TBH this is not unlike reporting a security bug to a company as a white hat, but more like a grey hat here.
If the few blokes using this scam their way into few hundred terabytes of free storage, so be it, it's not worth the hassle for Google, imo.
edit: Apparently an account can create up to 250 docs a day https://developers.google.com/apps-script/guides/services/qu...
This. They probably thought of this exact scenario before adding unlimited docs. They probably even expected somebody to make a script for it. Hell, a few of them might even have a script.
As long as a lot of people don't start abusing it or make a file-sharing service based on it, then they probably won't care. Basically, not until it's a significant enough threat to their bottom line.
Ultimately, it's no different than the inevitable person that just has a script to generate garbage and upload it to Google Docs as fast as possible. That's what the 250 docs a day limit is there for.
The README.md says that UDS can store ~710kb per doc.
:shrug:
I found myself in a similar situation a couple months ago. An android App falsely charged me on the Play store. After trying to contact Google for multiple weeks I gave up and disputed the charge on my credit card. This resulted in Google coming after me for 8.99$ and threatening me to close all my Google accounts including gmail, calendar, photos, drive and everything I rely daily in Google.
That was a wake-up call for me. I decided to move everything OUT of Google. That company got too much power, it should worry way more people.
However, I was scared for my Google account so just ended up dropping it. Ridiculous.
I'm curious to know how this happened. Would you mind sharing more info?
As I understand it, the only way for an app to 'charge you on the play store' is to:
1) Be a paid app (in which case you pay before the app starts installing), or
2) via in-app purchases, which are handled by the app initiating the IAP, and then Play services taking over to ask for confirmation.
In either case, the transaction is only confirmed by a user action (tapping a button) with the app having no control.
Sure, it's possible for an Android app to trick you, by covering everything apart from the button with something fake, but I'd be surprised if such an app found its way into the Play Store.
After using the app for a couple of days and restarting the phone, the app seemed to hit a bug and behave like if I didn't buy the subscription, prompting me to buy another subscription which I did thinking that this would unblock the backend and somehow merge with the fact that I already had a subscription.
Unfortunately, Google Play charged me again for a subscription I already had. Both the app creator AND Google Play were difficult to join. The App creators never replied to any of my emails. Google Play got an automated support website that decided that "I was not eligible for a refund" and there was nothing I could do about it. It also seems to be impossible to contact a real human being to explain the situation.
Have you been successful in it? Any guidelines / tips? How hard is it?
It really is a suite that can combat Google's suite — and you can truly own it. Other than that, DDG for search, and your own domain for email (so that you could transfer it between different hostings if necessary).
I do have a Google account, but I use it for precisely two purposes: Google Play (my phone wouldn't work without one) and YouTube subscriptions (I can use an RSS reader for this, but it's a bit inconvenient). You can create a Google account without creating a Gmail account.
[0] I use fastmail + custom domain, which works great, but you have to guard the domain very closely.
What do you mean by guarding the domain? To prevent large volumes of spam?
I'm intrigued by this, would you kindly share more on this!?!
Access to my email account probably gives you more access to my life and identity than my SSN [0].
I long for the day that we [1] all get assigned a public/private keypair instead of SSNs. That won't fix everything, but it's a huge step above a shared secret that is limited to 9 digits [2].
[0]: Even without signing up for a bunch of services, it's basically impossible at this point (at least in the US) to not have an email address associated with your bank account, car loan, mortgage, credit card, or even just watching TV.
[1]: "We" meaning "US citizens" or anyone else with a similar system.
[2]: I realize you also need info about the person and not just their number, but also apply that to keypairs.
What is the remedy for when someone loses or leaks their keypair?
Most of our ID cards (health, driving license) already have an expiration date and the subkeys should have one anyway.
The only thing I haven't managed to find a even close to decent alternative it's photos. Google Photos is just simply too good. I would be even willing to pay but really, all the other apps struggle to get sync right or have some other crappy stuff that makes them barely usable.
- Bought a new domain name and moved my mails in fastmail. I have been super happy with it so far.
- My Gmail address is now only for spam or very low importance emails.
- All my Pixel pictures are still uploaded to Google Photos, but I backup everything once a month or so.
- I don't use Google Drive for anything anymore. I have an Evernote account and a Dropbox account.
- Completely switchecd to DDG and Firefox.
- I'm still using my Pixel2 as of now but my next upgrade will be an IPhone, or a rooted Google-Independent Android phone.
- Use Yandex Maps instead of Google Maps. It's very accurate and navigation is smooth. Way better than Gmaps imo.
- Use Office 365 instead of Google Docs.
- You can use One Drive for cloud storage or buy a cheap VPS.
You might not want to be tied to Microsoft but Google is not the only option.
Edit: Overlooked the comment about Apps. Microsoft offers apps for mobile, but not Linux. Although even on Windows I use the browser to access the services which will work on Linux.
What's needed is a syndication of data, and inter-operable apps. Like how xmpp worked. But of course, all vendors don't like this, because it turns themselves into a commodity.
This may happen only if you manage to get it to the front page of HN or have many Twitter followers. In most cases you don't stand much chances though.