back
310 comments
This seems entirely legitimate. Facebook were using Apple's support for enterprise distribution based on having a corporate certificate on your device, designed to allow distributing internal apps that don't make sense on the App Store proper, to distribute an app to their users - presumably because they knew it wouldn't make it through the approval process for doing distribution using TestFlight, which is what is meant to be used for this sort of app release.
Yes, this is the optimal measured response from Apple. They're treating Facebook the way they'd treat any other company that did this.

It's also a step up from the warning they gave with the whole Onovo thing. Strike two...

Wonder what’s gonna happen to Google and others who distribute their research apps the same way?

https://support.google.com/audiencemeasurement/answer/757381...

It seems Apple have been trying to occupy the moral high ground on privacy for quite a long time now. It's relatively easy for them to differentiate themselves from the other big tech companies, because Apple's products cost so much that, for once, you are not the product.

Unless FB and Big G start charging for their services, I don't see how they can change their behaviour.

I wonder if the $20 payment was so that Facebook could plausibly claim they _were_ distributing internal apps to employees?

I'm sure "employees" is defined loosely enough in the agreement to include "contractors", and the bar there is pretty low, getting paid pretty much makes you a contractor.

For someone who isn't as familiar with the mobile development can you say how do beta testing services like Applause, BetaBound and uTest differ from TestFlight? Is it just that latter are verified to be compliant with the App Store's TOS?
I hope Apple will be taking down Google's enterprise distribution certificate as well, as they are abusing it to let consumers sideload a VPN app for data gathering: https://support.google.com/audiencemeasurement/answer/757381...

And on top of that all of those from other companies doing the exact same thing for data gathering.

The problem on the Android side goes deeper, as the "Onavo Protect" app is still alive and kicking in the Google Play store [1]. The Facebook Research app here is a shallow repackaging of the iOS version of Onavo Protect, which was banned from Apple's App Store at least.

It doesn't appear Google is interested in doing anything here. They would likely have to do something about the thousands of other trojan horse VPN apps, too. It's just that those are not as transparently owned by a privacy-invading internet giant (and those apps probably sell your private information directly to the highest bidder even more eagerly).

[1]: https://play.google.com/store/apps/details?id=com.onavo.spac... - the positive, uninformed reviews of this app give me a feeling like I'm reading a dystopian novel.

Yea, how many other companies abuse the Enterprise program like this? Should we really trust Apple to enforce their TOS when they struggle to keep up with the usage of their own platform? If there’s informed consent, Apple isn’t really protecting users.

Those teens in the FB case tho.

Great find! I hope Techcrunch and others will write similar articles about this app.
My first reaction was: "Wow, FB finally went over the line and is actually an evil spyware distributor."

Then I started thinking about what this app really is. At $20/month per user, it's clearly impossible to recoup that money on a per-user basis via better ad targeting. This app is a market research app with a very small opt-in panel, just like having a Nielsen box on your TV.

I've never felt like Nielsen's data collection is evil, so it makes me wonder if my reaction is rational.

Also, looks like Nielsen has a similar program: https://computermobilepanel.nielsen.com/

These continued moves of desperation show a company terrified of losing its massive data-gathering surveillance machine.

Hoping Apple demonstrates its commitment to privacy by doing more than hurting internal functionality and speak to the only thing that matters to FB - its ability to surveil people.

This is exactly what Apple would do to a small indie developer if they found they did something similar. Glad to hear that they aren’t afraid to do it to a company like Facebook.
I think Apple is right here — they’ve detected a breach of term and shut it down.

But I still think they are wrong for blocking 3rd party apps. I understand they believe it is for my safety and security, but there needs to be a happy medium. They should have a way for experts to side load apps.

It's nice they have the capacity to do that to protect their consumer ecosystem (indirectly), however, if I'm making an enterprise ecosystem decision to build out a fleet of mobile tools for my company, "Apple has and has used the capacity to shut down the ability of the hardware we purchased to run software we wrote on that hardware" gives me pause adopting that ecosystem.

Their purpose was generally-accepted as just in this case, but what if next time, it's because someone started competing with them and they didn't like it?

This is having a real effect internally at Facebook.

In many ways this is a good punishment, disruptive to the bad actor and minimally disruptive/invasive to the consumer.

>Apple has shut down Facebook’s ability to distribute internal iOS apps, from early releases of the Facebook app to basic tools like a lunch menu. A person familiar with the situation tells The Verge that early versions of Facebook, Instagram, Messenger, and other pre-release “dogfood” (beta) apps have stopped working, as have other employee apps, like one for transportation

I love the thought of someone at Apple holding a meeting on this and saying "well, fuck them" while sending out the kill command on the CLI :)
While I have no sympathy at all for Facebook, this is a rather chilling reminder of Apple's ability to decide what you're allowed to run on your own phone.
Glad to see rules being enforced on a powerful organization.
They have stripped them of the enterprise certificate. This does not affect installed apps from the app store of course.

But still a clear statement from Apple.

I keep going back and forth regarding whether Onvaro is just "opposition research" or a sign that while Facebook is still as powerful as ever, that they are running out of product ideas. Of course it could be both, but the use of Onvaro and 'Facebook research' have a hint of desperation.
So this is what Schadenfreude feels like.
Hopefully this (likely, and unfortunately only momentary) pause in facebook employees' evil progress will inspire even a few of them to quit and use their experience for good instead.
This isn't going to stop anything. Attribution was already "laundered" through multiple different agencies and firms who were conducting this research.

They'll just cut a check to another company and proceed from there and/or a company will just sell them the data on "teen social and mobile usage" and Facebook will be able to truthfully state that they had no idea the means by which it was collected.

It's heartening to see that Apple isn't afraid to rap their knuckles when they misbehave, despite their being such a force in the tech space.
Can somebody explain the technical specifics of what was installed and what is revoked ? I'm not familiar with with iOS. My assumptions are: The original app, which was distributed by fb, installed a systemwide CA to MITM traffic after prompting the user. Is this not available to regular apps distributed on the store ? This app was not on the app store but distributed out of band. In order to sideload apps on iOS, they still need to be approved by Apple ? So Apple maintains a whitelist of developer certificates who can side load apps. Now, Apple has blacklisted this signing cert. However, this doesn't do anything to the CA, right ? However, the article says, "Revoking a certificate not only stops apps from being distributed on iOS, but it also stops apps from working." How does this work exactly ? Apple triggers all the clients in the world to freeze/remove these apps ?
Wasn't Zuck trying to actively encourage the use of Android over iOS for employees anyway? :)
It's pretty crazy to think about what Apple is capable of doing now. By banning an app, they can easily kill a small company, and now they've caused some huge internal headaches for Facebook. I know Facebook broke their rules and totally deserved it here, but it's interesting to think about the power Apple has obtained by tightly controlling their platform.
I see this as a start of a political battle between Apple and Facebook (maybe Google too with their Screenwise Meter app). First Facebook tries to push the limit of what Apple would deem acceptable. Then Apple pushes back and show that it's clearly not acceptable.

Now waiting for Facebook's response.

I'm curious as to what Facebook will need to do to get around this assuming Apple intend to have the certificate revoked indefinitely. Couldn't Facebook just start signing their apps with an alternative certificate Apple has already granted them?
This scares me. Not so much the action by apple ( they are flexing their muscle), but the reactions here. "Great!", is the jist.

It you think an unilateral revoke, and shutdown of a company internal tools, because of an external issue, without recourse is a good thing... I'm guessing you have no issues with Crazy EULA's, Monopolies, Corporate abuse, Corporations doing as they please. ( I can keep going down this slope.. )

Facebook had a program, with willing participants, that broke a third parties rules. We can argue infinitum about this.

But this is a company, STOPPING your usage of YOUR hardware, AFTER you purchased it (I'm talking about apple stopping Facebook from distributing internal tools as well, this is the side effect of this ). Think deep and clear about this. Are you ok with this?

Secondly, from the company (apple ) that literally turned everyones devices into wiretaps, globally, and ignored the issue for who knows how long... This is just.. wow. ( and they continue not to issue a formal reason for this ).

Just.. wow.

With the news yesterday about Facebook's ambitious research project this seems entirely okay.
I was really hoping Apple would yank the certs instead of just the usual “that’s not allowed, please stop and don’t do again” leniency they usually give larger companies. This is the only way to make companies listen
It starts to become interesting. Popcorn time!

I can't hide a small grin right now.

Good on Apple.
Excellent. Full marks to Apple on this. Those could be anyone's kids being taken advantage of.

Apple can't risk their integrity being associated with what Facebook are pulling.

Break the deal, face the Wheel...
i’m curious why the internal tools would fail testflight beta review. i had an app fail beta review, but was still able to distribute with testflight after explaining to the reviewers it was for internal use only...
If Apple keeps that block, then Facebook may have legal grounds of unfair business practices and sue Apple for opening up its walled garden, correct?

Certainly would be ironic that the biggest data hoarder in human history ends up breaking the biggest monopoly in the mobile space.

I love watching big tech companies fight, it's like a soap opera
How come this is already gone from the front page?
Does the timing of this have anything to do with the Facetime bug? It feels like they could have done this a long time ago.
How bad will this hurt facebook?
How long before Facebook creates its own phone and OS?
How long until Facebook creates its own phone and OS?