{"id":32231,"date":"2021-04-22T15:53:48","date_gmt":"2021-04-22T19:53:48","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=32231"},"modified":"2021-05-07T14:30:24","modified_gmt":"2021-05-07T18:30:24","slug":"the-app-store-isnt-catching-the-most-egregious-scams","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2021\/04\/22\/the-app-store-isnt-catching-the-most-egregious-scams\/","title":{"rendered":"The App Store Isn&rsquo;t Catching the Most Egregious Scams"},"content":{"rendered":"<p><a href=\"https:\/\/pxlnv.com\/linklog\/app-store-scams-reporting\/\">Nick Heer<\/a>:<\/p>\n<blockquote cite=\"https:\/\/pxlnv.com\/linklog\/app-store-scams-reporting\/\">\n<p>One more thing that I think is critical is that it is, right now, impossible to flag an app as a rule-breaker or a scam. Say you download an app and it is, in some way, worth reported to Apple. Let&rsquo;s start in the App Store, where there is no button to report an app, not even in the app listing&rsquo;s share menu. If you go to Apple&rsquo;s <a href=\"https:\/\/reportaproblem.apple.com\/\">Report a Problem<\/a> website, you will see all of your purchases and downloads from your Apple ID, and you will be be asked a question, &ldquo;What can we help you with?&rdquo; for a dropdown menu containing these options[&#8230;] If you pick the last one, you&rsquo;ll be sent to a screen where you will be told to contact Apple Support if you think your Apple ID has been compromised; it has nothing to do with the items you purchased or downloaded.<\/p>\n<p>[&#8230;]<\/p>\n<p>But it appears that, if a scam makes its way into the App Store, Apple is entirely dependent on users posting on social media or contacting Apple through another channel to be alerted to problems.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.theverge.com\/2021\/4\/21\/22385859\/apple-app-store-scams-fraud-review-enforcement-top-grossing-kosta-eleftheriou\">Sean Hollister<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.theverge.com\/2021\/4\/21\/22385859\/apple-app-store-scams-fraud-review-enforcement-top-grossing-kosta-eleftheriou\"><p>Recently, I reached out to the most profitable company in the world to ask a series of basic questions. I wanted to understand: how is a single man making the entire Apple App Store review team look silly? Particularly now that Apple&rsquo;s in the fight of its life, both <a href=\"https:\/\/www.theverge.com\/2021\/4\/8\/22373826\/epic-games-v-apple-fortnite-app-store-antitrust-lawsuit\">in the courts<\/a> and <a href=\"https:\/\/www.theverge.com\/2021\/4\/11\/22378697\/apple-witness-senate-judiciary-hearing-antitrust-app-stores\">in Congress later today<\/a>, to prove its App Store is a well-run system that keeps users safe instead of a monopoly that needs to be broken up.<\/p>\n<p>That man&rsquo;s name is <a href=\"https:\/\/twitter.com\/keleftheriou\">Kosta Eleftheriou<\/a>, and over the past few months, he&rsquo;s made a convincing case that Apple is either uninterested or incompetent at stopping multimillion-dollar scams in its own App Store. He&rsquo;s repeatedly found scam apps that prey on ordinary iPhone and iPad owners by luring them into a &ldquo;free trial&rdquo; of an app with seemingly thousands of fake 5-star reviews, only to charge them outrageous sums of money for a recurring subscription that many don&rsquo;t understand how to cancel. &ldquo;It&rsquo;s a situation that most communities are blind to because of how Apple is essentially brainwashing people into believing the App Store is a trusted place,&rdquo; he tells <em>The Verge<\/em>.<\/p>\n<p>[&#8230;]<\/p>\n<p>And we&rsquo;re starting to hear from Apple insiders, too, that the company&rsquo;s claims about App Store security are overblown. Eric Friedman, the head of the company&rsquo;s Fraud Engineering Algorithms and Risk (FEAR) team, will be testifying in next month&rsquo;s Epic Games trial. In a recent deposition he spoke of the App Review team as &ldquo;bringing a plastic butter knife to a gun fight&rdquo; and &ldquo;more like the pretty lady who greets you with a lei at the Hawaiian airport than the drug sniffing dog.&rdquo; His team reportedly believed App Review&rsquo;s job was incentivized to get apps &ldquo;through the pipe&rdquo; and &ldquo;move people through&rdquo; like TSA employees.<\/p>\n<p>[&#8230;]<\/p>\n<p>By the way: you know that app that John Gruber helped draw attention to in 2019, the one that reportedly charged $10 every week for wallpaper you could find free online? <a href=\"https:\/\/apps.apple.com\/us\/app\/background-beautiful-photos\/id1171036231\">It&rsquo;s still on the App Store<\/a>. Never got removed.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/pxlnv.com\/linklog\/eleftheriou-profile\/\">Nick Heer<\/a>:<\/p>\n<blockquote cite=\"https:\/\/pxlnv.com\/linklog\/eleftheriou-profile\/\"><p>It is remarkable because it is so simple. Hollister was easily able to replicate Eleftheriou&rsquo;s scam-finding techniques, which combines data that Apple makes publicly available and information estimated by SensorTower. Some of these scams are raking in, according to Eleftheriou and SensorTower&rsquo;s data, millions of dollars per year, and they are plentiful.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/stratechery.com\/2021\/podcast-subscriptions-vs-the-app-store\/\">Ben Thompson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/stratechery.com\/2021\/podcast-subscriptions-vs-the-app-store\/\"><p>App Review [somehow] seems far more effective in figuring out how to navigate from a privacy policy on a web page to a purchase page (and subsequently rejecting the app) than it is in rooting out scams. <\/p><\/blockquote>\n\n<p><a href=\"https:\/\/world.hey.com\/dhh\/apple-is-an-accomplice-to-fraud-b4197da7\">David Heinemeier Hansson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/world.hey.com\/dhh\/apple-is-an-accomplice-to-fraud-b4197da7\">\n<p>Now the problem is that Apple is defacto an accomplice to fraud. They knowingly aided and abetted scams that preyed on consumers and cost them millions. They were alerted and warned, specifically and repeatedly, about these scams, and not only did they do nothing, they continued to profit from the scams! Every scam that ran through the in-app payment system paid Apple a 30% cut of the take.<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/04\/09\/apple-and-epics-proposed-findings-of-fact\/\">Apple and Epic&rsquo;s Proposed Findings of Fact<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/03\/18\/flicktype-developer-sues-apple\/\">FlickType Developer Sues Apple<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/02\/03\/scammy-keywatch-and-trezor-apps\/\">Scammy KeyWatch and Trezor Apps<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2020\/09\/30\/widgetsmith-and-the-case-of-the-missing-app-store-bunco-squad\/\">Widgetsmith and The Case of the Missing App Store Bunco Squad<\/a><\/li>\n<\/ul>\n\n<p id=\"the-app-store-isnt-catching-the-most-egregious-scams-update-2021-05-05\">Update (2021-05-05): <a href=\"https:\/\/twitter.com\/keleftheriou\/status\/1385311694302314498\">Kosta Eleftheriou<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/keleftheriou\/status\/1385311694302314498\">\n<p>Apple&rsquo;s non-answers to Senator \n@ossoff&rsquo;s great questions in <a href=\"https:\/\/techcrunch.com\/2021\/04\/22\/apple-downplays-complaints-about-app-store-scams-in-antitrust-hearing\/\">yesterday&rsquo;s hearing<\/a> should anger all of us. They did not offer any explanation for why it&rsquo;s so easy for me to keep finding multi-million-dollar \n@AppStore\n scams that have been operating for years.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/twitter.com\/keleftheriou\/status\/1389381738023907329\">Kosta Eleftheriou<\/a>:<\/p>\n<blockquote cite=\"https:\/\/twitter.com\/keleftheriou\/status\/1389381738023907329\">\n<p>Two years later, the developer account of a fraudulent and LIFE THREATENING app is still up on the @AppStore! &#x1F92F;<\/p>\n<\/blockquote>\n\n<p id=\"the-app-store-isnt-catching-the-most-egregious-scams-update-2021-05-07\">Update (2021-05-07): <a href=\"https:\/\/www.macrumors.com\/2021\/05\/06\/phil-schiller-on-app-store-knockoffs-in-2012-is-no-one-reviewing-these-apps\/\">Juli Clover<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.macrumors.com\/2021\/05\/06\/phil-schiller-on-app-store-knockoffs-in-2012-is-no-one-reviewing-these-apps\/\"><p>At the time, Temple Run was a super popular iOS exclusive title, and in February 2012, a fake version of Temple Run hit the  App Store  charts. Schiller sent out an email to Eddy Cue, Greg Joswiak, Ron Okamoto, Phillip Shoemaker, Matt Fischer, Kevin Saul, and others on the  App Store  team. &ldquo;What the hell is this????&rdquo; he asked. &ldquo;How does an obvious rip off of the super popular Temple Run, with no screenshots, garbage marketing text, and almost all 1-star ratings become the #1 free app on the store?&rdquo;<\/p><p>&ldquo;Is no one reviewing these apps? Is no one minding the store?&rdquo; he ranted on, before asking whether people remembered a talk about becoming the &ldquo;Nordstrom&rdquo; of App Stores in quality of service.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/take.surf\/2021\/05\/06\/macrumors-phil-schiller-on-app-store-knockoffs-in-2012-is-no-one-reviewing-these-apps\">Jesper<\/a>:<\/p>\n<blockquote cite=\"https:\/\/take.surf\/2021\/05\/06\/macrumors-phil-schiller-on-app-store-knockoffs-in-2012-is-no-one-reviewing-these-apps\"><p>Oh, spin me once again a yarn about how the App Store is inherently slathered in discerning curation; so discerning that low effort scams emerge, and so discerning that automated processes are dreamed up to salvage the situation, with automatically triggered removal of <em>already approved applications<\/em> without consideration for due process or developer impact the inevitable and apparently desirable outcome.<\/p><\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2021\/05\/06\/epic-v-apple-day-3\/\">Epic v. Apple, Day 3<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Nick Heer: One more thing that I think is critical is that it is, right now, impossible to flag an app as a rule-breaker or a scam. Say you download an app and it is, in some way, worth reported to Apple. Let&rsquo;s start in the App Store, where there is no button to report [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2021-05-05T20:35:42Z","apple_news_api_id":"35aa1dc6-80e3-445a-882e-9d6b7c38f338","apple_news_api_modified_at":"2021-05-07T18:30:29Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAA==","apple_news_api_share_url":"https:\/\/apple.news\/ANaodxoDjRFqILp1rfDjzOA","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[1846,91,2036,31,1837,1372],"class_list":["post-32231","post","type-post","status-publish","format-standard","hentry","category-technology","tag-app-review","tag-appstore","tag-app-store-scams","tag-ios","tag-ios-14","tag-phil-schiller"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/32231","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=32231"}],"version-history":[{"count":3,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/32231\/revisions"}],"predecessor-version":[{"id":32407,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/32231\/revisions\/32407"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=32231"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=32231"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=32231"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}