Live data from Hacker News

Google have declared Droidscript is malware

groups.google.com

401–410 of 665 posts

Re: Google have declared Droidscript is malware

#401
post #323

> ...after taking into consideration the information that you have provided, we have confirmed that we are unable to reinstate your publisher account. I hate when using euphemism slides into flat out lying like this. They are not "unable" to reinstate the account, in fact they are the only party able to reinstate the account, that's why the account holder was contacting them instead of someone else. They are "unwilli…

It's not lying because there is some implicit information in the "we are unable" statement. What is implied in statements like this is that they're unable due to their policies. If not for implications like this, almost every single use of "unable" (or "can't", for that matter) ever in a sentence would be "lying" unless something is against the laws of physics.

A pet peeve of mine is the deferral and personification of "policy". Policy is just your opinion that you happen to have written down in the past. It holds no power over you, you write the policy! It's not like the US law, which while also just words on paper, is enforced (and often chosen by) other people over you. Me deferring to the law (vs. my own opinion) has meaning because they can be different. The way we really know this is that we repeatedly see policy broken all the time -- again, because it's just a pretend separate agent, not an actual entity that wields power over you. It does in fact ultimately just serve to disguise an active action as a passive one "Oh, I checked the book of rules (that I wrote) and it said I can't let you do that. Shucks. Man, that book, its a tough negotiator. Nothing we can do I'm afraid." I think it is their right to write the rules, but just own up to it. Say "we aren't doing it because we don't want to," that's the truth, because if they did want to, they would, regardless of the "policy".

Re: Google have declared Droidscript is malware

#402
post #253

Earlier quoted context omitted.

This is one case though where that lack of understanding leads to the right conclusion. The average user is giving up nothing by losing the right to run arbitrary code, because they never were running arbitrary code.

Plenty of users run f droid.

Hard to say how many though.

... which is, unfortunately, a weakness of F-Droid's own making (for the right reasons!). Because they don't do stat-tracking on users, they don't have numbers. So Play Store is able to claim "1 billion active monthly users" (as of 2015) with some certainty, F-Droid can give an approximation and a shrug.

Re: Google have declared Droidscript is malware

#403
post #361

Earlier quoted context omitted.

I disagree. If you buy a product from me with 30 day warranty and it breaks on day 31 and you contact me, I will not give you a refund because: a) I haven't agreed to do so b) I'm not bound to do so c) I don't think it's warranted in this case. But I'm not "unable" to issue a refund. In another case I may say "hm it's out of warranty but you know what, it really shouldn't have broken like that and you're a good custo…

If I were to ask you if I could get a refund for an item out of warranty, what language would you use to refuse me? I'm struggling to come up with a response that doesn't use the terms "unable" or "can't" that wouldn't come across as fairly rude.

> Unfortunately the warranty on your product has expired and we do not issue refunds for products outside the warranty period.

If you pressed me I would admit that yes, in some exceptional cases we issue refunds for products outside of warranty but we're not doing so in this case because [whatever, the product broken due to misuse, etc.].

To say I am not issuing a refund or that I do not issue refunds on out-of-warranty is truthful or reasonably so. It's perfectly possible to communicate that without being rude or claiming to be "unable."

Re: Google have declared Droidscript is malware

#404

Earlier quoted context omitted.

Those are still "yours" in a sense, so don't fall into the feature set the poster you are replying to is talking about. Though the immobilizer somewhat skirts the line. (Or at least from my personal view). Think John Deere implementing software lockouts in the tractor ECU. That is nothing more than forcing their business model onto the end user through digital logic.

Those are the sorts of things that need to be legislated. You should not be able to lockout people from ECU for example, but the person would have to be willing that a compromised ECU can blow up/damage their engine and they will have to accept that the warranty is invalid the second they mess with the ECU programming.

[deleted]

Re: Google have declared Droidscript is malware

#405
post #399

> ...after taking into consideration the information that you have provided, we have confirmed that we are unable to reinstate your publisher account. I hate when using euphemism slides into flat out lying like this. They are not "unable" to reinstate the account, in fact they are the only party able to reinstate the account, that's why the account holder was contacting them instead of someone else. They are "unwilli…

As a cashier, I am certainly "able to" just hand you the goods and let you leave without paying, but in reality due to laws, regulations and good morals I am unable to do that.

It's reasonable to say you're unable to do something because it's against the law and doing it would make you a criminal. Equally its fair to say you 'can't' do something that would go against your morals.

That is not equivalent to what's happening here. There is no law preventing Google reinstating the account, and corporations don't have morals because they're not people. The only thing preventing them doing it is that the employees involved choose not to.

Re: Google have declared Droidscript is malware

#406

Earlier quoted context omitted.

> However, it's a safe assumption that the vast majority of people Google support deals with are spammers. If Google gave a detailed explanation to all of them it would mean a ton of additional work – which would create an unsustainable situation at this scale. You describe a situation where Google was going to put a whole company out of business -- probably ending your friend's job, as well as that of many other hon…

I liked all of your comment, but this passage in particular: > No, we need a Habeas Corpus for tech companies. If you are banned, you have to be told why. Make it a law. I don't care if it results in more spam. The whole ordeal seems like an attempt to educate app developers by whipping, where the victims have to guess what they did wrong.

“The opaque email responses will continue until morale improves.”

Re: Google have declared Droidscript is malware

#407
post #399

> ...after taking into consideration the information that you have provided, we have confirmed that we are unable to reinstate your publisher account. I hate when using euphemism slides into flat out lying like this. They are not "unable" to reinstate the account, in fact they are the only party able to reinstate the account, that's why the account holder was contacting them instead of someone else. They are "unwilli…

As a cashier, I am certainly "able to" just hand you the goods and let you leave without paying, but in reality due to laws, regulations and good morals I am unable to do that.

As a cashier you are not empowered to make this decision. You are not "able to" violate store policy this way and keep your job. If a store owner or manager wishes to give someone a product for free or issue a full refund, yes they are "able to" do that.

The rep in TFA uses "we," referring to Google. Google is able to reinstate accounts, and The Google Ad Traffic Quality Team is able to reinstate accounts depending on their judgement of whether someone is violating policy. If they are not able to reinstate accounts, can you explain to me why they're adjudicating account ban appeals? Do they say "no" to everyone?

The key point here is that the agent(s) are responsible for interpreting the policy. They have decided that Droidscript violates their policy, and I personally have no opinion about that. But to imply that it's "out of [our] hands]" is dishonest.

Just say "upon review we've determined that your app violates our policies so we will not be reinstating your account."

Re: Google have declared Droidscript is malware

#408

Earlier quoted context omitted.

> wrapping every API with Javascript sounds non-trivial. I am not an expert in JS or the Android API, but I wonder if you couldn't do it automatically? If types line up closely enough, I would think that you could get a list of Android APIs (pull it from AOSP if you have to) and mechanically translate to a JS API.

If Android's JVM supports reflection, you could do it dynamically at runtime, and there are probably already JS+JVM integrations that would work.

Drozer does (did?) this, except with Python rather than JS. https://github.com/FSecureLABS/drozer

Re: Google have declared Droidscript is malware

#409
post #82
post #25

It's seriously time to re-embrace the idea of ownership and control of our devices, and reject Android and iOS altogether. Developing for those platforms has become worse and more restrictive over the years, and this kind of crap is now just everyday news. How good are Pinephones[1]? Are there better alternatives? [1] https://www.pine64.org/pinephone/

The biggest problem with "alternative" platforms is just the lack of app support. I used to have a Nokia N9; great phone. But it didn't support WhatsApp and I was out on the loop on the WhatsApp chat all my other coworkers were in. Then there's things like banking apps, flight check-in apps, food ordering apps, dating apps, etc. etc. Can you do without those? Sure, of course. But if I want to order food where I live…

I dream of a dual phone (conceptually 2 phones glued back to back) where you do web and open stuff on one side, and the inevitable proprietary apps on googled-android on the other side, with a quick button to freeze the prop side (for power saving and mitigating spying).

(Or same where the 2 phones are somewhat multiplexed on a single screen, preferably in hardware.)

Re: Google have declared Droidscript is malware

#410
post #118
post #73

Earlier quoted context omitted.

>> "Can't you just make us a general-purpose computer that runs all the programs, except the ones that scare and anger us? Can't you just make us an Internet that transmits any message over any protocol between any two points, unless it upsets us?"[1] The War On General Purpose Computing continues. Far too many business models depend on selling general purpose computers as "appliances". They presume it is possible to…

the issue is we as a market expect them to be responsible for the security of the OS and its apps. Its very difficult to manage security without control.

Only from certain perspectives.

If I'm a network engineer at a company, I need full control of the network to ensure security. As just a user of that network, I would have to understand that I don't have full control for security reasons. But it's not my network.

When it comes to consumer devices, there's no reason why security requires locked down devices that the so-called "owner" of the device can't control. The end-user should always be in charge. If the manufacturer chooses to put escape hatches in front of features that could lead to security compromise, then that's fine. But those escape hatches should exist, and I refuse to buy a general-purpose computing device that doesn't have them.

The Google vs. Apple argument here is specious; the locked-down nature of Apple's devices is not necessary for their better (but honestly still not great) security, and the less-locked-down nature of Android is not what makes it a security minefield.

Post reply on HN