Google have declared Droidscript is malware
groups.google.com
groups.google.com
I hate when using euphemism slides into flat out lying like this. They are not "unable" to reinstate the account, in fact they are the only party able to reinstate the account, that's why the account holder was contacting them instead of someone else. They are "unwilling" to reinstate the account.
I know it's all just bullshit but it bothers me anyway.
If not for implications like this, almost every single use of "unable" (or "can't", for that matter) ever in a sentence would be "lying" unless something is against the laws of physics.
But I'm not "unable" to issue a refund.
In another case I may say "hm it's out of warranty but you know what, it really shouldn't have broken like that and you're a good customer, so I'll give a refund anyway." I can do that because I am able to issue a refund.
As for their policy, they are both the authors and interpreters of their own policy, so the "my hands are tied" argument is pure BS. If they are unable to reinstate accounts, why do they have an appeals process at all?
"I cannot continue this relationship"
"I can't kill this guy"
"I just can't eat meat anymore"
"I cannot continue like this"
These are all examples where someone clearly could for physical reasons, but they can't for other reasons they are bound to, whatever these reasons are.
It could be as simple as "Google management reviewed this app and decided it cuts into the bottom line of some service offered by Google." If the low-level person writing emails is aware of this fact then it would be reasonable to understand why they are unable to share the true motivation for suspension. What is more likely is the low level email writer looks up the account and the reason for suspension listed is, verbatim "Ad fraud - <3 Mgmgt." Then the low-level person would not be stretching the truth at all when they say they are unable to reinstate the account and are unable to provide more information.
Just because this usage of "unable" doesn't match your strict personal definition doesn't mean they are wrong. People generally agree and understand what "unable" means in this context, so you're kinda SOL.
Similar arguments apply to the Google store the person or more likely the software system that composed that email might be unable to reinstate the account, but Google most definitely is. But Google is merely unwilling to do so.
The thing is that they can't bend the policy for certain players without being sued for unfair business practices/anti-competitive behavior, which is why Google has to enforce it on everyone if they want to enforce it on anyone.
You're right that this isn't solely a faceless corporate thing. People say "I can't" when "I won't" for the same reasons Google did. We even ask "can you watch my kids?" Again, the same reasons drive the language. It lets a false but face-saving implication stand: You will pick up my kids if you can and if you won't than I'll assume you couldn't.
We also "ask" our employees or waitresses to do things, even though it's technically an order.
All this is good and fine. Language is supposed to embed cultural niceties that speak to our values and smooth relations between people.
The Orwellian shit comes in when it comes in. These cross from figures of speech into euphemization and the Orwellian point is that these things run deep. A bank manager is literally unaware of where her own prerogatives, organisational norms, hard corporate policies and regulatory rules begin and end. They are constantly implying (and thinking) that whatever is annoying/abusing their customers is not because of them. Usually it is.
“Unable” is dishonest because it passes responsibility beyond the veil of the typical user’s ignorance. We’re so used to this sort of language that we’re conditioned to allow it even when we know it’s bullshit. It shuts down discussion and allows its wielder (inevitably a corporation) to avoid explaining itself. In the developed Western world we have a big problem with letting corporations do whatever the hell they want without explaining themselves, so I don’t think we should let them get away with this sort of thing anymore, and not being satisfied with mealy-mouthed evasion is one of the first steps down that road.
Hell, they can even change their policies if they want, so they aren't really "unable".
If you tried hard enough, you could probably manage this.
You can do it if you are stonger than the other person. You may not do it, according to the law.
Were the implied statement made explicit, then yes it'd be accurate.
Unable due to their policies, which they wrote and they can change (and which they often choose not to follow anyway).
I agree with OP - it’s not that Google isn’t able to do this, it’s that Google doesn’t want to.
https://youtu.be/Y1QQSFlm0dI?t=81
The audience is laughing because this notion is ridiculous.
The rep in TFA uses "we," referring to Google. Google is able to reinstate accounts, and The Google Ad Traffic Quality Team is able to reinstate accounts depending on their judgement of whether someone is violating policy. If they are not able to reinstate accounts, can you explain to me why they're adjudicating account ban appeals? Do they say "no" to everyone?
The key point here is that the agent(s) are responsible for interpreting the policy. They have decided that Droidscript violates their policy, and I personally have no opinion about that. But to imply that it's "out of [our] hands]" is dishonest.
Just say "upon review we've determined that your app violates our policies so we will not be reinstating your account."
That is not equivalent to what's happening here. There is no law preventing Google reinstating the account, and corporations don't have morals because they're not people. The only thing preventing them doing it is that the employees involved choose not to.
When someone points a gun at a cashier and says "this is a robbery and I'm gonna shoot you if you move a muscle," the cashier usually uses their ability to hold still out of concern for their safety.
The distinction matters.
We've gone from a world where we can run any software on our devices, to one where Apple and Google tell us how we can make money, what we can run, and what speech is permitted.
It's Orwellian, but with corporate greed instead of nation state fascism.
Though FWIW I’m unable to disagree.
I’ve sometimes spent hours crafting a single reply to politely decline a request. It’s not even proportional to the prospective importance of the customer, it’s a matter of respect for all potential users.
Also, sometimes, investigating the issue to determine the right words has revealed hitherto unknown problems, uncovered new possibilities, highlighted alternative solutions that may be palatable, or even changed the outcome entirely.
Discussing the language used is actually thereby more productive & constructive than simply piling on Google for being careless, callous and pompous yet again.
Non-plain English is usually a flag that the person you’re dealing with is not smart.
The usage of plain English words is something we do strive to see more often. We do hope that it can be utilised more often going forward. Unfortunately at this time we advise that the occurrence of non-plain English may indicate a violation of our MTC (minimal thought capacity) guidelines.
I don't think it's that they're not smart. It's that they have a separate agenda, often deflecting responsibility. People often use this sort of indirect wording even without consciously realizing it.
They share your phone/email with lots of dealers if you request a quote and don't read the fine print like I didn't...
You may see “we” as the company itself setting its own policy/ process
> We understand that you may want to know more about the issues that we’ve detected. Because this information could be used to circumvent our proprietary detection system, we’re unable to provide our publishers with information about specific account activity.
> Once you’ve made changes to your site(s), app(s) or channel(s) to comply with our programme policies and terms of service, you can reach out to us using our appeal process. Please make sure that you provide a complete analysis of your traffic or other reasons that may have led to invalid activity in your appeal.
I realize that the term Kafka-esque is a bit overused nowadays... but this sounds exactly like a plot summary of Der Process.
"Which policies?"
"That's none of your business."
"How are we violating them?"
"I'm not going to tell you."
"What can we do?"
"Fix the issues, and then appeal."
"Which issues?"
"I've said too much already."
Obviously I can't say "of the last 2500 ad clicks zero of them had any mouse movement over the ad before the click event" because then the publisher obviously just fixes their fraud software.
This isn't specific to Google or even advertising. Every company has figured out when dealing with abuse and fraud sharing the minimum amount of information is beneficial to the health of the ecosystem as a whole.
https://gutenberg.org/ebooks/7849
It's a really entertaining read.
And yes, it perfectly matches this situation - right in the very first sentence already.
I listened to the audiobook of that (read by Geoffrey Howard), and while the reading itself is fine, you'll want to avoid the editors' preface because it gives out some plot points and the ending. (PSA: if you make audiobooks, don't put editors' or critics' opinions anywhere before the end, even in ‘footnotes’. Only clarifying notes for unfamiliar terms.)
AdSense is the product where Google pays you for running banner ads; they can and frequently do kick people off of it for secret reasons. When my company was kicked off of AdSense back in 2010, I wrote about it extensively. https://www.choiceofgames.com/2010/08/were-banned-from-googl...
Google will never tell you why they ban people from AdSense, and there's no effective way to appeal. (They have an "appeal" process, but what are you supposed to write in the appeal when the charges against you are secret?!)
At least we can still publish Android apps, right? (We now run Facebook ads instead.)
But Google's email to DroidScript saying that the DroidScript app was removed from Google Play Store for "Ad Fraud" says otherwise.
Publishing status: Suspended
Your app has been suspended and removed due to a policy violation.
Reasons of violation
APK:206 Ad Fraud
App violates Ad Fraud policy.
Surely Google could have just revoked DroidScript's access to Google ads, while allowing DroidScript to ship on the store, like they did for us.If Google ever yanked our Android app over "ad fraud," we'd have no recourse. We've appealed our AdSense rejection a dozen times over the last 10 years and we always get a form letter rejection. We have no idea what they think we did wrong, and we never will, so we can never fix it.
Thank god we don't run AdSense ads anymore. Based on this, I never want to run them again!
https://www.huffpost.com/entry/why-google-bothered-to-ap_b_2...
So i say always maintain separate google accounts for individual apps, for individual usages. Separate your personal google account from your business account, from your ad-network account etc. And i would argue that each individual app should own their own account (you pay for this of course, because of the fee per account i guess).
Now the different accounts would still be linked to the same entity, and as stories like this make the news, more people would split their services on multiple account. As a response, it doesn't look like a stretch to me if next time Google would go after all account owned by the entity the deem responsible.
I mean, they already crossed the line of banning all services associated with an account. Wouldn't be surprising if they cross a few more lines as long as there is no critical impact for them.
And blood-black nothingness began to spin... A system of cells interlinked within cells interlinked within cells interlinked within one stem... And dreadfully distinct against the dark, a tall white fountain played.
"DroidScript is an easy to use, portable coding tool which simplifies mobile App development. It dramatically improves productivity by speeding up development by as much as 10x compared with using the standard development tools. It’s also an ideal tool for learning JavaScript, you can literally code anywhere with DroidScript, it’s not cloud based and doesn’t require an internet connection. Unlike other development tools which take hours to install and eat up gigabytes of disk space, you can install DroidScript start using it within 30 seconds!"
So... having read through their marketing material, this is an on-device tool that opens up what appears to be most of the Android application API to at least the user of the device, and potentially to any Droidscript applications they grab from other sources, and... maybe to other apps on the device? It's not clear from a quick read how extensive the runtime control is.
So just right out of the gate this is defeating basically the entirety of the Play Store vetting process. Droidscript itself may not be engaged in advertising fraud, but it makes advertising fraud trivial to deploy. (And it needs to be said: this is the kind of app that would never have been legal at all on any version of iOS.)
Add to that that it's a closed source IDE for an open platform, and my intuition sides with Google here. My guess is that when details come out it will turn out that at-least-plausibly harmful Droidscript garbage was being pushed to users and Google decided to kill it.
Pythonista is a complete Python programming environment which provides access to camera, music, contacts, the network, and so on, and has been available for iOS since 2016. What specifically distinguishes Droidscript from Pythonista such that you think Apple would reject Droidscript?
Uh... Seems like the actual problem (given that scenario) is that adware is being pushed to users, not whether or not Google defended its ban in public. Complaints about customer service (from everyone, not just Google) are a dime a dozen, actual user security is clearly more important, right?
Your answer presupposes a frame where Droidscript is innocent. What if it's not, and it knowingly nodded to a community of junkware being pushed to its users (again, I have no evidence!). In that case you'd want it banned without "decency", right?
If I can't ship my closed source IDE on the platform is the platform really open?
> My guess is that when details come out it will turn out that at-least-plausibly harmful Droidscript garbage was being pushed to users and Google decided to kill it.
Of course they will say it was because x, y, and z were done to protect the users. But is it really for the users' benefit or just about control over their walled garden?
For clarity: the Play Store is not an open platform. The Android API being exposed by Droidscript very much is.
Yes, I'm sure Google will carefully release details that paint them as the good guy. Certainly, we don't want to be needlessly unfair to them, but there is zero reason to give them free trust them at this point.
No more than being able to build an app on my laptop and push it over ADB.
> (And it needs to be said: this is the kind of app that would never have been legal at all on any version of iOS.)
It also needs to be said that this is why I don't use Apple devices. What they inflict on their platform is not an argument for what should happen elsewhere.
I think that this is what has happened. The author of DroidScript claims that
> Unfortunately we also have to inform our users that we could no longer support AdMob for use in their own apps either, because we can't test it anymore and can't guarantee that Google won't treat them in the same brutal way.
So apparently users were able to do stuff with AdMob on DroidScript's back, and maybe AdMob registered these fraudulent actions with some Google-ID which was assigned to DroidScript.
Compared to what? If someone wants to run a random APK that has some kind of ad fraud in it, they very easily can even if Droidscript doesn't exist.
If droidscript enables ad fraud, isn't it an issue with how the android sandboxing model is fundamentally broken? Given that there are far more people using phones than computers, and a lot of new smartphone users will have never used a desktop or laptop computer, droidscript might be their first venture into programming and/or hacking. Let's not shut it down.
> (And it needs to be said: this is the kind of app that would never have been legal at all on any version of iOS.)
Exactly, iOS is not an open platform and Google has decided they want to be more like iOS.
My gut feeling says these devs aren't telling the whole story.
You can code up Garbage in Java just fine and get it on the app store. I've seen apps send passwords in plain text....
When did we collectively decide that programmable computers were a Bad Thing?
You mean the one that doesn't exist?
I wouldn't really be surprised if EVERY scripting/programming app in the play store technically violates some play store rules, though.
Define "fixed", it was removed from Play Store but anyone can still install from APK or F-Droid, right?
If that's the argument I can sort of see Google's point here. The Play Store is supposed to be curated and the application should follow certain guidelines. This tool as I understand it effectively provides a loophole that lets people run non-curated code without jailbreak. I know that Apple removed apps for similar reasons in the past.
TFA is a bit misleading, the whole "AD FRAUD" angle is frankly irrelevant, it's just that since Google considers that the app violates the guidelines it can't be eligible for the ad program.
Installing non-curated apps has always been supported on Android - no jailbreaking required. Just get an APK either straight from the developer or through any number of alternative app stores, open it, click the "yes, I'm sure" option in the security popup and you've got yourself an app.
Also, according to DroidScript itself, Google accused them of ad fraud, so maybe there is something there.
Independent developer/small organization gets their app/YouTube channel/Google account shut down overnight because of false positives triggered by their system.
It takes weeks and insistence with bots to just get to speak to a human.
When you get to speak to a human, they usually respond with template responses and refuse to provide further information.
Rinse and repeat the same kafkanian process again and again.
In all honesty, what the hell is everyone waiting to get off Google? Gmail accounts, app stores, YouTube, ad networks... Alternatives exist nowadays for all of the products developed by a shapeless and faceless corporation that listens to nobody.
I wish a long and successful journey for the Droidscript guys on F-Droid or any alternative store. Time for Google to understand that without the content uploaded by us (users, creators and developers) they are nothing but a useless empty box.
It's a synthetic but effective barrier to prevent the majority of people from setting it up.
The mobile environment is as bad as chit, and company stores. This won't change by the will of the people alone.
It's hardly fair to suggest other wise.
Do not support Apple. Do not support Google. Support freedom.
Does it look like any of the references to the malware domain could come from the app itself? Then it's the app's fault. Otherwise, it's the user's fault.
You can also use Python to write ad bots and malware, but that's not a sufficient reason to ban the whole Python language (or any other programming language).
There's a good chance this app was being used as a vector for hacking, spamming or ad fraud. Not by the developers of this app, but by others who found this app being a useful way around the security of the Google Play store approval process.
Do they exist? True. Are they "good enough" for the average person? False.
To add insult to the injury, they have nowhere near enough reach to build a network effect outside the narrow community of tech geeks or communities that are somehow underserved by the status quo (including communities built around repulsive things, which gives bad reputation to open and uncensored solutions).
But using this sentence is simply not OK:
> Because this information could be used to circumvent our proprietary detection system, we’re unable to provide our publishers with information about specific account activity.
The developer/publisher must be given a chance to correct the issues. This is simply not fair.
I'm pretty sure Google can do better than to rely on security by obscurity.
---
> Unfortunately we also have to inform our users that we could no longer support AdMob for use in their own apps either, because we can't test it anymore and can't guarantee that Google won't treat them in the same brutal way.
Couldn't it be possible that one of those users was using AdMob in a fraudulent way, and that this was then linked to Droidscript? I don't know how Droidscript works, how it creates those apps, but it could be possible that Droidscript then was responsible for the fraudulent use a user did.
The biggest issue here I don't think is the malware tag, but the ad fraud accusation.
Even thought as somebody pointed out the page linked can be biased, based only on what they state and the emails from Google, this is another case of David Against (automated) Goliath.
From my point of view this is just another drop in the pound of what is already being built as a case against Google (and also Apple) for monopoly.
P.S.: I've used Droidscript in the past, and I do think it's too powerful an app that can be abused. But that happens to a lot of things in life, right?
they provide no information or clues leaving the author to guess.
the author guesses that somehow someone extracted their identifiers from the apk.
google comes back and says more clearly that it's something to do with how the ads are positioned, essentially accusing them of trying to trick people to accidentally click.
this information should have been provided before the appeal, and google gains literally nothing from hiding this information from the author.
the malware claims have more validity, but the way they handled the ad-fraud claim is inexcusable.
If Droidscript is flexible enough to allow end-users to create an ad fraud engine, it's too flexible for the store. Play Store is relatively consistent in its position that a tool that bootstraps policy violations is itself a policy violation.
But it would be great if Google could offer a concrete reproduction case, and from a developer-service standpoint it completely sucks that they don't.
I'd love to make some money while fucking with ad networks... :)
Now I know that I can get the guidance I need to fix the problems my product is having. Also this helps reassure the public about the big companies intentions in that these FUD stories will become instantly irrelevant. You want your stuff fixed? Pay for the guidance. You don't want to spend the time fixing the issues? So be it. But don't expect anyone to listen to your problems.
On top of this, if it's a small open-source project, create a way to streamline funding for the guidance. If a lot of people depend on your project they'll almost certainly chip in a small sum per person for the guidance you need.
I'd say by default those sessions should be posted online for public viewing just so everyone can learn from the mistakes of the original team, or to make a judgment of how disingenuous Google is being about the issues. At the request of the project requesting those services they could make those sessions private.
Also this could lead to real innovation in the tooling for example Google consultants could write unit tests that would need to pass in order to be allowed on the Google App store. Those unit tests would then, potentially become public so everyone could just download the unit tests from Github in order to confirm their software meets requirements.
The other thing is Google would almost certainly see this as a cost center. Billing people at-cost (or slightly above that) for consulting services is way more labor intensive and tbh annoying for companies with a trillion dollar + market cap.
I guess that is way when you deal with company with too much power, there is no way to appall, complain, or do anything that will save your business. So, I guess, and from few stories I read if they find out that you have type of business that is interesting for them, they can simply suffocate your business by standard mafia means, like in the movies first they send a "negotiator", then they beat you a bit, and if you do not comply they "burn" your place down.
So, company that had slogan "Don't be evil!" what a joke...
1) Don't make your business dependent on Google 2) Don't make any of your data dependent on Google (don't use Gmail, Workspace etc) 3) Don't make applications you build dependent on Google
Hint: If you can't migrate away from Google within a working day, you're doing it wrong.
> The Google Play system has declared DroidScript is Malware and accused us of committing Ad Fraud! Needless to say, we are extremely upset and totally flabbergasted at this shocking allegation!
That kind of hyperbole sets off all my BS detectors.
As I go through the back and forth, DroidScript speculates this:
> Our main guess was that one of our users was experimenting with our AdMob ID after extracting it from our APK...
What I don't see is that they ever went back to the policies to check if that was legit. If it wasn't and you tell Google, "right, that was totally a feature but we've removed it," then, you just indicated that you deliberately implemented a feature that violated the terms of your agreement.
> How can they expect people to build organisations or businesses supported by advertising revenue, when they might be subject to this type of summary execution at any moment!
I agree that Google's communication with their customers is awful, but this is not a new problem: _you have to read your contract_. And that means get a lawyer to go over it and explain to you what it really means and not what you'd like it to mean.
A user reverse-engineering your app to pull out its AdMob ID is neither a feature nor something the app dev can reasonably be faulted for.
Hard truth: a lot of internet ads is fraud. With paper, radio and TV, any ad buyer can cheaply verify that their ad spending ends up where it should by buying a paper at a random train station or listening to the airwaves.
On the Internet, it's worse than the Wild West, with fraud and deception on every part of the chain.
How is this a hyperbole? The first sentence is literally and completely true. And the developer seems legitimately upset and shocked.
It's not hard to imagine truely being extremely upset that something you probably spent hundreds of hours on got shut down for inscrutable reasons outside your control.
This non-profit org was highly focused on the educational market. I think they would have gladly stripped _all_ advertising out of the app while they worked on other funding schemes to try to eke out survival. Google is not giving them that option.
I would also like to stress that this is why we should give more effort to alternative platforms, even if they are "worse than the current offerings". For example I don't see people jumping ship off of YouTube and managing their own PeerTube instances anytime soon, but it is sooo important that something like that exists, and it should be looked at by people making content on YouTube more seriously.
20 years ago my AdSense account was frozen for click fraud -- my appeal is still pending. Ironically the website it was on was shut down 19 years ago.
If Google thinks the ability to execute arbitrary code puts users' data at risk why don't they go the full iOS route and ban everything, from scripting apps to other JS engines beside Chromium?
I am so sick of their behaviour, the only reason I am still on Android because things like F-Droid still exists and iOS is even more closely guarded.
The War On General Purpose Computing continues. Far too many business models depend on selling general purpose computers as "appliances". They presume it is possible to sell a computer that isn't Turing complete.
Google messing around with their app store is peanuts compared to the government banning or restricting 3D printers because they could be used to evade gun control for example.
Just buy some cheap SOC from the market and load the software, close it in a blackbox and call it a day. It's going to be the future now. God forbid they also talk to internet and runs an OS version from 2014 and never gets patched. It's a botnet paradise.
It's not just regulators who are nervous! What if someone modifies the firmware in their self-driving car and introduces a bug that causes the car to crash and kill someone?
But, the "freedom is indivisible" take is not always useful, particularly not on its own. There are practical realities to contend with and the world of appliance-computing is big and complicated. A lot of issues relate to back competition, or lack thereof, for example.
>> an Internet that transmits any message over any protocol between any two points, unless it upsets us?
Look... The problems coming to fruition today have been talked about on HN/etc. for decades. They're hitting the political stage, and all those discussions have near zero impact. The ideas were never translated to general consumption form. We always prefered to be right over effective.
The average politician has never stops to think about how www, linux, email, gnu, wikipedia and such are possible, what that means. If they did, they don't have the vocabulary for it. We didn't give it to them. Just let them read "cathedral & bazaar" or somesuch. Instead of working we snarked our incomprensible principled platitudes. Worse, we arrogantly assumed we'd win anyway. The internet couldn't be locked down. A country who tried to make Great Firewall would fail. Property rights would be redefined^ because digital copyright is impossible and the internet is more important than Beatles royalties. How wrong we were. How seldom we remember it.
Classic ideologies like Marx, Rand & such tend to fall into this exact arrogant trope. I am so right about everything that it's all inevitable. History will conspire. The arrogant fools. Us too.
Think of all the pull that Disney, EMI, etc have. Every politician can recite the case for copyright verbatim, along with the other talking points. Protecting their interests is literally one of the main things the US uses its might for. It's always a non negotiable demand in trade relations. Every politician or hack commentator knows to cite "stealing intellectual property" as a complaints against china or whatnot. Major digital legislation (eg DMCA) was written by and for them, along with other laws.
Conversely, very few politicians or hack commentators could articulate a digital freedom case, a case against copyright militancy, or a case the against software patents. Those that can will be freestyling it. No "talking point" sheets. No consistency. No real lobby. No solidarity. No effectiveness.
How the f##k do EMI & Disney have much more influence than us, or at least Google & such? We are arrogant fools. That's how. They're entertainment industries. We're the engine of modern economies. DMCA affected the tech business just as much as Disney. We even had status quo on our side, so all we needed was a hung jury. How did we lose this? It's a joke. Like Mike Tyson losing to McBride.
Right to Repair should have been long won. We should be battling for OS mandates on the back of it by this point.
So... where are we now? Politicians and journalist-types are literally starting to think of regulating social media as a "common carrier." Concepts recycled from early 20th century Telcom sagas. Not "neutral" carriers. Not "open" networks. No "free as in freedom." In fact, it seems like no idea from the personal computing age has influenced anything. No one who understands FOSS or how the www works is even in the room... the room where decentralising an internet-based communications network is being strategized. Do we realize how big a failure this is?
^No shade intended. I agreed ATT. I still do in the abstract. But, the lack of "what we need to do" was a mistake, IMO. History does not drive itself: http://www.paulgraham.com/property.html
https://github.com/termux/termux-packages/wiki/Termux-and-An...
I don't think that I am ok with not being able to easily run my own executables since I rely on running a few Go utilities in the Termux CLI.
- iSH: an Alpine Linux shell environment, powered by an x86 to ARM JIT emulator
- Scriptable: an iOS automation tool using Javascript, it can even integrate with native iOS APIs like photos and calendars, create native UIs, etc.
- Pythonista: a Python IDE, you can create 2D games, use it as a REPL, integrate with native APIs, and much more
And of course, there are the 1st party apps, Playgrounds and Shortcuts.
It is.
Even mozilla firefox is banned on the premise that it can run arbitrary code and yes, that is the official apple instance.
The fact that they apply it when they see fit and allow other times, and that it is totally arbitrary and opaque based on their own private interests, is exactly what everyone with common sense tried to explain when criticizing the walled garden.
Google just doesn't care about what your app does until they start seeing click fraud, upon which they ban your app, delete your Gmail, and ghost you. They've even done this to paying GSuite customers, game studios they were working on, and their own employees' spouses. As far as I can tell, antispam is at the top of the org chart and can overrule all other layers of management. I would never trust Google with anything I can't backup or migrate to another service.
The console tab of Chrome's developer tools allow arbitrary code execution. That example is not a security violation, ergo arbitrary code execution is potentially but not necessarily a security violation.
A valid remediation requires more than just arbitrary code execution, such as privilege escalation or leaking containment.
The difference is that fdroid is actually helping users through being transparent about it. The other stores and their policies usually are not transparent, and therefore nobody knows whether there were financial motivations involved in the decisions.
What I don't like is google claiming droidscript harms Android through a malicious AdMob ID. Even if that were the case, what happens to the 100.000+ installs that are rolled out already? And the Apps built with DroidScript?
If there's no support you can contact (at Google) and no changelog on what happened, the policies get intransparent and look more like a financial motivation rather than a decision that seemed to be beneficial for the end-users.
Thus, being above the law Google has no need to concern itself with bothersome matters such as fairness, justice and one being considered innocent before the Law until proven otherwise by due process.
Do we really have to go demonstrate on the streets before our legislators will act to stop this out-of-control monster?
That said, there's also probably no money in Android apps it isn't on the Google Play Store. I doubt most Android users know how to install apps from anywhere else, much less search other app catalogs. So I guess I really shouldn't be amazed at all.
I worked on a very similar Open Source tool for really long time called PHONK https://phonk.app (priorly called Protocoder)
It started around the same time as Droidscript but PHONK has been always a hobby project rather than a business.
I can imagine how painful might be for the Droidscript devs if that's a part of their monthly income...
This type of actions by big actors should keep us awake to protect the web with tech, companies and user diversity.
Within 20 years, you will need the equivalent of a concealed carry permit to run Linux on a computer connected to the internet.
What I find interesting is the little information they give you after a ban. Apparently if they explained the reasons of the banning then other people could use that information to find flaws and 'game the system'.
This means that, if you deliberately made something against the rules and were banned, you can then 'explain your mistake and the measures to not do it again'. But if you don't do anything unusual and simply break one of the crazy rules they have by mistake, it's game over.
P.S. If you have a blog and practically all of your visits come from a single source (perhaps a link in something popular) don't EVER use admob on that blog. You will be banned.
It's true that giving all details might lead to people gaming the system, but c'mon, a bit of details wouldn't be so bad.
This isn't some sort of fairly inconsequential website like HN or Reddit we're talking about, but literally people's livelihoods. This is like the cops walking in to your house to arrest you for theft, but they won't tell you what you stole, where you stole it, or how they know it was you. You now go to prison, have a nice day.
Perhaps they're right 95% of the cases. But in 5% of cases they're wrong, and bye-bye livelihood and many years of work down the drain.
I still own some apps that Google Play removed because they don't fit some "programs". The thing is that the apps never opted in on those "programs".
For companies I work with that spend 1 000 000+ Euros monthly on Google services it is the opposite way around. Staff from Google more or less are fixing everything, even setting up Google Analytics reports and so on.
Google will be the tell when it is time to sell all these insanely overrated stocks that we all own.
I don't understand how they can blame the publisher for this type of action. I understand they obviously can't pay out for the fraudulent clicks, but instead of banning the account, simply don't count the fraudulent clicks! What's so difficult about that?
It's like if you told a student that there was no punishment for cheating, the questions they cheated on just wouldn't count. This doesn't hurt that bad, because if you were cheating on a question you (most likely) didn't know the answer.
[1] https://boingboing.net/2012/01/10/lockdown.html
[2] https://boingboing.net/2012/08/23/civilwar.html
edit: fixed link - thanks for the bug report
When FOSS tablets and phones become competitive, I'm really interested in getting one. Maybe even before they're realistically competitive.
E.g., have a thorough public review process as a last resort (most nations are investing in cyber security anyway and this may provide a valuable proving ground) and force app-store providers to comply. Providers may oppose the verdict, but will have to provide detailed proof and concise reasoning in an appeal process.
Is this mean anybody with a grudge has an easy way of destroying any developer's revenue stream?
I simply don't trust Google to be fair in anyway, and not crush the little guy without reason.
Does this imply that Google is holding them responsible for apps originating from their platform which might also have been sources of bad traffic ...separately from their own in-app advertising?
Off topic: I won't be buying a new phone for a looong time so I can keep Termux's functionality.
You'd need a whole governance structure for your project so it wasn't controlled by a sole entity. There would need to be assurances that using your project was stable long-term. That there were adults driving the bus, and that everyone could use the bus, etc.
You'd need to provide a roadmap for everything needed to be built to replace Android, piece by piece. (I guess you could re-use sections of open source code, but some would need to be rewritten from scratch?)
You'd need to contact developers, vendors, service providers, etc, the whole ecosystem existing around smart phones, and get them on board with your project. Sell it to them as "no longer being answerable only to Google and Apple". You'll also have to provide alternative revenue sources, as they may depend heavily on Google and Apple services for their revenue.
And then you need to find people to do the work, and get paid for it.
I'm guessing all this would take at least 6-12 months to get off the ground and some serious capital.
In the same vein... question.
Google is absolutely terrible at customer support and handling these kinds of issues. I once read in a comment posted here that they apparently don't even regard issues as valid signal unless 10,000 users are affected. (I've personally always instinctively shied away from app/site feedback buttons myself, and now I know why.) I'm guessing it's because con$i$tent ridiculou$ adverti$ing revenue ("we can do no wrong") has caused the death/deselection of normal customer support feedback loops.
Sooo... could a startup, or startups, fill the absolutely massive vacuum that is being created here?
For every story that trends on HN, how many more false negatives of people being bankrupted are there that never see the light of day? :(
I can only think that this number is probably remarkably high given that stories have to trend on social media and/or popular websites, for multiple days, before a connection is made and the problem can be fixed.
Once again, the more I look at this, the more I get the impression that this is a huge hole that could be filled to great benefit.
But thinking about it, I don't think it would be monetisable:
- It would ultimately be a company taking people's money to leverage a few private contacts. It doesn't take much squinting to see this as extortion and gatekeeping, which happens everywhere but would legally be very interesting to defend (especially against a company the size of Google). :/
- The contact issues only exist because of process and organizational failure, so even if private contacts were successfully established, the signal/noise ratio was ideal, and this company did perfect triage, it wouldn't take long for manglement to hear of the situation and decree that no Google employee were allowed to interact with the company professionally
- The whole thing would have to operate under the radar to operate at all... and maybe such operations exist and are successful, we've just never heard of them. Problem.
Running the whole thing as a volunteer operation maybe sounds like it could work though.
And if issues don't get fixed until >10,000 people "notice" maybe such an operation could have noticeable presence before being acknowledged.
Just thinking out loud. What think?
For every story that trends on HN, 9 times out of 10, it turns out Apple/Google/Microsoft/Facebook were right, and the company was doing something dodgy.
The platform would require HN profile info, GitHub account details, maybe a keybase identity or two, perhaps a project website, etc, demonstrating years of organic ongoing activity, to be submitted with cases in order for them to be lodged. Basically any and every type of dev-oriented signal that would be extremely difficult for a scammer to fake.
Google would see this malware coming from Droidscript; Droidscript would not see anything in their code that could be causing it.
a user base built on such foundations is no base at all. unfortunately , only open platforms can be considered a solid enough base for building any kind of community
HOWEVER, I really don't think that's the case. I mean look at Hacker News! They built up their brand and product through grass roots efforts. Large ecosystems take notice and recognize, I think, reputation in smaller ecosystems.
When a group gets banned like this and feel it's their only hope, I'm skeptical.
My guess is either these guys are playing dumb or they don't understand why the best software engineers in the world think they're doing malicious stuff. Either way they don't appear to be ready for the "big time".
You can’t have business with Google when all the rules of engagement are set by them.
[0] : https://www.f-droid.org/en/docs/Setup_an_F-Droid_App_Repo/
Don't.
How did it get this way? How did we allow it and for so long? I really don't know. Here we are, the community involved yet somehow this method of customer [non]interaction grew out from underneath us.
*spelling edit: fire -> for
You can often hear people on here excusing this by saying "if they didn't do this, their business model wouldn't scale". Well yes. If you can do the automation and it works then you have a business at scale. If not, perhaps your business shouldn't be a scale business. As is, the negative externalities of this imperfect automation are significant.
the problem of a non-free market, in this matter, would be a government monopoly, with the same problem: they can do as they like.
the alternative to this currently is not easily applicable, and does not give the current advantages of the "big" (whether they are companies or governments the result does not change; really, it is the same).
if you think that Russia and its coming private Internet, or the American NSA security system, or even that I know ... Amazon and eBay, or Facebook and its network (not just the Social Network site, but all its additional services, and where it gets to manage what it manages), or even Chinese censorships on the Internet, are different from each other (to give random examples), think again.
then of course comes troll-boss Trump (they ban him from Twitter and other similar sites) and everyone thinks (confused) that this is not real wath I am writing in this comment.
we are beyond the conspiracy, here the conspiracy comes to life by itself, randomly, without anyone creating it; now in its own life.
who is at the top decides for who is below the top, obviously the developers of Droidscript appeal, they do not like this decision, but they are like everyone else they are subject and subject to the "big".
if you don't want big problems from the "bigs", don't support them, don't use them.
How good are Pinephones[1]? Are there better alternatives?
I used to have a Nokia N9; great phone. But it didn't support WhatsApp and I was out on the loop on the WhatsApp chat all my other coworkers were in.
Then there's things like banking apps, flight check-in apps, food ordering apps, dating apps, etc. etc. Can you do without those? Sure, of course. But if I want to order food where I live then the only option is to use an app.
No platform will have any chance of any sort of adoption unless it supports some way of running those apps. There are options here, for example Jolla/Sailfish OS can run Android apps (no idea how well that works in practice; the latest update says it supports "Android 9, and the support for Android 10 is already nicely on the way").
It's a "vendor lock-in" ecosystem that's worse than the Windows lock-in of yesteryear IMO.
Since I don't really use my phone all that much I decided to "just use an iPhone" (because it's the only phone that's not huge), even I think they're really horrible.
For regular companies, if they want to shoot themselves in the foot by not being on the web, they're welcome. It's not such a huge issue as it would be with government for example.
Also "any chance of any form of adoption" is a bit overstatment. I still use a dumbphone, and if I migrated to pinephone, lack of the kind of apps you mention would certainly not concern me. Even then, many apps have web alternatives here, or alternative GPLed clients for Linux (that includes whatsapp, apparently), that can be made native on pinephone.
(Or same where the 2 phones are somewhat multiplexed on a single screen, preferably in hardware.)
Websites.
I'd encourage more people here to purchase one, even if just to tinker with. There's so many "I'll buy one when it's ready" replies, but that may never happen if there's no money to fund the companies trying to make an alternative to Android/iOS.
Android is opensource, and is technically really great. There is a great opensource community of people that are very capable in this area, and supports already the vast majority of devices in the world.
You only need to get rid of Google. Which many custom Android provide. Personally my smartphone is a Pixel 5 (IMO best smartphone currently available that fit in a hand), running Android, without any Google application. I'm very happy with it, and from what I discussed with Pinephone users, it's lightyears more usable than what exists for Pinephone.
Android itself might be really good, but it's pretty obvious that deGoogled phones have a strong chance of being functionally useless in the future.
Their product line does not really inspire much faith. I can't say I've bought a device in the past 10 years which has dead pixels on the display. To me, this is a defect, given that I can pick up a device, overwrite Windows with Linux, and have a device without dead pixels.
Though of course as it is a much smaller venture, you can’t hound a sales rep until they accept to repair it nonetheless.
How do you know if you're the target customer for a PinePhone? You read the 'dead pixels' warning and think 'I don't care... I want a Linux phone'. People who would find a couple dead pixels unacceptable would also likely find the features and functionality of it unacceptable as well. For months it couldn't take pictures or (reliably) make phone calls/text.[1] Now we can take poor quality pictures and have marginal phone functionality and think life is good! It's not that we're nuts (ok, maybe a little ;-) but rather that we accept this a long term process/effort and not something that will be even remotely perfect anytime soon.
[1] Hell, mine will never be able to reliably work with most USB-C chargers due to a hardware bug in the first iteration. Didn't care... I want a Linux phone! (and I'm too cheap to replace the board, I'll wait for a v2 to fix that and other issues)
[0]https://www.fxtec.com/ [1]https://puri.sm/products/librem-5/
I like mine, but the ancient CPU needs a serious upgrade. There's also the Librem 5, but it looks like they're heavily back ordered.
If this droid script equivalent were going to start reading my emails watching me through the camera, reading my clipboard, or tracking my real world location, I’d definitely want something that alerted me to that before it happened.
Android has supported permissions since at least Froyo (2010), and these permission requests were made on-demand/runtime rather than pre-install with Marshmallow (2015). So Droidscript would be unable to do any of those things (except reading the clipboard) until you explicitly granted those permissions to the app.
So just get serious about using alternate stores, which the platform fully lets you do (f-droid, amazon app store, whatever).
Overall I would agree, but I don't see how this specific example has anything to do with that sentiment.
You still have control of your device and can install DroidScript from APK or F-Droid, it was only removed from Play Store, Google's own store.
Obviously this is awful for DroidScript themselves, but you as a user didn't really lose any ownership over your phone due to this specific issue.
I don't really care what software is ran in my truck, as long as it works (And that's why I'll not buy a Tesla). It's a phone, use it to call text and guide and browse some internet. That's it.
I mean, exactly what recourse do you think you'll have once it stops working..?
You'll sell your not working truck (to who?) and buy a new one (that is also soft-locked because it was the only way to stay competitive?)?
Right to Repair: https://www.youtube.com/watch?v=nvVafMi0l68
With that said your truck analogy isn't perfect. Your truck will last as long as you keep it going. That can be 20 years or more. It would be more like having a truck that the doors do not lock anymore after 2 years and you cannot fix that you must buy a new truck if you don't want thieves.
I use it for chat apps, phone calls (usually via chat apps), and occasionally wandering around Imgur when it would be socially awkward to not be on my phone.
The rest of the time I've come to appreciate being present in the moment.
So yeah, I'm looking at the new generation of Linux phones with interest. If I can run the chat apps in a browser OK, then I think it might work for me.
Maybe it's time to call phones what they really are: pocket computers with a legacy voice call functionality that is increasingly irrelevant to anyone who isn't a Boomer.
Now, regarding the locked-down of both iOS and Android ecosystems, I can see both points of view. The majority of ordinary users need to be protected from increasingly sophisticated malware stealing their online banking credentials or other mischief, but power users also need to do whatever they want to do once they've signed a disclaimer
But it does suck if there is no legitimate way to release an IDE targeted to run on a mobile device via the Google Play Store.
As with privacy (Facebook privacy settings, cookie boxes), it's easy to bamboozle the general public with complexity and then interpret their confusion and (violated) trust as consent.
I like what they are doing, but it is definitely not mainstream products.
The bigger point is the system is clearly broken, but how in the world can you fix it?
There are plenty of other companies that have many more humans in the chain where problems like these eventually get resolved once proper appeals are conducted or someone physically walks into a business and participates in whatever verification method is required.
The idea that Google is somehow special is laughable. Compared to some other industries that are directly consumer facing the number of apps and developers is actually small.
Also, they're not doing it without pay. They're taking a 30% cut from an industry approaching a trillion dollars in annual revenue. Again, the idea they can't solve this problem if they were willing to spend the money is absurd.
The question is how we can break the cycle in favor of hackers rather than in favor of big corporations.
Highly recommend.
I'm ready for the detachment from Google. This is why I got an Android.
Damned if you do, damned if you don't. Which to choose? About ready to just burn all of my electronics and live in a damn cabin.
https://www.theregister.com/2021/04/27/droidscript_google_ba...
From one of the emails they got from Google:
> We don't allow apps with any code that could put a user, a user’s data, or a device at risk.
Maybe they think the ability to execute arbitrary code is too powerful of a feature?
Yes, probably.
But maybe they can act and speak like humans, maybe even make a phone call before just deleting without notice a well established 7 years old app with more than 100k users, cancelling all revenue from user's subscriptions, and all that while sending bot-like mails just saying that they can't give more information about why they are killing an organisation.
I think this is really serious. A respected business is going to be shut down, real people are going to be fired and Google isn't even able to answer to an email asking why it's happening ?
Trying to see it from Googles point of view though. Perhaps there is a useful distinction to be made between end-user apps, and apps and functionality targeting developers. There is developer tooling to be found outside the Play store. Far away from the general audience and the risk of causing them security issues.
I can't say I agree with it, and Droidscript could well be a godsend to somebody making good use of it.
There should be an avalanche of truly malicious apps and related dev malpractice they could root out from their platform before this.
IIRC Apple even went to extremes and banned browsers which do not use their own JavaScript interpreter.
This presents a component which Droidscript developers can use to display AdMob ads in their apps. AdMob appears to be a Google property.
Some interesting quotes:
> The AdView shows advertisement banners from the popular AdMob platform.
> Ads are not touchable when running in the DroidScript IDE.
So there's a confirmed experience where actual ads are displayed in a non-standard way? Any guesses if this violates Google's ad fraud policy?
> Warning: Don't repeatedly click on your own ads unless you are using a valid testId, or Google may suspend your Admob account!
So it's the responsibility of individual users to correctly configure their ads to avoid committing click fraud (accidental or otherwise).
I can see how Google might come to the conclusion that Droidscript has built a platform for committing click fraud, whether that's their intention or not.
This seems incongruent with the wording in the original post:
> they ask you for a "complete analysis of your traffic or other reasons that may have led to invalid activity in your appeal". Well, we had no idea what could have caused this and couldn't think of anything we could do
Really? No idea?
Edit to add: I get that there's a larger debate here around the general fight over device ownership and access to general purpose computing. I'm side-stepping that because I don't have much to add. What I do believe is that this particular piece is hardly concrete enough to bolster the case against Google.