Google’s Monopoly is Stifling Free Software?
medium.com
medium.com
Google still hasn't figured out that the web is their content providers and they need to support them, and treating their producers with contempt and neglect is a glorious example of how stupid and shortsighted the entire company is right now about their long term strategy (how many ads will you sell when the web is a mobile Facebook app?). They should as soon as possible, as a bare minimum, start providing representatives and support for the content providers that make people actually use the web and help them to be successful, similar to how Twitch has a partnership program.
The other, even more serious issue, is that with Google there is no way to get the feedback and learn what exactly they consider wrong?
Let’s also talk about their “unwanted software policy” that leads to this kind of warnings. The policy mostly sounds okayish, but there are some points that bother me. For instance, there is a point explicitly prohibiting working with Google APIs in a nonstandard manner. What does that even mean? Is ad blocking software blocking google’s ad server can be categorized as unwanted now? Or any AV that scans Chrome downloads?
These sorts of problems are the reason I stopped doing Android and OS X apps, being that beholden to companies who have shown time and again to do not just wrongfully takedown apps but also act anticompetitively in their marketplaces, it is just asking for trouble. Stick to games and website apps and avoid genuinely innovative takes on anything that Google (and Apple) has any remote interest in or your business might just disappear overnight and you won't have the funds to stop them.
This sort of protection is just messed up but I can't see the USA taking action against this giant of a company any time soon. You still see people complaining about EU fines for anti-competitive behaviour regularly here on HN and yet they are a drop in the bucket. The web isn't free anymore and those that want their data to be their own went underground into the self-hosting community.
Fun fact:
According to German law a company is required to provide (real) support under its support contact address.
Google ignored this law for years.
A few years ago they got sued over this. Now there is a legally binding court ruling demanding from Google that they comply with the law in force.[1]
Fast-froward 5 years, and guess what. Google continues to ignore the law, and since than additionally the court ruling.
[1] https://www.heise.de/newsticker/meldung/Google-muss-unter-Su... (It's in German, but the translation I've tested on https://www.deepl.com/translator is quite perfect)
Google ignores it because they can afford to.
They are specifically heuristic algorithm based and by definition they aren't perfect but can actually keep up with the massive volumes and unknowns. It is /not/ random or capriciously applied even if outcomes are flawed which makes the comparison apples to hand grenades regardless of false positives.
Even if their approach utterly sucked it wouldn't be libel or defamation any more than saying "Never trust a company which changes its name without the old name featuring sonething which becane obsolete." or "Any company with a rate of growth over 10% for ten consecutive quarters is probably a Ponzi Schene".
Any time they make a statement about another entity which is demonstrably untrue and causes harm to somebody's reputation or prevents them from generating revenue, that is grounds for a defamation lawsuit. The fact that they have automated their defamation does not remove their culpability.
It might also be a violation of anti-trust law since Google has its own software-delivery channels which are not subject to the same warnings.
>Even if their approach utterly sucked it wouldn't be libel or defamation any more than saying "Never trust a company which changes its name without the old name featuring sonething which becane obsolete." or "Any company with a rate of growth over 10% for ten consecutive quarters is probably a Ponzi Schene".
It's completely different because those statements are not made about specific entities, nor do they make specific accusations about any entities.
Obviously not. The UWS policy has been around for a long time and adblockers haven't been swept up in them.
"What if they change the rules in the future and suddenly do something I don't like?"
If the Safe Browsing system suddenly starts doing things that people don't want, then the other browser vendors will stop using it. Problem solved.
They don't have to change anything about the rule!
They need only to change their "interpretation" of said rule. In fact the rule is so vague they can interpret it in any way they want.
Apple has similar issues these days, with their weird "app notarization" requirements that may even require you to pay the platform vendor in order to be acknowledged as a "trusted" developer.
OK, sure, Windows adds an additional problem, but the Google problem still needs to be solved.
> Reproducible builds will definitely help with this, both by establishing social trust in your release
"social trust" is not (so far as anybody knows) a metric that Google uses to decide whether a particular download is malicious.
> and by having a single version of the binary that will eventually stop getting these warnings
Only a single version of the binary was uploaded, and "eventually people will stop getting these warnings" only solves the problem for the current release, not the next one or the one after that.
Google’s standards are arbitrarily set and applied, with no evidence of community involvement in setting those standards.
This describes the precursor to monopolistic behavior.
Google is completely opaque, there is no documented path to get rid of the warning.
Not sure if an EV cert makes a difference as you say, but they are certainly prohibitively expensive.
A regular code signing cert can be bought for about $6/month, and an EV cert for about $25/month (if you shop around or buy multi-year certs). Both are expensive in the context of open source, but I'm not sure I'd call the cost prohibitive.
1: https://blogs.msdn.microsoft.com/ie/2010/10/13/stranger-dang...
2: https://blogs.msdn.microsoft.com/ieinternals/2011/03/22/ever...
3: https://blogs.msdn.microsoft.com/ie/2012/08/14/microsoft-sma...
Where?
Having one's website and/or downloads flagged as harmful, and potentially being deindexed for hosting malware, is not something any software developer can ignore.
If Bing and Edge flagged my downloads, I would honestly not care as they control 2% of the market. The Windows "this file was downloaded from the internet" warning is something that, regrettably, is so common that users already ignore it, and it happens even for many commercial software programs. Although I do consider that an unfortunate hurdle for free software developers as well, the harm is substantially smaller.
As such, I respectfully disagree.
Let’s take some examples from the post. If a domain is 15 years old and implicitly trusted by this point, then an attacker is just going to compromise an ancient WordPress install to post malware.
If an OSS developer occasionally releases software, attackers might approach them to add a new SDK or monetization opportunity (happened many times to VLC - good thing JBK hasn’t been tempted!), or just straight up attempt to compromise their infrastructure (e.g. download servers, has happened to many pieces of software like Transmission).
If we actually had Let‘s Encrypt for code, attackers would trivially get certs for their stuff. Then end-users would have to decide which certs to trust or not, which would significantly weaken the purpose of code-signing.
Short of just sandboxing all binaries by default, I don’t see a great solution to make binary downloads safe. macOS is already moving very heavily in that direction.
The OS vulnerabilities being exploited should be fixed. The solution of a white list solution managed by unaccountable tech oligarchs should be laughed at and then resisted at all costs.
Once again, the title has been (ungrammatically) editorialized with a question mark. It would appear that this is HN editorial staff policy[1]
What is the purpose of this policy, and in particular what criterion is being applied here, that does not apply to (e.g.) the (considerably more subjective) title "McDonald's holds communities together" which remains un-editorialized on the front page of HN?
I am similarly curious about the difference between "Apple News No Longer Supports RSS"[2] and "Google bans niche browsers from Gmail"[3] (to my eyes they are virtually identical submissions - third party forum-based verifications of changed behavior of Big Five software).
[1]https://news.ycombinator.com/item?id=21767023
Dreading the day that Google decides to turn this warning into a search penalty. The other image resizing websites typically upload the images to their server and download the resized ones back again. That sucks for users, who have to wait for all that to happen and have the privacy of their images put at risk.
1. Create a DNS record for subdomain and name it to something like downloads.byuu.org
2. Put a file there. The preferred naming scheme is to categorize it by product or product category, so something like downloads.byuu.org/emulators/higan.zip will do fine.
3. Start by putting the downloads in non-executable file formats first, e.g. use higan.zip instead of higan.exe. It's a no-brainer for a Windows user to launch the file from ZIP archive
4. Make links to downloads from your main website as you would usually do
5. Everything should be smooth now
6. Your downloads.byuu.org subdomain will slowly gain reputation
7. Once it has an established reputation, you will be able to put .exe files there. Gaining the reputation will take about several months. I would expect about 12 months to be on a safer side
8. Enjoy and be creative
The URL scheme is the convention I follow, but I also include the version# in the file name.
I did put the executable inside of a ZIP archive, along with a text database and a few video pixel shaders. One change I made recently was moving from .7z to .zip since some users don't have 7-zip installed, but I presume Google is smart enough to scan inside 7-zip archives even if Windows isn't (out of the box at least.)
I've been providing these releases for fourteen years now. I have no idea what suddenly changed other than it took about two years to release a new version due to a lot of massive changes.
I appreciate the reply all the same, thank you for taking the time.
If you want to stand your ground you could simply add a password to your archive (works best with 7zip as you can avoid exposing the filename with extension); just mentioning it for the records.
Cannot confirm that. IP is virtual thing in terms of HTTP web hosting. I have experience with attaching fresh IPs to existing domains and attaching fresh domains to old IPs: the only thing that matters for HTTP reputation is DNS. IPs do not really matter unless they are seriously blacklisted by a manual action (which is not your situation I presume).
>Google is smart enough to scan inside 7-zip archives
Google sees raw EXE files as a risk factor. Once domain serves a naked EXE, Google gives it a higher risk score.
Publishing an EXE file inside archive (of any format) significantly lowers that risk because an archive cannot be directly executed by OS.
(Please note that a lot of corporate internet gateways do not allow naked EXE files via HTTP for the very same reason)
Also my program was inside a ZIP archive. It did not help me.
Yes, it's still money that cash-strapped OSS devs might not have, or indeed might not want to pay on principle. And yes, the validation process is a total farce and a PITA.
But I don't think it helps the argument to use the most expensive certificate they could find as an example.
Also, having a cert does not mean your software won't be marked as "uncommon" - presumably Google (and Microsoft) use a certificate as a signal, but it seems only the number of downloads really counts. And I do agree with the thrust of the article, that this harms OSS and indeed small businesses.
It's a tough call, but it's somewhat understandable what Google is doing. Arbitrary binary downloads from arbitrary websites are for the most part a problem for the majority of users.
There is nothing stopping a savvy user from still finding and downloading your binaries. You should probably figure out a better distribution channel.
Remember that all the hoops you have to jump through to get a signed binary are also required for anyone who would want to pirate your software and re-release it with a virus ( which I have seen done in the emulator community before ).
The simplest regulation could be: all policies have to be transparent, consistent, with predictable outcomes, and there must be a process for addressing grievances.
Then Google would have to hire 20 000 support people and act like a regular company.
Detailed regulation of specific markets often misses the mark or comes far too late. I think it's time for a radical rethink of competition policy.
For instance, I wonder what would happen if we were to ban all mergers and acquisitions involving companies above a certain size.
It's obviously a very blunt instrument and I can think of many good arguments against it.
But I think we need simpler rules that are less prone to policy mistakes, protectionism, arbitrary definitions and selective enforcement.
This is de-facto the case. Mergers are monitored by the FTC etc. subject to a lot of scrutiny.
Unfortunately, even with this - it's really, really hard to define what monopolies and anti-competitiveness really is.
Some think Disney should not own distribution, but Apple is also vertically integrated - and distribution channels are so volatile it's hard to regulate.
It's possible things might settle down in a few years and we might be able to establish boundaries.
No, it's not the case. Only mergers between two large companies are monitored and then they are allowed to go through most of the time.
What I'm talking about is banning all M&A (and even certain asset purchases) where _one_ of the companies involved has more than, say, $20bn revenue (or some industry specific metric). Large companies would only be allowed to grow organically.
Obviously startups and VCs would hate the idea, because it would block one of the most favoured exit strategies. What it would mean is that startups would have to sell themselves to medium sized companies, join forces with each other, and/or go public and compete with the giants.
The FTC probably should allow most mergers to go through.
It would likely not be efficient for companies to not be able to acquire one another beyond a certain scale, I suggest deference should be given to the liberal side of the equation, with regulation affecting only within certain constraints.
The hard part really is defining those constraints, and determining what constitutes anti-trust.
AWS massive subsidy of their delivery operations putting FedEx out of business by shipping for less than cost would be ... problematic. Taking Search profits and giving away Android for free is a form of dumping. But then without this, some entire industries might not exist!
Maybe so, but it is not the case that mergers get blocked purely based on the size of the companies involved. It's simply not lawful for the FTC (or other regulators) to do so.
>The FTC probably should allow most mergers to go through.
That is the status quo and it is clearly unsatisfactory in some areas.
>I suggest deference should be given to the liberal side of the equation, with regulation affecting only within certain constraints.
I completely understand why you are saying that, and it has always been my preference as well.
But the problem is that these constraints have become so difficult to specify that the likelihood of ineffective, counterproductive or abusive regulation has risen dramatically.
That's why I'm wondering whether it wouldn't be better to accept that size itself invevitably creates problems that no case by case game of what-a-mole will ever solve.
We need simpler rules that can be consistently enforced.
I'm far from convinced that my particular idea is any good. I'm just putting it out there as an example for the kind of simplicity that I think we need.
They can explain the issue on a web page gating the download page.
What alternative is there? Even if I trust you, how do I know a hacker hasn't cloned your site and added malware?
There's no trust, accountability, or security. Instead, app stores and package managers provide these things. They're not perfect, but they're waaay better than totally untrusted binaries.
And if you're an advanced user, you can ignore the warning. Or know to download binaries linked from a project's GitHub page, etc.
Let's face it: the "open web" is not a secure or trustworthy place for downloading binaries period, unless you're on a well-known trustworthy site (again -- Mozilla, Microsoft, Adobe, etc.).
Now I'm confused.
In other words, whatever brands you know from life experience are a legit product, not malware that will turn your computer part of a botnet. If you're a designer then you know Sketch and Adobe, etc.
Yes vulnerabilities are found -- nothing in this world is 100% perfect -- but in practice, running JavaScript in your browser is orders of magnitude safer than running binaries with access to your filesystem, hardware, and more.
If you want to go toward security, unilaterally disabling parts of the web because of parts of third party legacy OS design is not the way to go, actually I don't see logically how the described approach of Google would yield any interesting true_malware_blocking / false_positive_blocking ratio. And you know what would be even safer? Shutting down the computer when the user attempts to browse the web. Browser vendor should let the OS antivirus take care of its own business -- if I want my complete computer to be taken care of by Google I can go buy a Chromebook...
I was saddened by the move of Edge to Chromium engine, but honestly while I used the old one from time to time for very specific purposes, I could not recommend it to anybody. I will still try to make people use FF by default, but I'm starting to think the position of the new Edge will be interesting and it could be good to try to switch some from Chrome to Edge.
Your idea that they are "trusted" is laughable, and it is also dangerous to our liberty and security to believe only these gilded companies should be authorized to say what software is allowed on a given platform
We have seen massive censorship as a result of this, with Apps being banned from various app stores not for security but for political reasons
It would be really nice (in the "this is why we can't have nice things" sense) if there were a way to distribute software tools to niche audiences without them necessarily needing to be technical audiences. Up until recently, the Open Web has been that system, but it seems Google can unilaterally disable it via their Safe Browsing feature.
We need independent stores which purpose is to prevent security issues and not impose additional limitations.
Preventing security issues requires imposing additional limitations, you can't have your cake and eat it too. Either the apps require serious review (i.e. a much, much higher bar of entry than iOS AppStore), or the apps need to be restricted so that they can't do much, so strict sandboxing.
Running unsigned, unsandboxed binaries from a small developer is a big security risk which can't be prevented in a cost-effective manner, so average users have to be warned that it might as well just encrypt their files for ransom.
- First, I disagree that every program an average consumer might want or need is available on an app store.
- Second, I strongly disagree that app stores provide security, trust, and accountability.
App store security is really bad. At best, we have Debian repos, which are clean-ish mostly because nobody cares about writing malware for desktop Linux so the moderation is much easier. At worst, we have Windows store and Android. These platforms are not effective at screening out malware, because content moderation doesn't scale to these levels, and blocking malware is just another form of content moderation.
Telling people to trust app stores and not downloaded binaries is like telling them to trust Amazon and not Ebay. You're right, there is technically a difference, but the difference is not big enough to matter. If you download random things from any source, you will mess up your computer. It'll just happen faster with downloaded executables.
There is (unfortunately) no shortcut to get around teaching people about security. At some point, native platforms will catch up to where the web was 10 years ago and start doing a better job of sandboxing executables, and then the job of educating users will be easier. We're just unfortunately living in the world where that hasn't happened yet.
"Get rid of unofficial software" is counterproductive to what we actually need to do -- to update our native permissions and security models to match modern users' requirements. But even though mass-moderation is a band-aide fix that doesn't even work well right now, it's heavily promoted by companies like Apple, Google, and Microsoft because under the guise of security it gives them a new stranglehold over the common-user software market, which was traditionally un-monetizable by them.
Maybe so, but it's still significantly better than native binaries.
> Telling people to trust app stores and not downloaded binaries is like telling them to trust Amazon and not Ebay. You're right, there is technically a difference, but the difference is not big enough to matter. If you download random things from any source, you will mess up your computer. It'll just happen faster with downloaded executables.
The difference very much does matter. I suspect many people on this website have had the same experience as me: I had to do frequent "maintenance" on my parents computers because they get filled up with IE toolbars and whatever other BS they could find to screw up their computers. After the switch to phones and app stores, this doesn't happen any more.
People without family members capable of fixing that sort of old problem are both (probably unconsciously) grateful for the app store takeover, and vastly more numerous than indie software developers grouching about not being able to run any code they like on anyone's computer anymore.
There's a fair amount of anecdotal evidence there, I can't give you hard stats to back that up. But I suspect a lot of the "app stores improved security" anecdotes people have are actually due both to family members just slowly getting better about security in general, and (to a greater extent) the fact that phones are doing a better job than Windows/Mac of embracing the web model of sandboxing applications.
> because they get filled up with IE toolbars
This example in particular makes me smile, because I have family members on Firefox today, and they still end up with random malware/adware extensions, they just install them from the official store. It does nothing to help -- I've asked them how they got installed, and they don't know where they came from. Websites just asked them to click somewhere, and they did.
Firefox has gone through all this trouble to make sure everything has to be signed and vetted, and it has made no difference at all to my family members :). What they should do is move the extension locking capabilities from the Enterprise version to the regular version, so I can set up Firefox with a few extensions and then freeze it so that nothing can be installed, even from the official store.
Chrome's app store isn't any better[0]. Anecdotally I have roughly two options when I set up someone's computer. Either teach them about security and harden the platform itself, or make it hard for them to install any software from anywhere (usually by moving them to something like Linux and manually handling all of their setup). I haven't personally seen any evidence in my tech support stories that official app stores are helping my family members.
Yes, the frequency will go down. But this is an area where the gains have to be more drastic to be worthwhile. The support frequency only matters for trivial malware like adware and crypto-miners. It doesn't matter for stuff like ransomware, password theft, or phishing attacks. And the gains today are probably about as good as they are ever going to get. Universally, moderation gets worse as systems scale. Android has more malware because it's a bigger platform. NPM gets more malware because its the biggest package manager. I very firmly believe that app stores don't scale, because we can look at app stores today and see that they're not scaling well. It's a security dead end.
[0]: https://adguard.com/en/blog/over-20-000-000-of-chrome-users-...
It has been solved by sandboxing.
Why is Chrome a monopoly? It doesn't even come pre-installed with Windows.
Microsoft, Google, and Apple all require certificate signing for software to show up as "trusted" ($350/year is really really annoying, but it is an insurmountable wall for someone distributing hundreds of bad apps). Google's approach lets popular free software get a pass without having to pay, but, yes, it's a trade-off.
In my opinion, the easiest thing to do is to (1) put the windows binaries on a separate domain, (2) provide screenshots (not links) telling people how to download them from the other website, (3) include screenshots of how to bypass the Google warning, and (4) include instructions on how to verify the authenticity of the binary out-of-band (checksum, etc). This matches how folks handle other unsigned binaries (for example, drivers).
So it's Windows Vista UAC all over again. Truly there is nothing new under the sun.
Youtube did that other other browsers, so could sites do that to Chrome.
It worked just fine if you pretended to be Chrome by changing the user agent.
https://www.reddit.com/r/firefox/comments/91hbkw/youtube_pag...
This is not necessarily a lasting fact. DuckDuckGo works just for fine and as for browsers so does Firefox. Even learning the differences in browser devtools isn't as hard as it seems. Don't presume the premise that produces a doomed conclusion.
Edit: why have I never run into this problem? Am I not a heavy app user or is this mostly on Windows?
Only companies with real search crawlers are Google, Baidu, Yandex, and Microsoft.
I understand it is an awful solution. But, like in politics, sometimes an awful solution might be your less bad choice.
I still don't in general like the slow erosion of the web, however.
It would be great if it wasn't, but I think Microsoft have always used it as a way to push UWP.
However there are many APIs that are not allowed because of sandboxing.
Certainly an emulator wouldn't be allowed.
Name the top 10 most hyped open source projects of the year.
Which ones are not corporate owned?
I really wish Let's Encrypt, or someone would offer free or at-cost EV code signing certificates.
Then you use Hacker News and other resources to develop your arguments and collect money from people that care to help.
GitHub, OS and free package managers or other aggregators provide mechanisms to share trust, moderate and review posted binaries.
Consider using these. I.e instruct users to install via their package manager. If your audience is not technical then you need to put it in the common man's package manager the app stores :/
I take your point, but if you download executables from Github using Chrome, IE or Edge, you're still going to get a warning when it's deemed "uncommon".
The only real option on Windows is the Windows Store, which AFAIK is only for UWP apps.
There is chocolatey and scoop, but I find chocolately a bit of a mess (e.g. duplicates, never certain which is the "main" download), and while scoop is good, the selection is still relatively small. These are also only really used for OSS software, which doesn't help ISVs.
Or is it just me (a non-native-English-speaker)?
"The sky is blue."
"The sky is blue?"
This requests confirmation, which can imply either "did I hear you correctly?" or "are you sure?".
It can also be used to request confirmation for a statement you're not repeating, like in these examples:
https://www.reddit.com/r/grammar/comments/16ogm8/question_ma...
But that tends to come off as presumptuous in most cases.
The use here is more informal. It can't be requesting confirmation, since it's not addressed to a single person, so it's just indicating general skepticism or uncertainty. In that case it's more of a statement than a question; you wouldn't answer it yes or no.
If I can get a confirmation from someone at Google that they will trust GitHub download links more, then I'm willing to go this route for now.
They don't give score to "GitHub accounts" but they use some form of score/accountability based on the domain. As far as I know the main vector they are trying to protect users against are emails with links to binary files hosted on random hacked servers.
I understand that you're in a risky line of “business” with emulation, where one wrong step can get you some lovely letters from lawyers. However, for the sake of argument: Is there any reason you couldn't get someone else to lend you their name so that they act under their real name for you? Surely that'd be an option for risk-averse people.
> In my own case, this has effectively prevented me from releasing compiled binaries of my own software going forward. If code signing is a requirement to distribute free software, then we need a Let’s Encrypt-style alternative for code signing—yesterday.
The whole point of a code signing requirement is to add a paywall so that only two kinds of people will have access to it: Bad actors sophisticated enough to steal a code signing certificate from someone who has purchased them.
It's a net gain for security. Software freedom, considering increasingly prevalent SaaS and closed-source apps on mobile devices, is already lost. So if we've already lost software freedom—as far as I can tell, more or less irrevocably—then we might as well at least reap the security benefit for the common person while we're there.
This just pushes the problem up a level. The front-person would assume the legal risk, and if they're trying to avoid it they will let the legal system know the "real" person.
IRL there are "goalies"[1] - indigent individuals who for a low price will assume the legal risk of, for example, registering ownership of a car. This is a grey area indeed.
[1] translation of the Swedish term "målvakt", from where I know of this phenomenon.
It's possible, but I would find it to be rather unethical. I am much more willing to allow an EV certificate to sign my software, or if I could get the BBB to respond to my requests to register with them, I could even consider purchasing my own EV certificate for my LLC. (my understanding is that the EV validation process confirms your business' validity through its BBB listing, and an article of incorporation is not enough.)
> The whole point of a code signing requirement is to add a paywall so that only two kinds of people will have access to it
Why is the web and Let's Encrypt any different? Websites execute code that can potentially harm your computer (via zero-days.) A paywall harms free software developers who can't afford hundreds of dollars a year for certificates, which is not a problem for me, but would be for many folks.
The web is as much of a remote code execution vehicle as it is an application platform that could theoretically do a lot of things without the remote code execution in the form of wasm/JavaScript. TLS solves the issue of people eavesdropping passively and MITM actively to do real-world harm by stealing credentials or injecting malware: It was a solution to an actual problem. Don't get me wrong, I am very much advocating for requiring TLS EV certificates if you serve JavaScript or WebAssembly once we've finished purging the plaintext web. It's a necessary evil to get more accountability for code and subsequently ease prosecution for hosting and distributing malware.
People downloading and executing other people's code is also a problem in need of a solution because of the very much non-trivial risk of malware these days. App stores have worked on mobile (at least it's improved the mobile threat landscape compared to traditional desktop computing). The idea of an app store can be made to work for desktop computers as well to reap the same security benefits of having a central, reviewing gatekeeper that is subsidized by everyone publishing there to pay a cost.
The proper solution would be to have mobile-like sandboxing capabilities on Windows, macOS and Linux, but that's still far. Mandatory code signing with personal identification is just a stopgap measure.
> A paywall harms free software developers who can't afford hundreds of dollars a year for certificates, which is not a problem for me, but would be for many folks.
I don't deny that this is a problem for many folks. But this assumes (executable) free software is desirable. It isn't. End-user software should be must be made at a loss (time) or for profit. This just makes the loss much more economically explicit. In the long run, this could give back value to software in the perception of users, which I consider to be a good thing.
Google has a large share of search activity, but it's not at all clear that they have pricing power on search (the usual yardstock for a monopoly) or that search is even a market at all, since no one pays for it.
Search advertising is a different story, of course.
Now if you listen to the various whines of said competition, Google sure looks objectively better too, using extreme personalization to drive more relevant search results to their userbase.
There is no pressure there. If alternate search engines were subjectively (not even objectively!) better, people would switch overnight. After all, they are just a click away.
Have you tried Google search lately?
It is almost never the case in technology that the superior product wins. It's the first to market with a really killer product. It takes massive inertia to displace an incumbent, and Google managed it because search engines prior to it were nearly useless portals (Yahoo, AltaVista, AskJeeves, etc.)
The requirements and conditions to displace Google now are virtually impossible, and that's even before factoring in their massive data profiling advantage.
Can't you add it to the Windows/Mac/Ubuntu App Store, though? There seems to be lots of free apps on there...
I surmise that this mostly impacts non-free platforms, where compiling software from source used to be quite non-trivial so it was common to just download binaries. These days you can probably get LLVM to work everywhere, though.
A few years back at my work we were digitally sign our binaries, so I don't think non free platforms are affected at all since it is not expensive to buy a certificate , only hobby/personal projects will be affected.
Also a signed binary does not mean there are no viruses or other bad things inside, so I am wondering if we want to identify the source of the binary can we find a technical solution so you can have your website and binary with the same key then you know that binary X is from X.com people, for some reason a few years back this certificates for signing were not cheap.
It's not "waste" if it's needed to establish trust.
> A few years back at my work we were digitally sign our binaries,
Just publishing hashes for the (reproducible) unsigned binaries over a secure channel (such as HTTPS as verified by Let's Encrypt) will give you the exact same security. Digital signatures embedded in executables add no security whatsoever, and make reproducibility harder. Just don't do it.
We had to sign our applications to prevent scary warnings to appear and then we would have to train our users to ignore that.
With that said, hosting the binary on those platforms won't necessarily help as Google can flag individual repos according to some other comments here.
I would, if at all possible, prefer to find a solution to this problem so that I can directly host my software.
At some point your domain will have a sufficient score and it will not show the warnings to users.
How long that will take is, however, outside of my knowledge and it would be nice to have some official reference about it; as it stands I agree with you that it feels like begging to a benevolent dictator.
But look at it from the other point of view: how does a non-technical user determine if a binary download is malicious?
And how, then, does Google/Microsoft/Apple protect those users from their ignorance?
Given that the internet is full of people attempting to get non-technical users to download malicious software, often my mimicking exactly the sort of site the OP has created, then is it really practical to insist that Google/Microsoft/Apple allow the OP's site to download software to a user's machine freely?
The advantage of the middle-man is that it acts as a trust agent (not necessarily well, of course). If you download a malicious binary from an App Store, that is the App Store's fault for letting it on there in the first place.
Let's say I keep bees as a hobby, and I write some small piece of software that tracks and calculates something to do with honey production. I post it to my favourite bee-keeping forum, other people try it and like it, and when a new bee-keeper joins the forum they're often advised by forum regulars to try my software out too.
That kind of software can be a huge help to people, but it's not a good fit for an appstore because it's never going to turn a profit, and at least on Apple's store (with the $99/year publishing fee) it'll drain money quite predictably and regularly.
A bee-keeping forum will never be trusted by as many people as Google/Microsoft/Apple, but the people who do trust it probably trust it a lot more.
But then it talks about distributing binaries. Cry my a river; most FOSS can and should be distributed primarily in source form, in a git repo hosted on a site like github. FOSS software can be released via distributions that can supply controlled, and accountable, and digitally signed binary packages to end users who aren't skilled enough to build from source. This includes Debian, SuSE, Google Play Store, Amazon App Store, Microsoft store, etc.
Training users to download binaries from random web sites? That's a security disaster, and it's a Good Thing that web browsers discourage such reckless behavior.
There is the downside that it's a cli-based app, but that's easily overcome with a GUI frontend add-on.
One of my favorite parts of it's architecture is that it's got a mechanism for adding third party repositories (buckets), so while the publishing policy for the main bucket is mostly limited to development tools, it wouldn't be hard for the community to build a new bucket for independent software developers to use as a general distribution mechanism.
And freeware/shareware have no tax on most stores, since 30% of zero is still zero.
Both Microsoft and Apple ban my specific class of software (emulators) in spite of unanimous court rulings establishing them as legal under fair use laws.
That's at least how I would try to work around the issue.
Regarding the blog post: I think this is a side effect of making the web a "safer" place for all kinds of users; nothing which I appreciate personally but I understand why a large mass of users clicking everything is a concern for Google/Microsoft/Apple.
I was once thinking that people could be educated to use the web in a better and safer way...now I think everyone (tech-savy users, big corporations) has given up on that and that "safe by default" is the norm.
I have never seen this happening, but if you come around proof of this please share the information.
Edit: this is the proof: https://twitter.com/notdan/status/1209642463859630081
They fixed it afterwards.
> some sites choosing to link to GitHub directly
They can link directly to the download on your site to the same effect?
No need to be this dismissive.
> if you want proof
While I agree that there are many reasons to prefer native technologies in many cases, this is not a proof. A clue, at best.
In terms of apps, the only thing it ensures is that only the entity that published the app in the first place can apply updates to it. For binaries, you can get this level of trust by using any kind of digital signature for your updates.
I used to distribute some small freeware tools for windows computers for a long time (~10 years). I stopped distributing binaries and only distribute source now (despite the fact that this likely cuts the user base literally to probably 0), because I decided it was simply impossible for me to guarantee the safety of these binaries.
I also got hassled by these security measures from MS/Google/etc., but honestly, they're right. I was making non-reproducible builds with dependencies I couldn't fully control on an insecure computer, uploading to a web host that I can't really trust, and letting the binaries sit there for months/years.
I used WordPress for a while, and it did get hacked a few times, despite keeping it reasonably up to date. I was first alerted to these hacks by google telling me they found malware on my site and were alerting people to that fact. My first reaction was obviously to be mad at google, but they were right.
Eventually I switched to a static website. But even that is hard to be fully confident in. I'm still trusting a cheap web host to keep their Apache (and whatever else) up to date. I bet cpanel is a cesspool of vulnerabilities given how janky I've observed it to be.
I suspect some or all of the above is true for the majority of the developers negatively affected by these security measures.
If you can actually be fully confident in your whole build and distribution stack, then you can probably easily afford the compliance/certificate costs to meet MS/Google/Apple's requirements to avoid getting flagged by these security measures.