>
So Apple's stance here is really that parents should have less control over their children's devices than employers have over those of their employees?Someone please correct me if I'm wrong as I haven't used any of these apps, but I thought the point here is that it's not the parents running an MDM server. I mean, I personally have long made use of MDM and profiles on iOS devices for myself and family, it's super useful (and necessary for some things like using S/MIME certs in native Mail). But I've done it via actual MDM, myself (you can also do a lot via simple distributed one shot profiles made with the free Apple Configurator software). There is no 3rd party involved.
It sounds like here that it was 3rd party apps/services that were making use of MDM functionality. "On behalf of parents" sure, but there's still a fundamentally different relationship and set of expectations for loading an app via the general App Store vs specifically enrolling a device/loading a profile from an employer someone has contractual agreements with, or someone running an MDM server themselves on their own behalf. There isn't really any way around the fact that MDM offers enormous power over devices, much of which happens without any user interaction or much (if any) exposure via the GUI. That's much of the point of it after all. That power certainly offers avenues for abuse that are different in scope.
I'm sure many of the 3rd parties are trustworthy and hopefully at least trying their best in terms of not themselves being hacked by malicious actors, but I think Apple also has a genuine legitimate concern here. A real goal for iOS is that someone can browse through the App Store and install absolutely anything they see and think looks interesting based purely on descriptions/reviews and face a known, fairly minimal and easy to reason about threat profile. Of course it hasn't always been perfect, but it's been a lot better at this then the general free for all. If some of those apps make use of MDM powers outside of normal MDM usage that breaks those expectations, that's not made up.
FWIW I personally think Apple should be required to allow other stores and permanent device owner created master signing cert loading capability, even if only via offering a more expensive "developer" model of phone with that capability not fused off. But the security and privacy tradeoffs there are worthy of consideration and efforts to find the best balances, and even in those cases I'd still be fine with Apple having their own curated App Store that remained as strict as they wished.