Apple Defends Decision to Remove Parental Control Apps
digit.fyi
digit.fyi
iPhones contain so much personal data on-device that Apple is absolutely responsible for protecting that data from illegitimate access. Using MDM which is clearly intended for enterprise management is an illegitimate use-case. Period.
The argument that their ability to use MDM APIs in the past and earn revenue due to a gap in Apple's vigilance dictates that they should be able to continue unimpeded is a logical fallacy.
Apple is under no obligation to offer unfettered API access to these companies just because they were filling a market need that Apple didn't want to pursue. You can tell if Apple wasn't under a market demand obligation to offer MDM to enterprises, they would cut that too.
One of the value props of the iPhone and the iOS ecosystem is that Apple exerts this level of control and editorializing on the platform. The result of which is easily seen when comparing the quantity of data mining apps on Android vs iOS.
I'm sure if I was one of these scorned developers, I would feel abused even victimized by Apple. Unfortunately that is a biased perspective. Apple is doing the right thing for consumers and end-users by blocking these apps.
The reporting on this was atrocious and seems to be a result of the recent competitive chatter about sandboxed computing platforms like iOS. Broader discussions around anti-competitive behavior on these platforms are needed, but this wasn't the poster-child.
What are the differences between the legitimate apps and the others?
Is the difference publicized by Apple somewhere?
Granting access to sensitive data via an app, under stringent but fair conditions, would be a compromise. For example, implementing a controlled device mode, where the "spy" data is on-device only, and spy mode is clearly notified in the status bar, or what-have-you, so the person being monitored knows the rules at all times they are on device.
From the press release “No one, except you, should have unrestricted access to manage your child’s device.”.
Edit: Is Apple offering similar applications? if yes are they using private APIs to implement the features?
Hopefully the parents either switch to Android if such a thing is still possible on Android or just get them flip phones with no data plan intended only for emergency calls. Where they can get a list of sent/received calls at the end of the month from the cellphone company at least, I assume.
Your argument also has merit, and I don't know where the balance is, but I don't think it's entirely one or the other.
These apps were dodgy. They effectively became a new and incredibly convenient vector for an app developer to spy on children. It's disgusting that people defend them.
MDMs are meant to allow a business to manage its devices through a third-party provider. They are NOT meant for personal usage, as they are privacy and security issues (who do you turn to when your device is bricked by your MDM?).
This is not the first time Apple is shutting down businesses misuing its APIs, and it won't Apple.
Should Apple provide parental control APIs? That's a separate issue. They currently don't have enough, and user who wants more can indeed switch to Android.
Do you think that is an appropriate level of access to grant?
Parents don’t need to switch to Android, they have tools built into iOS that offer the features they need without essentially giving away the device to a third party company.
No one is saying that. Just like privacy laws don’t exist to protect encrypted hard drives full of pedophilia. The right to privacy does NOT enable or endorse deviancy or illicit behavior! At all! Privacy is a human right, not an adult right.
Kids do deserve to have an assumption that when they are texting with their friends that their parents aren’t watching them. Especially teenagers. What about the young boy in a conservative Christian family who is struggling with his sexual identity? What about the young girl who is trying to learn how to report her abusive family members? These are the reasons why children’s privacy are important. Young people need their own secure places to express themselves and form an identity — that doesn’t happen, thankfully, under parental supervision.
That said, of course it’s a parent’s job to protect their children. But spying on a personal device like a cell phone is oppressive and paranoid.
The kids are safe, no need to think about them.
You mean the same app that allows a random third party company to record and track everything that your child does on his phone?
Yes and switching to ^Android* that has built in Google surveillance that tracks every time you open an app and also has a horrible security record is really a better alternative.
The crux of the complaint is that Apple is pursuing this market need with Screentime introduced at the same time Apple started banning these competitor apps from developers
> “Over the last year, we became aware that several of these parental control apps were using a highly invasive technology called Mobile Device Management, or MDM.
> “MDM gives a third-party control and access over a device and its most sensitive information, including user location, app use, email accounts, camera permissions, and browsing history.”
They make this sound like MDM is some scary third-party attack on their platform, neglecting to point out MDM is a system they designed. There's always been some schizophrenia from Apple around MDM (publicize new control features to admins in one release, add a big scary vague user-facing warning when that feature is actually used in the next release), but their general stance has consistently been that you, as a company, have a right to enforce whatever restrictions are available on devices used by your employees so long as you own them, and so long as you accept whatever user-disclosure features they decide to implement. Likewise, you have a right to enforce a more limited suite of controls on your employee's personal devices, so long as it's all opt-in.
I would presume any parent intending to enforce restrictions on a child's device also purchased that device. So Apple's stance here is really that parents should have less control over their children's devices than employers have over those of their employees? Or are they really talking about some exploit of the MDM framework? Because the way it's phrased here clearly seems to be framing MDM in general as a nefarious tool.
I think the prospect of MDM establishing itself as a necessary evil for consumer use-cases is such affront to their thoughts about individual data privacy rights that they would rather trash MDM than risk that possibility.
If you want to get a sense of how Apple thinks parental management of a device and enterprise management of a device in a corporate setting differ, all you need to do is compare the experiences and features. MDM is like a nuke compared to screentime and parental controls.
As a final note Apple refuses to even provide the management server portion of MDM, another clear signal that of their split feelings on the matter.
Apple is a huge, gargantuan company, and it wouldn't surprise me that the implementation details around enterprise deployment probably didn't get far up the chain to the people who actually care about this stuff. Someone like Tim Cook might have spent five minutes talking about its existence in 2018.
> So Apple's stance here is really that parents should have less control over their children's devices than employers have over those of their employees?
No, Apple's stance here is that app developers should have less control over your child's device than employers have over those of their employees.
> the way it's phrased here clearly seems to be framing MDM in general as a nefarious tool.
MDM is a nefarious tool when incorrectly used. Its intended use is to allow big corporates to deploy nerfed and bugged phones to their minions.
Facebook and Google abused MDM a few months ago and the community cheered when Apple ripped these toys away from them. The same abuses are now discovered to be used to make creepy "child control" apps that place an app developer in control over your child'd entire phone. After all the shit went down against Facebook and Google, these app developers received fair warning that what they were doing was wrong.
Right, sure. I got a work device and the company owns it and I don't do my own personal stuff on it (and hopefully other folks follow suit). If the company screws up its security, those devices are utterly compromised. MDM, for all its good intention, is a comprehensive surveillance system for a phone. It is a little piece of the corporate panopticon on your pocket. That can actually be quite convenient, but I certainly think folks should keep the aspects of their lives separate.
It's a bit different with kids and parents though? MDM is a massive invasion of privacy and unlike in the work phone relationship, we'd expect a vulnerable young person's entire personal life to be embedded on the device. Also, children generally don't have the option to walk away from their parents and find new, less restrictive parents.
It is true, the parents own the device legally. They can take it away. That isn't necessarily a call for Apple to enable parents to run spyware run by third parties. Quite frankly, third parties no well-informed consumer should trust given their abysmal track records for privacy and security issues. The idea of Kaspersky running the intermediary rendezvous server for all of my child's private communications is pretty scary to me.
I appreciate the desire to keep kids safe, but coming from an abusive home I have to tell you that computers were my escape from physical and mental abuse and I am fairly sure I wouldn't be alive today if my parents could have closed a net as powerful as MDM around my life.
Someone please correct me if I'm wrong as I haven't used any of these apps, but I thought the point here is that it's not the parents running an MDM server. I mean, I personally have long made use of MDM and profiles on iOS devices for myself and family, it's super useful (and necessary for some things like using S/MIME certs in native Mail). But I've done it via actual MDM, myself (you can also do a lot via simple distributed one shot profiles made with the free Apple Configurator software). There is no 3rd party involved.
It sounds like here that it was 3rd party apps/services that were making use of MDM functionality. "On behalf of parents" sure, but there's still a fundamentally different relationship and set of expectations for loading an app via the general App Store vs specifically enrolling a device/loading a profile from an employer someone has contractual agreements with, or someone running an MDM server themselves on their own behalf. There isn't really any way around the fact that MDM offers enormous power over devices, much of which happens without any user interaction or much (if any) exposure via the GUI. That's much of the point of it after all. That power certainly offers avenues for abuse that are different in scope.
I'm sure many of the 3rd parties are trustworthy and hopefully at least trying their best in terms of not themselves being hacked by malicious actors, but I think Apple also has a genuine legitimate concern here. A real goal for iOS is that someone can browse through the App Store and install absolutely anything they see and think looks interesting based purely on descriptions/reviews and face a known, fairly minimal and easy to reason about threat profile. Of course it hasn't always been perfect, but it's been a lot better at this then the general free for all. If some of those apps make use of MDM powers outside of normal MDM usage that breaks those expectations, that's not made up.
FWIW I personally think Apple should be required to allow other stores and permanent device owner created master signing cert loading capability, even if only via offering a more expensive "developer" model of phone with that capability not fused off. But the security and privacy tradeoffs there are worthy of consideration and efforts to find the best balances, and even in those cases I'd still be fine with Apple having their own curated App Store that remained as strict as they wished.
Of course they should remove them too.
Research shows customers do care about a company's ethics / moral stance, so I don't see why Apple wouldn't want to do this.
Apple already takes a moral stance on certain things. This isn't a debate. If they don't want to allow something on their App store, they will shut it down, even if it's 100% legal. These are the slipper slopes people have talked about for years. This is not new.
Apple has shown that if it doesn't want to support something, they won't. This means it's perfectly reasonable to hold them to account for things that are supported by their platform. This is why some platforms simply don't do any policing, or very limited.
Their laws are their laws, and they suck. I’d rather have an app that at least allows some women to escape.
I agree, SA's culture promotes a toxic repression of women. But before Apple goes world policing I'd like to see them take a domestic stand, because last time I checked spouse spyware apps are still in the store and aren't auto-banned. Please correct me if Apple took action since then.
So by using it, you're giving some complete strangers access to snoop on everything in your child's phone. Even if you trust the developer not to abuse that, you're trusting them to keep their own systems secure and to not hire an employee who might abuse it. We know how that worked out for the NSA where they had people using their surveillance programs to snoop on exes.
If you want to use MDM to manage your child's phone, the way to do that is with a service where you manage the MDM yourself like a company would do with their fleet of phones, not to hand the keys off to an untrusted third party.
Ah. That makes perfect sense and I'm changing my mind on this one. Apple did the right thing.
Similar thing, I had a nest camera in my daughter's room when she was under 3. Now I've removed it, because she is old enough to have time to herself. I know one parent who demands to have a camera in their kids room and one of those kids is 14. That's beyond awful.
> “When we found out about these guideline violations, we communicated these violations to the app developers, giving them 30 days to submit an updated app to avoid availability interruption in the App Store,” a spokesperson explained. “Several developers released updates to bring their apps in line with these policies. Those that didn’t were removed from the App Store.”
I'm in education and the iOS schools we deal with use different MDM solutions, and certainly not Apple's MDM software.
Talk is cheap and sells well...
You are mistaking them for Facebook or any of the other engagement-driven, ad-selling companies.
In fact, the less you use them, the more profitable it is for them.
And viewing figures are going to have a big impact on future Apple tv content.
E.g. I have an Office 365 subscription. I haven't used Office in forever, but it comes with 5Tb of OneDrive space (family account), so I keep the subscription to store my photos. However, I've filled less than 100Gb so far and I'm sure my family has even less than that. Same thing with Prime, some months I buy a few things things, others nothing at all. But I know that every package arrives the next day, so I keep the subscription.
TV content is a bit special in this regard, true. However... If you keep binge watching, how long until you have nothing else to watch? Would you not cancel your service, then? The service is then _forced_ to keep delivering new quality content at the same speed that you watch it. Maybe Apple doesn't want to play that game.
https://searchengineland.com/apple-search-ads-expected-to-ge...
Again, nobody spends all day searching the App store. Apple's business model is not driven by your engagement. They make vastly more money when you make discreet choices, like buying a device, purchasing a subscription, etc.