Live data from Hacker News

Dear Dash Users – A message to all Dash users from the Kapeli Blog

blog.kapeli.com

31–40 of 110 posts

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#31
post #3

Earlier quoted context omitted.

What actually happened: 1. Guy publishes good paid app and gets a tonne of good reviews 2. He helps out a relative by buying an apple developer account for them, giving them a machine to test with 3. Relative also uses same "com.kapeli.*" bundle ID 4. Relative decides to buy 1000 fraudulent reviews 5. Apple tells the relative to stop posting fraud reviews, who refuses 6. Apple terminates both developers accounts sinc…

> 3. Relative also uses same "com.kapeli.*" bundle ID Just saying: anyone can freely create any App ID they want. I just successfully created "com.google.android.nougat" as a test.

Do you expect to use this identifier to make money (in a fraudulent way) and Google not caring over several years?

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#32
I was rooting for him really, because I myself am also at times very frustrated with how Apple treats developers.

But I've lost trust in this guy after reading his blog posts and especially the phone call he published.

The only reason I can think of why the phone call took over 7 minutes is because he wanted to record it and publish it. Really. If you summarize the phone call. It's basically Apple asking him to publish that his account was indeed linked with the fraud account (not even that he's the one who committed the fraud) and he's working with Apple to resolve it, and rest is this dash guy complaining on and on which is completely unnecessary since Apple already knows that and is saying they understand and want to work with him to "make this right" (The Apple guy literally said "make this right").

Also it is very hard to believe at this point that a "relative" did all this. If I--or any normal person--was in the same situation (I am paying for a relative's developer account with my own credit card with my device and turns out that the relative is committing a fraud), my first reaction would NOT be telling Apple "This has nothing to do with me", but "I had no idea, I am still pissed that you guys didn't notify me, but I also understand your position and will talk to my relative to make sure this doesn't happen. After all, I am the one funding this fraud regardless of whether I was aware or not aware.")

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#33
Weird that i find out about this here - wonder if he's able to send an email to Mac Store purchasers like myself. Regardless, i migrated my license, and all seems to be working now.

Glad the issue didn't impact me too negatively, and i hope this is true for most of his customers.

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#34
post #28

This is hilarious: My preferred solution would be for a fellow developer to get it back on the App Store, as a free app. Especially because: Open sourcing doesn’t look like a good solution at this time, as most of my users are not iOS developers and are not familiar with compiling an app for their devices. I may be missing something but the author cannot open source the app, but expects a fellow developer to get it o…

It would be tough to take the existing app and reupload it, but this guy could certainly provide another developer with a built binary which they would then submit.

You'd have to be mad to actually do that, though. We see quite clearly how Apple can react when they think they've been wronged, and who knows what that binary actually contains.

Seems like the best approach would be to open source it and convince somebody (perhaps several somebodies) to build it from source and put it on the store for free. Obviously, the source release would need to be under a license that was compatible with an App Store release (i.e. no GPL).

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#35
post #28

This is hilarious: My preferred solution would be for a fellow developer to get it back on the App Store, as a free app. Especially because: Open sourcing doesn’t look like a good solution at this time, as most of my users are not iOS developers and are not familiar with compiling an app for their devices. I may be missing something but the author cannot open source the app, but expects a fellow developer to get it o…

That is likely to get the "fellow developer" banned/suspended with the current App store policy.

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#36
post #17

There feels like no right side in this story. * Apple terminated both accounts because of fraudulent activity, but only one account was contacted to let them know of this activity. * Kapeli shared financial information and test devices with this other account, whether it was a relative or not. * Apple said "Hey, write a post telling the whole story and all will be cleared. Just don't say we were at fault." * Kapeli a…

Well, Kapeli recorded and uploaded the phone call, shooting himself in the foot.

Call it what you will, but it's the only time in this whole story that hasn't been "he said, she said."

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#37
I14n is fun — to watch for the audience.

Apple behaves as if everyone has a credit card and the mapping from credit card to (legal) person is unique. That isn't so in Romania and Apple's heuristics go boom.

The same assumption shows up again a little later in the imbroglio: Apple asked him to admit some sort of wrongdoing, however gently, because credit card maps to person to the person they spoke to carries some responsibility, etc. Bogdan rejected, because credit card doesn't map to person and giving someone $25 isn't wrong.

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#38
post #17

There feels like no right side in this story. * Apple terminated both accounts because of fraudulent activity, but only one account was contacted to let them know of this activity. * Kapeli shared financial information and test devices with this other account, whether it was a relative or not. * Apple said "Hey, write a post telling the whole story and all will be cleared. Just don't say we were at fault." * Kapeli a…

Generally, I don't get this:

* Kapeli shared financial information and test devices with this other account, whether it was a relative or not.

The assumption here is that for some reason a credit card number and device identifiers (unclear where they come from...but maybe mac address?) are enough for Apple to "link" accounts. I contest this for the same reason I think someone knowing my birthday and social security number is _not_ enough for them to be confirmed as "me".

While I don't think Apple is wrong to use this as a psuedo-identifier, I do think it is wrong for them to insist that, "we did nothing wrong" and fail to reinstate the pseudo-linked account immediately after being contacted.

I don't know if Kapeli is telling the truth about the situation...and his reputation is tarnished my eyes, but I definitely don't think Apple should insist that the accounts _must_ (with 100% certainty) be linked based off of the circumstantial credit card and test devices registered to them.

At this point Apple should either reinstate the account or come out with all the information they have to justify their actions. But having "closed door" conversations and throwing allegations at one another without proof and documentation is ridiculous.

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#39
post #4

This guy has shown quite a talent for self-sabotage. Apple was willing to reinstate him if he'd undo some of the PR damage he'd created by spelling out that he shared the credit card with someone, and that maybe that's not the best idea. Instead, he was enjoying the spotlight so much, he used the opportunity to escalate further, even publishing his phone call with Apple (illegal on one side of that conversation at le…

"(illegal on one side of that conversation at least)." This is actually not correct, it depends on the state/country he is in.

Not always true: see "Kearney v. Salomon Smith Barney"

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#40
post #22

This whole thing has taught me a lesson. I initially sided with the weaker side because I own a copy of Dash, and it is great software, and because one tends to side with the underdog. After listening to the recording of the conversation, my feeling is that Apple is handling this in a very fair and professional way, and that I was too quick to take sides. I think it is not unreasonable to assume that: same credit car…

I generally agree with you but wanted to point out that:

> same credit card + same hardware = same developer

is fine as a pseudo-identifier for fraud detection...but I don't think is actually an identifier. It's kind of like someone knowing my social security number and birthday but not actually being me.

IMO, Apple should have immediately reinstated the account once contacted about a potential edge case rather than insist that, "they did nothing wrong" because the implication of that is that the above two pieces of information is legally acceptable as personal identification and that the developer _did_ do something wrong.

I may not believe Kapeli 100% and his reputation is tarnished some in my eyes, but I don't agree with Apple standing on the notion that CC + device identifiers together are sufficient PII. Fine for fraud detection in a "pseudo-" context...sure...but not enough to deny immediate reinstatement.

Post reply on HN