Live data from Hacker News

Let's guess what Google requires in 14 days or they kill our extension

blog.pushbullet.com

691–700 of 811 posts

Re: Let's guess what Google requires in 14 days or they kill our extension

#691
post #494

Earlier quoted context omitted.

That's the thing I'm sympathetic to - having fixed the bug , it's frustrating that it's not clear what the next steps are. But given that they had the bug, Chrome was absolutely in the right to deny them the first time. And while I don't like Chrome's position that they're too busy to explain to everyone what they're doing wrong, if extensions that go "oh hey, we don't actually need access to literally every website,…

Would it be better if Chrome said "There are 200,000 extensions on the Chrome store, each and every one of them deserves attention, we need to spend at least 30 minutes looking at each one and composing a response, we have a ten-person team, we'll get back to you within 5 years?" Yeah, but with 100 people it would take only a few months and after that it would take far less people to maintain everything. Also, they c…

Well of course they are using some sort of "lint" system and they know the reason.

Why not give the information to the user? There is no need to use any manual labor here.

Re: Let's guess what Google requires in 14 days or they kill our extension

#693
post #463

Earlier quoted context omitted.

> "no support and no service" model? this is one of the reasons why Google cloud will lose to AWS in the long run. AWS is customer obsessed, Google is not.

I’ve emailed and sent Linkedin msgs to 3 people who work at gcp for cloud credits. They didn’t care. AWS gave us credits + support in less than 3 days. I wish Google best of luck with their 5yr strategy. Hope their enterprise game is better than their startup one.

... so you're upset that you didn't get a service for free?

Re: Let's guess what Google requires in 14 days or they kill our extension

#694

Earlier quoted context omitted.

Yes, to a degree. But for instance, tax authorities don't have to reveal the algorithm they use to determine who gets audited.

Being audited isn't an explicit accusation that you've violated anything either; at best, it's an implicit suspicion to which the tax authority is fully entitled to probe and we as taxpayers are given reasonable opportunity to corroborate claims.

Absolutely. My point is simply that you can tell people what the rules are and which ones they may have broken without revealing absolutely everything about how you detect any malicious behaviour.

Re: Let's guess what Google requires in 14 days or they kill our extension

#695
post #474

For people focusing their comments on this particular extension + the permissions it asks for, please take a quick look at the numerous recent posts in the official forum for Chrome extension developers to see it's not an isolated issue: https://groups.google.com/a/chromium.org/forum/#!forum/chrom... It's a systematic issue that isn't specific to anything Pushbullet is doing and it's been like this before the pandemi…

The rule still applies: if you build your business on someone else's property, don't act surprised when they they casually destroy you. It has happened again and again and again. Building for FB or Google is you making yourself their serf, and you will be allowed to exist at their whim.

Their business isn’t solely built on google. Part of it relies on browsers and google have a dominant position in browsers. Should no one build a business related to browsers until google is toppled? I wouldn’t follow your “rule”, as most successful businesses started out by violating that rule.

Re: Let's guess what Google requires in 14 days or they kill our extension

#696
This is just completely disingenuous from Google.

> - Request access to the narrowest permissions necessary to implement your product’s features or services.

> - If more than one permission could be used to implement a feature, you must request those with the least access to data or functionality.

> - Don't attempt to "future proof" your product by requesting a permission that might benefit services or features that have not yet been implemented.

My first thought was "oh it would be NICE if G actually enforced these". But the truth is that they're not. One glance at the Android Play store, and it's abundantly clear that Google is letting shitty apps request whatever unnecessary permissions left and right.

Literally the top flash light app requires "full network access", GPS precise and approx location, "view network connections" and "receive data from internet".

It's complete bullshit, Google isn't policing these permissions at all, but just using it as an arbitrarily enforced rule.

It's pretty clear what the incentives are. Android already has a flashlight, but this one has ads, harvests and sells your data, and uses Google Play Billing Service. Win for Google. On the other hand, there's PushBullet, which gives users more control and this is key, the option to use a platform that is not controlled by Google. It has nothing to do with user privacy.

And the whole nice thing about these permissions is that they are granular, this means it should be trivial to point out which one is wrong or better and why, like an error message. That is not "gaming the system", it's literally what these permissions are for.

This is also clearly not an automated scanning process that PushBullet accidentally got hit by. Because it would have to have been a very slow running process, given the heaping amounts of trash in the Play Store. And then it just happened to pick PushBullet instead of the Flashlight app that has 50 times more downloads??

Re: Let's guess what Google requires in 14 days or they kill our extension

#697
post #494

Earlier quoted context omitted.

But you're completely ignoring the point that even without the all http(s) permission they will still be kicked off the store, so that has nothing do do with the issue at hand. If localhost is the issue, Google could literally respond exactly the way you did and the problem is gone, "why do you need http://localhost/?" This isn't about permissions at all. This is about communication and whether it's worth putting eff…

That's the thing I'm sympathetic to - having fixed the bug , it's frustrating that it's not clear what the next steps are. But given that they had the bug, Chrome was absolutely in the right to deny them the first time. And while I don't like Chrome's position that they're too busy to explain to everyone what they're doing wrong, if extensions that go "oh hey, we don't actually need access to literally every website,…

> But given that they had the bug, Chrome was absolutely in the right to deny them the first time.

This is not a given at all.

Google's communication was and is absolutely unclear on what is their problem.

And if you'd take their communication on their word (dumb idea), they have been pretty clear that this was in fact not, "the bug", and that is has in fact not "been fixed".

Regardless of your (and my) opinion about apps requiring access to every site on the www -- Google did exactly the opposite of indicating that this was the problem why PushBullet is threatened to get kicked off the Play Store.

Re: Let's guess what Google requires in 14 days or they kill our extension

#698
post #463

Earlier quoted context omitted.

>We hear you and are eagerly looking to improve things. Joking aside, isn't this just what people should come to expect from the company that has always tried to normalize the "no support and no service" model? If these antics start causing GOOG to lose share in the browser market then they may review these policies, but I highly doubt it. At the end of the day GOOG is an ad company and publicly-traded at that. They…

> "no support and no service" model? this is one of the reasons why Google cloud will lose to AWS in the long run. AWS is customer obsessed, Google is not.

I definitely agree. Microsoft Azure also, I feel customers have a very big part in the direction. (And right from day 1, long before azure, Microsoft focused on having “partner networks” which meant that although you weren’t dealing with Bill Gates directly you were part of a chain of motivated people all the way through to Bill.) Google’s way is not gonna last.

Re: Let's guess what Google requires in 14 days or they kill our extension

#699
post #486

Earlier quoted context omitted.

This isn't very actionable advice, though, since there is basically no such thing as a software product that isn't built on somebody else's property. You might think, "Ah-ha, web apps!" But no, Google can still casually destroy you there. Or you might think, "Ah-ha, desktop apps!" But the OS vendor can casually destroy you there.

> Or you might think, "Ah-ha, desktop apps!" But the OS vendor can casually destroy you there. Casually? The amount of effort and goodwill, say, Microsoft would need to spend to prevent me from installing $PROGRAM on my computer is significantly higher than the amount of non-effort a single extension reviewer would need to expend to click "no" arbitrarily because they are having a bad day. How would Microsoft do it?…

Microsoft could add the software to Defender's database of signatures. Or just probably revoke your certificate.

Re: Let's guess what Google requires in 14 days or they kill our extension

#700
post #518
post #494

Earlier quoted context omitted.

That's the thing I'm sympathetic to - having fixed the bug , it's frustrating that it's not clear what the next steps are. But given that they had the bug, Chrome was absolutely in the right to deny them the first time. And while I don't like Chrome's position that they're too busy to explain to everyone what they're doing wrong, if extensions that go "oh hey, we don't actually need access to literally every website,…

I can only assume that this isn't the result of a human flagging Pushbullet like this; I expect it's an automated system. And if that automated system can make a decision to flag the extension, it could also include in the email specifically what caused that flagging to happen. At this point I'm really starting to become unsympathetic to the idea that they can't tell you what you're doing wrong because it'll enable p…

> I can only assume that this isn't the result of a human flagging Pushbullet like this; I expect it's an automated system

There isn't. Take a quick look at stupid popular apps on the Play Store, almost all of them require completely unnecessary permissions literally in conflict with the bullet points that Google listed in their email to PushBullet.

Also note that almost all of them have 10-50x the amount of downloads compared to PushBullet.

The odds just spell bullshit.

Their "automated scanning process" didn't just happen to pick the popular app that gives users more control and platform independence from Google.

Because really that's what it's about, PushBullet is dangerous to a closed ecosystem like Google wants.

(also, I believe that given the permission system, and if an automated scanning system was in fact in place, it should be super easy to exactly point out what is wrong, like compiler errors. and being granular permissions, there's no "gaming the system" about it, you either get the permission or you don't)

> If you're going to run a platform like this and capriciously threaten to kick people off of it, it's pretty antisocial to hide the reasons why.

I don't believe Google gets to be "antisocial", they're not a person. They exist since ~20 years and are made of shifting people, none of whom really control it. As far as it can be "antisocial", I wonder if it even vaguely "realises" that its interchangeable parts are the same entities as its consumables.

Post reply on HN