Live data from Hacker News

Let's guess what Google requires in 14 days or they kill our extension

blog.pushbullet.com

541–550 of 811 posts

Re: Let's guess what Google requires in 14 days or they kill our extension

#541
post #494

Earlier quoted context omitted.

That's the thing I'm sympathetic to - having fixed the bug , it's frustrating that it's not clear what the next steps are. But given that they had the bug, Chrome was absolutely in the right to deny them the first time. And while I don't like Chrome's position that they're too busy to explain to everyone what they're doing wrong, if extensions that go "oh hey, we don't actually need access to literally every website,…

> That's the thing I'm sympathetic to - having fixed the bug, it's frustrating that it's not clear what the next steps are. That may not have been the bug, your guess is as good as literally anyone's right now. That's the issue at hand.

By "the bug" I mean the fact that they're asking for permissions on any site when they don't need them - which is a bug (and a serious one) whether or not Chrome notices.

Re: Let's guess what Google requires in 14 days or they kill our extension

#542

Earlier quoted context omitted.

At the very, very least, they could identify which of the permissions are in violation and need to be made more restrictive, and which aren't. Someone at some point at Google clearly had that information when they decided to flag the extension, but Google's processes failed to ensure they communicated it. For the record, I actually agree with you that this is a good policy and will be a positive outcome for users. Bu…

Most of the discussion on this link is about how Google is being developer hostile. I think that's getting plenty of attention. > At the very, very least, they could identify which of the permissions are in violation If they've flagged this through user reports of the permissions being too wide then they may not actually know which permissions need to be changed. This is purely speculation though.

Most of the discussion on this link is about how Google is being developer hostile. I think that's getting plenty of attention.

You are certainly within your rights to state things divisively if it pleases you. I was merely suggesting how you might make your point in a way people will agree with you.

If they've flagged this through user reports of the permissions being too wide then they may not actually know which permissions need to be changed.

Even if this were true,

1) what about the update that narrowed the permissions, surely Google knew which permissions remained in violation? Remember, it was the rejection of that update that prompted this post

2) user reports of permissions being too wide should also be required to identify the specific permission that is in violation. That would not only help the developer, but also help Google make the decision on whether to ultimately ban the extension

3) Google should have clearly stated in the initial message that they hadn't actually verified that the alleged violations are occurring

Re: Let's guess what Google requires in 14 days or they kill our extension

#543
I think folks are drastically missing the forest for the trees here. This is just one minor example of the INSANE process that is now the Chrome Approval Process. I've seen extensions go for many months getting random rejections with no reason given.

This forces developers to GUESS as to what is wrong. Want to try and develop according to a roadmap or timeline- forget about it. There is no "app store" approval process that conducts itself in this way.

Fact is Chrome is 80% of the market so Google doesn't worry about competition. If Google Chrome is broken- then the internet is broken. It harms new entrants trying to develop and innovation.

After the 2nd or 3rd rejection- have a HUMAN intervene. Explain what is wrong. Devs are more than happy to make the changes. But you can't do this "make you guess" bullshit.

DOJ and EU need to get involved. Someone at Google with their wits about them and revamp the whole process. It's a travesty against the developer community and should be fixed ASAP. Also from what I hear they need to start with new LEADERSHIP.

Re: Let's guess what Google requires in 14 days or they kill our extension

#544
post #497

Earlier quoted context omitted.

The tool could tell them what the problem is. There are fine grained permissions, and Google could say which of those fine grained permissions are used badly. OR, they could just restrict those permissions themselves in the browser.

If it did, it'd be easy for malware authors to work around the scanner. The system we've got right now isn't great , but I've yet to see any better ideas.

Couldn't malware authors start from the other direction? Create a no-op extension with no permissions and gradually add things until it's no longer approved.

Re: Let's guess what Google requires in 14 days or they kill our extension

#546
They don't give shit about your 4.5 star rating. Your 4.5 star rating doesn't mean you are the most private or most secure over there. Facebook got 4+ rating on all there apps with 1B+ users, that doesn't mean they need access to those call logs,messages and everything on your phone. Keep you permission to the minimum, for both security and privacy. Chrome team doesn't give shit about people like you.

Re: Let's guess what Google requires in 14 days or they kill our extension

#547

Earlier quoted context omitted.

You can probably get around this by setting up some DNS like localhost.pushbullet.com -> 127.0.0.1. It's probably not in the spirit of what they're asking for though, if it is indeed the problem.

If you have a half-decent router or firewall, this won’t work from outside the network.

My router (AVM FRITZ!Box) blocks DNS results for anything in the LAN range, as part of protection against rebind attacks.

But actually 127.0.0.1 seems unaffected:

    $ host 127.0.0.1.xip.io
    127.0.0.1.xip.io has address 127.0.0.1
    $ host 192.168.1.1.xip.io
    # no result

Re: Let's guess what Google requires in 14 days or they kill our extension

#548

I think folks are drastically missing the forest for the trees here. This is just one minor example of the INSANE process that is now the Chrome Approval Process. I've seen extensions go for many months getting random rejections with no reason given. This forces developers to GUESS as to what is wrong. Want to try and develop according to a roadmap or timeline- forget about it. There is no "app store" approval proces…

After 2nd to 3rd rejection if it will require a human to intervene Google will have to hire half the earthlings to deal with crappy spammers that will simply spam google store with their extensions.

The answer is not human interaction, the answer is automation tool to give more details as what was detected and didn't pass.

Re: Let's guess what Google requires in 14 days or they kill our extension

#549
post #497

Earlier quoted context omitted.

The tool could tell them what the problem is. There are fine grained permissions, and Google could say which of those fine grained permissions are used badly. OR, they could just restrict those permissions themselves in the browser.

If it did, it'd be easy for malware authors to work around the scanner. The system we've got right now isn't great , but I've yet to see any better ideas.

I don't understand what you're talking about. If the scanner looks for extension with permissions for all your web browsing activity, so malware authors stop asking for permissions for all your browsing activity...isn't that great news?

Re: Let's guess what Google requires in 14 days or they kill our extension

#550
Google has 70% market share. If Chrome is broken- innovation nd the internet is broken.

If we really want to fix this. 1. Use Survey Monkey to collect info from other developers having issues (which is like all of them). 2. Isolate instances of severe delays, inability to innovate, harm to business, negligence etc. 3. Send to DOJ and EU Antitrust

Post reply on HN