https://www.theinquirer.net/inquirer/news/3063669/google-is-...
If, as you admit yourself, Apple is far better in terms of privacy, would it not be helpful, even if they are not perfect, to praise their (relative) sainthood and bury them with money?
That way, they would be reward for their strategy, might double-down on it (maybe even achieving perfection in your very smart and perpetually critical eyes), and inspire others to follow their lead.
From "The State of Mozilla 2017" https://blog.mozilla.org/blog/2018/11/27/state-of-mozilla-20...
Today, the majority of Mozilla Corporation revenue is generated from global browser search partnerships, including the deal negotiated with Google in 2017 following Mozilla’s termination of its search agreement with Yahoo/Oath which required ongoing payments to Mozilla that remain the subject of litigation.
In my mind, a reasonable settlement includes not installing spyware on users' iPhones through the enterprise development program, so it looks like they're doing precisely that.
I think that in this particular case, Google overreached, it's an inconvenience to them, and they'll roll it back. In the general case, though, Google's got way more power than Apple (and more than most nation-states) and they just haven't been called on it yet.
Does that count ad revenue from ads running on smartphones?
Apple’s market aligns with the most profitable markets for Google.
I think a mistake to make here is thinking that Apple gives a toss.
Apple’s business model is selling high margin products. More share requires lower costs, which increases operational risk and reduces profitability. That’s why Apple stock is cheap compared to other big tech companies... a problem with execution today has a bigger impact than a company like Google that has a stream of revenue from ads on every platform.
You’re going to see changes in the model as they are hitting a growth ceiling, but they’ll probably take a different services path than Google.
I would say rather to avoid laws it's to avoid appearing as a commodity and losing its "fashion" or "hip" status. If everyone has an iPhone suddenly it is less desirable to own an iPhone.
[1] https://deviceatlas.com/blog/android-v-ios-market-share#us
As mentioned in a separate Verge article-
"One giant platform declared another giant platform’s market research program inappropriate, then disappeared it with a Thanos-style finger snap"
also from same article, attributed to Nilay Patel
"Hi, I’m the nagging voice in the back of your head pointing out that it’s pretty intense that Apple can simply decide to prevent people from running code on their phones."
Edited for punctuation
Google can make the terms of use "None of our services and any kind of services deployed on Google Cloud may ever be displayed on an Apple device" and it will have the same legitimancy.
I don't know why there's so many people who think putting something in a bullet point as a policy/law just makes it somehow different.
The difference is that Facebook and Google agreed to and were fully aware of the terms beforehand.
Remember those cyberpunk stories where not the elected governments but rivaling multinational companies are the law? This is how we get there.
Heh. They already have, to Amazon though. See all the petty fights Google and Amazon have engaged in over youtube, chromecast etc. This is a good PR move by Apple though, especially when game studios are clawing out of the 30% cut and people are beginning to ask for the right to repair or the ability to side load apps. Apple saves the day yet again by providing value through the app store.
"Your company, organization or educational institution would like to use the Apple Software (as defined below) to develop one or more Internal Use Applications (as defined below) for Apple- branded products running iOS, watchOS, tvOS, and/or macOS, and to deploy these Applications only for internal use within Your company, organization or educational institution or for limited use as expressly set forth herein."
https://developer.apple.com/terms/ → Apple Developer Enterprise Program License Agreement
Further, some stories have reported that Facebook says they acquired such parental permission for the minor participants.
Additionally, the minimum age for non-agricultural workers is 14 anyway, so even then they're in the wrong and can't legally hire 13-year olds as contractors or employees. There's also several other rules in the FLSA pertaining to workers under 18 including minimum wage. I have a sneaky suspicion $20 per whatever period it is (unless said period is a few hours) is going to be under that wage.
Not to mention there's a whole lot more can of worms being opened specifically around minimum wage and recording hours that I highly doubt either Facebook or Google were actively managing.
I've never seen that relationship result in anyone being called a contractor and I've signed too many film contracts. I don't know where OP is getting this notion.
Here you can see a VentureBeat reporter – and one who is actually a member of the California State Bar of Attorneys – raise some of the same questions as I have:
https://venturebeat.com/2019/01/31/the-odd-reason-apple-kill...
Late in this article, you can see Facebook's statement that all minors who participated did so with signed parental consent forms:
https://gizmodo.com/facebook-is-paying-teens-to-install-a-re...
Facebook's statement: "Key facts about this market research program are being ignored. Despite early reports, there was nothing ‘secret’ about this; it was literally called the Facebook Research App. It wasn’t ‘spying’ as all of the people who signed up to participate went through a clear on-boarding process asking for their permission and were paid to participate. Finally, less than 5 percent of the people who chose to participate in this market research program were teens. All of them with signed parental consent forms."
You are a "contractor" if you are providing services under a contract. A contract exists whenever there is a definitive agreement to exchange valuable considerations – even in the absence of a written, signed contract.
But the sign-up for these apps might have included an explicit "signing" phase! (It's even possible that FB/Google asked for participants' SSNs, just in case any payments went over $600.)
(And if they’re under any sort of confidentiality agreement or other conditions on their app usage, they fit under the Apple terms’ concepts of “Permitted Users” and “Internal Use” even better.)
You're looking for the "Apple Developer Enterprise Program License Agreement" — I found it in ten seconds. The only production applications allowed on the cert are internal applications ("Internal Use Applications developed for macOS can be distributed under this Agreement using an Apple Certificate or may be separately distributed.") Or applications under development (2.1 Permitted Uses and Restrictions, Program Services). Also outlined are explicit unpermitted uses and a general declaration that anything outside of 2.1 won't fly (2.6 No Other Permitted Uses, specifically "You may not use the Apple Software, Apple Certificates, or any Services provided hereunder for any purpose not expressly permitted by this Agreement,").
You'll need to sign in with your Apple ID to open this: https://developer.apple.com/services-account/download?path=/...
Hope this helps.
---
Edit: for anyone who wants to spare themselves the chain, OP is missing the distinction between vendors, contractors, and other service providers and is interpreting the presence of any contract as rendering a person as a contractor. In this case, it's likely (IANAL) that each individual user of the service would be described as a vendor selling access to their data. The data itself is not created for Google's (or Facebook's in that previous case) consumption.
https://www.quora.com/What-is-the-difference-between-a-vendo...
https://english.stackexchange.com/questions/248665/contracto...
--
Added in response to edit: The links to Quora/StackExchange, however, miss the point. Anyone who's entered a contract to provide a service in return for compensation is a 'contractor', both in legal terms, and in layman's terms. Facebook's description of their on-boarding, especially, suggests there was sufficient "meeting of the minds", mutual agreement, and exchange-of-valuable-considerations as required for a contract to exist:
Facebook statement via <https://gizmodo.com/facebook-is-paying-teens-to-install-a-re...:
"Key facts about this market research program are being ignored. Despite early reports, there was nothing ‘secret’ about this; it was literally called the Facebook Research App. It wasn’t ‘spying’ as all of the people who signed up to participate went through a clear on-boarding process asking for their permission and were paid to participate. Finally, less than 5 percent of the people who chose to participate in this market research program were teens. All of them with signed parental consent forms."
> Google’s private app was designed to monitor how people use their iPhones, similar to Facebook’s research app.
Googling this, I don't see references to 1099, W2, or Corp to Corp contracts which might help anyone say it's "internal." Paying someone for a service does not make them a part of internal operations of a company.
It's this Screenwise Meter app which got the certificate nixed, and with it, any other apps on that cert were shattered. The aforementioned app was a non-internal app used in a production capacity, which falls out of the bounds of test/dev/internal apps enforced by the contract.
Tl;Dr: Google had in service a production application using a developer/internal cert. This caused the cert to fall in scope for revocation.
If the mechanism for bringing participants into "Screenwise Meter" involved a contracted payment, it plausibly matches some of the expressly permitted uses, in the Apple Enterprise terms. (If it included an express written contract that limited the participants' use of the app, it further matches certain explicit requirements of the Apple terms.)
(There's another clause about using a specific "Network Extension Framework" that seems like a bigger problem for Facebook/Google, depending on what they likely did with that API and the info retrieved. But these clauses, about "internal use" and "permitted users", seem fully compatible with an internal-research-program using a panel of compensated research-subjects.)
They can't sign a contract. They can't become contractors.
Why do you keep fighting this? It doesn't even seem like devil's advocate anymore. :/
---
it's anyone "under contract".
It's not. I'm not an employment lawyer, but that's definitely not true. At all. Under any circumstances.
If you need help with it, check this: https://www.quora.com/What-is-the-difference-between-a-vendo...
But further, even if it was a violation if minors were involved, that'd leave open the question of whether use by contracted adults was compliant under the terms. (And supposedly the Google app wasn't offered to minors.)
And, paid research subjects meet the legal definition of contractor, as outlined here or elsewhere:
https://dictionary.law.com/Default.aspx?selected=939
Simply insisting "definitely not true" is not convincing.
In this case, it's likely (IANAL, nor are you) that each individual user of the service would be described as a vendor selling access to their data. The data itself is not created for Google's (or Facebook's in that previous case) consumption. The users of the service were selling rights and were not producing anything for hire.
https://www.quora.com/What-is-the-difference-between-a-vendo...
https://english.stackexchange.com/questions/248665/contracto...
---
This is becoming tedious. I'm out.
It’s behind the developer wall but the whole thing is here. https://download.developer.apple.com/Documentation/License_A...
Compensated members of these apps' research panels are quite literally "contractors" of FB/Google, and possibly even under written contracts that explicitly limit the apps' use as Apple requires. So what you've quoted doesn't demonstrate a violation.
The only provision I see that's close to what you're talking about is the definitions section, which provides that Permitted Users include "contractors . . . who have written and binding agreements with You . . . to protect Your Internal Use Application from unauthorized use"
It's quite the stretch to say that this language, which by its text limits contractors to authorized uses, somehow expands the scope of authorized use. Even if you could get to that conclusion, it would not be "expressly set forth."
"Internal Use Applications or Passes developed using the Apple Software may only be deployed to and used by Your Employees or Permitted Users for internal use purposes or for limited use by Customers on Deployment Devices on Your (or Your Permitted Entity’s) physical premises or in other locations when the use is under Your (or Your Permitted Entity’s) direct supervision and physical control as set forth in Section 2.1(f)."
Is it being used by "Permitted Users", which is elsewhere defined as including "contractors"? Yes.
Is it for "internal use purposes"? An internal customer research program, which is a cost-center and involves compensated research subjects, where the data is kept internal-confidential – and where perhaps even the research-subjects are under various kinds of NDA – is pretty "internal use" from my perspective. So, yes.
There's the "express authorization" that the following sentence doesn't revoke.
(Even the 2.1(f) allowance for customer use might be satisfied if the app has a central monitoring/disabling switch that counts as "direct supervision and physical control". But that's a little murkier, and the 2.1(f) allowance isn't strictly necessary for this use by compensated research subjects.)
It is not defined elsewhere as including contractors. It is defined elsewhere as including contractors who use it for authorized purposes. The bootstrapping you're attempting here is circular reasoning.
“Permitted Users” means employees and contractors of Your Permitted Entity who have written and binding agreements with You or Your Permitted Entity to protect Your Internal Use Application from unauthorized use in accordance with the terms of this Agreement.
If the research panel subjects were under a written agreement to only use the app in the manner it was intended – such as keeping aspects of its use confidential, or disabling it when other non-compensated others were using their devices – doesn't that match the definition? Or are you claiming some other "circular" bootstrapping of extra fuzzy limitations on what "Permitted Users" are?
> "Internal Use Application" means a software program (including extensions, media, and Libraries that are enclosed in a single software bundle) that is developed by You on a custom basis for Your own business purposes (e.g., an inventory app specific to Your business) for specific use with an Apple-branded product running iOS, watchOS, tvOS, and/or macOS, as applicable, and solely for internal use by Your Employees or Permitted Users, or as otherwise expressly permitted in Section 2.1(f). Except as otherwise expressly permitted herein, specifically excluded from Internal Use Applications are any programs or applications that may be used, distributed, or otherwise made available to other companies, contractors (except for contractors who are developing the Internal Use Application for You on a custom basis and therefore need to use or have access to such Application), distributors, vendors, resellers, endusers or members of the general public. For the sake of clarity, Internal Use Applications do not include third-party applications even if some customization has been done.
There's other damning bits later in the license agreement, including:
> You must provide clear and complete information to users regarding Your collection, use and disclosure of user or device data, e.g., a description of Your use of user and device data in the Your Internal Use Application.
and
> Notwithstanding anything to the contrary in Section 3.3.9, You and Your Internal Use Application may not use the Network Extension Framework, or any data or information obtained through the Network Extension Framework, for any purpose other than providing networking capabilities in connection with Your Internal Use Application (e.g., not for using an end-user's Internet traffic to serve advertising or to otherwise build user profiles for advertising).
I don't see the definition of "Internal Use Application" as clearly prohibiting app usage by these research panels – paid contractors of FB/Google. And, the disclosures to panel members may have met the "clear and complete information" clause.
But the limits on the "Network Extension Framework" usage might be a violation. I suspect FB/Google were effectively building "user profiles for advertising" with this data... though perhaps they could make a case that these specific networking hooks were walled away to a separate, non-prohibited purpose.
Even if you make the argument that the users of this app are paid contractors of FB/Google, they are not contractors who are "developing the Internal Use Application for You on a custom basis and therefore need to use or have access to such Application", so it still seems pretty clear cut.
And, other sections of the terms (just before that) expressly enable "a software program… for Your own business purposes… and solely for internal use by Your Employees or Permitted Users" – where, as noted, "Permitted Users" also was defined to include "contractors".
They're being paid for a product (their data). By what I'm gathering, I could define Netflix as my contractor for delivering my team streamed movies for $n per month... which isn't true unless a more specific relationship e.g. a c2c is put in place.
(Yes, when Netflix agrees to provide you with something in return for your payment, you've entered a contract with them, and they are your contractor. If somehow you were an US entity with 50+ netflix subscriptions for different offices, and thus paid them more than $600/year, you technically might be on the hook to file a 1099.)
Source. Now. Because I highly doubt this is accurate. I have never heard of someone having to file a 1099 for purchasing services, of any kind. Hell, half of everyone's time would be spent filing 1099s because as a society we spend far more than 600 dollars with any one company over the course of a year literally all the time.
You're using what is known as a "cute trick".
Judges are rarely amused by "cute tricks". Like a Sovereign Citizen believer you can keep claiming to be correct all the way to a loss in court, followed by denied appeal after denied appeal.
There’s no trickery here: that’s the ordinary legal meaning, and it is those who insist on only the far narrower regulatory/tax ‘contractor’ category who are playing semantic tricks.
It doesn't matter how many people "explain" falsehoods, like the idea that minors can't enter contracts (even with parental permissiion), or that a person being paid by a company under the terms of a contract is not a 'contractor'. They're wrong despite their multitudes.
Compare this account from a reporter at VentureBeat – who also happens to be a member of the California State Bar – who makes similar points as I have, about how compensated panelists are “arguably limited purpose ‘contractors’ providing data solely for the developer’s research purposes “:
https://venturebeat.com/2019/01/31/the-odd-reason-apple-kill...
Not since 2007 - http://members.calbar.ca.gov/fal/Licensee/Detail/215049
And his CV suggests he only practiced any law at all between 2001 and 2004 - http://www.jhorwitz.com/jhresume.pdf
Disingenuous of both him and you to claim he has any authority to speak from a legal point of view on this, really, no?
But still, a legal degree, one-time certification, and some legal practice are kind of relevant, compared to anonymous commenters who are just insisting by repetition "but that's not a 'contractor'!"
Is it your reasoned argument that an individual receiving payment for services rendered to a corporation, under the terms of a mutually-agreed contract, is not a "contractor" in the eyes of the law?
Ok, I'll remove you from the disingenuous. He stays though because he should definitely mention it on his CV.
> a legal degree, one-time certification, and some legal practice are kind of relevant
Yep, he's definitely probably got more standing than anonymous commenters. But that's a low bar. He didn't practice contract law (it was transactional IP) and it was 14 years ago - it's an almost certainty he isn't au fait with current contract or employment law.
> Is it your reasoned argument
I don't have one knowing nothing about US contract or employment law. My layperson viewpoint is that it's quite clear they weren't Facebook contractors in the terms of the Apple agreement.
IANAL, but I know the rough outlines of US contract and employment law as a frequent party to contracts, occasionally to disputes, and as a US person who has both contracted others and been a contract worker.
If you have a contract (which doesn't even have to be written), you're a contractor. Full stop. And, an agreement to provide payment in return for performing certain actions (like installing an app, leaving it running, answering questionnaires, maintaining confidentiality, etc) is a contract, even if it's a clickthrough agreement. Ergo, compensated research panelists are 'contractors' in the eyes of the law.
Yes, and I explicitly said I didn't have an argument but only my "layperson viewpoint".
> IANAL, but I know the rough outlines of US contract
Great. I don't care. Argue with other people about that. All I wanted to do was correct the perception that the journalist was a member of the bar and had some kind of legal standing.
> ...though perhaps they could make a case that these specific networking hooks were walled away to a separate, non-prohibited purpose.
They could not. The primary purpose of the Facebook and Google research apps was not to provide a VPN service; as such, using VPN services was a violation of the program terms. The use cases mentioned -- "to serve advertising or to otherwise build user profiles for advertising" -- are examples of prohibited use cases, not the full extent of the prohibitions.
The terms are very clear. Apple wants to control distribution of apps, the enterprise program is only supposed to be for employees or for end users using under the direct personal supervision of an employee as part of an in office test. The conditions are clearly defined.
Given that the users of the app in question were being paid by Google, one could argue they are employed... or at least are contractors.
On the other hand, given the users did not have the rights generally associated with being an employee or a contractor... and they were not even getting minimum wage...
But at that point IANAL and courts would need to decide
Google or FB isn't going to touch that with a 10 foot pole, and no there is no need for courts to decide, they don't want these users considered employees or contractors in any way. Also monetary compensation is very common in some research industries without said people being contractors or employees. Simply put Google and FB F*up big time in violating the TOS.
I'm not sure how it could be much clearer that this is not intended to be used to distribute apps to customers.
Inacceptable. Such a company should not be allowed to do business in EU. Much worse than what happened with Microsoft in the 90ties.
Apple is not a state-owned company. They can do whatever they like, and you can choose to support them by purchasing their stock and/or their products. You can choose not to support them by purchasing neither their stock or their products.
There are several federal and state laws that define what they "can not do", and this isn't one of them. Why should a business owner(s) "not have the right" to run their business any way they see fit, so long as they do not violate the law?
Your analogy to MS doesn't hold water - MS was told not to do something by a governing authority, and they did it anyway. The governing authority stepped in and enforced their rules - nothing out of the ordinary there.
Thats not really true. There are a multitude of anti monopoly laws and consumer protections that may apply to Apple's actions.
> Why should a business owner(s) "not have the right" to run their business any way they see fit
Because one company having too much market power, and being in an oligopoly type situation is bad.
Because we have consumer protection laws for a reason.
Because when a consumer buys a device, they have the legal right to do whatever the heck they want with it, and Apple tried, and failed, to sue consumers for doing things to devices that the consumer owns.
The courts have sided quite a few times in favor of consumers, regarding how they have the legal right to do what they want with devices that they own.
And if the current laws don't 100% cover this situation that we are in right now, then hopefully the law will be reinterpreted to apply to it.
But even beyond that, it makes perfect sense to criticize, and retaliate against, companies that hurt consumers, and try to take away their rights.
Apple is a chief offending, in just how many bad things that they have done, to try to take away consumer's legal rights to doing what they want with devices that the consumer owns. They tried, and failed, to sue people. This deserves to be criticized, and retailiated against.
We limit what business owners can do for 'greater good' in quite some areas. I think it is necessary here too. Apple: enforce access, Android: limit data snooping.
Your comment might make sense of Apple were some sort of government entity, but it isn't; it was completely Facebook and Google's decision to abide by Apple's terms and conditions, something that will have been pored over by legal team upon legal team. This is not something Facebook or Google will have entered into lightly, and yet they explicitly chose to break the terms and conditions.
If I run a restaurant and one of the house rules is that you're not allowed to harass my staff and make the dining experience unpleasant for other customers, and you do that, of course I'm well within my rights to throw you out.
The problem isn't that Apple are allowed to throw Google out of the enterprise program; the problem is that Apple users aren't allowed to install Google's apps without Apple's permission.
It's fair enough to say that Google can't complain because they knew the terms of the enterprise agreement. But I'm not sure it's fair to say that Apple phone purchasers are clearly told when they buy a phone that Apple can disable their employer's internal apps.
Maybe, except that the enterprise app distribution system is a service provided by Apple. It has associated terms and conditions.
I'm not saying you're wrong, but I don't think it's the argument to be making right now; if the topic were jailbreaking, sure. As it is, it's about abusing a service. The enterprise app distribution system is not sideloading in the same sense as it is on Android; it is a service for a specific purpose.
> But I'm not sure it's fair to say that Apple phone purchasers are clearly told when they buy a phone that Apple can disable their employer's internal apps
For the individual employees, no, they probably don't know this. However, they have no real need to know; this is an implementation detail on the employer's end.
The employers 100% know about this, or else they wouldn't agree to the terms and conditions of the enterprise app distribution system. Legal teams will have pored over this. Nobody is ignorant of the implications of their actions; it just happened to be that two high-profile companies made the mistake of thinking they were immune to punishment.
But no, any company involved in the enterprise app distribution system knows 100% what getting that certificate revoked means. Especially a tech company!
Because they became too big. It's the right of e.g. the EU to allow them to operate. Or better said, the law could be changed to disallow operation if certainy conditions are not met. Apple then has the choice to either adapt or leave the EU market.
You're talking like the EU has one set of rules for companies from its members and another for others, but that isn't the case. The EU treats all monopolies equally; Apple isn't close to a monopoly.
Of the actors involved here, Google is the one that the EU is most concerned about.
Apple is only acting on their own turf, their services. Their reach is not far spread outside of the iOS landscape, heavily dwarfed by Google's Android at something like 85% share.
If some app decides to include a crypto-miner, that burns up your battery, your sure going to want apple to yank that from all the phones, as quick as possible, not sit there an hope your pocket doesn't melt before you can figure out which app to uninstall.
It's my device, if I am fully informed and decide to run a crypto-miner application I should be able to do so. If I want to run 'In A Permanent Save State' [1], Apple shouldn't be allowed to censor this (not that I would agree with the subsumptions in that app, but that is not relevant here).
[1] https://www.forbes.com/sites/timworstall/2012/11/13/the-very...
no - you are free to run any code on YOUR phones with the enterprise program - you are clearly not free to run any code on OTHERS phones using this program..
As a user, I can not choose what code to run on my iPhone.
The only way to run a non-official app would be if the app was open source: put it in testflight for your personal use.
This is the main reason I have sworn off all Apple devices.
If someone won’t give you the code, but instead will only supply it via Apple’s store, that’s between you and the supplier.
That is a very limited subset of iPhone users.
The only reason Fortnite used Apple's app store is because Apple has made it practically impossible to side load apps.
What’s difficult is to distribute commercially, or maliciously without going through Apple.
Not really. If any lone developer/small company did this, Apple would have banned the whole developer account.
I'd rather Facebook feel the hurt for its audacity than Apple be forced to backtrack because they made too many enemies.
In what way does Apple have anything to fear from FB or Google, or even depend on either of them at all? Where is the "force" going to come from, their users threatening to switch to Android? I don't think these incidents would be enough to lend that eventuality any weight.
Sounds like you just confessed to violating Apple's terms.
Apple's platform, their rules.
Apple is likely shooting themselves in the foot here. These companies' IT departments will no longer be able to support iOS devices for accessing intranet resources, which means no engineers will be using iOS devices as daily drivers, which means their iOS apps will fall further behind their Android apps in quality.
The argument is somewhat moot, anyway. Apple has simply decided that privacy is a tenet of their value proposition, that value is reflected in their contacts granting in-house certificates, and these companies broke the terms of these contracts.
Yeah, that's just marketing. If they really cared, they wouldn't accept a 9 billion dollar payout per year to make Google the default search engine for IOS.