Live data from Hacker News

Your app is not compliant with Google Play Policies: A story from hell

sylviavanos.nl

151–160 of 197 posts

Re: Your app is not compliant with Google Play Policies: A story from hell

#151

This kind of incompetence makes me seriously doubt that Google is doing anything to more substantially review apps for deeper security issues, either statically or at runtime. The asymmetry of effort in this situation is profound: consider that you spend all your time and effort writing a, long, complex, thoughtful message by hand (the app), taking hundreds or thousands of hours, but then they respond with machine ge…

> This kind of incompetence makes me seriously doubt that Google is doing anything to more substantially review apps for deeper security issues, either statically or at runtime. I actually know the team that does security vuln automation for Google Play. They've found millions of vulns in apps over the years. One of the challenges they face is precisely this sort of headline: how do you use static analysis to find vu…

Sounds to me like what you're saying is that the walled-garden approach of needing to approve every app that ever gets developed as a whole is what's infeasible without creating kafkaesque conditions dealing with their automation, and I fail to see how you've made a case for this automation being all that good in the first place, given that your main argument for it is that it's found "millions of vulns in apps over the years" but then later cite "millions of apps" as a reason you can't expand the support team.

I would suggest that it might be worthwhile to use OS-level features to stop apps from behaving maliciously in more general ways, but a lot of what I would consider malicious behavior (e.g. sending user analytics to third parties, feeding them misleading ads, messing with other processes, etc) is part of google's business model or claims of added value in many cases, so that seems unlikely to happen.

You are nonetheless astute to point out that we can't really blame the individual or even group-wise incompetence of their support teams here. What it is worthwhile to blame is the entire business model of trying to own and control a platform that supports so many users in the first place without giving them the autonomy to self-govern. No company can possibly be so many things to so many people and not screw them over. In a way, it's the same problem planned economies have. Even making the very generous assumption that this is never out of malice or greed, we can still view the major problems millions of people face due to this scale and inflexibility as practically inevitable.

Re: Your app is not compliant with Google Play Policies: A story from hell

#152
post #81

It just amazes me that developers try to cram editorializing into the title of the app, when you're already given a search word field and a description field in which to tell the world about your app. IRL nobody searches for "Cheerios - Toasted Whole Grain Oat Cereal for the Whole Family".

It's sad but if you search for 'cereal', you're going to see the one with the awful title higher up in rankings.

I feel this just shows lack of imagination in the search algorithm. It seems pretty trivial to discourage this kind of thing - to start with, how about penalizing longer titles or longer lists of keywords?

Let the publisher decide whether to rank low for lots of words, or high for a few.

Re: Your app is not compliant with Google Play Policies: A story from hell

#153

This kind of incompetence makes me seriously doubt that Google is doing anything to more substantially review apps for deeper security issues, either statically or at runtime. The asymmetry of effort in this situation is profound: consider that you spend all your time and effort writing a, long, complex, thoughtful message by hand (the app), taking hundreds or thousands of hours, but then they respond with machine ge…

> This kind of incompetence makes me seriously doubt that Google is doing anything to more substantially review apps for deeper security issues, either statically or at runtime. I actually know the team that does security vuln automation for Google Play. They've found millions of vulns in apps over the years. One of the challenges they face is precisely this sort of headline: how do you use static analysis to find vu…

>Google pays external hackers who find vulns in popular apps via a rewards program.

How does that work? Is the submission farmed out to a 3rd party as part of the verification process, and proactively checked? Or is it reactive, similar to a bug bounty? Are there people out there making their living running apks in desktop simulators looking for issues?

I always wondered about the economics of checking huge quantities of arbitrary code (well, bytecode) for vulnerabilities, even for a 30% cut (which is probably 0 for 99% of apps, right? I would expect a power law distro). Kinda sounds like Google solved this by running the apks through something like a CI/CD gauntlet and then...hoping for the best.

And of course you can't be too transparent or bad actors will game the system. It's almost as if, as a sibling commentor mentions, it's just not possible to adequately run a walled garden that adequately detects malice at scale.

Here's an idea: instead of charging 30%, you should waive that if the dev team agrees to vet 5 other apps for you, over time, especially the open source ones.

Re: Your app is not compliant with Google Play Policies: A story from hell

#154
post #3

ugh, that's annoying.. At least you made it onto HackerNews, so your problem might get silently resolved in the shadows It really sucks that Google can't be bothered to provide 5 minutes of human support despite taking such an enormous cut of all revenue from these apps

That's what I was hoping about my similar problem with facebook, but alas ... no kind HN denizens have offerred any help yet :)

Post is still here if anyone's interested or can help: https://news.ycombinator.com/item?id=29876423

Re: Your app is not compliant with Google Play Policies: A story from hell

#155
It's the same with all of FAANG.

It's now been almost two months since my facebook page of 56k users was hacked, and nobody at facebook seems to give a shit: https://news.ycombinator.com/item?id=29876423

I just gave up and made a new page now. Hopefully the hacker won't manage to claim that one too.

Re: Your app is not compliant with Google Play Policies: A story from hell

#156
post #44

Earlier quoted context omitted.

"Text Free - Call and Text Now" Updated January 10, 2022 "Free Now" - Update January 11, 2022 Many other examples have recent updates too.

I was always wondering how Free Now can stay in the Play Store with their name. Maybe it is a trademark thing (as this is a trademark). But yeah - the rules seem quite arbitrarily enforced. As said in other discussions about Google - I decided to untangle my life from Google further. Quite hard actually as I am a paying GSuite customer and a lot of stuff actually is tied to this account. :-(

we have an isp in france called Free - so yeah, at least somewhere it's a trademark. though this is not the real reason they ban it. people are cheapo so they all want free stuff, so they tend to search for " free", and google tries to reduce the squatting on this keyword.

it always baffled me how people always feel this need to explicitly search for free stuff, without looking first if it is always free (esp. in the case of opensource software). I once had to cleanup of viruses the computer of a classmate that got all the viruses because he searched for "python free" and fell for a crappy, virus-loaded, fake version...

Re: Your app is not compliant with Google Play Policies: A story from hell

#157
My app has been removed from youtube oauth multiple times because we keep getting different verifiers. We've even had permission revoked after being approved. All we do is use a oauth to get their userid and read their livechat for a chatbot. They just can't get their shit together.

Re: Your app is not compliant with Google Play Policies: A story from hell

#158
post #86
post #63

Earlier quoted context omitted.

HM is a bubble with bias against Google. People here seem to believe that bashing this company publicly will somehow change how they operate. Interestingly enough, back in the day Google used to be a darling of HN community. I suspect folks might be disappointed to see how things turned out at the end.

It's almost as if over a decade or more if time that people can see the result of behavior they didn't see as problematic initially. Or that google might have changed how they operate in small ways as they are steered differently. Expecting any one person to still have the same opinion of any one other person a decade later might be asking a lot. It's nothing strange that a community of people would have differing th…

Google was a hedge against Microsoft which was a hedge against IBM.

The tech world is always running from one monopoly to another.

People should think differently about Google because it is different and now has become the monopoly.

Re: Your app is not compliant with Google Play Policies: A story from hell

#159
post #52

I think you were lucky they told you anything . On Quora they just say "your answer was deleted for violating Quora policies. Click here to read our policies." This sort of "tell them nothing" approach seems pervasive in the online world. Blame the lawyers. Their lawyers must caution them "Don't give any details. That just opens us up to more questions & legal actions." The fact that it's completely self-serving and…

I despise the tell them nothing approach and I think it's despicable, but that said I think there is a more legitimate reason than the lawyers. If the person is a spammer or otherwise not legit and you tell them what they did wrong, it's a lot easier to hack around the problem and beat the automated moderation and get your malware into the store. I don't think that justifies the harm it does to regular people, but it…

At that point, why not put up an option for paid tech support? It would make life costly for the spammers, and give an option for people with a critical and legitimate problem.

Re: Your app is not compliant with Google Play Policies: A story from hell

#160

Earlier quoted context omitted.

> This kind of incompetence makes me seriously doubt that Google is doing anything to more substantially review apps for deeper security issues, either statically or at runtime. I actually know the team that does security vuln automation for Google Play. They've found millions of vulns in apps over the years. One of the challenges they face is precisely this sort of headline: how do you use static analysis to find vu…

>Google pays external hackers who find vulns in popular apps via a rewards program. How does that work? Is the submission farmed out to a 3rd party as part of the verification process, and proactively checked? Or is it reactive, similar to a bug bounty? Are there people out there making their living running apks in desktop simulators looking for issues? I always wondered about the economics of checking huge quantitie…

> How does that work? Is the submission farmed out to a 3rd party as part of the verification process, and proactively checked? Or is it reactive, similar to a bug bounty?

Bug Bounty. Person finds vuln in popular app. Person submits vuln to Google. Vuln gets reported to developer. Person gets paid.

> Are there people out there making their living running apks in desktop simulators looking for issues?

Most of them use tools, I think. I don't know stats on any individual who is making bank off this but given four figure payouts per issue I could definitely believe somebody living in eastern europe or whatever is making bank on this.

> I always wondered about the economics of checking huge quantities of arbitrary code (well, bytecode) for vulnerabilities, even for a 30% cut (which is probably 0 for 99% of apps, right? I would expect a power law distro). Kinda sounds like Google solved this by running the apks through something like a CI/CD gauntlet and then...hoping for the best.

I'm not sure it is just hope. I don't know how that team works specifically, but I know that they aren't just saying "hey we hope it works" in their reviews with leadership.

> Here's an idea: instead of charging 30%, you should waive that if the dev team agrees to vet 5 other apps for you, over time, especially the open source ones.

If you think that Google's policy enforcement and support is a kafkaesque nightmare now, could you imagine if your app was booted off Play because some other devs working at some company you've never heard of decided your app was bad? How would Google evaluate the quality of these investigations? With only five apps you don't have enough volume to develop a reputation so Google would either be forced to repeat all of the investigations or simply have zero oversight over the process.

Post reply on HN