Live data from Hacker News

Your app is not compliant with Google Play Policies: A story from hell

sylviavanos.nl

161–170 of 197 posts

Re: Your app is not compliant with Google Play Policies: A story from hell

#161
post #151

Earlier quoted context omitted.

> This kind of incompetence makes me seriously doubt that Google is doing anything to more substantially review apps for deeper security issues, either statically or at runtime. I actually know the team that does security vuln automation for Google Play. They've found millions of vulns in apps over the years. One of the challenges they face is precisely this sort of headline: how do you use static analysis to find vu…

Sounds to me like what you're saying is that the walled-garden approach of needing to approve every app that ever gets developed as a whole is what's infeasible without creating kafkaesque conditions dealing with their automation, and I fail to see how you've made a case for this automation being all that good in the first place, given that your main argument for it is that it's found "millions of vulns in apps over…

> Sounds to me like what you're saying is that the walled-garden approach of needing to approve every app that ever gets developed as a whole is what's infeasible without creating kafkaesque conditions dealing with their automation, and I fail to see how you've made a case for this automation being all that good in the first place, given that your main argument for it is that it's found "millions of vulns in apps over the years" but then later cite "millions of apps" as a reason you can't expand the support team.

People definitely make that claim. I don't think I fully agree. From the reviews of this particular system I've seen, they are able to actually hit virtually zero false positives. The challenge is that this comes at a high cost of missed issues, which also generates complaints.

> I would suggest that it might be worthwhile to use OS-level features to stop apps from behaving maliciously in more general ways, but a lot of what I would consider malicious behavior (e.g. sending user analytics to third parties, feeding them misleading ads, messing with other processes, etc) is part of google's business model or claims of added value in many cases, so that seems unlikely to happen.

Unfortunately, people also get pissed when platform behaviors are locked down to prevent abuse. Heck, people demand to have access to rootkits despite also wanting it to be impossible for a malicious app to harm them.

Re: Your app is not compliant with Google Play Policies: A story from hell

#163
post #87

Earlier quoted context omitted.

What makes these platforms attractive to the end user is that they're the only things available for sale down at the phone store. And what makes the decision between the two available choices is what your friends have, or what you already have, or what's on sale, or about a trillion other things that are more likely to be "top of mind" for the average buyer. I bet not one user in 1000 gives any thought to "app curati…

I very much appreciate how freely I can install apps from the app store. I hear about, I install it, I try it out, no worries. Whereas without curation I'd spend twenty minutes making sure it was mentioned by multiple sites or people I trust and doing a set of web searches to check for reports of malicious behavior, and I'd still worry about it, especially about updates. Putting out a good, well-behaved app and then…

What if someone else did all of that privacy research and monitoring for you, only it was a set of volunteers, and they did it for free? This is what F-droid does except they verify that apps on their store are clean at the source code level, compile the source code, and then publish it in their app store on behalf of the authors. When I'm looking for an app in the F-droid repo, I only need to wonder, "Is it any good?", because it is at least safe. They also warn you if the app does anything at all you might object to. For an example, check out the page for Firefox below, which at least gives you an idea of the kind of information available in the app.

https://f-droid.org/en/packages/org.mozilla.fennec_fdroid/

At times, Apple has removed apps capriciously out of self-interest and done things that aren't good from a privacy perspective. I trust F-droid to be a more equal an honest arbiter more than Apple since they don't have and reason to do something I wouldn't like. Basically, I'm saying that (in addition to scummy app stores) there would likely also be some app stores that do a better job than what Apple does at protecting you from the bad actors you just mentioned.

Re: Your app is not compliant with Google Play Policies: A story from hell

#164

I have the same experience with the Google Play Store. For all the complaints people have about the Apple App Store, at least their reviewers are human and you can discuss things with them. And they block updates but don't remove the app without warning! My experience with the Google Play store: I get an email on a friday night after working hours stating that the app of my company was removed after a routine check a…

The number of times I've heard of people only getting support from Google because they know someone on the inside is quite astonishing. If I were an Google employee looking to make a few extra bucks I'd definitely start offering to help "nudge" account issues for a few extra bucks under the table.

Every time I get fucked-up support dead-ends like this now I go to war against the management of that company. I pay to get hold of all the home phone/cellphones/personal email addresses of the highest position employees I can find and bug the shit out of them until one of them capitulates and gets a minion to fix the problem.

I just harassed the C-suite of a unicorn that wouldn't give me a refund for something that wasn't delivered. "We can't give you a refund because FedEx says it was delivered." IT WAS DELIVERED TO SOMEONE ELSE AND THEN FEDEX COLLECTED IT AND RETURNED IT AS YOU CAN SEE IN THE TRACKING LOGS. "Thank you for your e-mail. As the package shows that it was delivered you will need to take this up with FedEx. I cannot help you further with this enquiry." A weekend of texting and emailing the management and now suddenly I have them giving me their corporate email addresses and a promise to have it fixed after the holiday.

Re: Your app is not compliant with Google Play Policies: A story from hell

#165

which one is more incompetent as a service company - Amazon, Google, Facebook, or Apple? I think my ranking would be Google, Apple, Facebook, Amazon, but that is not so much decided via any sort of logical evaluation but only due to my feeling on the matter.

For all the problems Amazon has and causes I will say I've always found their support to be pretty excellent. From what I understand Amazon's foundibg philosophy is focused on just serving the customer at the cost of any other externality and that's where most of the conterversy surrounding them comes from is placing whatever is needed to please the customer above every other concern. But that means when working with…

> From what I understand Amazon's foundibg philosophy is focused on just serving the customer at the cost of any other externality and that's where most of the conterversy surrounding them comes from is placing whatever is needed to please the customer above every other concern. But that means when working with them they are pretty great.

I have tried for years to report counterfeits on Amazon to their customer support to no avail. They don't want to collect that data, it seems, despite the severe effects their products can have on customers.

Re: Your app is not compliant with Google Play Policies: A story from hell

#166
post #38

Earlier quoted context omitted.

Dont worry, google is working hard to make sure that even employees are unable to do anything of that sort. Gather the world's information and make it uniformally unsupported.

Just speculating, but another possibility may be a new kind of business popping up: Google App Store experts who can somehow prevent these problems and/or make them go away. Similar to Google-SEO consultants, or college-admissions consultants who help rich kids get into universities they normally couldn't.

There is already this service which works to get your Facebook account back:

https://hacked.com/

Re: Your app is not compliant with Google Play Policies: A story from hell

#167

It's the same with all of FAANG. It's now been almost two months since my facebook page of 56k users was hacked, and nobody at facebook seems to give a shit: https://news.ycombinator.com/item?id=29876423 I just gave up and made a new page now. Hopefully the hacker won't manage to claim that one too.

There is a paid service to help you get these back.. O_O

https://hacked.com/

(I guess it is that common?)

Re: Your app is not compliant with Google Play Policies: A story from hell

#168

Earlier quoted context omitted.

>Google pays external hackers who find vulns in popular apps via a rewards program. How does that work? Is the submission farmed out to a 3rd party as part of the verification process, and proactively checked? Or is it reactive, similar to a bug bounty? Are there people out there making their living running apks in desktop simulators looking for issues? I always wondered about the economics of checking huge quantitie…

> How does that work? Is the submission farmed out to a 3rd party as part of the verification process, and proactively checked? Or is it reactive, similar to a bug bounty? Bug Bounty. Person finds vuln in popular app. Person submits vuln to Google. Vuln gets reported to developer. Person gets paid. > Are there people out there making their living running apks in desktop simulators looking for issues? Most of them use…

>could you imagine if your app was booted off Play because some other devs working at some company you've never heard of decided your app was bad?

I would assume they'd give a reason for booting the app, which could be verified by Google and the author. I would imagine the more likely error mode would be simply clicking "okay" without actually looking at the code at all. You know, like some devs do with code reviews!

Re: Your app is not compliant with Google Play Policies: A story from hell

#169
post #52

I think you were lucky they told you anything . On Quora they just say "your answer was deleted for violating Quora policies. Click here to read our policies." This sort of "tell them nothing" approach seems pervasive in the online world. Blame the lawyers. Their lawyers must caution them "Don't give any details. That just opens us up to more questions & legal actions." The fact that it's completely self-serving and…

I despise the tell them nothing approach and I think it's despicable, but that said I think there is a more legitimate reason than the lawyers. If the person is a spammer or otherwise not legit and you tell them what they did wrong, it's a lot easier to hack around the problem and beat the automated moderation and get your malware into the store. I don't think that justifies the harm it does to regular people, but it…

Japan immigration does this too - they reject applications but won't say why it was rejected, because people wanting to enter the country for illegal reasons might be able to use that information:

https://www.mofa.go.jp/j_info/visit/visa/faq.html

Re: Your app is not compliant with Google Play Policies: A story from hell

#170

It's the same with all of FAANG. It's now been almost two months since my facebook page of 56k users was hacked, and nobody at facebook seems to give a shit: https://news.ycombinator.com/item?id=29876423 I just gave up and made a new page now. Hopefully the hacker won't manage to claim that one too.

There is a paid service to help you get these back.. O_O https://hacked.com/ (I guess it is that common?)

$899

Holy c...!

Post reply on HN