From what I've read, the Facebook research app installed a new root certificate on the device which allowed man-in-the-middle interception of all encrypted internet traffic. Which is obviously a huge issue.
From what I've read, the Google app does not appear to be doing this.
I am assuming the main reason that Apple revoked the enterprise distribution certificate for Facebook is due to this man-in-the-middle attack on encrypted traffic. The fact that they are solely circumventing the Appstore using an enterprise distribution certificate is a different issue.
Is my understanding of all this true? It would seem to me that Google isn't really doing anything that bad and Facebook has had its enterprise distribution certificate revoked for good reason.
“We designed our Enterprise Developer Program solely for the internal distribution of apps within an organization. Facebook has been using their membership to distribute a data-collecting app to consumers, which is a clear breach of their agreement with Apple. Any developer using their enterprise certificates to distribute apps to consumers will have their certificates revoked, which is what we did in this case to protect our users and their data. “
I wonder if Facebook may argue on what constitutes an "organization" or "consumer", because the sum of all Facebook users is clearly a something... and as much as those users consume, they are also the ones ultimately contributing to Facebook's profits... it's not so black and white after all.
One thing I'll point out is that Comscore has been doing this with websites since the early 00s. They packaged it as some sort of "free website antivirus protection" or some related BS, and when you installed it it installed a root certificate in your browser, specifically so that Comscore could read all your SSL traffic for ecommerce purchasing analytics. I even remember if you used their uninstaller to uninstall it, it left the root cert in place. IIRC Comscore at one point claimed millions of installed users.
Google is doing exactly the same thing as Facebook. Both are using Apple's enterprise distribution certificate to track what is going on on users' devices.
From what I've read, the Google app does not appear to be doing this.
I am assuming the main reason that Apple revoked the enterprise distribution certificate for Facebook is due to this man-in-the-middle attack on encrypted traffic. The fact that they are solely circumventing the Appstore using an enterprise distribution certificate is a different issue.
Is my understanding of all this true? It would seem to me that Google isn't really doing anything that bad and Facebook has had its enterprise distribution certificate revoked for good reason.