Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They're using MacBuildServer, which provisions it with its own enterprise account, which is against ToS and I would expect macbuildserver's public provisioning to get shut down and the profile revoked


MacBuildServer created at least one of the certs they use for signing inhouse/universal distribution apps on 2013-05-15T16:48:45Z, and it has not yet been revoked. If it does get revoked, they can just remove that part of their service, and continue to allow people to upload their certs, keys and provisioning profiles for building server side. (o.O)

Once MBS becomes more popular, Apple will have to react to prevent others from abusing this. This is the first real test I can recall of their enforcement policy. Honestly, I can't see any enterprises that rely on iOS internally risking TOS violations in a similar public manner even if Apple decides not to enforce TOS with MBS.


Yep, it's just this one feature, the rest of the build service is safe, and potentially cool from a features standpoint. I assume the fear is it would be fairly trivial to add an app store on top of this.


Right, that is the fear, and I think Apple may only act if the competing App Store is affecting their bottom line via lost revenue. But who would build something like this knowing Apple can shutdown their business at any time?

Cydia is the only real competing appstore I am aware of, and they are relying on iOS bugs that Apple keeps patching.


Yeah, this is blatant abuse of the enterprise certificate program. This kind of activity sucks for those of us that use the enterprise signing cert for legitimate purposes.


This is definitely an abuse of the program, but it hurts to see you use the word 'legitimate' to mean 'apple-sanctioned'. They're not tricking anyone, just letting people install custom apps without paying apple a huge* developer fee.

*$100 is more or less acceptable, $100 per year for revocable permission to compile is awful


"They're not tricking anyone"

Don't forget Apple. They told Apple that they would not use this key in certain ways, even though they do.

I don't see the problem with calling this "illegitimate". Jailbreaking so you can sideload apps is legitimate. Somehow cracking Apple's verification so you can sign apps without their involvement would be legitimate. But signing up for an enterprise account and then using the keys they give you as part of that in ways they tell you not to is, I think, legitimately illegitimate (ahem).


Okay, I guess I should have expected that to be taken literally. Sorry. I meant that they are tricking, to 1% margin of error, nobody. The core of their business is legitimate. They're not scammers.


Or we can put a different spin on it, and say that they are "only" tricking their major contractual business partner, the one entity without which they would have no business to begin with.


The most important business question would be how they make their money. As far as I know their main service does not depend on violating the license in any way, so they are nowhere near being fraudsters. If they were leaching all their money off of Apple I would accept the judgement, but I don't think that's the case.

Edit: @downvote, am I wrong? I was trying to trust this comment https://news.ycombinator.com/item?id=6047309


> $100 per year for revocable permission to compile is awful

If you're making any kind of serious money on the app store, this cost is practically nothing. Maybe 2-4 hours of your time, tops.

Think about how much the Macbook Pro you use to develop on costs.


I program as a hobbyist. I would like to be able to fiddle around with my ipod touch. For me, $100 per year to test if I would like programming in that environment is too much.


It's completely free to fire up Xcode and play in the simulator all day long. All the developer account gets you is a signed certificate and access to the App Store. You're free (physically and monetarily) to experiment to your heart's content within the simulator.


For access to the app store, the fee is fine. For the ability to put the code onto your actual phone instead of a simulated phone it's a complete ripoff. It shouldn't be bundled like that.


Check what "legitimate" means.


First definition is obeying laws/rules, that fits.

Second definition is "Being in accordance with established or accepted patterns and standards", and that's where it hurts me to read the characterization. They are doing something acceptable and that is very standard in the realm of computing, and seeing it discouraged sucks.


To be granted an enterprise or standard developer signing certificate, you must agree to a contract that stipulates the valid uses of that certificate.

I think it's reasonable to call blatant disregard for contractual obligations "illegitimate".


Are there any other examples of apps that would normally be forbidden in the App Store that can be installed in this way?


Yeah, Apple also bans tethering/proxy apps as well as anything related to P2P.


I would imagine you could install Gnu GO, VLC, or any other GPL software that has been removed from the App Store.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: