Live data from Hacker News

Open-source apps removed from Google Play Store due to donation links

lists.zx2c4.com

451–460 of 579 posts

Re: Open-source apps removed from Google Play Store due to donation links

#451
post #442

Who do you trust more, to secure their infrastructure? Google or F-Droid / a bunch of volunteers who may or may not be very security-conscious? Not to downplay the effort that F-Droid contributors (or any Android FOSS groups) make, but it's a very legitimate concern. Would an attacker have an easier time infiltrating Google or a member of F-Droid the development community? Are users of F-Droid higher value than users…

At least read up on how f-droid does their reproducible build infrastructure before you spread FUD.

What about my comment is FUD?

Regardless of the fact that builds are reproducible, F-Droid has infrastructure. How is that infra secured? How are the servers that store signing keys secured? How are the build servers accessed? How is the access secured?

Okay, so the builds are reproducible -- is someone maintaining a concurrent system that verifies reproducibility and provides notification of a collision when things don't match up with built and served binaries?

Re: Open-source apps removed from Google Play Store due to donation links

#452
post #441

Earlier quoted context omitted.

Then break-up is still not the solution. Microsoft didn't get split in the late 90's / early 2000's. Anti-trust case against Google / Apple seems far more appropriate and doesn't require new legislation. All in all, that whole "break-up" argument is just political white-knighting by wanna-be elites (ie. Warren & co).

I don't follow this line of reasoning at all. By all accounts, Microsoft should have been broken up. They were convicted of abusing their monopoly position in a court of law. It was a travesty of justice that it was not carried out. Had this happened, the new companies would have been vastly more competitive, and the current state of computing might have been much better.

It's hazardous at best to assume the state of something with so much variables.

As for continuing being GAFA advocate (while still thinking they should be compelled to open up "Stores" to competition), vertical integration provides enough economy of scale to achieve ever greater complex things. Also, 1) you can't just "break-up" any GAFA. They're just gonna move out of State and be welcomed somewhere else, and 2) what you're asking put Government in a very awkward position as setting up both enough regulations to block new players, but also blocking player to achieve a certain size. Finally, this argument is getting awfully close to the "broken window" fallacy. You can't just "create competition" out of thin air.

Re: Open-source apps removed from Google Play Store due to donation links

#453
post #448

Earlier quoted context omitted.

Oh do come off it. This is bureaucratic bullshit at its' finest. We're talking about a hyperlink in the app. Linking to wireguard.com would be fine. How about if wireguard.com had a big donate button? How about if wireguard.com has 'Donate' in bold? I know you're not the person actually signing off on this - but to the one that is - fuck you. In bold. No-one is getting sued because of one step being removed in a hype…

It's not a lawsuit that people are afraid of. It's potential action from financial regulators, who are famously inflexible and disinterested in being nice to open source software developers in genuine financial need. Parties like Google and Apple are well aware of the potential consequences, and thus are similarly inflexible and disinterested in being nice to a fairly small group of use-cases that exposes them to an…

Unless you're casting literally any action ever as being subject to "potential action from financial regulators", which is theoretically true but simply asinine to discuss, this completely misses the point.

It is not a real concern for Google to have a hyperlink https://wireguard.com/donations buried inside an app distributed on the Google Play Store.

I don't believe your concern is legitimate. It's arse covering gone mad, sorry.

Rhetorical:

You can email me, my email is in my bio, and I will respond with a way that you can send me money. If dang reads this post and does not take it down, does that put HN at risk of AML action for potentially 'aiding the money flow'?

edit: actually, you can click through enough links on my bio and get directly to donation pages. now we're really fucked, right? who's gonna turn off the lights?

Re: Open-source apps removed from Google Play Store due to donation links

#454

Earlier quoted context omitted.

You think a breakup will change anything?

Yes — if there were real competition between multiple app stores, some of which provided better systems of vetting than others (both for users and for developers), then the kinds of stores that had these policies would die off.

Or, they will all pre-emptively adopt stronger policies to avoid freeloading. OSS apps don't pay for bandwidth used in downloads, and Google is the one benefiting most from all the free apps on their platform. So if _they_ aren't comfortable with the situation, I can't see a breakup solving that.

Re: Open-source apps removed from Google Play Store due to donation links

#455

Google Play In-app Billing does not support donations [1], so open source developers should be allowed to link to their own donation pages. Google Play policies do not spell out that linking to donation platforms such as Patreon is forbidden. Disallowing developers from using in-app billing for donations, while also barring them from linking to external donation platforms, puts open source projects in a difficult pos…

Why can't open source app developer have companion donation app like many freemium android apps do?

Re: Open-source apps removed from Google Play Store due to donation links

#456

In an ironic twist, our app that Google supported via Summer of Code was removed. Whoever came up with this policy and started enforcing it at Google is completely tone-deaf, needs to be fired and publicly called out so we can set an example as a community that this sort of behavior will not be tolerated. We have contacted engineering leadership at Google and they are in the process of figuring out who it is internal…

If you think that's an appropriate and proportional response to an employee making a mistake or misunderstanding an internal policy, I sincerely hope that you're not in charge of anyone at your day job.

Re: Open-source apps removed from Google Play Store due to donation links

#457

Earlier quoted context omitted.

Blame the companies that want & use DRM, not the DRM provider. It's the same thing that happened on PC ages ago. If you don't like DRM, don't support games & apps that use DRM. Complaining to SecuROM that they are supplying market demand isn't useful. At least SafetyNet isn't a badly made rootkit that destroys your hardware and it's only real flaw is being semi-functional DRM.

> Blame the companies that want & use DRM, not the DRM provider. I've got enough blame for everyone involved, don't worry. > Complaining to SecuROM that they are supplying market demand isn't useful. Appealing to the ethics of an entity that doesn't have any is not useful. But I wasn't writing to Google. > At least SafetyNet isn't a badly made rootkit that destroys your hardware and it's only real flaw is being semi-…

> "Whatabout SecuROM"?

I don't understand what you're attempting to get at with this.

PC DRM back in the day was notorious for rootkit vulnerabilities and even bricking CD/DVD drives (example: https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk... ). The point was just at least SafetyNet isn't straight up broken like the wild-west of arbitrary DRM providers of yester-year.

Re: Open-source apps removed from Google Play Store due to donation links

#458
post #205

The Apple/Play stores are essentially a totally broken implementation of something that had existed for over a decade before: package repositories. It's embraced and extended Linux/BSD package/ports trees, except without things like the ability to add a 3rd party repository with other authors signing keys, pin certain versions, etc. https://battlepenguin.com/tech/android-fragmentation/#packag... We could go on about…

I do wonder how crappy an opensource package repository would get if it faced the kind of sustained attack by con-men that Play & Apple have to deal with.

kind of like npm

Re: Open-source apps removed from Google Play Store due to donation links

#459
post #416

Earlier quoted context omitted.

> Just let the in-app purchase unlock some cosmetics in the app like games do. I contribute to projects that are committed to never locking away features behind licenses or in-app purchases, because most open-source projects in that space eventually went down that route.

You might not have to actually lock anything away. It might be acceptable to "unlock" a theme that you could otherwise just install in some other way, or there might be some other workaround.

Like another poster said, unlock a text box, in the settings, or about page, or wherever, saying: "Thank you for your support!"

Re: Open-source apps removed from Google Play Store due to donation links

#460

Earlier quoted context omitted.

It's understandable that they want to process payments only for registered organizations, but that still does not explain why are open source apps being taken down for linking to an external page that lists ways to support projects.

Probably because Google or it's financial partners have compliance programs that require all money flows they enable go through the required regulatory channels. If an affiliated party is breaking regulations, you can often get in trouble by continuing to be associated with them once you're aware, and ignorance isn't a valid defense.

They are not enabling this money transfer. They have nothing to do with it at all.
Post reply on HN