Live data from Hacker News

Google have declared Droidscript is malware

groups.google.com

31–40 of 665 posts

Re: Google have declared Droidscript is malware

#31
post #29

Earlier quoted context omitted.

> Add to that that it's a closed source IDE for an open platform, and my intuition sides with Google here. If I can't ship my closed source IDE on the platform is the platform really open? > My guess is that when details come out it will turn out that at-least-plausibly harmful Droidscript garbage was being pushed to users and Google decided to kill it. Of course they will say it was because x, y, and z were done to…

> If I can't ship my closed source IDE on the platform is the platform really open? For clarity: the Play Store is not an open platform. The Android API being exposed by Droidscript very much is.

Fair, I misinterpreted what you were saying.

Re: Google have declared Droidscript is malware

#32
post #14

I had to go look to see what this was: "DroidScript is an easy to use, portable coding tool which simplifies mobile App development. It dramatically improves productivity by speeding up development by as much as 10x compared with using the standard development tools. It’s also an ideal tool for learning JavaScript, you can literally code anywhere with DroidScript, it’s not cloud based and doesn’t require an internet…

Time for one of these again. So... having read through their marketing material, this is an on-device tool that opens up what appears to be most of the Android application API to at least the user of the device, and potentially to any Droidscript applications they grab from other sources, and... maybe to other apps on the device? It's not clear from a quick read how extensive the runtime control is. So just right out…

I don’t get your point. Sideloading apps was always possible on Android even without a jailbreak. We’re not in Apple world, so it’s unclear which Playstore rules got broken here.

Re: Google have declared Droidscript is malware

#33
post #25

It's seriously time to re-embrace the idea of ownership and control of our devices, and reject Android and iOS altogether. Developing for those platforms has become worse and more restrictive over the years, and this kind of crap is now just everyday news. How good are Pinephones[1]? Are there better alternatives? [1] https://www.pine64.org/pinephone/

Maybe it's just time to see phones as what they are - a phone.

I don't really care what software is ran in my truck, as long as it works (And that's why I'll not buy a Tesla). It's a phone, use it to call text and guide and browse some internet. That's it.

Re: Google have declared Droidscript is malware

#34
post #25

It's seriously time to re-embrace the idea of ownership and control of our devices, and reject Android and iOS altogether. Developing for those platforms has become worse and more restrictive over the years, and this kind of crap is now just everyday news. How good are Pinephones[1]? Are there better alternatives? [1] https://www.pine64.org/pinephone/

I haven't tried any Linux phone, but a couple of other alternatives include F(x)tex [0] and Librem 5[1]

[0]https://www.fxtec.com/ [1]https://puri.sm/products/librem-5/

Re: Google have declared Droidscript is malware

#35
post #14

I had to go look to see what this was: "DroidScript is an easy to use, portable coding tool which simplifies mobile App development. It dramatically improves productivity by speeding up development by as much as 10x compared with using the standard development tools. It’s also an ideal tool for learning JavaScript, you can literally code anywhere with DroidScript, it’s not cloud based and doesn’t require an internet…

Time for one of these again. So... having read through their marketing material, this is an on-device tool that opens up what appears to be most of the Android application API to at least the user of the device, and potentially to any Droidscript applications they grab from other sources, and... maybe to other apps on the device? It's not clear from a quick read how extensive the runtime control is. So just right out…

That said, an open-source version of this on F-droid would be hella cool, but wrapping every API with Javascript sounds non-trivial.

Re: Google have declared Droidscript is malware

#36
post #5

Why not just publish it on f-droid?

They have a subscription model and ads which are not allowed on FDroid. FDroid also requires the software to be opensource.

FDroid do allow subscriptions and ads. They label them 'AntiFeatures' which is not as bad as it sounds; many people will still happy install the App. However FDroid to strictly insist all code is free and open source; this dose mean you are rolling your own Ad and Subscription libraries.

Re: Google have declared Droidscript is malware

#37
post #25

It's seriously time to re-embrace the idea of ownership and control of our devices, and reject Android and iOS altogether. Developing for those platforms has become worse and more restrictive over the years, and this kind of crap is now just everyday news. How good are Pinephones[1]? Are there better alternatives? [1] https://www.pine64.org/pinephone/

Maybe it's just time to see phones as what they are - a phone. I don't really care what software is ran in my truck, as long as it works (And that's why I'll not buy a Tesla). It's a phone, use it to call text and guide and browse some internet. That's it.

Phones are the only pocket computers that see quick advances in performance and battery use. For someone who wants a pocket sized computer, it's just most convenient to combine it with your phone.

Re: Google have declared Droidscript is malware

#38
post #25

It's seriously time to re-embrace the idea of ownership and control of our devices, and reject Android and iOS altogether. Developing for those platforms has become worse and more restrictive over the years, and this kind of crap is now just everyday news. How good are Pinephones[1]? Are there better alternatives? [1] https://www.pine64.org/pinephone/

I’d be hesitant to jump on another platform unless it has a way of locking down app permissions similar to iOS. I think it’s been shown that the app review process is a farce, but the permissions system like the new app tracking feature is great for privacy and security.

If this droid script equivalent were going to start reading my emails watching me through the camera, reading my clipboard, or tracking my real world location, I’d definitely want something that alerted me to that before it happened.

Re: Google have declared Droidscript is malware

#39
post #28
post #22

Earlier quoted context omitted.

I think your thoughts on this are plausible, if not likely. However, the usual complete lack of communication by google is the actual problem. Perhaps droidscripts could mitigate googles concerns, if they had the decency to explain them.

> However, the usual complete lack of communication by google is the actual problem. Uh... Seems like the actual problem (given that scenario) is that adware is being pushed to users, not whether or not Google defended its ban in public. Complaints about customer service (from everyone, not just Google) are a dime a dozen, actual user security is clearly more important, right? Your answer presupposes a frame where Dr…

Banning it first is fine. banning it first, then not giving a reply to the concerns they have is not. Even if they have reasonable believe or proof that droidscript is indeed malware, it looks like at least a chunk of their userbase uses it for legitimate usecases and the devs, who likely invested at least a few hundred hours of work in it, deserve at least some communication.

Re: Google have declared Droidscript is malware

#40
post #6
post #3

Well, is it? The linked post is obviously biased, so I'd rather wait for more information instead of getting my pitchfork out immediately.

It seems to me that the nature of the app is whats causing the issue. From one of the emails they got from Google: > We don't allow apps with any code that could put a user, a user’s data, or a device at risk. Maybe they think the ability to execute arbitrary code is too powerful of a feature?

> Maybe they think the ability to execute arbitrary code is too powerful of a feature?

Yes, probably.

But maybe they can act and speak like humans, maybe even make a phone call before just deleting without notice a well established 7 years old app with more than 100k users, cancelling all revenue from user's subscriptions, and all that while sending bot-like mails just saying that they can't give more information about why they are killing an organisation.

I think this is really serious. A respected business is going to be shut down, real people are going to be fired and Google isn't even able to answer to an email asking why it's happening ?

Post reply on HN