Apple to start requiring written consent for third party API usage in apps
9to5mac.com
9to5mac.com
I understand Apple's position here, especially with APIs that control vehicles. It's just a sad fact that Tesla hasn't provided a safe public API to control their cars.
This sentence scars the bejeebus out of me to think this could even be a thing. If you mean to control things like entertainment system, then maybe i'm okay with that. But I would not consider that controlling the car
1. They only allow for tokens that take a very long time to expire, it's something like 3 months.
2. Although a few of these apps allow you to get the token on your own and send it to them (thus not exposing your password), that's too technically demanding for most users and so most of the apps have you get a token by giving your email/password, thus you expose it to them.
For those that don't know, Tesla pays people for security vulnerabilities, welcomes hacker attempts, they disclose things after they fix them, there's a list of the things and people who found them at their website, etc. There is a separate computer system for the drive train that is not accessible through this system.
It might not be able to drive itself, but it can definitely control how fast and its direction, which would be super scary for some random dev to have any impact on.
Frankly, this is Apple arbitrarily choosing apps they don't like and findng a loophole to block it.
Who guarantees there even is a "third-party relationship business between the Developer and Tesla"?
Should Apple let any app that claims to have one or be officially sanctioned or whatever dupe customers?
Next thing you'll tell me there's a Sanity Clause, with little elves helping him, etc.
Yeah, I know. My question is: "who guaranteers that the app maker has any agreement with Tesla"?
One could release an app claiming so, without Tesla approval, and do shady stuff -- where Apple gets part of the blame from customers.
Historically Apple has always required consent for using such APIs and in many cases that’s a result of the API owner complaining.
I came across a remote control app getting rejected months ago for using an unofficial TV API.
Or would Apple also block such a thing?
Apple's argument is that they know that there's no official API so his can't be legal.
So much power in a company is really scary IMHO.
It’s quite common for you to instead do such a thing, since the cost of hosting such a service is nothing for you. The APIs are also extremely stable, so it’s not like Tesla is going to pull the rug from under you.
The only benefit of layering your own API on top of Tesla’s would be some sort of data collection.
EU has already ruled that APIs are not subject to copyright, https://econsultancy.com/will-the-oracle-google-lawsuit-kill...
_Technically_ it is a crime to access a remote computer without permission -- Computer Fraud and Abuse Act [1].
[1]: https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
In the wiki article, this deals with the "Remote APIs" definition, not the "Libraries and frameworks" definition. https://en.wikipedia.org/wiki/API#Usage