Live data from Hacker News

Let's guess what Google requires in 14 days or they kill our extension

blog.pushbullet.com

701–710 of 811 posts

Re: Let's guess what Google requires in 14 days or they kill our extension

#702

This is just completely disingenuous from Google. > - Request access to the narrowest permissions necessary to implement your product’s features or services. > - If more than one permission could be used to implement a feature, you must request those with the least access to data or functionality. > - Don't attempt to "future proof" your product by requesting a permission that might benefit services or features that…

It's classic google. Now that they are a monopoly, they don't have to compete for developer's attention. That's why I will never give a cent to Google Cloud, I know too well how it's going to end up if they ever become a major force in the cloud, I'm not going to invest anything with them and strongly suggest any business I work in to minimize their exposure to Google product. They all end up the same way.

Re: Let's guess what Google requires in 14 days or they kill our extension

#703
post #596
post #518

Earlier quoted context omitted.

I can only assume that this isn't the result of a human flagging Pushbullet like this; I expect it's an automated system. And if that automated system can make a decision to flag the extension, it could also include in the email specifically what caused that flagging to happen. At this point I'm really starting to become unsympathetic to the idea that they can't tell you what you're doing wrong because it'll enable p…

> And if that automated system can make a decision to flag the extension, it could also include in the email specifically what caused that flagging to happen Unless it's a black box machine learning model that just says yes/no but can't tell you why

This isn't something vague or hard like OCR, voice-recognition or image classification.

It's a finite list of app permissions.

Unless it's a random number generator that just says yes/no but can't tell you why -- is just as valid of a non-excuse for using the entirely wrong solution to a problem, and surprise the solution doesn't work very well.

Re: Let's guess what Google requires in 14 days or they kill our extension

#704

Earlier quoted context omitted.

I mean they can. It's their store. I don't think they should, but still

I'm pretty sure the parent comment understands that they can, and also agrees that they shouldn't.

I’m not at all certain about the latter. They’re pretty consistent in ignoring users and providing shitty service.

Re: Let's guess what Google requires in 14 days or they kill our extension

#705
post #403

Uh, yikes: > As I looked at the permissions and what our extension actually needs to operate, I noticed a great opportunity to reduce our permissions requests. We do not need to request access to data on https://*/* and http://*/* . Instead, we can simply request data access for https://*.pushbullet.com/* , http://*.pushbullet.com/* , and http://localhost/* . This is a huge reduction in the private data our extension…

Why do they need http access on push bullet?

Re: Let's guess what Google requires in 14 days or they kill our extension

#706

Earlier quoted context omitted.

Not really, because malicious actors don't care about their reputations, accounts, etc. A reputable developer has a reputation to maintain (by definition), which makes Google's threat to permaban them a threat indeed. A disreputable developer doesn't care about their reputation (again, by definition). They can create a new throwaway account every day and apply using the same (or slightly, easily, altered) code with d…

The point is making it more expensive for malicious actors. You can't make it impossible to get malicious extensions in, but you can make it harder. It's the same as captchas. You can also defeat captchas, but adding them reduces abuse a lot. As with captchas you're making it harder for good actors too. The difficult part is finding a good balance. Reputation can be bought too btw.

> The point is making it more expensive for malicious actors.

Malicious actors don't care about expenses nearly as much as benign ones do. So the point ought to be, if you want me to fix something, tell me what's broken.

Re: Let's guess what Google requires in 14 days or they kill our extension

#707
post #679
post #170

Earlier quoted context omitted.

No, they make every effort to ensure that installing extensions outside the store is annoying so that you can't push your malware by just having users download and install it. This kind of malware plagued Firefox for years until they made extension signing mandatory

If I am in a position to install random shit into Firefox I am also in a position to just modify Firefox , so that doesn't accomplish anything at all except remove functionality from users.

Except most targets won't modify their Firefox.

Re: Let's guess what Google requires in 14 days or they kill our extension

#708
post #403

Uh, yikes: > As I looked at the permissions and what our extension actually needs to operate, I noticed a great opportunity to reduce our permissions requests. We do not need to request access to data on https://*/* and http://*/* . Instead, we can simply request data access for https://*.pushbullet.com/* , http://*.pushbullet.com/* , and http://localhost/* . This is a huge reduction in the private data our extension…

Yeah. I'v refused to install extension in the past because Chrome tells me this extension wants to read all data on all web pages... No thanks. (Except those extensions I KNOW must have those permissions)

Very good thing app store may nudge people changing permission scope.

Hope extension authors manage to meet the deadline and get their extension re-approved.

Re: Let's guess what Google requires in 14 days or they kill our extension

#709

Earlier quoted context omitted.

> Stop using their browser, stop using their search. The more people that do this in general, the better. We've given Google entirely too much power to control what people see and read (and it follows, control over what they say and think). They don't have our best interests at heart, they have financial interests at heart, and everything else flows from there. I'm not saying this is evil, but it's certainly not _goo…

What should I use for search? I tried switching to DDG for a month but I kept finding myself manually typing in Google.com to make the more obscure searches.

That is my exact habit now - DDG for the easy/lazy stuff, google for more obscure. I'm still giving them some search info to profile me, but hopefully it's skewed enough that it's value is lower. And I'm definitely giving them less ad views.

I actually prefer DDG in a few fronts, like configuration of language and region.

Re: Let's guess what Google requires in 14 days or they kill our extension

#710
post #693

Earlier quoted context omitted.

I’ve emailed and sent Linkedin msgs to 3 people who work at gcp for cloud credits. They didn’t care. AWS gave us credits + support in less than 3 days. I wish Google best of luck with their 5yr strategy. Hope their enterprise game is better than their startup one.

... so you're upset that you didn't get a service for free?

If you're serious about spending a lot on the cloud it's reasonable to expect a taste. Just like an ice cream store.
Post reply on HN