Live data from Hacker News

Google have declared Droidscript is malware

groups.google.com

171–180 of 665 posts

Re: Google have declared Droidscript is malware

#171

Earlier quoted context omitted.

What are you going to do? Stop using Google products? Good luck.

Yes. Android and gmail are my last two to get rid of. I was wanting to play with mail in a box, but this morning had an alert on my phone demanding my birthdate within 14 days. So, I'll be expediting google out of my life within the next 14 days.

Android is so bad for privacy.

Re: Google have declared Droidscript is malware

#172
post #53

Earlier quoted context omitted.

Check out their philosophy[0]. They aren't exactly a company targeting end user consumers. They want to put affordable hardware in the hands of a community of tinkerers. [0] https://www.pine64.org/philosophy/

Well, as both an end-user and tinkerer, I'd rather not have to own two devices when I can go out and get one that will cover all my bases.

Good luck with that. See how long that last, if the current trend continues. Soon you might have to aquire a certified developerversion to unlock your device to tinker with it.

Re: Google have declared Droidscript is malware

#173
post #26

> We don't allow apps with any code that could put a user, a user’s data, or a device at risk. If Google thinks the ability to execute arbitrary code puts users' data at risk why don't they go the full iOS route and ban everything, from scripting apps to other JS engines beside Chromium? I am so sick of their behaviour, the only reason I am still on Android because things like F-Droid still exists and iOS is even mor…

Technically, f-droid is a walled garden of sorts, too.

The difference is that fdroid is actually helping users through being transparent about it. The other stores and their policies usually are not transparent, and therefore nobody knows whether there were financial motivations involved in the decisions.

What I don't like is google claiming droidscript harms Android through a malicious AdMob ID. Even if that were the case, what happens to the 100.000+ installs that are rolled out already? And the Apps built with DroidScript?

If there's no support you can contact (at Google) and no changelog on what happened, the policies get intransparent and look more like a financial motivation rather than a decision that seemed to be beneficial for the end-users.

Re: Google have declared Droidscript is malware

#174
post #82
post #25

It's seriously time to re-embrace the idea of ownership and control of our devices, and reject Android and iOS altogether. Developing for those platforms has become worse and more restrictive over the years, and this kind of crap is now just everyday news. How good are Pinephones[1]? Are there better alternatives? [1] https://www.pine64.org/pinephone/

The biggest problem with "alternative" platforms is just the lack of app support. I used to have a Nokia N9; great phone. But it didn't support WhatsApp and I was out on the loop on the WhatsApp chat all my other coworkers were in. Then there's things like banking apps, flight check-in apps, food ordering apps, dating apps, etc. etc. Can you do without those? Sure, of course. But if I want to order food where I live…

> It's a "vendor lock-in" ecosystem that's worse than the Windows lock-in of yesteryear IMO.

For regular companies, if they want to shoot themselves in the foot by not being on the web, they're welcome. It's not such a huge issue as it would be with government for example.

Also "any chance of any form of adoption" is a bit overstatment. I still use a dumbphone, and if I migrated to pinephone, lack of the kind of apps you mention would certainly not concern me. Even then, many apps have web alternatives here, or alternative GPLed clients for Linux (that includes whatsapp, apparently), that can be made native on pinephone.

Re: Google have declared Droidscript is malware

#175
post #165

Earlier quoted context omitted.

I still like my car to have an immobilizer, and locks on the ignition and doors. There is certainly some level of access controls that most people definitely want.

And who owns the keys to those things? You, or the manufacturer?

Many vehicles have the keys stored in their ECU/Immobilizer signed/encrypted with the manufacturers' key.

There are some (mostly older) where you can directly reprogram the eeprom but those cars are easier to steal, because anyone can also do this.

Re: Google have declared Droidscript is malware

#176
Whatever their reasons may be, they may be legitimate.

But using this sentence is simply not OK:

> Because this information could be used to circumvent our proprietary detection system, we’re unable to provide our publishers with information about specific account activity.

The developer/publisher must be given a chance to correct the issues. This is simply not fair.

I'm pretty sure Google can do better than to rely on security by obscurity.

---

> Unfortunately we also have to inform our users that we could no longer support AdMob for use in their own apps either, because we can't test it anymore and can't guarantee that Google won't treat them in the same brutal way.

Couldn't it be possible that one of those users was using AdMob in a fraudulent way, and that this was then linked to Droidscript? I don't know how Droidscript works, how it creates those apps, but it could be possible that Droidscript then was responsible for the fraudulent use a user did.

Re: Google have declared Droidscript is malware

#177
post #87
post #73

Earlier quoted context omitted.

>> "Can't you just make us a general-purpose computer that runs all the programs, except the ones that scare and anger us? Can't you just make us an Internet that transmits any message over any protocol between any two points, unless it upsets us?"[1] The War On General Purpose Computing continues. Far too many business models depend on selling general purpose computers as "appliances". They presume it is possible to…

The battle really parallels the larger right to repair debate. (Especially if we realize the latter is probably is better called the right to exercise control over purchased goods.)

Agreed. I would feel better about this if I didn't think apps and local computing were really important. The alternative to phone apps is the web, but the web will never be fast (imo) and is simultaneously getting less open every day as well.

Re: Google have declared Droidscript is malware

#178
post #37

Earlier quoted context omitted.

Phones are the only pocket computers that see quick advances in performance and battery use. For someone who wants a pocket sized computer, it's just most convenient to combine it with your phone.

But they are horrible as production machines, at least until when our brain is no longer using our body as interfaces. For pure pocket sized computing, why not use RPi? It's both much cheaper, more customizable, and it runs Linux. With enough tweaking you can make it run completely headless, plug-and-run mini computer that you can ssh over local network. I think the biggest problem with the combining idea is that com…

Phones are kinda too small, but iPads (which are, in essence, oversized phones) are just fine for production machines if you don't equate productivity with programming.

With a Pencil and Procreate, it's really hard to beat for drawing and illustrating. With an external keyboard and some kind of stand writing is a joy, I like it better than on a proper computer because of a ton of little things that help me keep focused and because the device is so portable and doesn't have the laptop form factor with a permanently attached keyboard, with bluetooth periphery it's more like a wireless battery-powered external screen.

Light to medium spreadsheet work is also totally doable, and I've build dozens of slide decks in various apps, with hand-drawn illustrations.

I use a Pi as a mini server, but doing creative work on one, I can't imagine that to be as nice and slick as on the iPad. Last time I tried the PiOS desktop, it definitely wasn't.

Re: Google have declared Droidscript is malware

#179

Earlier quoted context omitted.

Arbitrary code isn't banned on iOS, there isn't anything (yet) that can create fully fledged apps like Droidscript, but a few cool apps are: - iSH: an Alpine Linux shell environment, powered by an x86 to ARM JIT emulator - Scriptable: an iOS automation tool using Javascript, it can even integrate with native iOS APIs like photos and calendars, create native UIs, etc. - Pythonista: a Python IDE, you can create 2D game…

> Arbitrary code isn't banned on iOS It is. Even mozilla firefox is banned on the premise that it can run arbitrary code and yes, that is the official apple instance. The fact that they apply it when they see fit and allow other times, and that it is totally arbitrary and opaque based on their own private interests , is exactly what everyone with common sense tried to explain when criticizing the walled garden.

My understanding is that what's banned on iOS is not arbitrary code per se, it's arbitrary code downloaded from the internet. Code you enter yourself, like in Pythonista, is just fine.

Re: Google have declared Droidscript is malware

#180

Earlier quoted context omitted.

I still like my car to have an immobilizer, and locks on the ignition and doors. There is certainly some level of access controls that most people definitely want.

Those are still "yours" in a sense, so don't fall into the feature set the poster you are replying to is talking about. Though the immobilizer somewhat skirts the line. (Or at least from my personal view). Think John Deere implementing software lockouts in the tractor ECU. That is nothing more than forcing their business model onto the end user through digital logic.

They're just as much "mine" as an iPhone is. It is extremely common for digital authentication of physical keys to be protected by encryption or signing by the manufacturer.
Post reply on HN