Live data from Hacker News

Google have declared Droidscript is malware

groups.google.com

541–550 of 665 posts

Re: Google have declared Droidscript is malware

#541

Earlier quoted context omitted.

Try Flutter! Great SDK to get started with mobile development, and dart is a really nice language

Having tried neither, Flutter sounds like the polar opposite of both the experience and capability that GP mentioned. I'm sure it's nice but can it be developed interactively in a PC browser as described above?

Flutter is hacking just your own app, Droidscript sounds like it could be used for anything in other apps (maybe even ad click fraud).

Re: Google have declared Droidscript is malware

#542
post #310
post #22

Earlier quoted context omitted.

I think your thoughts on this are plausible, if not likely. However, the usual complete lack of communication by google is the actual problem. Perhaps droidscripts could mitigate googles concerns, if they had the decency to explain them.

But if they do, a malicious actor can use that information to circumvent their restrictions, and its their walled garden, so they have very little incentive to tell everyone exactly what they don't like.

If their restrictions are so trivially circumvented... then they probably already have been.

This is the epitome of security by obscurity.

Re: Google have declared Droidscript is malware

#543

This is the same story that HN readers have read hundreds of times over the past couple of years, just with different subjects. Independent developer/small organization gets their app/YouTube channel/Google account shut down overnight because of false positives triggered by their system. It takes weeks and insistence with bots to just get to speak to a human. When you get to speak to a human, they usually respond wit…

I wonder if it's even a false positive. Imagine some ad fraud agency is using droidscript as a means to click on ads programmatically in a completely different app (which seems possible based on the overview) - how does Google distinguish between that and any other app using the same APIs to fraudulently click ads? What if there's actual malware that uses droidscript as a vehicle to do this to unsuspecting users' phones at night?

Re: Google have declared Droidscript is malware

#544
post #16

TL;DR: They are being accused of ad fraud, without any evidence provided, and they are asked to reply with an analysis of why they think their traffic ?? is legit (when they have no idea what is it that Google considered "not legitimate"). The biggest issue here I don't think is the malware tag, but the ad fraud accusation. Even thought as somebody pointed out the page linked can be biased, based only on what they st…

the ad-fraud accusation is my biggest concern as well. they provide no information or clues leaving the author to guess. the author guesses that somehow someone extracted their identifiers from the apk. google comes back and says more clearly that it's something to do with how the ads are positioned, essentially accusing them of trying to trick people to accidentally click. this information should have been provided…

Ad fraud will just fix their errors if Google provides any information about how it detected the ad fraud. They're fine with some false positives if it means 99%+ of ad fraud is squashed.

Re: Google have declared Droidscript is malware

#545

Earlier quoted context omitted.

A valid explanation, but not one I believe applies here. This ban is not only not explaining how it detected unwanted activity, it is not explaining what activity it detected. "We detected you faking ad impressions, though we won't tell you how we (believe we) know" is very different to "We detected you (or your app) doing something wrong, stop doing it and you will be fine. We won't tell you what you did wrong".

"Our ML system registered a hit on your account, which is almost always associated with policy violations, but we don't know what the trigger was, or why that set of data about your account is almost always associated with policy violations... it just is."

We're on the cusp of independent artificial intelligence and it's incredibly lame.

Re: Google have declared Droidscript is malware

#546
This article is big news, because it shows that Google will permanently yank your Android app if your website violates AdSense's secret fraud detector! If you're running Google AdSense ads and you have an Android app that you care about, take down the ads immediately and switch to another vendor.

AdSense is the product where Google pays you for running banner ads; they can and frequently do kick people off of it for secret reasons. When my company was kicked off of AdSense back in 2010, I wrote about it extensively. https://www.choiceofgames.com/2010/08/were-banned-from-googl...

Google will never tell you why they ban people from AdSense, and there's no effective way to appeal. (They have an "appeal" process, but what are you supposed to write in the appeal when the charges against you are secret?!)

At least we can still publish Android apps, right? (We now run Facebook ads instead.)

But Google's email to DroidScript saying that the DroidScript app was removed from Google Play Store for "Ad Fraud" says otherwise.

    Publishing status: Suspended

    Your app has been suspended and removed due to a policy violation.
    Reasons of violation
    APK:206 Ad Fraud
    App violates Ad Fraud policy.
Surely Google could have just revoked DroidScript's access to Google ads, while allowing DroidScript to ship on the store, like they did for us.

If Google ever yanked our Android app over "ad fraud," we'd have no recourse. We've appealed our AdSense rejection a dozen times over the last 10 years and we always get a form letter rejection. We have no idea what they think we did wrong, and we never will, so we can never fix it.

Thank god we don't run AdSense ads anymore. Based on this, I never want to run them again!

Re: Google have declared Droidscript is malware

#547

This is the same story that HN readers have read hundreds of times over the past couple of years, just with different subjects. Independent developer/small organization gets their app/YouTube channel/Google account shut down overnight because of false positives triggered by their system. It takes weeks and insistence with bots to just get to speak to a human. When you get to speak to a human, they usually respond wit…

Google is 1/2 of the mobile duopoly. No app developer can avoid Google Play Store (for publishing their apps) and Firebase Cloud Messaging (for sending push notifications to their apps).

I have ~800 applications installed on my phone and there are fewer than a dozen of them that I would not immediately uninstall were they to send me a push notification. I don't buy that "no app developer" can avoid using FCM, the overwhelming majority of applications have no use for them besides spamming users with desperate pleas to return to a screen that can serve advertisements.

Re: Google have declared Droidscript is malware

#548

Earlier quoted context omitted.

Are Play Store regulations the only defense against this kind of attack? If so, then yikes!

Android's fine-grained permissions system isn't a good fit for something like Droidscript; one script could use a permission for valid reasons, then another could do something bad.

Why was this downvoted? It seems like a reasonable comment.

Re: Google have declared Droidscript is malware

#549
post #255

Earlier quoted context omitted.

Are you serious? It takes a minute to disassemble literally any APK with AdMob SDK and abuse their ID's. These values are not secrets. If a billion dollar company like Google can't detect simple fraudulent activity like this, how are their ads supposed to be worth a single dollar?

> how are their ads supposed to be worth a single dollar? Hard truth: a lot of internet ads is fraud. With paper, radio and TV, any ad buyer can cheaply verify that their ad spending ends up where it should by buying a paper at a random train station or listening to the airwaves. On the Internet, it's worse than the Wild West, with fraud and deception on every part of the chain.

> With paper, radio and TV, any ad buyer can cheaply verify that their ad spending ends up where it should by buying a paper at a random train station or listening to the airwaves.

Good luck verifying that the FM radio station you bought as spots on really averages 150,000 concurrent listeners. Sure, you know your ad was there, but that doesn't help you.

Re: Google have declared Droidscript is malware

#550
post #488

Earlier quoted context omitted.

I used to work detecting ad fraud. Publishers would do bad things, call in, and try to get their account rep to get details. Obviously I can't say "of the last 2500 ad clicks zero of them had any mouse movement over the ad before the click event" because then the publisher obviously just fixes their fraud software. This isn't specific to Google or even advertising. Every company has figured out when dealing with abus…

What about false positives? How did you account for that?

People have this misconception that ad networks some how get joy from turning people off for no reason. Every ad shown is a penny in their pocket, even if its 100% fraud. When advertisers start asking for money back is when investigations are launched and accounts are terminated.

There are literally no false positives. It may be fraud, it may be the ad is too close to a back button and gets accidently clicked, it could be the ads don't display right. But at the end of the day, it is a revenue decision.

Post reply on HN