Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

From what I've read, the Facebook research app installed a new root certificate on the device which allowed man-in-the-middle interception of all encrypted internet traffic. Which is obviously a huge issue.

From what I've read, the Google app does not appear to be doing this.

I am assuming the main reason that Apple revoked the enterprise distribution certificate for Facebook is due to this man-in-the-middle attack on encrypted traffic. The fact that they are solely circumventing the Appstore using an enterprise distribution certificate is a different issue.

Is my understanding of all this true? It would seem to me that Google isn't really doing anything that bad and Facebook has had its enterprise distribution certificate revoked for good reason.



No, Apple’s statement makes it clear that the use of the enterprise distribution certificate signing method for this use case is an issue.

https://www.recode.net/2019/1/30/18203231/apple-banning-face...

“We designed our Enterprise Developer Program solely for the internal distribution of apps within an organization. Facebook has been using their membership to distribute a data-collecting app to consumers, which is a clear breach of their agreement with Apple. Any developer using their enterprise certificates to distribute apps to consumers will have their certificates revoked, which is what we did in this case to protect our users and their data. “


I wonder if Facebook may argue on what constitutes an "organization" or "consumer", because the sum of all Facebook users is clearly a something... and as much as those users consume, they are also the ones ultimately contributing to Facebook's profits... it's not so black and white after all.


It doesn't really matter what Facebook says, Apples TOS is basically "we can ban you without consequences whenever we want"


Nope, you are wrong!

Google is doing the exactly same thing as Facebook is doing here and so are many other companies.

It’s common practice for businesses of all types to conduct customer research. Not just in qualitative ways but also quantitatively as in this case.

I personally don’t think there is anything wrong with that...though others here disagree on that point.

Of course all of these companies are in violation of Apple’s terms...so obviously Apple is in the right to enforce them properly.


One thing I'll point out is that Comscore has been doing this with websites since the early 00s. They packaged it as some sort of "free website antivirus protection" or some related BS, and when you installed it it installed a root certificate in your browser, specifically so that Comscore could read all your SSL traffic for ecommerce purchasing analytics. I even remember if you used their uninstaller to uninstall it, it left the root cert in place. IIRC Comscore at one point claimed millions of installed users.


Google is doing exactly the same thing as Facebook. Both are using Apple's enterprise distribution certificate to track what is going on on users' devices.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: