Live data from Hacker News

Google have declared Droidscript is malware

groups.google.com

441–450 of 665 posts

Re: Google have declared Droidscript is malware

#441
post #100
post #39

Earlier quoted context omitted.

Banning it first is fine. banning it first, then not giving a reply to the concerns they have is not. Even if they have reasonable believe or proof that droidscript is indeed malware, it looks like at least a chunk of their userbase uses it for legitimate usecases and the devs, who likely invested at least a few hundred hours of work in it, deserve at least some communication.

I used to work at Google, and a friend reached out to me for help – his company's app was in a similar situation, with similar communication from Google. This was a good friend from high school, so I pressed the issue using internal channels. The person handling it on Google's side was very assertive about them violating a policy, and after some back and forth I received a _vague hint_ about what was the supposed vio…

> Yet it still turned out Google had been right all along.

No they weren't. It was not right to terminate the entire app because someone used an image wrong.

Re: Google have declared Droidscript is malware

#442
post #310

Earlier quoted context omitted.

But if they do, a malicious actor can use that information to circumvent their restrictions, and its their walled garden, so they have very little incentive to tell everyone exactly what they don't like.

Okay, but this developer isn't "everyone", and there seems to be no reason not to explain in this case.

Unless the developer decides to share on Twitter or HN or w/e, and now malicious actors know as well.

Re: Google have declared Droidscript is malware

#443

Earlier quoted context omitted.

Those are still "yours" in a sense, so don't fall into the feature set the poster you are replying to is talking about. Though the immobilizer somewhat skirts the line. (Or at least from my personal view). Think John Deere implementing software lockouts in the tractor ECU. That is nothing more than forcing their business model onto the end user through digital logic.

Those are the sorts of things that need to be legislated. You should not be able to lockout people from ECU for example, but the person would have to be willing that a compromised ECU can blow up/damage their engine and they will have to accept that the warranty is invalid the second they mess with the ECU programming.

That's no good because the car can malfunction for reasons other than damage caused by the ECU, and the warranty covers those reasons too. You shouldn't have to lose your warranty on part A because you modified unrelated part B.

Re: Google have declared Droidscript is malware

#444

Earlier quoted context omitted.

Caveat: I work at Google but know nothing about this area and my opinion here is entirely personal. > which would create an unsustainable situation at this scale. Financial sustainability may have something to do with it, but I suspect the larger issue is that providing too much detail essentially trains malware authors to route around the company's defenses. Imagine the Play Store as a castle which has both good tow…

That doesn't seem to be a problem in this case? Telling spammers they are blocked due to copyrighted images trains them not to upload copyrighted images. Win-win.

picking up copyrighted images is another indicator that user X is a spammer, providing that info would eliminate the signal

Re: Google have declared Droidscript is malware

#445
post #28
post #22

Earlier quoted context omitted.

I think your thoughts on this are plausible, if not likely. However, the usual complete lack of communication by google is the actual problem. Perhaps droidscripts could mitigate googles concerns, if they had the decency to explain them.

> However, the usual complete lack of communication by google is the actual problem. Uh... Seems like the actual problem (given that scenario) is that adware is being pushed to users, not whether or not Google defended its ban in public. Complaints about customer service (from everyone, not just Google) are a dime a dozen, actual user security is clearly more important, right? Your answer presupposes a frame where Dr…

> Seems like the actual problem (given that scenario) is that adware is being pushed to users

Google itself is adware.

Re: Google have declared Droidscript is malware

#446
the problem of a free market in the management of the important hubs of a sector (as is Google for most of the services of its type on the internet) is that they (the big names in the sector, those who reach the top with the free market), are which then once they arrive they can do as they prefer.

the problem of a non-free market, in this matter, would be a government monopoly, with the same problem: they can do as they like.

the alternative to this currently is not easily applicable, and does not give the current advantages of the "big" (whether they are companies or governments the result does not change; really, it is the same).

if you think that Russia and its coming private Internet, or the American NSA security system, or even that I know ... Amazon and eBay, or Facebook and its network (not just the Social Network site, but all its additional services, and where it gets to manage what it manages), or even Chinese censorships on the Internet, are different from each other (to give random examples), think again.

then of course comes troll-boss Trump (they ban him from Twitter and other similar sites) and everyone thinks (confused) that this is not real wath I am writing in this comment.

we are beyond the conspiracy, here the conspiracy comes to life by itself, randomly, without anyone creating it; now in its own life.

who is at the top decides for who is below the top, obviously the developers of Droidscript appeal, they do not like this decision, but they are like everyone else they are subject and subject to the "big".

if you don't want big problems from the "bigs", don't support them, don't use them.

Re: Google have declared Droidscript is malware

#447
post #314

Earlier quoted context omitted.

Also I think the analogy doesn't quite work because a truck is a truck. You can do some customization, you might (or not be) able to change some parts, or being a mechanical engineer you might even be able to repair it or enhance. But it will always fundamentally be a truck. The difference from phones is that a phone is a computer, and as such it has computer's endless potential. For some it can be just a phone, sure…

You are displaying your ignorance of trucks. For decades now, all automobiles and trucks have included proprietary computer systems. Some are easy to hack and alter. Some are more expensive/challenging, but people do it. An EV is missing _most_ of the mechanical parts that defined a "truck" for a century, and is basically only four tiny motors, brakes, a computer system, and a battery with wheels. The sole characteri…

They have computers but you can't use them to compute in any effective way. You can tune it, great, just like if it didn't have a computer.

Re: Google have declared Droidscript is malware

#448
post #383

Earlier quoted context omitted.

If Google chose to use the "uncowardly" wording, I'm sure someone would just post saying Google is arrogant and cocky bastard. No matter what someone will find some point to complain. Human nature.

That seems like a dismissal that could be applied to any criticism of any corporation. Can you explain what value it adds in this specific case?

What value to add to criticize this specific case?

Whether they use "unable" or "choose not too" shouldn't matter.

Just treat it the same.

Re: Google have declared Droidscript is malware

#449
post #384

Earlier quoted context omitted.

Alas, granularity very quickly turns into users clicking through piles of crap without thinking about it. With great power comes great user error.

I disagree - it turns into users clicking through piles of crap if you've got a crap UX. If the UX is well tuned to display this information and let the user break out to greater levels of detail or keep things simple then you can find a good middle ground. Given the amazing strides in usability we've seen in nearly every other field it baffles me why everyone isn't onboard with the fact that we can take the learning…

There's so many crazy gotchas in android permissions, though... eg, most users won't know that there's a connection between wifi and geolocation data. That's a non-obvious connection with a real trade-off: the app might have some interesting wifi-based functionality, but in exchange the app authors might harvest your geo data.

Consider the permissions for the lowly keyboard app...

A proper understanding of fine-grained permissions basically requires a working knowledge of how that permission might be or has in the past been abused.

And ultimately, fine-grained permissions are probably answering the wrong questions. The user expresses some basic trust via the initial app installation; what permissions ultimately help with is deciding whether or not to keep trusting the developer. If the app ask for lots of unexpected stuff, it's probably malware and should be uninstalled. If the permissions seem reasonable, the app is probably fine, and the user just wants to delegate responsibility to the app to do what it needs to do to get shit done.

It's really /all/ about trust. If you can't trust a random app, installation is a high-friction event. Check the stars, number of users, read a bunch of recent reviews, carefully go through permissions providing access for exactly what's needed. If you /can/ trust a random app, you can just install it, use it to read the fscking QR code and go on with your day. The need for trust is why we've ended up with centralized app stores with stringent content policies, and all the false positives that come along with it.

Re: Google have declared Droidscript is malware

#450
As still so many people don't get it:

1) Don't make your business dependent on Google 2) Don't make any of your data dependent on Google (don't use Gmail, Workspace etc) 3) Don't make applications you build dependent on Google

Hint: If you can't migrate away from Google within a working day, you're doing it wrong.

Post reply on HN