upvote
At least they're exposing their nefarious plans for the purposes of... Offering people mental healthcare?

It's probably just some Apple bug.

reply
Why did a mental healthcare company have the ability to exploit this?

Do you think they accidentally found this 5 seconds before their exploit was launched or do you think they might have actually put some effort into doing this since they are an organization of people.

reply
I am pretty skeptical it’s intentional. Very risky move. If they make apple look bad they can say goodbye to getting featured in the app store, or could even get pulled from the store completely.

I can see a fucked up ceo greenlighting a trick to get their app installed on your phone without asking. I can’t really see them having it repeatedly download.

I suspect it’s a bug, or worst case a backdoor that’s been triggered with a commercial app instead of spyware accidentally or “accidentally”.

reply
I cannot possibly imagine the company as a whole would approve of this, much less anyone at the company who wants to keep their job. If it’s found that they exploited Apple to cause this, Apple might force-remove their app worldwide and definitely will kill their developer account pending any lawsuits. That’s the sort of thing that gets a CMO fired. Seems extremely unlikely, but if their C_O gets fired on Monday or Friday, then we’ll probably know why :D
reply
> The fact that it’s happening shows that they always had the ability...

That may not be the case here, and certainly isn't the assumption we can make more generally.

We regularly see regressions in platform security.

reply
[flagged]
reply
Please don't comment about the voting on comments. It never does any good, and it makes boring reading.

https://news.ycombinator.com/newsguidelines.html

reply
When this forum handles the bot and propaganda problem I might consider those rules.

Currently we are inundated by accounts who don’t give a shit and make a new automatically 3 seconds after their flagging.

As long as those accounts are allowed I don’t really care for the stated rules that aren’t actually enforced.

reply