Live data from Hacker News

The Google Play app review process now regularly takes longer than a week

gultsch.social

291–300 of 357 posts

Re: The Google Play app review process now regularly takes longer than a week

#291
post #285

Earlier quoted context omitted.

Haha. I used to have some blog posts detailing things a bit more, but I let it die when Heroku cancelled their original free tier years ago.

what was the url? asking for a wayback friend

https://web.archive.org/web/20220119132757/https://davidmurd...

Re: The Google Play app review process now regularly takes longer than a week

#292

Earlier quoted context omitted.

Back in early 2000s, pretty much all Windows machines were infested with malware. Do you want to bring back those glorious days? Back in the day users didn't really have much valuable and sensitive stuff on their machines and malware was rather benign - just sending spam, not trying to fuck up that specific user. Could be a bit different when it's a smartphone user depends on.

People still can install/run whatever they like on their PCs, so why further restrictions needed or am I missing something? Also, further restrictions doesn't seem to work on the mobile/TV market where actual malware still infects iOS/Android/TV devices despite all the "hops" that it has too go through. Code signing with warnings about non-signed apps is enough

Hmm? Malware on iOS is extremely rare.

I remember in Bitcoin community ~10 years ago, standard recommendation was than an iOS wallet was secure enough (I don't recall even a single case where wallet was stolen via malware), but any private keys on Windows were strongly discouraged, as most cases of stolen wallets were on Windows.

I'd say popularity of iPhone shows which way people prefer, but you do you - what prevents you from voting with your wallet and buying a Linux phone?..

Re: The Google Play app review process now regularly takes longer than a week

#293

Earlier quoted context omitted.

How did you "accidentally" do something that was so obviously not allowed?

He accidentally got caught.

I responded to others with more details if you're interested

Re: The Google Play app review process now regularly takes longer than a week

#294

Earlier quoted context omitted.

How did you "accidentally" do something that was so obviously not allowed?

I didn't know what a "money transference service" was, and certainly didn't know this service that I didn't know about was highly regulated. I only created it because I had Google Play Credits that were gifted to me. I built an app to "convert" them to cash for myself. I had never built an app before. I was proud of it and tried to make it pretty and professional and useful for others, and used it as a learning exper…

Right but... You've used gift cards before right? The whole point is that you can't convert them to cash. Not only that but Google/Apple gift cards are notorious for being used in fraud.

I guess if you're young...

Re: The Google Play app review process now regularly takes longer than a week

#295

Earlier quoted context omitted.

Haha. I used to have some blog posts detailing things a bit more, but I let it die when Heroku cancelled their original free tier years ago.

If you're inspired to rehash it here or another blog you'll have at least this additional reader.

https://web.archive.org/web/20220119132757/https://davidmurd...

Re: The Google Play app review process now regularly takes longer than a week

#296

Earlier quoted context omitted.

The app stores are neither necessary nor sufficient to curb malicious software. Conflating the centralized app stores with safety is a mistake that only serves the gatekeepers.

Just because something is not perfect that does not mean it's worthless. Most things security things operate this way where it's impossible to stop all malware or attacks.

When analyzing whether something is a net good for society, I look not only at the value it brings, but the cost that it brings. The mobile ecosystem normalizing the idea that the vendor that sold you your everyday computing device is the sole arbiter of what can run on that device is of enormous cost to society, but anytime anyone brings that up, there's an immediate retort bringing fear, uncertainty, and doubt about software obtained outside of those centralized silos.

As I've said countless times before, the answer is clear. Operating systems can install software from repositories. The vendor of the operating system can provide a default set of repositories. Third parties can also provide their own repositories. Device owners can choose what repositories to install software from.

Saying that there can only be one true repository is carrying water for trillion dollar companies to further extract money from their customers.

Re: The Google Play app review process now regularly takes longer than a week

#297

MAYBE operating systems shouldn't have gatekeepers which can deny access to billions of customers for any and no reason at all. Apple and Google are WELL past due for regulation in this space. The fact that we cannot download and install software from the internet onto our phones JUST like we can do with our computers is a symbol of our inept and ineffective politicians. And before someone says "well akshully you can…

Back in early 2000s, pretty much all Windows machines were infested with malware. Do you want to bring back those glorious days? Back in the day users didn't really have much valuable and sensitive stuff on their machines and malware was rather benign - just sending spam, not trying to fuck up that specific user. Could be a bit different when it's a smartphone user depends on.

The reason that modern computers are no longer filled with malware has nothing to do with completely irrelevant locked garden app stores on phones.

The reason is because Bill Gates put out a memo because it was fucking embarrassing that you could trivially smash the stack on default open API endpoints for services that consumers never used and shouldn't have been trivially routable from the open web in the first place.

Meanwhile in app stores, you don't have to hack anything, because consumers just download your botnet software willingly and directly.

42% of all apps on LG smart TVs turned your TV into a "residential proxy" botnet participant. 30% on Samsung TVs. There is no "hacking" in the world of apps because it's completely normalized for whatever app you build to also for some reason include remote control functionality from like 6 different companies. All of those apps pass review no problem.

Re: The Google Play app review process now regularly takes longer than a week

#298
post #173
post #51

By the way, the same is happening for the Apple Store. Their review process is advocated as usually within 24 hours ( and heavily advertised by Apple as such, see https://developer.apple.com/distribute/app-review/ ) and it is taking now much longer. In the last month, I had to go through the review process twice, and twice I needed to contact them personally after waiting for 1 week of waiting. It did however helped,…

I'm sure submissions have absolutely skyrocketed with model advancements since the beginning of the year. I'd be curious to see the numbers. I know Github's commit numbers have been pretty staggering YoY.

Yup, my bets are on this. It’s not only github that gets ~order of magnitude more PRs and commits, but probably app stores too.

Wonder how it will change app stores for the future.

Re: The Google Play app review process now regularly takes longer than a week

#299
post #284

Earlier quoted context omitted.

Now do that again without careless work or spoiled ingredients. Do you still want them punished or facing so much regulation they can't exist? Because you'll definitely get that with software; even really good development will have flaws, and single flaws can lead to a thousand or million hacks.

All humans face scrutiny in their interactions with others. Software only got this bad, because we educated users broken tools are acceptable and fixable with computer reboots and anti-virus.

I dunno, people seem to accept most kinds of tool being fussy or flaky.

But the special thing about security flaws is that they turn a one in a billion error into a guaranteed attack. It's moderately hard to make something that doesn't feel buggy, but ridiculously hard to be secure. If you hold to the standards of a bake sale it's the former. If you want full security then nobody releases anything outside very strict contracts.

Re: The Google Play app review process now regularly takes longer than a week

#300
Google's review is complete horseshit. It has been darkly funny to watch them try to compete with Apple by adding strict review (way stricter than Apple's) and still terrible applications make it in while legitimate ones have trouble.

Just go back to the way it was before, and scan the apps with static analysis tools. This security theater is stupid and always was (for Apple and Google).

Post reply on HN