Google fined €100M by Italian antitrust over Google Play abuse of dominance
repubblica.it
repubblica.it
If this company (ENEL) wasn't a huge state-wide electric company (inheriting their power and ties from the previous state-owned monopoly) how many chances do you think they had to fight?
As a small fish you're just dumped.
https://www.coindesk.com/coinbase-bitcoin-app-apple-app-stor...
https://venturebeat.com/2014/12/14/bitcoin-wallet-coinbase-n...
This is what is wrong with walled gardens, laws should be made by lawmakers, not Apple.
I'll take it down a couple of notches to make it easier: HN could serve every user under the Sun and still be entitled to have a (perfectly legal) rule that says "Don't solicit upvotes". No amount of "oh but at their scale" will change that.
Apple, Google, Facebook, etc. or any company actually do not write laws (they lobby and bribe for them but that's a different can of worms). They just write their own rules for their own products and services. Those rules have to be within the law and even if common sense and current evidence may say they break the law, it's up to a judge in an antitrust lawsuit to decide.
As I tried to explain above, HN is free to have a rule which says "Don't solicit upvotes" but they can't have a rule "Don't talk to women". The simple answer is because no matter what that rule says, tit's not a law, it's just a rule which can be applied only until a judge decides it's against the law.
Other folks are also noting that, because humans are sometimes bad at evaluating each others' intent, it is probably a good idea to attempt to make one's intent clear if going this route, lest you annoy the gatekeeper.
b) I don't know what qualifications you think an app reviewer needs. They are not looking through the code but simply playing with the app on a range of devices.
c) It is only a few hours for updates. Initial app submissions often take days/weeks and are very thorough.
There was a news here where malware was found on the Apple iOS store, and Apple changed their mind in the last moment and refused to inform the victims.
The reality show you (if you want to see) that
- malware happens (you can't make automatic analysis code to detect all possible issues )
- Apple users will mostly have a wrong image of the Store security due to Apple not informing victims when bad things happen and a big PR budget to paint a fiction.
The reviewers are there mostly to make sure you do not put a link to your website and buypass the Apple payments and make sure that the app does not crash and use the approved UX. I really hope you are not that navie to think they are opening the app in a debugger and checking for weird code.
As for code, they run relatively extensive automatic tests to detect whether private (banned/undocumented) APIs are used, I don’t know how effective they are at catching malware, though.
This was done on Windows too, you were not forced but any business would sign their application, otherwise they user would get a scary warning that the developer is not know.
>As for code, they run relatively extensive automatic tests to detect whether private (banned/undocumented) APIs are used, I don’t know how effective they are at catching malware, though.
The sandbox should solve this, unless the Store bans APIs only for some or worse there are hidden APIs that should not be used and the sandbox is to dumb to notice you are using them , then this would be security by obscurity.
This topic is different then most of the other topics about side loading apps, in this case the giant refused to allow an application on the store, or allow access to an API without a good enough reason. This reveals again that rules are not fair and is very hard to get justice for the users.
I would suggest a law to force the giants to give always an exact reason of why an action aganst someone happened, I have personal experience where an account of mine was banned and I have no way to appeal and I have no idea what was wrong. The giants are shitting on us all, as long as the numbers of the victims are low enough some flashy ads would solve their PR problems. We need something to make it fair for the users, make it easy to get our justice.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32...
This regulation specifically looks at platform-to-business relationships, and requires actual disclosure of reasons, notice periods, etc.
What we need to see are cases using this law (as it's pretty clear from article 4 what business' rights are), so it becomes too costly to trample over businesses in an unaccountable way. Once the cost of human intervention and support is lower than that of their legal bills and penalties, human support and intervention will return. Platforms are getting away without humans in the loop as a result of the lack of cost impact to them of a mistake. Once it hits their bottom line and gets their counsel in a pickle, it will start to change rapidly to preserve their bank balance.
The whole thing is a scam.
Which leads to the account being banned.
> and this sometimes comes from binary dylibs that the developer didn't write.
Which are detected through analysis if they are common spyware.
>The whole thing is a scam.
Clearly not.
>Which leads to the account being banned.
Only if it gets noticed.
>> and this sometimes comes from binary dylibs that the developer didn't write.
>Which are detected through analysis if they are common spyware.
Facebook got away with it for many years.
>>The whole thing is a scam.
>Clearly not.
If it weren't then they would let people choose to use the App Store. It only exists to protect Apple's services from competition.
True, but they are getting better at noticing.
>> and this sometimes comes from binary dylibs that the developer didn't write. >Which are detected through analysis if they are common spyware.
> Facebook got away with it for many years.
You know about that because they were stopped. And since then Apple has tightened the rules and stepped up detection.
>>The whole thing is a scam. >Clearly not. > If it weren't then they would let people choose to use the App Store.
No, because that would enable social engineering attacks once again.
> It only exists to protect Apple's services from competition.
This is straight up bullshit. You keep saying it, but it’s false at face value.
Millions of scams have been stopped.
https://www.apple.com/newsroom/2021/05/app-store-stopped-ove...
>You know about that because they were stopped. And since then Apple has tightened the rules and stepped up detection.
Nope, lots of people knew it was happening for years before Apple actually stopped it and it happens with other libraries still.
>No, because that would enable social engineering attacks once again.
People still get tricked into installing CA certs which is just as effective since everything has to be done in a browser due to the App Store restrictions. So no this hasn't prevented social engineering attacks, it's only changed them and it's come at an extreme cost.
False. Once a scam has been detected, the developer account can be disabled, which adds cost to new attempts, unlike windows defender.
> Nope, lots of people knew it was happening for years before Apple actually stopped it and it happens with other libraries still.
That doesn’t change anything.
>No, because that would enable social engineering attacks once again.
> People still get tricked into installing CA certs which is just as effective since everything has to be done in a browser due to the App Store restrictions.
> So no this hasn't prevented social engineering attacks,
A false statement. Many kinds of social engineering attacks have definitely been prevented.
> it's only changed them
Here you admit that significant classes of attack have been prevented.
Your argument is that because not all attacks have been prevented, there is no value in preventing attacks.
This is an obvious fallacy.
>Here you admit that significant classes of attack have been prevented.
I don't think people care whether they lost things on their phone because of malware or because of a fake CA cert, the attack works pretty much the same way and has the same result.
>False. Once a scam has been detected, the developer account can be disabled, which adds cost to new attempts, unlike windows defender.
You don't need a dev account to distribute malware in dylibs.
>> Nope, lots of people knew it was happening for years before Apple actually stopped it and it happens with other libraries still.
>That doesn’t change anything.
It means the App Store doesn't stop malware before it's able to exfiltrate data from large numbers of users for long periods of time. That's the justification for it.
Ok, but that’s not what you said before,
> (completely forfeiting ownership of personal computers by anyone that wants to participate in group chats with iphone users.)
This is false. There are many group chat programs, that people use cross platform and they are more popular than iMessage.
Nobody if ‘forfeiting ownership’ of anything anyway - that’s just an ideological tautology.
If you you want a platform that can do both iMessage, and install apps without review, then you can use a Mac.
So literally no part of your statement is true.
>Here you admit that significant classes of attack have been prevented.
> I don't think people care whether they lost things on their phone because of malware or because of a fake CA cert, the attack works pretty much the same way and has the same result.
They may not know or care about the technical details but they do care about the risk level, so this is a moot point.
>False. Once a scam has been detected, the developer account can be disabled, which adds cost to new attempts, unlike windows defender.
> You don't need a dev account to distribute malware in dylibs.
No, but you do to distribute it to App Store users.
>> Nope, lots of people knew it was happening for years before Apple actually stopped it and it happens with other libraries still. >That doesn’t change anything.
> It means the App Store doesn't stop malware before it's able to exfiltrate data from large numbers of users for long periods of time. That's the justification for it.
False. It just means that some apps slip through the protections. It doesn’t say a thing about the ones which are stopped.
This is a repeat of the earlier fallacy: “if the protection doesn’t stop all attacks then we don’t need the protection”, which is obviously not true.
>Ok, but that’s not what you said before,
It's not worth the cost IE a scam, literally what I wrote in my first post.
>If you you want a platform that can do both iMessage, and install apps without review, then you can use a Mac.
Ah yes let me just go ahead and fold up the macbook so I can put it in my pocket. If you want to be included in a group of iPhone users that use iMessage you must own an iPhone. Apple knows this and that's why there's no web interface for iMessage.
>No, but you do to distribute it to App Store users.
Someone does, but it does not need to be the dylib author.
> just means that some apps slip through the protections.
This wasn't some, it was happening (and likely still is) on a massive scale and affected most popular apps.
>This is a repeat of your earlier fallacy: “if the protection doesn’t stop all attacks then we don’t need the protection”, which is obviously not true.
Forcing the "protection" on everyone, despite the extreme cost, is wrong. Especially since the "protection" does very little to stop this kind of attack in practice. Not a fallacy, it's not worth the cost IE a scam.
This is true but also meaningless. If you want to be included in a group of Android users who use Facebook messenger, you must own an Android device. If you want to be part of a group of Windows users who use signal, you must own a Windows machine.
All three are true, but presumably you can see they have absolutely nothing to do with app review.
There is no extreme cost.
You say the protection does very little - but that ignores the numbers: https://www.apple.com/newsroom/2021/05/app-store-stopped-ove...
>App Store stopped more than $1.5 billion in potentially fraudulent transactions in 2020
They never justify or source this, they literally just pulled it out of their ass.
>Apps rejected for containing hidden or undocumented features
A lot of those are probably development tools that users legitimately wanted.
>Other rejected apps
Good job they blocked some stupid obvious scams. The web is full of these so the users careless enough to fall for them will still get scammed. I don't see how that justifies the ridiculous situation they've created.
>credit card numbers are never shared with merchant.
The whole point behind credit cards is that you don't care if someone steals the number. Otherwise everyone would be using PKI instead of shouting an ID number at eachother. So yeah, thanks I guess for saving some banks money but that does little to help the end user.
You do realize they have the data, right?
>Apps rejected for containing hidden or undocumented features A lot of those are probably development tools that users legitimately wanted.
You never justify or source this, you literally just … … I think you know how this goes.
>Other rejected apps > Good job they blocked some stupid obvious scams. The web is full of these so the users careless enough to fall for them will still get scammed.
No, people trust the App Store more than they trust the web. That’s the whole point.
> I don't see how that justifies the ridiculous situation they've created.
The situation where consumers are happy to pay for software because someone is weeding out scams?
>credit card numbers are never shared with merchant. The whole point behind credit cards is that you don't care if someone steals the number. Otherwise everyone would be using PKI instead of shouting an ID number at eachother. So yeah, thanks I guess for saving some banks money but that does little to help the end user.
I guess you’ve never had a card stolen or been the victim of fraud. Eventually you can get your money back in most cases, but it can take a long time and be a huge hassle.
Again you argue against beneficial protections for no apparent reason.
Nope, you can use Facebook messenger from an iPhone or even a Pinephone. Apple is running the only popular chat app which demands you use only their hardware.
> If you want to be part of a group of Windows users who use signal, you must own a Windows machine.
No you don't need a windows machine for this, just something that can run signal.
>All three are true, but presumably you can see they have absolutely nothing to do with app review.
They do because anyone participating in a real time iMessage group is forced to put up with whatever software policy Apple dictates on their phone.
>There is no extreme cost.
The cost is that you have to hand your ssh keys over to closed source apps to use ssh, you can't use decent chat applications because the app author has to have a full-time ops team (distinct from the team managing the chat server even though they already have the resources) managing the F**ing notification server because those are Apple's policies. You can't run most desktop apps because of licensing restrictions. There's almost no community maintained software so almost everything on the phone either costs a ton or harvests every last bit of data it can find (which is typically beyond what Apple supposedly allows) and anything remotely useful is unprofitable to maintain.
Quite simply: the cost is that almost all the software is absolute shit.
> They never justify or source this, they literally just pulled it out of their ass.
They pulled it out of their data.
> Nope, you can use Facebook messenger from an iPhone or even a Pinephone.
Exactly - as I said, there is no shortage of cross platform apps you can use to do group chat.
> Apple is running the only popular chat app which demands you use only their hardware.
So what? There are many options. Nobody has to use it.
> Quite simply: the cost is that almost all the software is absolute shit.
Not for most consumers.
If you are someone who insists on inspecting the source code of SSH apps, I applaud you.
You are one of a tiny minority of specialists who can do this. End users in general quite obviously cannot.
That’s why they buy a consumer product which doesn’t require them to.
>You are one of a tiny minority of specialists who can do this. End users in general quite obviously cannot.
"Experts" inspecting the source code for apps allowed for some bare minimum security checks. Companies buy out smaller software projects and add spyware to them fairly often (on the iPhone this usually happens via dylibs rather than the App publisher purposefully doing it.) and Apple has removed one of the only ways to catch this without an adequate replacement. The effect is much worse overall security.
Yes.
and Apple has removed one of the only ways to catch this without an adequate replacement.
No - these can be scanned for during app review.
> The effect is much worse overall security.
No, consumer software outside the App Store is rarely examined by experts who have access to the source code.
This certainty is not a general practice.
The Debian repos are not a software store.
I agree. This is why Apple is offering ‘login with Apple’. It’s safer than entering credentials.
> this happens all the time.
No it doesn’t. There are a few rare cases, but many more are stopped by review.
> Having some contractor spend a few hours poking at the GUI doesn't mean consumers aren't required to be responsible.
No, but almost nobody is dealing with SSH keys, and those who are should know how to deal with them.
These are consumer devices - if you need a device you can inspect the source for, these are not for you, but clearly almost nobody can do that.
https://developer.salesforce.com/docs/atlas.en-us.packagingG....
[Edit] I should add that an annual listing is $150 and the initial security review is $2550, so no free cheese either.
Small developers don't get same access as big developers and their apps get klled for smallest reason just by having some obscure policy or change in policy.
Developers don't have same access as Apple google eg: Screen Time
Hence, security theater.
https://news.ycombinator.com/item?id=26888190
A scam is when you've been deceived or defrauded.
If you consent to pay $10 a week for an app that doesn't provide what it claims to, that's one thing, and that should be actionable. But if it does what it claims to, not liking the price does not equate to being a scam.
At best you get to take your marbles and refuse to play entirely; which isn't exactly a reasonable long term strategy.
There should be competition between app stores.
Compared to Windows as a case study of what happens when you let users install anything they want from untrusted sources, it seems that the app stores do fairly well at culling obvious malware. At least that's what I experienced comparing the number of time I had to cleanup a friend or family member's computer filled with malware and browser toolbars vs. iphones and androids.
What you don't see, is all the apps that steal the user's data.
Curation obviously helps but it's difficult to measure to what extent.
True
> What you don't see, is all the apps that steal the user's data.
Exactly this. Apple now has policies against fingerprinting etc. which can’t be prevented by sandboxing.
> Curation obviously helps but it's difficult to measure to what extent.
https://www.apple.com/newsroom/2021/05/app-store-stopped-ove...
On the other hand, you can't be completely sure that sandboxes on mobile devices don't have actively exploited security issues as there are many ways to bypass app review from discovering the true functionality of an app.
Anything widely known gets fixed quickly. There are plenty of holes in browser sandboxing. The number approximately doubles as soon as you look at anything !Chrome, too.
To exploit those you need to get past app review in the first place, though, and the type of code that can do stuff like this for the most part sticks out like a sore thumb when subjected to static analysis.
Most of Apple's checks around this stuff are automated, I understand, and are applied to every submission instantly.
Basically, for certain classes of apps, macOS is now already taking the iOS "App Store or gtfo" model.
https://www.macrumors.com/2021/05/07/app-store-35-percent-of...
Compare that to Google Play
The last article explicitly mentions that most of the malware needs iPhone to be jailbroken or the app to be installed outside of the App Store, which kind of proves my point.
The research by Panda Security also showed that the ratio of malware on Android compared to iPhone is 50 to 1.
https://www.pandasecurity.com/en/mediacenter/mobile-security...
Drivers licenses aren't only about competence. Sure, there's a test. But, there's also the ability to revoke a license.
This is not supported by the article at all.
> They only arbitrarily restrict choice,
This statement is total bullshit. Even if a few scams get through, and even if Google has abused its store, it’s not only arbitrary.
> they don't actually improve security (if any, that's provided by the sandboxing, not by the store "review").
No, Sandboxing cannot stop large classes of well known social engineering scams.
https://www.apple.com/newsroom/2021/05/app-store-stopped-ove...
Here is data proving that walled gardens do in fact protect consumers greatly.
You don’t have to like them, and of course there are downsides, but let’s not pretend there are no benefits.
The real problem isn't the wall, it's the gate. Adwords, Android, FB, Twitter, Spotify, Steam... those are all about controlling the gate. At that point, others do the work and the gatekeeper makes the profit.
That is, you pretty much expected to download software and have it trash your machine on a regular basis.
Things are better today, half of that is people realizing that it has to get better ("national security" today, but it's much bigger than national in scope) and the other half is people realizing it is possible to get better, and Apple's App store is one reason for that.
---
Improvements in HW and SW are what helped Microsoft, not the Microsoft store -- since Win 8 I think I've had a Windows machine where it was really possible to download third-party apps from the Microsoft store about 10% of machine*years. Part of that is that it was disabled on corporate laptops I've used, the other part is that the metadata database for the Microsoft store gets corrupted on a regular basis.
I've contacted Microsofties about that and what they tell me is that I should delete my account on my computer and then reinstall the account and spend or two work days reconfigurings all of the "normal" Windows apps that I used on an everyday basis (Firefox, Jetbrains, Creative Cloud, Python, ...) I tell them "there's a procedure to rebuild the metadata database because I've see the database get rebuilt when the six month OS updates happen" and they act as if they didn't hear anything.
For that matter Microsoft seems to be a counter-example to "the power of monopoly".
For instance there are several third-party gaming "app" stores for Windows such as Steam. One thing they all have in common is that they work.
When Win 8 came out DropBox and a number of imitators had apps that worked for Windows. There was one DropBox imitator that didn't work, and that was Microsoft's OneDrive. Office was jiggered to push you to save files to OneDrive, but if you were saving files to OneDrive you could frequently NOT BE ABLE TO SAVE FILES AT ALL!
To add insult to injury, this would also trigger harassment from Word the next time I open it about the files it didn't let me save. It's like this
https://tonyortega.org/2021/04/12/scientology-answers-danny-...
I guess it proves that running an "app store" without brand awareness doesn't lead to industry dominance.
For example, you can give your grandma an iPad or a chromebook, and there’s very little chance of her accidentally installing x nasty malware.
Give her a proper laptop, and at any one time she’s about 6 clicks from something dodgy, especially if she’s on social media.
I’m against walled gardens, I just disagree that there’s no security upside to it
As OP points out you do not need an app store monopoly, you just need adjustable device settings.
I find this much preferable to the situation on Android.
Should this say “…ruled it was because…”? I can’t figure out the reason for the fine otherwise.
To "rule out" is to use a ruler to cross a line through something in a written list of items, thereby eliminating it from consideration.
But as for the meaning, that's what it's always meant when I've heard it said. So it definitely means that, at least colloquially.
This will just encourage them to kill all the genuinely useful stuff they do because honestly their legal teams can't spend hours vetting all of these small features and apps which provide immense value to certain subsets of users. And for what ? The shitty JuicePass app with under 2.5 rating.
Distracted driving is a big problem, but my experience is that people have superstitious ideas about what is safe and what is dangerous in areas like that.
You can certainly do experiments, and the conclusion you seem to reach is that you're in a lot safer with a car that has physical buttons for the audio, heat, etc. (Had "luxury" carmakers been on the ball five years or so they would have kicked the infotainment systems to the curb and would be giving customers a premium experience today -- how many $1000 does Android Auto knock off the resale value of your car?)
I want Android Auto to know what type of plug I have and Google Maps to just show me all compatible chargers. And possibly handle payments. Like what Tesla has been doing for years [0].
Now there's some government developed app to duplicate that functionality but only for their special snowflake network and only in their jurisdiction. Just crossed the border from France to Italy? Install this app (is it in international app stores as well? Do I have to switch my phone to that country?). Ohh now it has it's own map but no navigation so I'm switching back and forth between that and Google Maps.
Of cause integration and ease of use become harder if there’s multiple networks and apps, but that’s separate from the question if they should be allowed by google.
- app developer (here, the giant state-backed energy company ENEL) complains to antitrust authority about getting denied access to store
- authority asks Google to justify itself
- Google makes a very weak argument, refuses to disclose the internal decision-making process that resulted in blocking access
- authority goes “oh really?”, proceeds to slap Google with a fine
Now Google can decide whether they want to take this to court (which, being Italy, will probably take 5 to 10 years); pay the fine and allow ENEL in; or just ignore the ruling and dare the state to slap them harder (which again, would probably mean a good 5+ years will pass before sanctions are actually enacted, but might result in higher fines).
[1] https://ec.europa.eu/info/sites/info/files/justice_scoreboar...
But what I meant to say is that one political side have complained about judges for 30 years, which has impacted the public opinion.
See the effects Trump has had on institutional trust in the US, and make it last 5 mandates.
wouldn’t a plurality make them the controlling shareholder?
So it means that they have a lot of say, but they can be overridden if every other shareholder disagrees.
Though looking at this a large but not 50%+ stake can also be "controlling": https://www.upcounsel.com/controlling-shareholder
But controlling looks to more about how much voting power and influence you have rather than how many shares, because remember companies can have different classes of shares.
You find that adwords engages in a blatant "monopolistic abuse" in some specific sense. In the Adwords EU case for example, Google was both monopsonising (google search) and monopolising search advertising. But, the actual violations are specific, like exclusivity requirements and other technical infractions buried in their take-it-or-leave-it contracts with "partners.^"
Google get a fine. They deny culpability. They pay a fine and move on. Whether it's 100m or 2bn doesn't really matter. Google are demonstrably willing to pay far more (eg acquisition, browser kickbacks, etc.) to maintain a monopolistic position. Besides minor tweaks, there's no reason for them to change.
What's the point? Antitrust can't be useful as a violation-fine paradigm. These cases/fines don't affect the monopoly or free the market in any useful sense.
IMO, we need some way to declare a company "Big" and apply special rules to them. If those rules are onerous, that might create some organic pressure to split and/or help smaller incumbents compete.
There is no point to antitrust if its totally reactive, handing out fines for moving violations. The point of antitrust is trust-busting, to affect market structure. The point if to have a competitive market.
All the 1990s stuff is playing out. Just like the MSFT case, we see that operating systems, browsers (now app stores) are monopoly prone and that it's a big deal. On the other side, the 90s "portal" concept is fully realized now. In the digital economy, controlling the windows of consumption is everything. None of the costs, all of the profit... literally all in a lot of cases.
^Newspapers didn't have the advantage search partners had in their monopoly claim, because Google doesn't have agreements with them. No contract, no abusive clauses. The take it or leave it offer is "give us your content for free, or go away." Formally, Google isn't even doing business with them.
Past a point, they should be regulated like an utility.
I'm torn on that though. EG, what would it actually mean if FB or twitter became "regulated like utilities?" Interoperability? Portability? IMO, these are pretty finicky problems for a regulator. I think it would likely look like the mandated personal data dumps we have today. Some clunky feature that few use, and don't change the structure of the market. Useful transparency, but not really game changing.
Regulated equal access? Court-like proceeding to confirm bans? I'm not feeling it. I suspect it will entrench monopolies further.
A Telecom or EnergyCo is fundamentally different from a FB or Google. Regulators needed to make sure everyone had access, because it's always more profitable to just exclude certain people/areas. Prices are an issue because infrastructure monopoly. Also because government/regulators typically fund a lot of the capex.
There is almost no cost, marginal or fixed, associated with instant messages, shares, likes, links, etc. If Facebook and Twitter folded tomorrow, we would still have plenty of all of these because they are not scarce. Maybe there's a case for cloud computing as a utility, but even here I'm hesitant.
Enough with analogies to 19th century monopolies. Platform monopolies should be regulated as platform monopolies, not utilities. New thinking.
In any case, google is the perfect target for actual trustbusting. Separate search from adwords and android. Ban default buying. Ban mergers.
The old challenge was (eg) trust busting steel without harming the actual production of steel. Today's problem has little to do with production. It does have a lot to do with share prices. Is there really an appetite for turning Alphabet from a $1.5trn company into a $150bn company?
The EU's initial proposed version of the "Digital Services Act", requires that when a service takes down information that they think is "illegal" or incompatible with the terms of service, They are required to provide the "facts and circumstances" used to arrive at that decision, as well as reference to the specific term of service they think is violated, and why they feel the information violates that.
Furthermore, they must provide an appeals mechanism for both information takedowns and any account suspensions/bans associated with them (and besides things like non-payment, I'd bet the majority of account suspensions/bans on online services are due to some posted content the company finds objectionable).
Lastly, if the internal appeals process fails to satisfy the user, the user initiate a what is basically an electronic binding arbitration process with a certified " out-of-court dispute settlement body" of the user's choosing, with this body having the power to overturn the companies decision.
That last part sound an awful lot like "Court-like proceedings to confirm bans".
I suspect the final law may not be as pro-consumer in these areas as the initial draft is (many big companies will not be happy about this part of the law and will try to kill it off).
If it does survive it would be much better then all too common: "We are banning you because we think you broke an unspecified part of the terms of service. We won't be more specific because we don't have to be, and are scared that people trying to break the rules could learn how they got caught. We won't even tell you that this was a fully automated process with no humans involved, that gets things wrong x% of the time. There is no appeal, unless you can get Twitter or the news media sufficiently riled up against us."
I suppose we'll see how it works out, assuming it does become law. There is devil in the generalities here, but plenty of devil in the detail too.
Detail-wise.... Compliance, currently, is the art of ticking boxes while not changing anything fundamental. Too often, politicians and advocates have their eyes on the spirit of (proposed) laws while corporations and their advocates put their eye on how "compliance" will actually work procedurally. The latter approach is more effective.
That doesn't mean no goals are ever achieved, but it does dampen a lot. EU transparency laws, right to be forgotten and such are good examples. They might establish moral rights, but they don't affect really achieve big practical goals.
Generality-wise... I think the problem for (eg) free expression is the platform oligopoly itself, not their corporate policies. That's not my main concern here though. My main concern is: These laws are only necessary because monopoly. The danger is that the laws entrench monopoly, by applying them unnecessarily to smaller platforms.
That said, we'll see when/if it happens. Thanks for the info.
Boolean searching works. Go back to a library catalog sometime and be amazed at how quickly you can get relevant results when every Tom, Dick, and Methuseleh aren't shoveling extra irrelevant feces into the index.
So Google has created incentives (via ad embedding in user-sites) for entities to generate content and compete with each-other for who can show the most ads. This in turn "pollutes the index" as the other poster phrased it, which makes it more and more difficult to find actual real (unique?) content, which then Google turns around and supposedly "helps" us with.
Let's be honest. Despite it's surface-level gigantic scale, the internet is actually very tiny when it comes to real genuine content. My wild estimate is that 99% of it is spam. Even in the case of user-generated content, for every genuine blog where someone shares their thoughts and unique insights or content, there are a thousand blogs which are just there to get ad-views by generating any content that might get someone to look there. I can't even find the former type of blog/site anymore. The only place I still encounter those on occasion is when it's linked to from HN. And the ones I do encounter that way, I find that even when I try to, I can't find it via any sort of generic search (i.e. not cheating by using the site name / author / unique phrases).
Splitting Google up won't fix this.
I only see this sentiment here on HN, along with many other shitty takes about how pure the internet used to be. Are you talking about that era when opening the wrong search result would bombard your screen with millions of popups and install 20 toolbars on your machine?
Please tell me when this magical time of no spam in search results existed? 1995?
After a while you'd start to recognize the Web rings. The "just link" pages became extremely obvious after a while, and you could generally reliably get the same results regardless of where you searched from or what you were doing when the time came to search. You had far fewer syndication mills, and you could even find resources reliably.
The net was a reasonably navigable thing even to children doing school research. Nowadays, I have to explain to kids all the myriad pitfalls that exist nowadays, when they look up something, ho back a bit later, and can't find their resource anymore.
And that's just the bloody legit stuff. When you talk malware, we're in a completely different world nowadays.
Would they make less money? Yes, probably. It's hard to say how much, but it would still likely be enough to run Google.
I think it's easier to understand the paradigm with Twitter or FB, since they're simpler. Facebook currently makes about $100bn pa from ads. Circa 2015, they were operating profitably on about $10bn ad revenue. Twitter has had a similar (more modest) trajectory. They spend a lot of money running FB & Twitter, because they can, but there's no reason to think FB or Google Search on far less revenue than they bring in currently.
There are versions of what I'm suggesting that likely affect revenue moderately, and versions that could hit harder. IMO, in either case, I don't believe there is any meaningful consumer harm or ill effects outside of FB's shareholders or perhaps employees.
This isn't true of all monopolies/sectors. It's true of FB, Google, maybe twitter.
Is this arbitrary guess really worth risking the whole farm?
That said, I think the risks are way smaller than previous era's trustbusting. I like FB as an example, as I said. I'm pretty confident that FB would be pretty much the same on far less revenue because they were pretty much the same on less revenue in recent years.
Comparable social media services run of far less revenue (scaled whichever way you like). You can also look at their accounts, which reveal a lot. The simplest clue is profit margins.
If we're wrong... one social media service declines and another takes its place. Personally, I see very little risk. The actual risk, IMO, is not really about keeping these services viable. There no "shit! I broke auto-manufacturing and now we don't have cars" risk.
It's about share price. Smallish declines in revenue can mean big declines in profit. Any decline in revenue can lead to a collapse of share prices, regardless of profit. The big techs are a big part of the S&P, and high profile. Quite a lot of the S&P's value relates directly to monopoly, so antitrust (IMO) directly conflicts with equity values... and things could get "macroeconomic" from there.
All that said, I'm not advocating anything intentionally destructive. Google is, I suspect, expecting to be broken up eventually. I think that was part of the Alphabet restructuring logic.
The primary objection that comes to my mind, in the vein of your comment,is a hayek-esque information argument. A Hayekian logic though, is totally incompatible with paragraph 5 above though, and I'm quite confident about that... so I don't know where it fits in.
They would just be Google ads customers, like any other website, and they would get paid for displaying ads.
(I'm sure the roaming fee limits played a big part in this, because it effectively allows any mobile operator to resell data at the wholesale rate, or even below it because data is usually sold in packages that are rarely used up in full.)
Why not allow the market to be more inclusive? This will help create exactly the competitive pressure that we all benefit from.
There really isn't one "theory of monopolies" that is useful in all times and places. Social Media is not Telecom or electricity. Amazon is not a railroad.
Trustbusting is an anti-monopoly strategy, and it doesn't really work in spaces where monopoly is unavoidable.
And regarding working well, aren't a lot of people in favor of municipal broadband (an utility) vs Verizon & co. (oligopoly, not even a full blown monopoly)?
Careful though. A monopoly may abuse its position, which is bad, but a big company may be big because they are good and people use them, which is good.
The general problem I see here is how you slice the market to say a given company has a monopoly. It sometimes feels like those going after large companies try to slice the market in such as way to say they are monopolies, when other slice it in another way to show that it's not. Which slicing is "correct" is really hard, especially when markets shift relatively quickly.
I disagree. When you look at a company that is dominant in some part of the marketplace at a given point it time, you need to understand how they got there. The monopoly poster child Standard Oil rose-up when there used to be many more oil processing companies, but Standard Oil was able to do things for cheaper because they used more byproducts from the oil to create different products (which let them sell things like lamp oil for less). So sometimes monopolies rise-up because that one company is able to fill a market segment better than the competition.
The question then becomes, once they have a monopoly and others see this, how can potential competitors react. Can others copy (and improve) the same processing system that the monopoly has to produce a similar product for a similar price (maybe even less)? If so, then they can rise up and the original company will no longer be a monopoly. But if that original company takes steps to squelch the competition, you start getting into what the US has defined as "anti competitive" practices. These were developed because the past showed us that this leads to harming consumers.
We also have a lot of government granted monopolies. Copyright and IP law are time-limited monopolies on a given product. We have private business that operate on federal land (like national parks) that may be given a local monopoly within that region. Sometimes we make tradeoffs and grant monopolies.
Google, has several market reasons for their monopoly.
(1) The biggest reason is like economies of scale and network effects, but not quite. Online ad markets need to be huge to be good. Bigger market means tighter targeting segments, which is everything. This is why FB & Google make >10X more per customer than their no. 2s and 3s. Data aggregation is like this too. Some data on some users is not proportionally valuable to all data on all users.
(2) Software's infinite economies of scale. Economists like to point to this reason (0 marginal costs) as primary, but FWIW, I don't think it's why google is a monopoly. It probably is why software is monopoly-prone. It does explain the OS/Browser centralisation pretty well.
(3)Normal economies of scale and network effects.
(4)Path dependencies.
Does that mean that Google's monopoly benefits consumers? Who are consumers anyway? Formally, it's advertisers. If monopolies aren't assumed harmful, why do we even need to curb anti-competitive practices in the first place?
>> government granted monopolies; Copyright and IP; federal land, etc
Agreed. I'm not talking about "monopoly," the dictionary definition. I'm talking about the phenomenon in 2021, a handful of companies, most with a tell-tale >30% profit margin. I'm not talking about the exclusive cafe inside on IKEA.
Depends why there is a lack of competition. Are there barriers of entry to the market? Were they put up by the company? Or do they just have such an awesome product at a great price they no one can offer a better / commutative alternative?
In any case, prosecutors needed to prove harm/abuse affected search partners, and the fine was presumably based around that.
There is a problem defining the market sometimes, but that wasn't a problem here. It's a "crack for economists" type of problem, with a lot more theory than needed for practical purposes.
The problem is/was that these courts aren't a tool that can do the job. Courts can keep monopolies from doing certain things, with varying degrees of effectiveness. They can't prevent a monopoly from being a monopoly.
I don't agree with "monopoly may* abuse its position*" though. Monopolies exert their impact by existing as monopolies. They may or may not (as in the adwords case) "abuse" this position in specific, known, ways like anticompetitive contracts in the adwords-EU case... but this tends to be pretty marginal.
Google bought Doubleclick in 2007. After this, they owned both the biggest search engine and the biggest ad marketplace... their competitors' only revenue source. Throw in Android, Chrome & a $20bn contract to be Apple's default.
At this point it's all about market structure and control over choke points, nothing to do with consumer preferences. I'm not saying shut down google, or prevent people from using it. I'm saying that a market structure with only one choice is a monopoly, and that's bad for everyone but the monopolist.
I agree in part, but I disagree that 'good' can be a state that applies universally. Personally, I think of it as a tag that you can apply to individual actions on a case-by-case basis. Also, is there any company that has gotten big solely because 'they are good and people use them'?
Can you name even one?
It's a small victory, but it's also a hole in the armor. One of many, as various antitrust cases handle various abuses. Unfortunately, progress is slow but we're making it.
It's also a problem on the megacorp scale. If Google wasn't allowed to do gmail, android and such, would we have been better off? That said, if we're only talking about a handful of megacorps, there's no need to be abstract or simple with rules. There are lots of ways to keep them in a lane.
Android, Youtube & adwords are great candidates for IPO. Why not force a float? This immediately fixes most of the issues so far demonstrated in court. It compensates AlphaGoog at market rates, preserves an incentive to innovate...
Before that though... ban mergers! Reverse merges. The whole foods acquisition is a worrying one. The "multiple" discrepancies between amazon and regular retail is so high that there's an arbitrage-like force pushing towards these acquisitions. Tesla & other auto manufacturers are a similar scenario.
Consider this... Acquiring the entire publicly traded retail sector would dilute Amazon's shares by circa 25%-50%, most of that going to Walmart and Costco. They could buy the fashion/apparel industry with petty cash. They could acquire UPS. That would make other online retailers compete with amazon like Google competes with its search partners... same logic as amazon marketplace, but more.
...yet, it will absolutely matter if it's $20B - Google's 2020 operating income was $41B.
You're making the claim that since Google wasn't fined enough, fines don't work - which is absurd.
Try making the fines a reasonably large percentage of gross revenue from the previous year - say, 10%. 10% of Google's 2020 gross revenue ($182B) is $18B, which is almost half of their operating income. That will have an effect.
Google (to take your example) happens to be able to (barely) afford 10% of their revenue taken from their income. Another company with a different cost structure (perhaps in another sector) might not be able to afford that. The upshot is that providing a codified “one size fits all” punishment could be disastrous (if you consider preserving companies to be desirable: for the sake of this argument I do, but entirely legitimately you might not).
In the case of Italy (I’m Italian) and it’s awkward, glacial justice system, that’s a very dangerous assumption to make. This place is already hostile enough towards businesses.
Fines are, largely calibrated one way or another. It's not marked to gross revenue... but it is usually marked to the infraction. In the EU-Adwords case, the $2bn fine was relative to the size of adwords search partners' EU market share. In this Italian case (I assume) the fine is scaled to the size of the monopolised sector... Italian apps or whatnot.
This is why I called it a "violation-fine paradigm." Courts can't arbitrarily fine companies "enough to make it hurt." It has to relate to laws, specific infractions. Laws have to be general. Etc.
My point is that the infraction itself is not the problem. It's a sign of the problem, a symptom... the problem is monopoly. There's no version of adwords partner agreement (including the post-fine version) that isn't still a problem, even if it doesn't contain abuse of power clauses. The problem is that the only meaningful market for search ads is Google's. Similar issue for Amazon marketplace. There's no version of Amazon marketplace policies where amazon retail competes on a level playing field... they own the field.
You fine a company for doing something wrong. Google do things wrong, from time to time... but the main problem is what Google is, not what they do. That's derivative.
What about revoking corporate charters and nationalizing?
I'm against capital punishment (due to the possibility of wrongful convictions), but if corporations want to be people, let's start executing them.
Shut 'em down, Uncle Sam takes the assets.
What do we win here? To me it seems that letting big companies get as big as they can allows them to use economies of scale to provide quality services cheaply to all of us. Search is a prime example here, only Google seems to be able to do it as well as they do. Many others have tried and failed.
Isn't the benefit of cheap/free services far outweighed by whatever arbitrary "abuses" that are alleged to have been perpetrated? Shouldn't our attitude be primarily of bewildered amazement at the status quo instead of attempting to micromanage how Google uses the massive, amazingly positive platform it built?
No, because pluralism and a robust and diverse ecosystem is more important than cheap shit. Handing effectively entire control over what is visible on the internet to one company is anti-democratic madness. You're basically pulling a "but Mussolini made the trains run on time"
Less permissive economic systems continue to fail spectacularly. No one is "handing" any control of anything, control is precariously maintained by staying ahead of competition.
Comparing Google to a dictator is ridiculous - who is Google murdering by deprioritizing someone's service on its platform?
a more balanced power dynamic
I'm not equating size and efficiency. I'm saying a combination of the two represents the optimal outcome for everyone. In a permissive economy, large, inefficient companies are vulnerable to competition, and tend towards failure.
Which companies would this apply to? Should Apple's vertical integration be disallowed and broken up? How would you split up Twitter?
Personally I think there are specific use-cases that should be identified and banned in competition law - for instance the issue here (which could be legislated against) is when companies become a marketplace/platform that they 'sell' their own services on, which their competitors also need to use their services to effectively compete.
It's the dual role of being both a marketplace and a seller on that marketplace at the same time that produces conflicts of interest and market abuse potential. Examples (on top of the Google example):
* Apple vs Spotify - Apple could retain 100% of margin on their music subscription service, while Spotify their competitor had to give away 30% of their margin to Apple if purchased via App Store (which was mandated).
* Amazon vs Marketplace Sellers - Amazon encourages other retailers to sell on their platform, but secretly spies on their data to understand if they should directly compete and undercut them.
This isn't the only thing that requires specific legislation - and other parts I personally think should be better-legislated include:
* Use of one product to entrench another non-connected product's market position (e.g. Chrome -> Google Ads is an issue because the dominance of Browser means that they also get dominance of online search, because they can track better than the competition).
* Use of market-power to ensure people offer the lowest cost on your platform, despite fees (Booking.com, Valve, Amazon).
Another similar avenue for helping increase competition which I've been exploring is a reduction in the duration and power of IP protections. This would increase the propagation of good memes and the rate at which they may be iterated upon by others.
- always having the possibility for a direct voting for e.g. a new law/regulation
- a (deep) hierarchy of delegates/representatives on a per topic basis
- immediate retraction of trust/support from a representative
- maybe some micro monetary support for representatives
I guess at this point they're so dependable in being an evil corporation that this can be seen as a form of tax.
Mostly 1 star reviews on it.
In theory all 50 countries that Google has offices could fine them $100M - $10B based on whatever their laws are at the time, regardless of how ridiculous the laws are. It doesn't even have to be truly bad stuff. It could be something like, a country doesn't like that Google didn't censor something worldwide.
It seems like we need a more centralized way to deal with this.
(And in the same spirit, precedence can be overridden relatively easily in a common law system, too, the judge just has to find an obscure aspect of the new case that allows her to argue that the old cases don't apply.)
So you want them to be protected. In other words, protectionism?
Every country does protectionism in some form, it's the only way to prevent monopolies. Even the United States, where politics are led more by the free market than by citizens, throws around embargoes and regulation when important parts of the economy is threatened.
One recent example is the American attempts at sabotaging the new gas line from Russia to the EU. Companies get threatened with embargoes, insurances get cancelled, all to maintain the European dependence on the US energy market.
Protectionism protects not only the local economy, but also protects countries from foreign influence. All the major world powers want their own version of important economic and digital infrastructure to protect themselves against the other powers trying to sway public opinion. Google and YouTube are major influences in the world and without an effective ban they will continue to do so. People want convenience above all else, their own long-term interests be damned. Ignoring the threats of a globalised industry benefits no country.
Fines are for show (when it comes to corporations). It's high time we start making people within companies responsible for the actions they take.
The company asked you to do something against the law/etc. Report it. Oh, you weren't taught the laws? that's a failure of the company not preparing you for the job. All higher ups should be personally fined or jailed depending on the act, you should be fined or jailed with a reduced sentence (ignorance of the law isn't a defense). And you should be able to sue the company for damages and lack of training.
These are wild ideas, I know, I'm just hoping for more personal responsibility and less hiding behind the company.
IMHO, The market dominance of features provided by big tech companies like google and many other companies which provides something as a service must be consciously evaluated whenever product (and its new releases with new features) hits the market.
Big tech companies like google have too much monopoly. Each country deserve their own local vendors who are responsible for creation and operation of platform. Restricting the scope of some technology platform as service especially to a particular nation or even states can help build local jobs, also keeping the sentiments for that region.
On international level if someone wants to succeed they must be allowed but should be given limited access in each country/state by the government from very start, so that they don't overpower the local market.
Yes, but something tells me Google doesn't give a damn.
Is it even possible to split them?
Or they're seeing weakness in the US and taking their geopolitical shots.
In a recent article on a new lobbying group trying to onshore chip production https://news.ycombinator.com/item?id=27121586 a lot of people pointed out it's this weakness incentivising lobbying.
In other words US establishment invites regulatory capture through expectation of lobbying action creating even bigger opportunities to draw a dire picture, and demand more state intervention favourable to the industry.
More lobbying & pushback > industry situation worsens > opportunity to draw a dire situation > favourable intervention & more handouts > repeat
The poorer they do, they bigger are the handouts.
Might be worth practicing.
"This is a very complex subject matter, and I don't know how to express my thoughts on it concisely. I don't want to get downvoted for my long-windedness."
It's less than a 1/5 of characters, but conveys just as much of the on-topic and non-meta parts of your response.
Judging by the upvotes I have received, other readers also agree that my summary was a good summary of your comment. I'd encourage you to practice making that paragraph you wrote smaller, with a goal of reaching a length similar to my rewrite's length. It's something I've been doing more often to make my own messages more concise, and it has definitely helped.
€100M would be about 0.0000125% of the revenue Italy expects in 2021. It's totally irrelevant to the national budget.
Somehow I have the hardest time finding (i) the real Google Play (app store) and (ii) the search form for apps (Google doesn't want you to search for an app and install it, they'd like to hit your brain with an electromagnetic pulse when you visit the app store and stare at mindless ads with your tongue hanging out the site of your mouth for hours. That is, the strength of the "platform" doesn't matter, just the perception of investors that Google products are still stuffed with ads, the king is on the throne, and such...)
They removed that restriction last April[1], now devs can publish nav, parking, charger apps etc. Sygic[2] as an example.
[1] https://android-developers.googleblog.com/2021/04/start-your...
https://9to5google.com/2020/08/11/android-auto-navigation-ap...