Live data from Hacker News

Google have declared Droidscript is malware

groups.google.com

371–380 of 665 posts

Re: Google have declared Droidscript is malware

#371
post #361

Earlier quoted context omitted.

I disagree. If you buy a product from me with 30 day warranty and it breaks on day 31 and you contact me, I will not give you a refund because: a) I haven't agreed to do so b) I'm not bound to do so c) I don't think it's warranted in this case. But I'm not "unable" to issue a refund. In another case I may say "hm it's out of warranty but you know what, it really shouldn't have broken like that and you're a good custo…

If I were to ask you if I could get a refund for an item out of warranty, what language would you use to refuse me? I'm struggling to come up with a response that doesn't use the terms "unable" or "can't" that wouldn't come across as fairly rude.

That feeling is specifically because we all know that depersonalizing and speaking passively 'softens' the blow.

"As your product is out of warranty we will not be issuing a refund."

Sounds rude, right? Because it draws attention to the fact that the decision is, at some level, completely arbitrary. But if you have your left hand write the policy and your right hand enforce it then you can say.

"I'm sorry but I'm unable to issue a refund because your product is out of warranty."

Makes it sound like that's just how the world works, doesn't it? And you come away feeling like "aww man they can't" instead of "they won't, money grubbing assholes." Customer service is, at its core, about managing emotions and often delivering bad news in a way that preserves the company's image.

Re: Google have declared Droidscript is malware

#372
post #255
post #19

The writing style of the piece looks like a political mailer. > The Google Play system has declared DroidScript is Malware and accused us of committing Ad Fraud! Needless to say, we are extremely upset and totally flabbergasted at this shocking allegation! That kind of hyperbole sets off all my BS detectors. As I go through the back and forth, DroidScript speculates this: > Our main guess was that one of our users wa…

Are you serious? It takes a minute to disassemble literally any APK with AdMob SDK and abuse their ID's. These values are not secrets. If a billion dollar company like Google can't detect simple fraudulent activity like this, how are their ads supposed to be worth a single dollar?

> how are their ads supposed to be worth a single dollar?

Hard truth: a lot of internet ads is fraud. With paper, radio and TV, any ad buyer can cheaply verify that their ad spending ends up where it should by buying a paper at a random train station or listening to the airwaves.

On the Internet, it's worse than the Wild West, with fraud and deception on every part of the chain.

Re: Google have declared Droidscript is malware

#373

Earlier quoted context omitted.

As for point 1: that depends; if your business operates on keeping the center of the bell curve happy, and you don't like to risk that, than implementing something that degrades that doesn't seem like a sound business decision. Keep in mind that this is from the 'producer' perspective. As for point 2: that should indeed be how it works, but the circumstances have changed, especially for large scale general purpose co…

> just 'run whatever code appears at the JMP', we might as well not have an internet. I'm old enough to have used the internet with a computer running Windows 98SE. As far as I can tell, besides data throughput, only webmail, maps, and media streaming have gotten materially better since that time, and even those peaked in an era when people were still running Windows XP SP3. Despite all this froth about how we need t…

The issue is that the users are not capable of overseeing the consequences of their actions, and when you function in a shared system that is not great. (understatement of the year)

Even technically skilled users won't benefit from a construction of 'trust on first use', when was the last time you verified the host key of a system you SSH'ed into for the first time? How do you trust a system purely on something like that? And even then, when you got an error that the host key no longer matched, did you go on a research run to figure out how this might have happened, or did you just replace the key in your local known hosts cache and went on with your day?

What about websites, do you disable all CA's and just use local key pinning on all the websites that you visit? This is something you could do right now. But you won't, and neither will anyone else because it is far too inconvenient. It makes the entire thing useless. And every time you send an email, are you going to verify the fingerprint of the supplied certificate as well?

While it might not obvious to you, the feasibility of this at scale is something you can figure out by simply talking to users, looking at A/B test, comparative research, and looking at the security configuration of various user's systems and asking why they might have chosen the configuration as it is, and what the impact to them, the people they interface with and the internet as a whole might be.

wrt phone taps: it's possible and not the point (and not useful; the Americans did plenty of local and global taps and almost none of the broad taps yielded anything useful over 10 years, it was only the highly targeted taps that yielded real results). It's also not froth, "locking up stuff" and "straight jackets". It's about a hard problem, with everybody having an opinion but nobody having a solution. And the only thing people seem to want to do in such a scenario is apply a scorched earth policy which besides the obvious destruction doesn't yield a solution either. With the current devices and services there is so much personal data, proximity and interaction that the value and impact is much higher than your landline at home. The point isn't to make it perfect or perfectly secure, but to make it hard enough that it isn't an attractive broad-spectrum target anymore. Making it cryptographically hard to hack into a baseband, a bootrom or kernel is a very effective method to make this protection a reality, and so far there has not been a successful alternative presented by anyone, anywhere.

Ultimate absolute liberty is a fallacy, externalities exist, and society doesn't work in anarchy (but doesn't flourish in strict hierarchy either). Until you can manipulate time and space, and modify matter at a subatomic level, you are and will always be dependant on externalities, and as such you have to work with those. How hard you make it for yourself or others depends on the degree of society and civilisation you can live with. You don't control the BGP tables on your ISP's routers, but that seems to be fine for all the millions of users. But all of this is straying away from the topic at hand quite significantly.

(Edit;) As to the 'value status-quo business plans': that is not something we value, but something the producers of some large-scale hardware and software manufacturers value. They aren't society's friend, but they do need it to buy its products. And if the USP of the product is something you want to remove, then the manufacturer is probably going to try to prevent that. This would be 'fixed' by you getting what you want and they getting what they want, but that is not technically feasible (or: has not been shown to be technically feasible yet), hence the long blocks of text describing that problem.

Re: Google have declared Droidscript is malware

#374
post #334
post #116

Earlier quoted context omitted.

Droidscript has support for writing custom intents, which Pythonista (and Scriptable, a JavaScript version of the same thing) do not have. A malicious Droidscript application could access other applications on the device. https://symdstools.github.io/Docs/docs/app/SendIntent.htm

I know that this has but a fat chance of being taken seriously by Google but... Isn't this a good chunk of the reason why people here on HN and elsewhere have been arguing for much more granular intent management on Android like they had in the early days? When we get permissions boiled down to one or two popups we end up with issues providing accurate privileges to applications (and might be forced to allow WhatsApp…

Alas, granularity very quickly turns into users clicking through piles of crap without thinking about it. With great power comes great user error.

Re: Google have declared Droidscript is malware

#375

> ...after taking into consideration the information that you have provided, we have confirmed that we are unable to reinstate your publisher account. I hate when using euphemism slides into flat out lying like this. They are not "unable" to reinstate the account, in fact they are the only party able to reinstate the account, that's why the account holder was contacting them instead of someone else. They are "unwilli…

Agree. 100%.

Re: Google have declared Droidscript is malware

#378
post #293
post #82

Earlier quoted context omitted.

The biggest problem with "alternative" platforms is just the lack of app support. I used to have a Nokia N9; great phone. But it didn't support WhatsApp and I was out on the loop on the WhatsApp chat all my other coworkers were in. Then there's things like banking apps, flight check-in apps, food ordering apps, dating apps, etc. etc. Can you do without those? Sure, of course. But if I want to order food where I live…

You can do the banking (from most banks) and food ordering from a web browser on your smartphone. No apps required. Grubhub, Uber Eats, Doordash, all those sorts of things. Most of them have a web version, and you can use that instead of an app most of the time. Just shake loose the Apple-induced app mentality that keeps you locked in.

A lot of hardware devices require use of an app these days. Any with wifi will also require use of location on ios and are thus unusable if you have location services disabled systemwide.

I just returned some IP cameras recently because of this.

Re: Google have declared Droidscript is malware

#379

Earlier quoted context omitted.

This is the first I've heard of Termux and now I'm curious what you use it for. Like are you SSHing into other environments?

https://www.passwordstore.org Here is a popular CLI app to manage passwords. I use it on my desktop, laptop and phone.

You don't need Termux for that, there are native clients for Android, I use this one: https://play.google.com/store/apps/details?id=dev.msfjarvis....

Re: Google have declared Droidscript is malware

#380
post #359
post #355

Earlier quoted context omitted.

"I can't agree with you" "I cannot continue this relationship" "I can't kill this guy" "I just can't eat meat anymore" "I cannot continue like this" These are all examples where someone clearly could for physical reasons, but they can't for other reasons they are bound to, whatever these reasons are.

Technically you are right. However the key here is exploiting the ambiguity. ‘We are unable to’ is a cowardly way of saying ‘we choose not to’, or ‘our policy dictates’.

If Google chose to use the "uncowardly" wording, I'm sure someone would just post saying Google is arrogant and cocky bastard. No matter what someone will find some point to complain. Human nature.
Post reply on HN