The amazing thing to me is that, at least on iOS, the game is pretty objectively bad. Of course that hasn't stopped me from sinking a lot of time into it this weekend. I've spent $10 on it, which is easily a record for free to play game for me. The server issues are one thing, but the game doesn't even get lots of basic things right. If the server goes away, or sometimes if I'm just out of the app too long, I have to…
"the game is pretty objectively bad. ...I am having fun."
Doesn't that mean the game is good? Lots of people enjoy Uno, not every game can be Go (nor should it). If you're having fun, you're doing it right.
I'm not sure I'm buying the small company angle. Sure, there are always going to be very creative people who work around complex rules, but that's not everyone. They could apply very basic checks and get rid of 99% of spam I've seen. Specifically, applying "you just moved more than 20km in one go and posted the same message including {bay/sell} => permaban".
For one moving 20km to Paste a message is easy and legal - using the Intel map. If you use the chat there it uses whatever location your focus is on. Also banning the "selling items" accounts does very little, they are cheap to recreate. The thing you have to control are farming bots.
> moving 20km to Paste a message is easy and legal
Anything you can do in Ingress apart from actually hacking the players' phones, or sending threats is legal. It doesn't mean it shouldn't be filtered. At some point more than half the lines in the chat were bots trying to sell stuff. Killing either part works - production (farming) or selling.
Currently discussing with friends best way to crack it and make it seem like there's a rare pokemon just up ahead - for all those people who slowly clog up the sidewalks and stations staring at their phones. Ideas welcome! (For the official record, since you have to say this these days - I'm only joking)
It's already been noted that the application itself doesn't verify the validity of TLS certs, so it's trivial to MITM the connection and there are currently people working to learn the ins and outs of the API.
im not interested in hacking or modifying things, but would love to get api access to the data - can you link to a forum where this stuff is being worked on?
Since it has the Pokémon company's brand (and therefore Nintendo's) I really hope to be a great app. One of the things I love about Nintendo with how well they polish all their software. Instead it's very clear to me that it's a Google app with Pokémon branding. Release fast, bugs are OK, we can fix them later. Don't worry about the fact that the iOS version feels like an Android app and is somewhat obnoxious to use.…
Pokemon Go isn't made by Google, it's made by Niantic. Niantic were originally linked to Google, but have been independent since October 2015. https://en.m.wikipedia.org/wiki/Niantic,_Inc .
It was an internal Google startup that spun out, so I'm assuming they're used to 'the Google way' of operating.
I don't feel great saying this stuff, but I don't know how else to communicate just how startlingly bad the app can be, and how much it feels like a terribly lazy port of an Android app.
I don't know. Maybe if I use the Android app for a few days I'd find out that more or less every single issue is just as bad.
For one moving 20km to Paste a message is easy and legal - using the Intel map. If you use the chat there it uses whatever location your focus is on. Also banning the "selling items" accounts does very little, they are cheap to recreate. The thing you have to control are farming bots.
> moving 20km to Paste a message is easy and legal Anything you can do in Ingress apart from actually hacking the players' phones, or sending threats is legal. It doesn't mean it shouldn't be filtered. At some point more than half the lines in the chat were bots trying to sell stuff. Killing either part works - production (farming) or selling.
I'm not saying it's nice and that I support those sellers, but I'd try to kill the root ... and the chat experience always was limited with Ingress. In my local groups it was good enough however to get into contact with people to get then to hangouts or slack or whatever. With Pokemon this is really missing.
The one thing which is missing (and which made Ingress the amazing game it is) is ingame notification and ingame player activity. Based on the gym activity there are at least 15-20 players in my town but there is just no way of contacting them. If I am lucky I can manage to meet one by random chance but currently Pokemon Go is a rather single player game. The other thing which is missing is a system which shows ingam…
This game is targeting young kids, so I'm not sure there will ever be any person-identifying interaction. A lot of online multiplayer games for kids don't have interactions beyond friending/favouriting someone. P-GO would be a prime candidate for 4chan type people and you can imagine how that would work together with location spoofing and global playground. I expect that Nintendo & Niantic know this (Ingress never so…
If the game is targeting young kids, it's missing out on its primary audience. For one thing, young kids often do not have cellphones of their own. But for another, I was recently at a mall in a fairly major city, and I did not see one person under 18 playing, but near every Pokestop, and every lower spawn rate Pokemon, I found dozens of people. Pokemon games have had somewhat adult humor and themes for years, though the TV show is undoubtedly meant for a younger audience. Given that most of the people who really wanted this game are people who grew up on Pokemon and are now adults, not at least providing the option to have social interaction feels a bit wrong. It could be abused, sure, but I think throwing the necessary resources at keeping it from being abused, and punishing abusers would be worth keeping the game relevant to its current primary consumer.
I'm not sure I'm buying the small company angle. Sure, there are always going to be very creative people who work around complex rules, but that's not everyone. They could apply very basic checks and get rid of 99% of spam I've seen. Specifically, applying "you just moved more than 20km in one go and posted the same message including {bay/sell} => permaban".
Perhaps it's just easier to leave it like the way it is? This way they can easily track spam-bots and the network behind it. If they start to implement more sophisticated by systems the spammers would also become more sophisticated.
At the point where you can't really talk to people anymore because your window is just flooded with spam, no. It may be easier for Nianic, but not for the players.
Besides, are you serious with that suggestion? Would you prefer email spam filtering didn't exist, otherwise it would get sophisticated? (easier to leave it that way viagra for sale now)
The one thing which is missing (and which made Ingress the amazing game it is) is ingame notification and ingame player activity. Based on the gym activity there are at least 15-20 players in my town but there is just no way of contacting them. If I am lucky I can manage to meet one by random chance but currently Pokemon Go is a rather single player game. The other thing which is missing is a system which shows ingam…
Walking around my neighborhood last night on two occasions at different times of the day, I encountered a dozen or more players both times: people of all ages out in the park or walking their dog. I live in an urban area half a block from a park with four Pokéstops in close proximity, but meeting/interacting with other players is not going to be a problem.
My small town has about 150 pokestops and only 10-20 players so we are spread pretty thin. The chances to meet someone are pretty slim.
It's already been noted that the application itself doesn't verify the validity of TLS certs, so it's trivial to MITM the connection and there are currently people working to learn the ins and outs of the API.
It verifies certs, it just doesn't pin them. So if you can hack your phone, you can hack it, shocker. Not a security flaw.
Curious why you don't think this is a security flaw. Surely a browser failing to pin certificates would be a bad thing, no?