Live data from Hacker News

Google have declared Droidscript is malware

groups.google.com

301–310 of 665 posts

Re: Google have declared Droidscript is malware

#301
> ...after taking into consideration the information that you have provided, we have confirmed that we are unable to reinstate your publisher account.

I hate when using euphemism slides into flat out lying like this. They are not "unable" to reinstate the account, in fact they are the only party able to reinstate the account, that's why the account holder was contacting them instead of someone else. They are "unwilling" to reinstate the account.

I know it's all just bullshit but it bothers me anyway.

Re: Google have declared Droidscript is malware

#302
post #82
post #25

It's seriously time to re-embrace the idea of ownership and control of our devices, and reject Android and iOS altogether. Developing for those platforms has become worse and more restrictive over the years, and this kind of crap is now just everyday news. How good are Pinephones[1]? Are there better alternatives? [1] https://www.pine64.org/pinephone/

The biggest problem with "alternative" platforms is just the lack of app support. I used to have a Nokia N9; great phone. But it didn't support WhatsApp and I was out on the loop on the WhatsApp chat all my other coworkers were in. Then there's things like banking apps, flight check-in apps, food ordering apps, dating apps, etc. etc. Can you do without those? Sure, of course. But if I want to order food where I live…

No, it's the bad hardware. With high-end hardware, it would be no problem to just run something like anbox and immediately have most of the important apps running. Except asshole apps that require DRM/safetynet of course, but I don't use them on my current android phone anyway.

Re: Google have declared Droidscript is malware

#303

Earlier quoted context omitted.

"In the case of fdroid, apps that violate open source licenses are not allowed" ...on the main repository. AFAIK, there's nothing stopping Google or anyone else from setting up their own F-Droid repository to distribute apps with proprietary code. The normal F-Droid app should be able to use a repository like that just fine. EDIT: Addressing the "PS" that was added... > Google advocates always make the argument that…

I totally agree with your points there. But I think that the main issues of Android (or AOSP) are even a level deeper than just the Play Services. There are lots of initiatives that try to create a free ecosystem for themselves (Lineage, /e/, Carbon, et al), with their own stores and sources for Apps. Most of them have varying degrees of success, due to gapps counterparts like microG [1] not being able to keep up wit…

I kind of agree, although I'm not sure it's fair to say that the problem with Android is that you can't easily replace it with another OS. That's not really an Android problem.

It's incredible what a smartphone can do given its form factor and a lot of that is thanks to their use of SOCs. I have no experience with OS development for SOCs, but I hear it is much more involved because a new version of the OS must be created for each SOC - specialized to work with the device tree supported by that chip. As I understand, Google doesn't do that work. Manufacturers have to fork Android and implement support for their SOCs on their own, then they have to maintain that fork as new Android releases keep coming. It's no surprise then that manufacturers don't want to invest addition support into other operating systems like LineageOS.

There's probably a better way to do things. I'm sure manufacturers could make information more available to OSS communities which would allow them to do the work themselves more quickly and effectively. Like you mentioned, standardization would also go a long way towards making our current smartphone ecosystem more friendly to third-party OSes. But ultimately, none of that is really Android's fault.

Even without Google's vendor deals, I doubt the likes of Samsung, Motorola, or any other major smartphone manufacturer would start supporting LineageOS. It's hard enough to even get Linux suppport from desktop/laptop manufacturers. LineageOS is a really amazing project, but I don't think it's the one paving the way for open source operating systems on smartphones. I think most of that work has to come from the hardware side with projects like the PinePhone.

Re: Google have declared Droidscript is malware

#304
post #261
post #196

Earlier quoted context omitted.

I keep hearing this and it's totally wrong. Desktop Linux has a huge app ecosystem and arguably has more high quality software than Android does. All of this works on the pinephone and other similar devices.

Okay, so how can I chat to my friends or companies with WhatsApp on Linux? How can I order food similar to Grab or Gojek on Linux? How can I get a date on Linux like Tinder? You can't. Sure, there are technological solutions to all of those, but in the real world that alone is pretty much useless.

You can use Watshapp multiple ways on Linux, including the web browser version [https://itsfoss.com/whatsapp-linux-desktop/].

Although, if you're using Whatsapp at all you're either massively ignorant or stupid. I mean, giving Facebook your phone number is just not wise.

Re: Google have declared Droidscript is malware

#305

Earlier quoted context omitted.

But for many people, maybe even most people, they're not just "a phone". They're a multi-purpose tool that comes in the form factor of a mobile phone. Camera, chat, web browser, games, social media, music player, access to nearly the sum total of human knowledge... Treating such as tool as merely "a phone" doesn't make any sense.

It’s still a phone actually and colloquially even if I use the Phone App infrequently. The point isn’t what you call it. OP’s point was and I agree that you don’t need to have full control over every device that can possibly run code. Just let it be a device that does its thing. It’s the difference in people that want calm technology vs “power users”. I want the device to exist waiting on my input and even though I h…

> The point isn’t what you call it. OP’s point was and I agree that you don’t need to have full control over every device that can possibly run code. Just let it be a device that does its thing.

That's not how I read the op, who said "It's a phone, use it to call text and guide and browse some internet. That's it". The tone in that reads not like "you don't need to..." it reads like "you should not...", which I disagree with. I rarely use my phone to make calls. I use it as a multi-function tool of tremendous capability. If I wanted a simple flip phone, I would have bought one of those, instead.

Re: Google have declared Droidscript is malware

#306
post #111

Earlier quoted context omitted.

> Now, it's a shame Google couldn't let them know what was the issue. However, it's a safe assumption that the vast majority of people Google support deals with are spammers. And there's a lot of them. If Google gave a detailed explanation to all of them it would mean a ton of additional work – which would create an unsustainable situation at this scale. I don't think that's reasonable. What if most are spammers ? Be…

Google has the scale to do this, but they also have a large enough monopoly where they don't have to, so they won't. It's not that it's unsustainable, it's that it is entirely sustainable to continue doing things this way.

Can you elaborate? I can see how Google can scale this automatically. But I don't see how Google can terminate, say, one million apps a day, if each termination entitles the spammer a one hour conversation with a technical representative.

Re: Google have declared Droidscript is malware

#307
post #161
post #73

Earlier quoted context omitted.

>> "Can't you just make us a general-purpose computer that runs all the programs, except the ones that scare and anger us? Can't you just make us an Internet that transmits any message over any protocol between any two points, unless it upsets us?"[1] The War On General Purpose Computing continues. Far too many business models depend on selling general purpose computers as "appliances". They presume it is possible to…

Even as a casual Android dev I've noticed it becoming more and more restrictive over the years, from restricting apps from reading storage, to restring apps from accessing clipboard, to restring apps from running in background, and a ton of other things all in the name of protecting customer. Every time I update to a new phone with a new Android version my hobby apps (which only I use, not published anywhere) are bro…

That's how platforms evolve. First they work to attract developers, and later they work to reduce abuse.

Re: Google have declared Droidscript is malware

#308

Earlier quoted context omitted.

This is one case though where that lack of understanding leads to the right conclusion. The average user is giving up nothing by losing the right to run arbitrary code, because they never were running arbitrary code.

Which is why it's all the more important to fight against it. Change your point a bit. People are fine with giving up Freedom because they were never really Free in the first place. Circular reasoning is sucha seductive fallacy because it'll fit any use case like a glove.

Tweaking your wording slightly, it's basically the fundamentals of social contract theory.

I may have the freedom to bash my neighbor's head with a rock, but they have the same freedom to do the same to me. This isn't as useful as the freedom to sleep at night, so we voluntarily give up this freedom.

Reframing to the topic at hand: if the freedom to mutate the code on my mobile device makes it more likely that I'll get pwned by some clever social-engineering than the odds I'll improve my quality of life by tweaking some behaviors on the phone, then it's entirely rational for me to give up that freedom. And, indeed, millions of phone purchasers annually make that decision.

Re: Google have declared Droidscript is malware

#309
post #116
post #103

Earlier quoted context omitted.

> this is the kind of app that would never have been legal at all on any version of iOS. Pythonista is a complete Python programming environment which provides access to camera, music, contacts, the network, and so on, and has been available for iOS since 2016. What specifically distinguishes Droidscript from Pythonista such that you think Apple would reject Droidscript? https://apps.apple.com/us/app/pythonista-3/id1…

Droidscript has support for writing custom intents, which Pythonista (and Scriptable, a JavaScript version of the same thing) do not have. A malicious Droidscript application could access other applications on the device. https://symdstools.github.io/Docs/docs/app/SendIntent.htm

Are Play Store regulations the only defense against this kind of attack? If so, then yikes!

Re: Google have declared Droidscript is malware

#310
post #22
post #14

Earlier quoted context omitted.

Time for one of these again. So... having read through their marketing material, this is an on-device tool that opens up what appears to be most of the Android application API to at least the user of the device, and potentially to any Droidscript applications they grab from other sources, and... maybe to other apps on the device? It's not clear from a quick read how extensive the runtime control is. So just right out…

I think your thoughts on this are plausible, if not likely. However, the usual complete lack of communication by google is the actual problem. Perhaps droidscripts could mitigate googles concerns, if they had the decency to explain them.

But if they do, a malicious actor can use that information to circumvent their restrictions, and its their walled garden, so they have very little incentive to tell everyone exactly what they don't like.
Post reply on HN