Live data from Hacker News

Google have declared Droidscript is malware

groups.google.com

491–500 of 665 posts

Re: Google have declared Droidscript is malware

#491
post #488

Earlier quoted context omitted.

"We've noticed that you're violating our policies." "Which policies?" "That's none of your business." "How are we violating them?" "I'm not going to tell you." "What can we do?" "Fix the issues, and then appeal." "Which issues?" "I've said too much already."

I used to work detecting ad fraud. Publishers would do bad things, call in, and try to get their account rep to get details. Obviously I can't say "of the last 2500 ad clicks zero of them had any mouse movement over the ad before the click event" because then the publisher obviously just fixes their fraud software. This isn't specific to Google or even advertising. Every company has figured out when dealing with abus…

What about false positives? How did you account for that?

Re: Google have declared Droidscript is malware

#492
post #488

Earlier quoted context omitted.

"We've noticed that you're violating our policies." "Which policies?" "That's none of your business." "How are we violating them?" "I'm not going to tell you." "What can we do?" "Fix the issues, and then appeal." "Which issues?" "I've said too much already."

I used to work detecting ad fraud. Publishers would do bad things, call in, and try to get their account rep to get details. Obviously I can't say "of the last 2500 ad clicks zero of them had any mouse movement over the ad before the click event" because then the publisher obviously just fixes their fraud software. This isn't specific to Google or even advertising. Every company has figured out when dealing with abus…

In a case like that, sure. But they don't provide any information even when they want the publisher to make a change. Our Adsense account once got suspended because ads were appearing on pages that contained user-entered search keywords. Occasionally users would enter keywords that google considered 'naughty', and didn't want their ads appearing alongside. If they'd just told us that, we could have added a filter to not show ads with the list of keywords they had a problem with. Instead it was an infuriating, weeks-long process of pulling teeth to get clues as to what the problem might even be, and then making a list of every conceivably bad word we could find or imagine (admittedly that part was a bit fun) before we were finally able to get re-approved. And presumably we only got that much leeway because we were a reasonably large account.

Re: Google have declared Droidscript is malware

#493

As still so many people don't get it: 1) Don't make your business dependent on Google 2) Don't make any of your data dependent on Google (don't use Gmail, Workspace etc) 3) Don't make applications you build dependent on Google Hint: If you can't migrate away from Google within a working day, you're doing it wrong.

And 'Google' here is shorthand for any entity from which you have no reasonable expectation of customer support which is both human and humane — so don't make your business dependent on Google, Facebook, PayPal, or any similar entity.

Re: Google have declared Droidscript is malware

#494
post #488

Earlier quoted context omitted.

I used to work detecting ad fraud. Publishers would do bad things, call in, and try to get their account rep to get details. Obviously I can't say "of the last 2500 ad clicks zero of them had any mouse movement over the ad before the click event" because then the publisher obviously just fixes their fraud software. This isn't specific to Google or even advertising. Every company has figured out when dealing with abus…

What about false positives? How did you account for that?

You make your peace with the fact that you'll have a certain rate of false positives, where you'll intentionally lose also some legitimate business in order to keep most of the "ecosystem" cleaner. Perhaps an unsatifying answer, but that's it.

It's not a situation like putting someone in prison where "beyond all reasonable doubt" is the appropriate mark; you can refuse to do business based on mere suspicion that may be mistaken. There's a limit where extra investigation or appeals is too costly compared to just accepting the lost revenue, and for small-scale customers, that limit is quite low. With fraud detection, you have to balance the tradeoff between false positives and false negatives, but you'll certainly have both.

Re: Google have declared Droidscript is malware

#495
post #321

Earlier quoted context omitted.

> So... having read through their marketing material, this is an on-device tool that opens up what appears to be most of the Android application API to at least the user of the device, and potentially to any Droidscript applications they grab from other sources, and... maybe to other apps on the device? It's not clear from a quick read how extensive the runtime control is. When did we collectively decide that program…

Some of us realised that end users don't want to program and that they can be better protected from themselves by only allowing execution of arbitrary code when they explicitly say they want it.

Presumably those end users aren't downloading Droidscript.

Re: Google have declared Droidscript is malware

#496
post #488

Earlier quoted context omitted.

"We've noticed that you're violating our policies." "Which policies?" "That's none of your business." "How are we violating them?" "I'm not going to tell you." "What can we do?" "Fix the issues, and then appeal." "Which issues?" "I've said too much already."

I used to work detecting ad fraud. Publishers would do bad things, call in, and try to get their account rep to get details. Obviously I can't say "of the last 2500 ad clicks zero of them had any mouse movement over the ad before the click event" because then the publisher obviously just fixes their fraud software. This isn't specific to Google or even advertising. Every company has figured out when dealing with abus…

I would believe this if Google wasn't notorious for providing the worst customer service that will avoid someone going to prison. Cable monopolies have a better reputation.

Re: Google have declared Droidscript is malware

#497
post #488

Earlier quoted context omitted.

"We've noticed that you're violating our policies." "Which policies?" "That's none of your business." "How are we violating them?" "I'm not going to tell you." "What can we do?" "Fix the issues, and then appeal." "Which issues?" "I've said too much already."

I used to work detecting ad fraud. Publishers would do bad things, call in, and try to get their account rep to get details. Obviously I can't say "of the last 2500 ad clicks zero of them had any mouse movement over the ad before the click event" because then the publisher obviously just fixes their fraud software. This isn't specific to Google or even advertising. Every company has figured out when dealing with abus…

A valid explanation, but not one I believe applies here.

This ban is not only not explaining how it detected unwanted activity, it is not explaining what activity it detected.

"We detected you faking ad impressions, though we won't tell you how we (believe we) know" is very different to "We detected you (or your app) doing something wrong, stop doing it and you will be fine. We won't tell you what you did wrong".

Re: Google have declared Droidscript is malware

#498
This really shows the issues with the private business model in conjunction with critical infrastructure as an oligopoly (as this poses crucial questions with regard to ownership of any reliant products). I know no way out of this short of turning tables.

E.g., have a thorough public review process as a last resort (most nations are investing in cyber security anyway and this may provide a valuable proving ground) and force app-store providers to comply. Providers may oppose the verdict, but will have to provide detailed proof and concise reasoning in an appeal process.

Re: Google have declared Droidscript is malware

#499
post #488

Earlier quoted context omitted.

I used to work detecting ad fraud. Publishers would do bad things, call in, and try to get their account rep to get details. Obviously I can't say "of the last 2500 ad clicks zero of them had any mouse movement over the ad before the click event" because then the publisher obviously just fixes their fraud software. This isn't specific to Google or even advertising. Every company has figured out when dealing with abus…

In a case like that, sure. But they don't provide any information even when they want the publisher to make a change. Our Adsense account once got suspended because ads were appearing on pages that contained user-entered search keywords. Occasionally users would enter keywords that google considered 'naughty', and didn't want their ads appearing alongside. If they'd just told us that, we could have added a filter to…

Now your app has a bunch of offensive language compiled into it. Surely that's grounds for nuking your account.

Re: Google have declared Droidscript is malware

#500

> ...after taking into consideration the information that you have provided, we have confirmed that we are unable to reinstate your publisher account. I hate when using euphemism slides into flat out lying like this. They are not "unable" to reinstate the account, in fact they are the only party able to reinstate the account, that's why the account holder was contacting them instead of someone else. They are "unwilli…

new-speak
Post reply on HN