Hacker News new | ask | show | jobs
by joeberon 3541 days ago
What actually happened:

1. Guy publishes good paid app and gets a tonne of good reviews

2. He helps out a relative by buying an apple developer account for them, giving them a machine to test with

3. Relative also uses same "com.kapeli.*" bundle ID

4. Relative decides to buy 1000 fraudulent reviews

5. Apple tells the relative to stop posting fraud reviews, who refuses

6. Apple terminates both developers accounts since they are all the same information (they look like the same person, same credit card, bank account, test machine, and bundle ID)

https://www.reddit.com/r/apple/comments/56uque/apple_dash_de...

4 comments

The accounts were linked (same devices, same credit card number): https://london.kapeli.com/downloads/Apple_Call.m4a (edit: direct link to the phone call with the Apple representative)

As much as they tend to piss me off for other things. I don't see any wrongdoing from them. It's like accusing them of cutting off the payments to a bakery that operates from the same bank account to that of a drug dealer.

Also that kind of blackmail: "You're sure you want that statement to become public?" is plain stupid.

Why is the developer being so dense? Just being difficult for no reason because he has a stick up his ass.

"You're sure you want that statement to become public" it literally makes no sense...

All he's done is posting that Apple call has burnt every bridge he had with them, and made Apple look great. Literally they sound very professional on that call and very willing to help him, and instead he is just being unnecessarily difficult.

Actually I wouldn't be so sure as to who burnt the bridge first. He posted the recording after Apple went public with their side of the story.

What happened to the supposed blog post? Why did Apple go to the press without getting back to him on the draft?

No one knows what happened between the phone call and Apple's press release. So we can't make judgment on that.

That said, I was amazed how that guy from Apple was being so patient with this guy being so immature. The Apple guy was trying his best to sort this out, but for every word he said, this Dash guy would keep complaining. This phone call could have ended in 30 seconds but took over 7 minutes because all this guy did was complain (which I think he did for the purpose of making this recording), and I don't even know what you would get from complaining that way when the other person was trying to help you. I would have been pissed if I was that Apple guy.

They weren't linked in the UI. They were "linked" in Apple's backend system according to secret heuristics. The dev had no idea they were linked, so I hate seeing people stating "the accounts were linked" as if that's something he should have known or anticipated.

How many random devs and accounts have been secretly "linked" to my account? I have no idea.

That's extremely naive, to think that accounts with the same CC are not linked.
I find it hard to believe that this happened without his knowledge. It was his credit card. It was his identifier. I can not imagine he never searched the store for lookalikes or his identifier, etc.

See https://software.com/publisher/kapeli

Just to clarify: On Friday my position was "I have no reason to believe Kapeli is lying and every reason to believe that Apple made a mistake". But after reading and listening to various sources I can not defend this position any more. It makes me sad.

Don't forget:

7. Apple offers to reinstate the developer account, iff the user makes a post pointing out how this wasn't Apple's fault.

> 3. Relative also uses same "com.kapeli.*" bundle ID

Just saying: anyone can freely create any App ID they want. I just successfully created "com.google.android.nougat" as a test.

I'm fairly sure you don't have the same user and CC on file as they do.
But it proves bundle IDs can only be treated as circumstantial evidence at most.
So you combine that with the same CC number on file, and the same development machines, and now you have a very good chance the same person is responsible.
Do you expect to use this identifier to make money (in a fraudulent way) and Google not caring over several years?