Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> AirPlay is a remote interface allowing a local application to control software on a remote device and stream data to it.

The first issue with calling this "using a private API" is that the part of the application under dispute doesn't open a connection to any remote service--but accepts connections from incoming Apple hardware. It is much more correct to say that Apple is "using a private API" in this case.

The second part of the problem is that even if Rogue Amoeba was initiating connections to AirPlay clients (which they are not, at least not the part of the program under dispute), this would not be an "API" as it is usually defined.

For example, OED calls an API:

> a system of tools and resources in an operating system, enabling developers to create software applications.

Wikipedia says:

> In general the difference between an API and a protocol is that the protocol defines a standard way to exchange requests and responses based on a common transport and agreeing on a data/message exchange format, while an API (not implementing a protocol) is usually implemented as a library to be used directly: hence there can be no transport involved (no information physically transferred from/to some remote machine), but rather only simple information exchange via function calls (local to the machine where the elaboration takes place) and data is exchanged in formats expressed in a specific language.

The rest of your post deals with whether Apple is right to do what they did or whether Rogue Amoeba is right to do what they did. Did you even read my reply? In this thread, neither of those two positions are relevant. If Rogue Amoeba had broken into Apple Headquarters and personally tortured Steve Jobs to extract the private key, that would not be relevant. What is relevant is whether Phil Schiller lied and misrepresented Apple's position in a dishonest way.

Let me break down, specifically, the misrepresentations, in numerical form for easy reference:

1. "not accurately recounted on Rogue Amoeba’s website." In what sense exactly is Rogue Amoeba's website inaccurate?

2. "accessed encrypted AirPlay audio streams without using approved APIs" this implies that there exists some approved APIs that RA could have used. Again, whether Apple should or should not provide these APIs is not relevant, what is relevant is that Phil implies that usable APIs exist when they do not

3. "or a proper license" This implies that a proper license exists, see 2. Again, not relevant whether or not Apple should or should not provide a license to RA, only relevant that they imply RA had the option to use it and did not

4. "in violation of Apple’s agreements" This may be in violation of agreements that Apple has with various hardware manufacturers, but this statement implies that RA is bound by these agreements or even knows or can find out what is in them. They cannot. Essentially, Phil is holding RA to a secret standard.

5. "Apple asked Rogue Amoeba to update their app to remain in compliance with our terms and conditions" According to RA, Apple ignored RA's questions for clarification for several weeks.

6. "We have an Airplay licensing program explicitly to assist companies in creating AirPlay capable products." - This implies that RA could have taken advantage of the licensing program and did not. In fact RA could not have taken advantage of the licensing program. Whether this is good or bad is not at issue; the issue is Phil is misleading the customer.

7. "Apple never said that we would pull the rug out from anyone" - iOS guideline 2.20, 3.10, 6.3, 22.7, and others explicitly say that Apple will pull the rug out from under developers. Whether or not these are reasonable or unreasonable guidelines is not at issue in this thread; the issue is that Apple does in fact say they will do it and Phil claims they will not.

8. "we in fact worked with this developer to ensure they update their app and remain on the App Store" For some definition of time elapsed and public outcry; see #5.

I hope this clarifies the issue. Whether RA was right or wrong to extract the private key in the way that they did (or use a private key they got from another source) is not an issue. The issue is: did Phil Schiller lie to a customer? I think I've made a pretty convincing case.



> this would not be an "API" as it is usually defined.

I beg to differ, and consider both definitions you subsequently give as incredibly restrictive as it would exclude some of the most used APIs in the wild. Everyone in the field will call the Twitter API an API, and everyone will agree that StatusNet implements the Twitter API.

That said, the consumer of the API is indeed AirPlay clients while the API is being served by Apple TV, Airport Express and AirFoil Speakers (Touch). But again this does not matter (and even if we called it a protocol, and really here we have multiple protocols at hand) and RA would have every right to implement it (just as Google implements the Java API, or Wine the Windows API, or StatusNet the Twitter API).

1. It is inaccurate in that it misses one of the most critical points of the discussion.

2. I agree that RA (probably) did not use any non-approved iOS API and that they have every right to implement the AirPlay API/Protocol. I maintain though that they can not make their implementation interoperate with existing AirPlay clients that encrypt the stream. Whether that falls under the "approv[able] API" wording is a stretch, but nonetheless possible. Even RA considered that case in their May 29th post. But this does not matter, since the rest of the phrase is linked to this one with "or".

3. No this does not. This says: "you do not have a license to do that". The fact that no such licensing scheme exists is relevant only in implying that they simply can't do that at all.

4. Apple's iOS developer agreement being quite vague, I'm pretty sure they could fit almost anything they want under this agreement, and this is bad.

5. According to RA, Apple rejected the app because they deemed it non compliant, and as such they "asked Rogue Amoeba to update their app to remain in compliance with our terms and conditions". Not detailing what was not compliant, however rough, does not make the previous statement false. The first Apple answer seems like the usual preset, generic and despicable answer. If anyone takes time to analyze and invalidate an application to such levels of detail, they should disclose their full process and reasons to reject the app together with the app rejection.

6. They do have a program, and it appears to exclude software makers. I find it very sad that it comes to such an escalating situation to at least extend the current licensing scheme to software manufacturers.

7. Agreed.

8. Both the part you cite and the point you make are entirely true, and the second part is simply outrageous. Apple definitely has to improve on that front.

So, did Schiller wrote an inaccurately worded letter? Sure it did. And while they handled the case in a heavy handed and awkward manner, can we call those purposeful lies? It might be, but I'm really not convinced. In the meantime Rogue Amoeba recognizes they "inquired as to the possibility of this type of licensing being available for software manufacturers in the future, [and being] informed that it was unlikely" yet still trying to push the update through approval.

What's more they go on to say, regarding accessing the encrypted content:

> "Quite simply, it is not. While there are multiple layers of encryption involved in the AirPlay audio streaming protocol, their primary purpose appears to be preventing third parties from building applications which interoperate with AirPlay."

In a word, they assumed they had the right to circumvent a mechanism protecting Apple's licensing scheme (however vile we think it is WRT interoperability), made a run for it, were caught red handed, and called out the web regarding the injustice. Maybe they genuinely believe they're right, but that does not make them the good guys.

To sum this up, I believe both sides are at fault, but I'm much more inclined to say that they are all acting in good faith, and that such matters would resolve with much less friction if there was not so much tension (mainly due to delay and opacity, which only increase the uneasy feeling that things are arbitrary) around the review process.


> I beg to differ, and consider both definitions you subsequently give as incredibly restrictive as it would exclude some of the most used APIs in the wild.

You'll have to take that up with OED and Wikipedia. I think it's fair to say that at the point that they agree with each other and disagree with us that we're the ones using the words wrong rather than them, and it's us who need to invent new words rather than they. That's what it means to be a language authority.

#1 seems like an overall summary statement so my response is implied by the below

#2 I can't detect any disagreement

#3 - "you do not have a license to do that" - They also don't have a license to rent a bouncy castle. Phil isn't listing things that they don't have a license to do, he's (attempting to) explain why Apple rejected the application. He's implying that a license exists.

4. The word "violation" has a specific legal meaning. In this case, I can tell you for sure that he's specifically referring to agreements that Apple has with hardware manufacturers (which actually say you cannot do this explicitly), which RA has never read

5. I will concede that Phil's statement is technically correct, but when you consider how the average customer would interpret this statement, it leads them to an incorrect conclusion.

6 & 7 - No point of disagreement that I can detect.

8. No point of disagreement that I can detect.

> can we call those purposeful lies?

Phil is on the board of directors of a publicly traded company and society holds such people to an extremely high standard of honesty. I'm not sure why the word purposeful is of any relevance, but they're certainly misleading statements and Phil Schiller is not employed by Apple to blab whatever he thinks of to say to random customers.

> In a word, they assumed they had the right to circumvent a mechanism protecting Apple's licensing scheme (however vile we think it is WRT interoperability), made a run for it, were caught red handed, and called out the web regarding the injustice. Maybe they genuinely believe they're right, but that does not make them the good guys.

The following set of words: {right, vile, made a run for it, red handed, called out, injustice, good guys} ascribe a certain moral narrative to this situation that I do not subscribe to at all. There are a lot of very worldviewish questions in here (e.g. what it means for a software company to be moral, whether morality can be meaningfully ascribed to a company, etc.)

I don't mean to dissuade you of these views, because I imagine that if we take the time to wade through it, we will discover that each other's positions are pretty reasonable. But that would require us to wade through a lot of psychology, philosophy, religion and ethics to arrive at that point, and so in the interests of time I would recommend steering clear of ascribing particular ethical conclusions to the actions of actors except in the narrow cases where it is actually important, in which case we must be willing to defend it at some length.

One such area (of valuable exploration) is whether, assuming Phil made misstatements in his e-mail, it was morally correct to send. I think we agree on enough of the points to conclude that these misstatements did exist, and so the problem reduces to whether a corporate director sending misstatements to a customer is immoral. From your reply, the operative test seems to be whether they constituted a purposeful lie which is, at the very least, an interesting test.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: