Live data from Hacker News

Let's guess what Google requires in 14 days or they kill our extension

blog.pushbullet.com

671–680 of 811 posts

Re: Let's guess what Google requires in 14 days or they kill our extension

#671

Earlier quoted context omitted.

Would it be better if Chrome said "There are 200,000 extensions on the Chrome store, each and every one of them deserves attention, we need to spend at least 30 minutes looking at each one and composing a response, we have a ten-person team, we'll get back to you within 5 years?" Yeah, but with 100 people it would take only a few months and after that it would take far less people to maintain everything. Also, they c…

Apple manages to do it somehow - when you get rejected, you can discuss the rejection reason if I remember correctly. Also, from 200k extensions probably most have less than five users, so they could prioritize those that have traction.

I see a lot of threads on HN discussing complaints about how locked down Apple is. I suspect many of the extensions that are problematic for Google never would have even been allowed into Apple's ecosystem in the first place.

In general, Safari's extension system is more restricted than Chrome's, and changes that Chrome is attempting to make to be more similar to Safari's approach result in fierce backlash exactly like this thread (e.g. https://www.wired.com/story/google-chrome-ad-blockers-extens...).

Re: Let's guess what Google requires in 14 days or they kill our extension

#672
post #630

Earlier quoted context omitted.

The theoretical problems that are also hypothetical I have some trouble following this. These are real, exploited capabilities. How are they theoretical and also hypothetical?

I just did not see any indication of the permission actually being abused by this specific extension, hence the hypothetical. That's not meant to dismiss that it is an issue but in this specific case I think the communication is worse than the potential problem given that the devs don't seem to have a negative track record and actively work on mitigating it. As for the redundancy, I blame my lack of coffee for that,…

Ah that makes sense, thanks. I think this is the bit where we disagree:

I think the communication is worse than the potential problem

In that I think the communication is really bad but the 'potential' problem is more than potential and also really bad.

Re: Let's guess what Google requires in 14 days or they kill our extension

#673
post #518
post #494

Earlier quoted context omitted.

That's the thing I'm sympathetic to - having fixed the bug , it's frustrating that it's not clear what the next steps are. But given that they had the bug, Chrome was absolutely in the right to deny them the first time. And while I don't like Chrome's position that they're too busy to explain to everyone what they're doing wrong, if extensions that go "oh hey, we don't actually need access to literally every website,…

I can only assume that this isn't the result of a human flagging Pushbullet like this; I expect it's an automated system. And if that automated system can make a decision to flag the extension, it could also include in the email specifically what caused that flagging to happen. At this point I'm really starting to become unsympathetic to the idea that they can't tell you what you're doing wrong because it'll enable p…

I agree, and will go further in that I believe they actually should have such an obligation: it should be a consumer right to find out why you were denied access to a platform--or a restaurant, or a barber shop, or a wedding cake maker, or whatever else that someone is refusing you service due to, as a business operating in the public--and that whatever reason that is must be something that either 1) has nothing to do with the customer and can be shown to have nothing to do with the customer (such as "we do not have enough workers to take more orders and we didn't do anyone other than you") or 2) is clearly and obviously "correctable" (so like "because you are gay" doesn't count); if the platform (or service or business) refuses to tell you, or their reason isn't "correctable", there should be heavy penalties attached for what amounts to opaque discrimination.

(FWIW, I appreciate the idea that eventually it would be useful to be able to ban a bad actor entirely from something to exclude the possibility of future harm: the past tense of "correctable" was "avoidable", and it needs to be very clear exactly what was done wrong and what could have been done differently for someone to end up in the situation of being banned from the usage of a platform, service, or business: the alternative where people get to apply secret and obscure reasons to refuse service is madness.)

Re: Let's guess what Google requires in 14 days or they kill our extension

#675
post #590

Earlier quoted context omitted.

Doesn't Mozilla get nearly all its money from Google; I've assumed that actions by Mozilla have been coloured by not wanting to ditch its multi-hundred-million dollar benefactor. Google has apparently paid Mitchell Baker personally multiple millions of dollars too. Seems Google know how to manage their risks. Mozilla seem perhaps even more beholden to ad revenue than Google.

> Google has apparently paid Mitchell Baker personally multiple millions of dollars too. What are you talking about?

Google fund Mozilla, it's not a secret, you can use a search engine and find such information.

Or did you mean to contradict me rather than ask a question?

Re: Let's guess what Google requires in 14 days or they kill our extension

#676

Earlier quoted context omitted.

I agree. This is hackernews, so it is easy why devs would feel otherwise, but as a nondev, I represent the the end users. Why would anyone think it is appropriate for google to reveal their hand, and allow blackhat operators to build apps up to the max limit of permissions? (If they were revealed by google via white glove customer service). If goog did provide guidance on permissions, goog would literally have to aud…

> If goog did provide guidance on permissions, goog would literally have to audit every app in the store, or come up with a way to separate bad actors from good ones. This makes no sense. For the sake of the grandmas, Google already needs to audit every app in the store and separate bad actors from good ones. How in the world would making it more clear how to write more secure extensions possibly worsen the extension…

> How in the world would making it more clear how to write more secure extensions possibly worsen the extension store's malware problem?

Unfortunately, information that helps the good guys get their extensions past the audit check is exactly the same information that helps the bad guys get their extensions in too. The bad guys simply move onto the next security flaw that Google hasn't anticipated.

Maybe the bad guys use some common tactics to get their scam extensions in the store which good guys don't, which is easy for Google to detect and flag. If you release a list of known no-no's, the bad guys just get smarter and avoid them.

This obviously skews in favour of refusing some good extensions to keep most bad ones out.

In terms of Google already auditing every app, check out the source code for Dark Reader https://github.com/darkreader/darkreader. It's fairly complex. I can only imagine how many extensions are as, or more, complex than that. I wonder how much auditing is done manually vs automated.

Re: Let's guess what Google requires in 14 days or they kill our extension

#677
post #463

Earlier quoted context omitted.

> "no support and no service" model? this is one of the reasons why Google cloud will lose to AWS in the long run. AWS is customer obsessed, Google is not.

It's so difficult to imagine a) getting ahold of someone at Google who can actually help you, and b) having some sense of assurance that they will actually help you. "Google deleted my X" posts always rise to the top on HN because they elicit a strong emotional response from developers. I think it's worthwhile to reflect on why that happens. For me, it's because I absolutely despise seeing an algorithm have control o…

I don't understand how people work for these companies as developers and implement these policies and systems and aren't just as angry about it and don't stand up to their supervisors over it: if frankly makes me have a really low opinion of people who work for Google, Apple, etc. :/.

Re: Let's guess what Google requires in 14 days or they kill our extension

#678
We tried to create an android app and we never were able to got it submitted. We never figured out why and just gave up.

I’ll never again try to create a business around an environment outside our control. Both Google and Apple are complete black boxes.

Re: Let's guess what Google requires in 14 days or they kill our extension

#679
post #170

Earlier quoted context omitted.

> It's a pity that Chrome doesn't allow extensions to be installed from the new Edge store Why would anyone want to do that? What's a real pity is that they make every effort to block users from installing their own extensions. App stores are terrible.

No, they make every effort to ensure that installing extensions outside the store is annoying so that you can't push your malware by just having users download and install it. This kind of malware plagued Firefox for years until they made extension signing mandatory

If I am in a position to install random shit into Firefox I am also in a position to just modify Firefox, so that doesn't accomplish anything at all except remove functionality from users.

Re: Let's guess what Google requires in 14 days or they kill our extension

#680
post #486
post #474

Earlier quoted context omitted.

The rule still applies: if you build your business on someone else's property, don't act surprised when they they casually destroy you. It has happened again and again and again. Building for FB or Google is you making yourself their serf, and you will be allowed to exist at their whim.

This isn't very actionable advice, though, since there is basically no such thing as a software product that isn't built on somebody else's property. You might think, "Ah-ha, web apps!" But no, Google can still casually destroy you there. Or you might think, "Ah-ha, desktop apps!" But the OS vendor can casually destroy you there.

> Or you might think, "Ah-ha, desktop apps!" But the OS vendor can casually destroy you there.

Casually? The amount of effort and goodwill, say, Microsoft would need to spend to prevent me from installing $PROGRAM on my computer is significantly higher than the amount of non-effort a single extension reviewer would need to expend to click "no" arbitrarily because they are having a bad day.

How would Microsoft do it? Add legit software to Defender? Ship a Win10 update that disables a key API call $PROGRAM uses? Add "if program == $PROGRAM then exit" to the CreateProcess code? All possible, none casual. To the best of my knowledge they've never done something like this. I'm less deep into Apple land but I expect something similar holds on macos.

Post reply on HN