Tales from the spam filter of an Android app developer
raccoon.onyxbits.de
raccoon.onyxbits.de
The gist is that spammers message the publishers of Play apps looking for willing developers to (a) integrate random tracking/advertising/analytics "SDKs", (b) integrate dubious/malicious software like cryptocurrency miners, P2P relays, or (c) sell their app outright.
The idea is that, at any given time, you don't know whether an app you've downloaded from the Play store has done any of these things, and the spammers probably know they can keep such "infected" apps on the Play store for long enough to turn a profit.
Do you rather have an app on your phone with access to your files that most probably runs dubious software alongside? Or, do you rather not miss out on the elegance and convenience it provides? I guess the answer depends largely on the content of your files and your personal preferences.
Also, Google hasn't flagged the app, which I believe they would if it was malicious as opposed to made by a company that had issues in other apps. So unless there's specific malicious behavior tracked, which I don't see, I'm not going to get rid of it.
"The Lumen Privacy Monitor" developed by the ICSI Haystack Project collects statistics of outgoing tracking traffic and their app origin on your device.
They have good intentions, e.g. with a system level image picker, but it's UX is one of the worst among the system level components.
Do you want your folders to be organized/displayed different?
Or you want this integrated without having to download an app?
To come back to the photos example, by default Android has a Document picker. Its .. bad. Unless you are picking a picture you have just taken, you won't be able to find what you are looking for.
At the very least, either allowing apps to respond to the search intent in order to allow them to handle the search however they want or at least delegating this task to one app (like Google Photo) that already has a good search feature.
More generally, I am not a big fan of exposing the file system to end users. It is relatively convenient for power users, but for all the other users it is a complete mystery.
For pretty long, Android has toyed with the idea of doing something else. Hiding away the file system as an implementation detail users don't need to know and offering a document based interface instead.
Whether this could work or not has remained unanswered though .. their implementation is so half assed that it is barely worth mentioning.
Amaze supports the features you've listed (tabs and SMB shares), as well as root access, and has a clean user interface:
After a bit of digging, it looks like Amaze is limited to 2 tabs, which you switch between by swiping left and right. I guess that's technically "multiple tabs" as their Play Store listing states.
There's also Ghost Commander if you're looking for an open source file manager with more capabilities. It uses a 2-panel layout, supports plugins, and has a long list of features:
https://f-droid.org/packages/com.ghostsq.commander
https://play.google.com/store/apps/details?id=com.ghostsq.co...
If you need a file manager that supports 3+ tabs at once, I don't think there's an open source solution right now.
1. Google Play Store's requirement that app devs publicly post a contact email address
2. Google's failure to invest more into eliminating bad apps from the App Store (somehow)
3. Google's scorched earth policy with regards to sucking all of the money out of the ecosystem for itself and a very small number of app dev winners -- leaving most of the app devs in the poverty zone
Google could partially address #1 by creating a mail relay which filters out the bad library actors. App devs could use an address into the relay instead of publicly posting their own address and being left to fend for themselves. Of course, that would mean even more of a developer's customer communication would be routed through Google. So that's not exactly optimal either.
Both stores use automatic detection for malware, the manual testing used by _both_ store is mostly there for business reasons in my experience.
Google used to be laxer about what you could do with its APIs, but it has started to become way stricter one or two years ago.
It always cause some drama in the dev community when they stop apps from misusing an API (even if the misuse was not shady) but it is mostly for the best.
By contrast, the App Store only requires a support URL to be included in the listing, not an email address.
With this culture of "free", it's no wonder if app developers cave and sell out to shady companies.
Unfortunately the grass is not really greener on the other side. Apple's app store is also focusing on the free with ads model.
As far as tracking goes, my experience as an app dev is that we have been adding the same sdks on both platforms at the same time with roughly the same possibilities and limitations.
I have only worked on high profile apps, so these SDKs were not on the shady side, but I have seen the spam as well.
I should note that even though the sdks are not shady, we are still tracking a LOT of data. I have a pretty neutral opinion on this though .. our only use for this is to look at how new features influence our metrics. Which can be positive for everybody. It is good to know that feature x has improved customer satisfaction by 5% so it is worth continuing to invest in it.
I wish there was more regulation on what we can collect, how we can use or not use that data, etc.
Having a standard for TOS where you can use customer data internally to improve your service but are forbidden to sell it might be beneficiary. Right now we have tons of pages of lawyerspeak for each and every app or service.
Even reading only those of the main services you use is a very time consuming task. Especiaylly when they change every five minutes for some companies.
Personally I have not received any of the offers mentioned in the article. Rather, I get spammed semi-regularly by 1. marketing firms/individuals promising to SEO and ASO my app to top places, 2. design/coding shops located in remote locations to help me with development
If any of the companies actually read the description of my app they would know that their services make no sense for me but hey, I guess they need to find the clients somewhere.
Like Facebook, Twitter, etc. Google built the Play store (and Android at large, really) as a barn with all the doors open, and have been slowly closing them when users get too angry about a given (ridiculous for a multi-billion dollar corporation) problem.
Apple, on the other hand, built a walled garden and added doors to it as needed, and occasionally has taken some away too. You can use the cynical read and say this is to further their position in the market as the "pro privacy" alternative to Google, or you can say it's part of their core company ethos, but the result is the same either way: buying an app off the App Store carries little/no risk, and Apple strongly favors users during any issues that may arise. Play store on the other hand can be 100% safe or extremely risky, with little/no way to tell beforehand, and Google's end user support is notoriously terrible.