple to use.
I believe trying to push the "store" model to desktops smacks of a solution that generates a lot of $$$ for M$ and Apple in search of a problem.
That being said, the official channels are sanctioned and sponsored by Apple (or Google) and so it is their reputation on the line when it comes to malicious or questionable Apps.
So I can completely understand Apple (or Google) removing certs or banning companies for violating the terms of their platform.
And I think this exertion of power might be a bad thing as it demonstrates that users do not really own their devices and are only allowed to do with them what Apple (or Google) permits.
My device is little more to me than something to run a web browser. I despise native apps. Facebook and Googles apps can - and should IMO - be run from a browser without crossing over into my personal contacts and photos.
Apple has zero authority over who I contact or what content I access over the web.
With any luck, this drives development back towards the web. I haven't had Facebook on my phone in years because their mobile layout is unbearable and their apps are invasive.
Why?
The last straw for me was when Facebook messenger pocket dialed a "friend" I hadn't talked to in 7 years. Not only was it something I had no use for, it was outright invasive.
I'm disagreeing with the premise that you have to develop for their platforms and distribute for it. That's not a fact. That's an opinion. While there may be some apps that _couldnt_ operate on the web, 99% of apps don't fall into this.
Facebook. Instagram. WhatsApp. Gmail. Google maps. Pinterest. These can all be done in a mobile friendly way in browser. They're intentionally not done because of "performance" and the fact that apps want deeper access to the device.
I don't want any or those apps getting access to my GPS. Or my files. Or my contacts. Id rather take additional steps to upload a picture, or type in my "from" address rather than auto-GPS.
You're setting your argument up for failure before you even present it when it's foundation is a clear and intentional misinterpretation of someone else's words.
Very, very few apps need to be developed natively.
The vast, vast majority would be better if developed for the browser.
This obviously depends on exactly what you're talking about, I concede there are some specific applications that require it. Maybe _your_ specific app requires in, in which case, _you_ have to live with the trade-off of the gatekeepers.
Mostly, it's a self imposed prison.
I never said anything of the sort, you're again manipulating what was said to give you an opportunity to stand on your soap box. I said Apple and Google control the distribution channel and have an interest in protecting it.
Web Apps are at a distinct disadvantage on both platforms because Apple and Google control the channel to dissuade them from reaching mass adoption.
If anything I said that these actions might actually help Web Apps.
I don't complain about my Xbox because I can buy a computer that can run most the same games where I can do anything I want (not to say I don't want to be able to do anything but phones are a much bigger market with only 1 real competitor which does allow you to side load apps)
I don’t want to put words in your mouth, but to paraphrase in saying there is ‘only one’ choice in the market that is truly open you seem to be arguing that any second option ought to be too. That competition on openness is more important that there even being a closed option at all. Surely that would give consumers less choice though, not more?
But as I have pointed out, there have been plenty of other options and every now and then a ‘truly’ open phone comes out again.
This control is a feature and one of the reasons I use iOS. I value a system I can trust to be free of malware. I know that when I recommend iPhone to friends and family, I will never have to field a support call involving a mountain of malware that was installed because they were tricked into clicking “ok”.
I trust my iPhone way more than my desktop, laptop, or any SaaS. Same with my iPad. I can’t wait for the end of the era of bad-guys-win-by-default.
typo i think but totally alters meaning
At the same time, maintaining that level of control seems to be a central feature of iOS's security and privacy model. It's not just about ensuring that only trusted software can be installed in the first place, it's also about having some sort of mechanism for fixing the problem when software that had previously been approved proves to be malware, or when a publisher who had previously been approved turns out to be a bad player.
For an example of what's possible in environment where you aren't limited to running trusted software, earlier this week I had a conversation with an acquaintance who had recently paid hundreds of dollars to a ransomware scammer. To me, the value of being able to prevent those kinds of abuse is pretty straightforward.
What Apple's doing with Facebook and Google is grayer, but I can see where they're coming from. They have strict privacy rules that they expect to be followed on all apps released to the public, and Facebook and Google were using the enterprise program to circumvent those rules. In light of that, you could argue that they had to follow through on their terms of service in order to demonstrate good faith to their customers who rely on them to enforce those privacy rules.
https://www.recode.net/2018/9/12/17848384/nicole-wong-cto-la...
But in reality, to yield this kinda of power, you MUST apply it equally and fairly. Apple has been far from a fair arbiter in its app platform.
I unplugged[0] from Google Last year - went DDG for search, went to iOS, dropped gmail for fastmail, etc. As time goes on I’m continually reaffirmed that I made the right decisions.
[0] I still use some Google services, like YouTube, frequently, some of my mail still goes through Gmail, albeit forwarded to my Fastmail account, and I occasionally use Maps.
In this case I'm voting with my dollars and paying a premium for a device made by a company that is, at least overtly, pushing for a bare minimum level of support for their customers.
It certainly doesn't hurt that they're nice phones too, though.
Some parts of the walled garden are annoying - having to go to the browser to buy Kindle books for example - but I think the tradeoffs of the Apple ecosystem are more than worth the benefits.
"Yup, getting consumers to bypass the app store and side-load our app is perfectly reasonable, no issues here. No way this could possibly backfire."
Only thing I could see is the PM's didn't actually understand what the enterprise certificate program was supposed to be for.
In my own experience people often avoid consulting legal when they think they can get away with it (or don’t realize they need to), although I’m sure it varies a LOT based on company culture.
And, on top of that, Facebook and Google have retaliatory power, so they know that Apple's response will be measured in a way that it wouldn't be with smaller developers.
This is what might be called a classic Stallman effect, where it has been pointed out since the mid-90s that if you don't have a few basic freedoms [0] then at some point an external party will shut you down for reasons you don't like. Google is in a lousy strategic position on this one because they gave up software freedom because Apple didn't seem like a threat at the time. They are lucky their internal apps were not being particularly targeted, I suppose.
This is why a good military plans on capabilities, not intents.
One thing is to break the rules Apple put down to keep iOS users safe and secure which is what Apple is targeting here, but another thing is just being stupid and unethical.
Regardless of their (FB+G) cries of "they consented to it", who really thinks a 13 year old understand the technical implications of installing a root certificate on their iPhone?
This might open the floodgates for Apple to shut down even more certs.
I expect in future you'll need to push these apps to the official app store, but have the ability to restrict who downloads them (to registered devices, or accounts - like with the Play Store beta program).
"By uploading or entering any User Content, you give Grammarly (and those it works with) a nonexclusive, worldwide, royalty-free and fully-paid, transferable and sublicensable, perpetual, and irrevocable license to copy, store and use your User Content (and, if you are an Authorized User, your Enterprise Subscriber’s User Content) in connection with the provision of the Software and the Services and to improve the algorithms underlying the Software and the Services."
If you were to write a book online using Grammerly they would have the full rights to what you wrote, and they could sell it themselves and not pay you a cent.
If you work for a company that uses Grammerly any IP typed into a windowd monitored by Grammerly also becomes their property.
Two years ago I looked into an enterprise license because I had so many employees using it, after reading the terms of service and speaking with their General Counsesl where he essentially gave the "my way or the highway speech","we own it all, and we can do what we want with it" I scrubbed the software and plugins from all our company computers.
Run from Grammerly
I would also loooove to know how this clusterfuck came about. But I guess we will never know that. I doubt this crosses Sundar’s desk, but I would be curious to know where the buck did stop. Was counsel involved or did a couple of teams just adopt a better to seek forgiveness stance?
That's exactly how they're supposed to be used, so barring rule changes you should be fine.
Of course, Apple has immense discretion here. Even if FB/Google lawyers can make a good case that their usage was technically compliant, Apple can still just unilaterally change the terms in short order. Public & regulatory sentiment would support them.
But I'd really like to know if Facebook's and Google's actions were plausibly compliant, under the actual language of the Enterprise agreement, at the time Facebook and Google (and likely others) pursued this strategy.
https://github.com/nicwise/apple-agreements/blob/master/appl...
2.1(f) Allow Your Customers to use Your Internal Use Applications on Deployment Devices, but only (i) on Your physical premises and/or on Your Permitted Entity’s physical premises, or (ii) in other locations, provided all such use is under the direct supervision and physical control of Your Employees or Permitted Users (e.g., a sales presentation to a Customer); and
It looks to me like "Permitted Users" includes "contractors" like those in a compensated research panel, and thus the Facebook/Google uses are plausibly enabled under the program.
And technically, entering a contract doesn't even require a signature – just a "meeting of the minds" to exchange considerations of value, like "my data" or "cash value gift cards". (And, these programs may have included actual signed agreements – I haven't seen strong reporting either way on that.)
That is the extent of my allowed use of that certificate. Anyone with any sort of ethics at Facebook/Google should have realized the same. Passing out gift cards and calling users "contractors" is against the spirit and letter of the contract.
https://www.zdnet.com/article/google-shuts-down-iphone-data-...
http://fortune.com/2018/12/05/google-tvc-shadow-force-letter...
They must have forgotten Apple doesn't like it when app developers run to the press...
https://web.archive.org/web/20141226094343/https://developer...
And, before you say it's the same as some company turning off your net based account, no it is not. For example if you upload porn to flickr and they delete your account in that case you're using flickr's servers. In this case Google is using phones owned by Googlers and other customers to run software by Google. Apple is not involved at all here unlike the example flickr case above. Apple should not be allowed to reach into another company and kill it.
AFAICT Google and FB did nothing wrong here. Those apps were test apps. How else are you supposed to beta test something? Tons of software does this. You build an app, you offer beta program. You had out codes for the beta users. Beta testing with direct employees is not useful because employees are no representative of actual users.
Google and Facebook appear to have used a different method of distribution than this and thus violated their terms.
If the companies are signing all of their apps under the same cert then it's kind of on them for being stupid to sign critical internal apps with the same cert they use to sign these privacy violating apps; but if Apple is globally disabling all enterprise distribution certificates under the guise that the companies violated their developer agreements and NOT disabling their user-facing apps then it still seems to me they are engaging in selective enforcement.
Regardless of how I feel about the ethical questions involved, I don't think this skirmish will end well.
Easier to hide the rule-breaking app in a swarm of legitimate ones.
This revocation only applies to the apps that are signed with the enterprise cert, so, for example, the Facebook app or Google Maps app in the app store are not affected.
Still, with a company the size of Google you'd still think they would have multiple certs under different legal entities even if they werent doing anything wrong.
Apple does not normally give these out (and why would they?)
Then you need each user to install each cert.
By now it should be fairly obvious that Apple hates Facebook for a very good reason- Facebook is Apple’s single biggest threat. I’m completely convinced this has nothing to do with privacy or protecting users, it just makes for a convenient excuse.
If people slowly start replacing iMessage with WhatsApp or messenger, that creates a bridge to leave iOS for Android since Apple’s software is one of the main features of the phone. If you become less reliant on the software the hardware suddenly becomes a commodity.
This whole episode is giving me pause about staying in the iOS ecosystem. Beyond that I think some antitrust litigation is going to hit Apple soon.
Edit: to elaborate I don’t mean a direct bridge to android, rather a substitute for iMessage that’s available on iOS and Android which makes switching relatively painless.
Every iPhone can do iMessage and FaceTime out of the box. That is a meaningful advantage for Apple, I think. Making something good enough that your users don't want to go find something 'better' and then making it 100% universal makes a strong ecosystem.
But what happens when Facebook continues to enhance its messaging platform and people slowly find themselves in a hybrid situation where they are communicating with a mixture of WhatsApp, iMessage, and Instagram?
Anecdotally, I probably use iMessage for 80% of my texts with my girlfriend but we still regularly use Instagram and WhatsApp for chatting, depending on the situation. I could foresee us ending up swinging the other way and using Whatsapp for texting and then getting used to it. Sound unlikely?
Suppose we are discussing what we want to order for dinner and WhatsApp has our favorite delivery places and their menus available and we can order and pay through the app. Now instead of texting back and forth and then opening Grubhub to look at a menu and order and pay we can do it all in one place. Pretty soon we are using WhatsApp to communicate and haven’t used iMessage in months. I find myself using WhatsApp so much I replace iMessage in the dock with WhatsApp.
Six months later I’m in the market for a new phone. Since I use third party software for just about everything now, all these devices are on a level playing field and maybe I try a Pixel this time and find I like it just as much as my iPhone. This may sound far fetched but this is how disruption happens and is pretty much how Facebook destroyed MySpace- users finding themselves using two services for the same purpose and eventually scrapping the one they use the least.
If you've done business with Google or Facebook, they behave _exactly_ the same way.
There are contractual obligations for both parties. Taking retaliatory action that is not permitted by the terms of the contract will result in a lawsuit.
I can’t see Google coming out of anything like that unscathed. Best case they lose customers, worst case they get an anti-trust case thrown at them.
Unless there is something else that Google can do that will work in their favor that I’m missing.
"What they're saying: Google confirmed it is being impacted: "We're working with Apple to fix a temporary disruption to some of our corporate iOS apps, which we expect will be resolved soon."
In a statement, Apple said "We are working together with Google to help them reinstate their enterprise certificates very quickly."
So Apple got to know it's terms are being violated after the press attention? Did they already know/is there a way they can detect this is happening? If not, then there could certainly be smaller players who have been routinely abusing this contract? I am trying to understand if Apple knew of this beforehand and are trying to avoid a PR disaster, or were caught off guard(which is scarier imo).
https://techcrunch.com/2019/01/31/apple-ban-google-data-app/
I'm curious what the TOS actually says, is there a link?
So if I just write an app for myself I can run it for my own phone indefinitely without going through the app store is that right? Seems like if you could do that, Facebook and Google could just do that for their internal apps?
I am genuinely just curious how it works.
[siggghhh]
In both cases Apple has reached an agreement to issue new enterprise certs for both companies. They can now use those certs for their approved purposes. If Apple finds that those certs are being used for disallowed activity they can revoke them again.
I don't really see any issue with that.
But Apple has been selective in enforcing this rule. If I recall, for many years Uber's driver App was distributed as an enterprise app. Uber has always claimed that drivers are not employees and so this was in clear violation of the ToS.
Imo, Uber's use case was legit. During early days Uber probably did not wish to have 2 Apps in the App Store to avoid customer confusion. Or maybe they were actively updating the Driver App and did not want to add days of App review holding up every update.
Apple should change their ToS and allow such use cases in some form. At times this would get misused (like FB/G) but opening up the walled garden to enable such "private" apps to be easily distributed can make iOS a more interesting platform. In any case they always have the final kill switch of revoking an Enterprise Cert for malicious use.
I expect we'll see a LOT of Apple Vs Google/FB in the near future - Google/FB's business model is what is under attack here, and I'd bet it'll be fought in terms of public privacy breaches, bugs, and other embarrassments rather than direct marketing. Welcome to politics silicon valley, its gonna suck.
One is a consumer, one is a contractor.
Seems like this doesn't apply then.
iOS should say “this app violates Apple agreements blah blah do you want to continue using it?”
Is this the achievement of machine learning and speech recognition?
Maybe Google should try to get a post on the front page of Hacker News? That that seems to be the only way to get the attention of Google's support.
Before Apple's response, it seemed like Facebook might get away with it because their app is so big and important -- blocking the app would hurt a large fraction of Apple's own customers.
But Apple's response is a clever way to show that, hey, they're big and important too! A large fraction of Facebook's employees use iPhones, not just for developing the iPhone app, but for general work purposes, because the iPhone is a great product. (I wonder how many of those employees will now switch to Android, though...)
Kindergarden, at it's best. What everyone is still unclear about is: how will this play out for them - and for Apple especially, of course.
We can only speculate. And order another ton of popcorn.