Live data from Hacker News

Let's guess what Google requires in 14 days or they kill our extension

blog.pushbullet.com

781–790 of 811 posts

Re: Let's guess what Google requires in 14 days or they kill our extension

#781
post #474

For people focusing their comments on this particular extension + the permissions it asks for, please take a quick look at the numerous recent posts in the official forum for Chrome extension developers to see it's not an isolated issue: https://groups.google.com/a/chromium.org/forum/#!forum/chrom... It's a systematic issue that isn't specific to anything Pushbullet is doing and it's been like this before the pandemi…

The rule still applies: if you build your business on someone else's property, don't act surprised when they they casually destroy you. It has happened again and again and again. Building for FB or Google is you making yourself their serf, and you will be allowed to exist at their whim.

This is not a useful comment. You are suggesting a world where no platform is extensible, which isn't realistic nor desirable.

When you are building for an extensible platform it's entirely reasonable to be surprised when the vendor sabotages you. Platforms like this are good because they help both parties, so there is an expectation that one side won't sabotage the other in general. When it happens it's surprising, and usually not a great outcome for the platform provider.

Re: Let's guess what Google requires in 14 days or they kill our extension

#782
post #518

Earlier quoted context omitted.

I can only assume that this isn't the result of a human flagging Pushbullet like this; I expect it's an automated system. And if that automated system can make a decision to flag the extension, it could also include in the email specifically what caused that flagging to happen. At this point I'm really starting to become unsympathetic to the idea that they can't tell you what you're doing wrong because it'll enable p…

> I can only assume that this isn't the result of a human flagging Pushbullet like this; I expect it's an automated system There isn't. Take a quick look at stupid popular apps on the Play Store, almost all of them require completely unnecessary permissions literally in conflict with the bullet points that Google listed in their email to PushBullet. Also note that almost all of them have 10-50x the amount of download…

That's a bit extreme. Google sends out emails every few months about new policy that may get checks. They definitely aren't very good at doing automatic checks that are relevant or have much relationship with the policies they publish.. But that is a bit different than strategically attacking specific apps beyond choosing the X thousand most popular apps to get the most users affected per presumed threat.

(I get various compliance spam and ignore it and among things with small numbers of users and/or owners who lost interest a small percentage a year fall out of the stores. The only differences are that we don't care enough to forward the threats Google sends us and no one would bother to amplify them.)

Re: Let's guess what Google requires in 14 days or they kill our extension

#783

This is scarily reminiscent of Facebook's App Review process. We submitted 8 identical Apps that, functionally, are just webhooks for Messenger events. All required documentation, justification for the two permissions we needed, screen casts, and test login credentials were submitted for the reviewers. 3 were approved. 5 were rejected - all for different reasons. Re-submitted the 5 with no changes; 2 more got approve…

did you write this up somewhere?

I haven't written a blog about it, but it's a common experience for those building B2B integrations with Facebook. Also common is feature deprecation with replacement functionality gated (read: withheld) behind a closed beta program. They're difficult to join and often can only be entered if you commit to supporting other Facebook APIs and features (those they wish to publicize).

Re: Let's guess what Google requires in 14 days or they kill our extension

#784
post #486
post #474

Earlier quoted context omitted.

The rule still applies: if you build your business on someone else's property, don't act surprised when they they casually destroy you. It has happened again and again and again. Building for FB or Google is you making yourself their serf, and you will be allowed to exist at their whim.

This isn't very actionable advice, though, since there is basically no such thing as a software product that isn't built on somebody else's property. You might think, "Ah-ha, web apps!" But no, Google can still casually destroy you there. Or you might think, "Ah-ha, desktop apps!" But the OS vendor can casually destroy you there.

Technically, yes, you are right. But let's burn that bridge when we get to it.

At the moment the issue is the app store concept; it is designed to be a choke point, it is designed to be obscure, and it is designed to casually destroy software the store owner doesn't approve of.

(What is the status of Microsoft's app store, by the way?)

Re: Let's guess what Google requires in 14 days or they kill our extension

#785
post #730
post #474

Earlier quoted context omitted.

The rule still applies: if you build your business on someone else's property, don't act surprised when they they casually destroy you. It has happened again and again and again. Building for FB or Google is you making yourself their serf, and you will be allowed to exist at their whim.

Except chrome isn't really a "property app" so much as a "proprietary OS"; it's the platform in which ~70% of desktop users spend >10 hours a day. This is different from eg Facebook, in that FB's valueprop is being "full stack" (content + controls + ads); while Chrome's design is open-ended -running other people's websites, with other people's extensions. The other side of the issue is tough, though: Chrome extension…

Google's 2014 net income was $14B. Chrome is one of the most valuable properties that Google owns, as it allows them to control a large fraction of advertising on the desktop, and advertising is their core business. They can afford to hire thousands more developers to vet Chrome extensions, yet they don't - implying that at least the upper levels of the Google command hierarchy don't consider this to be a problem or don't care about fixing it.

Re: Let's guess what Google requires in 14 days or they kill our extension

#786

Google are cutting the branch they are sitting on. I only use Chrome because certain extensions are not available on Firefox. During all these years, they've become impossible to deal with. I open Chrome with 10 tabs and after a couple of hours it's using gigabytes of RAM. From a thin client, it became the thickest client in the visible universe. It's time to consider options... not that there are many.

I just started using Brave and most extensions are available. Pretty good from privacy point of view as well. Check it out.

Still the same memory hog under the hood. I mean, how can a browser use 10+ GB of memory unless they are a doing a million things wrong?

Re: Let's guess what Google requires in 14 days or they kill our extension

#787

Earlier quoted context omitted.

You can probably get around this by setting up some DNS like localhost.pushbullet.com -> 127.0.0.1. It's probably not in the spirit of what they're asking for though, if it is indeed the problem.

If you have a half-decent router or firewall, this won’t work from outside the network.

Have you seen this fail? Drop box and spotify use this same trick, i assume it had wide support.

Re: Let's guess what Google requires in 14 days or they kill our extension

#788
post #494

Earlier quoted context omitted.

But you're completely ignoring the point that even without the all http(s) permission they will still be kicked off the store, so that has nothing do do with the issue at hand. If localhost is the issue, Google could literally respond exactly the way you did and the problem is gone, "why do you need http://localhost/?" This isn't about permissions at all. This is about communication and whether it's worth putting eff…

That's the thing I'm sympathetic to - having fixed the bug , it's frustrating that it's not clear what the next steps are. But given that they had the bug, Chrome was absolutely in the right to deny them the first time. And while I don't like Chrome's position that they're too busy to explain to everyone what they're doing wrong, if extensions that go "oh hey, we don't actually need access to literally every website,…

> But given that they had the bug, Chrome was absolutely in the right to deny them the first time.

Except they didn't and the extension was sitting at the store for a long time now.

> And while I don't like Chrome's position that they're too busy to explain to everyone what they're doing wrong

Maybe not, but after a couple of instances of back and forth they should take 1 minute to write a couple of sentences. There are limits to automation.

Re: Let's guess what Google requires in 14 days or they kill our extension

#789
post #614

Earlier quoted context omitted.

I agree. This is hackernews, so it is easy why devs would feel otherwise, but as a nondev, I represent the the end users. Why would anyone think it is appropriate for google to reveal their hand, and allow blackhat operators to build apps up to the max limit of permissions? (If they were revealed by google via white glove customer service). If goog did provide guidance on permissions, goog would literally have to aud…

> If goog did provide guidance on permissions, goog would literally have to audit every app in the store You’re talking about vetting suppliers and products in order to ensure they’re selling safe products that consumers want. That sounds like an ordinary part of every retailer’s job to me.

Huh? How many products are sold at macys which allow its consumer to go perfectly bankrupt due to purchasing? How many products ask for permission to ask for visibility into your bank account info? Your personal travel history? and disclose insight on how they are using this info in a way you can understand.

When devs start signing their apps with their full name and information where they live, lets talk.

Re: Let's guess what Google requires in 14 days or they kill our extension

#790
post #614

Earlier quoted context omitted.

I agree. This is hackernews, so it is easy why devs would feel otherwise, but as a nondev, I represent the the end users. Why would anyone think it is appropriate for google to reveal their hand, and allow blackhat operators to build apps up to the max limit of permissions? (If they were revealed by google via white glove customer service). If goog did provide guidance on permissions, goog would literally have to aud…

> If goog did provide guidance on permissions, goog would literally have to audit every app in the store You’re talking about vetting suppliers and products in order to ensure they’re selling safe products that consumers want. That sounds like an ordinary part of every retailer’s job to me.

Please read about convexity or asymetry before saying something like this.
Post reply on HN