Google terminated our Developer Account, says it is “associated”
old.reddit.com
old.reddit.com
This is beyond the pale. Google should not have the power to decide who you are and are not allowed to hire. It both goes against the basic concept of a limited-liability corporation, and harms worker rights.
Especially not retroactively.
"Your former employee broke the rules at their next job, so you're banned" is just bizarre.
The secondary sanctions exist because it's near-trivial to automatically create dozens of proxy accounts for a bad actor to launder reputation through. So in addition to direct fraud detection, Google has had to automate secondary "Is this account probably the same bad actor" detection.
That system, like any such system (including human review), has false-positivies where two accounts are believed to be the same owner when they are not. But the automation-with-insufficient-human-review problem is specifically Google's mistake, and there's room for improvement.
Anti-fraud is a tough space because you can never be 100% sure which actors are legit and which are scammers… after all if you knew who the scammers actually were you’d have blocked them all ready.
I always make sure there is some kind of escape hatch for legit users who get caught in our system. These escape hatches might not be super awesome for real users, especially if they fell into a bucket that strongly labels them as scammers, but at least they have an out.
It's both. When you work with tech companies this kind of overautomation is rife. When you work with any other type of business they give you an account manager and you manage these issues openly together with a relationship. If there was a human at Google who picked up the phone and worked out the problem with the developers before this ban was imposed, this could have all been nipped-in-the-bud before an account was terminated.
My current account doesn't have much money in it, but my bank would call me if there is an issue which would terminate my account, and I'm confident that they would work with me to offer up solutions rather than instantly terminate it. Google should provide developers more respect than my bank offers average consumers.
There is no excuse for them not picking up the phone and just talking these things through before they implement the bans (unless there is active malicious behaviour in an app, in which case I would expect a suspension to happen and be followed up with a phone call straight away).
The only way to fix this is to legally require it, because nobody's going to stop the profit train by themselves.
Or they've simply removed those tasks under the rubric of automation.
That's not correct. Google is more profitable because it is a monopoly and routinely engages in illegal anti-competitive behavior.
It's precisely because this is the case that it's able to have nonexistent customer service and stay in business.
Which is why both need aggressive regulation.
[1] e.g.: https://www.bbc.com/news/business-36737666
[2] among others: https://www.forbes.com/sites/enriquedans/2021/01/19/jedi-blu...
I don't know what Google's rates of customer service failures actually are, but even a minuscule of rate of horror stories seems to hurt brand, judging from HN comments.
I wonder whether fixing half of, say, 0.00000001% of cases that would otherwise be PR horror stories, could translate into measurable boost to brand value.
Maybe all the math has already been done, and all possible wins for creative automation motivated by business payoff (and promo bids) have already been achieved, or maybe not.
I doubt it. Brand value is a notoriously fuzzy concept, and corporate decision-making features a heavy measurement bias. A toxic brand might be measurable by the time it's influencing enough purchaser decisions to show up on "would you consider?" surveys, but that's an advanced stage of the problem.
I've never worked with or for Google, but having worked for software companies my whole life, I suspect that it's overautomation, combined with "silo-ing". Even if somebody identifies the problem from the user's perspective, it becomes a rats nest of responsibilities to untangle to figure out who or what group(s) can address it and how. The people who actually understand how a particular component works and can change it are limited to their particular component and the people who are nominally in charge of "everything" have no detailed visibility into anything at all.
Ultimately it did not disappear in 30 days. Was it because I upload passport photos? Not sure. Because I spoke to customer service? Not sure. Because the original shutdown notice was a mistake? Not sure. The lack of clarity made it worse.
I've heard stories about people losing personal accounts like this due to GCloud usage. At work, where I'm CTO, I have open access +MSAs to the three major cloud providers -- BUT I am very hesitant to use anything but AWS/Azure. The risk of something going wrong with GCloud and that metastasizing to my (or anyone's on the team) personal Google account (or vice versa) is huge and just not worth the risk.
I'm still forced to use Google stuff here and there but I'm no longer dependant on them, and coincidentally I've been sleeping much better recently.
While I have a work iPhone 12 so I use both iOS and Android daily, I do actually prefer the Android ecosystem, plus iOS being locked down in terms of installing third party apps is a disqualifier for my personal device. Also bugbears like the headphone jack, though I might be out of luck there in Android in another device rotation.
The up-front cost and setup time is a stiff investment, but I’m much easier in mind now.
The other side of the coin is my wife’s gmail, which is going to be deleted come May. So... we gotta figure that out.
Yes, NextCloud and Owncloud both integrate with OnlyOffice Community Edition[0][1] which supports collaborative editing of text documents, spreadsheets, and presentations.
My collab needs are pretty light, I only work with a few family and friends, but I haven’t run into anything I wanted to do in Synology that I couldn’t.
Gmail is worst-in-class at this point. It's slow, it's bloated, it's bad at spam filtering compared to the alternatives. They've been riding on people remembering email before Gmail, but not really actually stayed competitive with any modern alternative offering.
Anybody that knows better, will avoid Gmail like the plague or use it for only the minimum.
One important point here, and I don't know how long you used Fastmail when you tried it, is that Fastmail uses a personalized spam filter. It probably took me six to eight months to receive enough spam on Fastmail to actually train it. (In the interim, they use a non-personalized filter, which as I said, still worked!) Gmail doesn't seem to be able to make personal spam decisions: When I was regularly using Gmail, some types of regular messages would spam-bin no matter how many times I marked them not spam or classified them as a particular category of mail.
Spam filtering on Fastmail has been the same/better than Gmail was - including possibly fewer false-positives on the Fastmail side. Gmail was getting worse about those, both with mailing lists and individuals' emails.
Like many on HN, I'm diversifying my data/access risk across more providers. Too many wake-up calls recently about Google locking people out. There are still some services Google is compellingly better enough that I still use them (Android, Maps, YouTube, Google Sheets), but Email was too precious to tie up with them. I also wanted to finally kick myself into stoping using the `gmail.com` address at all anymore (maybe 20% of my emails before the migration).
The difference is night and day. I can look in the spam folder for my work email now and there are hundreds of spam messages there for the last 30 days, and absolutely zero false positives. I have seen a handful of spam messages come through, but it's in the single digits over the last two years.
That's often the case with one of my friends who has a Gmail email address: anything that I send him (once or twice a year) doesn't even show up in his spam list without first making him start an email exchange to me => in my opinion that kind of filtering is just too easy to do (come on Google, at least put it into the spam folder and/or show it as a colored/blinking line and/or put some warnings whatever - don't just delete it), and of course it poses questions about oligopoly etc. How Gmail works is just not fair (in my opinion) :(((
EDIT: Verified. Not yet for iOS.
I use various google services, and do a monthly backup of everything. I guess that's a sane thing to do with any service, even self hosted ones.
It's a questions of eggs per basket. Google wants you to keep everything in their one basket, and the result is that if they arbitrarily terminate your account, you lose everything. If they give you 30 days like OP, you have to remember all the different places you need to download content from.
If you split your services up, a sudden termination only affects a few things rather than everything, and a forewarned termination has a much smaller surface area you need to consider.
Google Takeout (takeout.google.com) should give you almost everything in one place. It's a good idea to do this periodically in case you don't get the 30-day notice. Be prepared to download a few dozen GB, though. And there is no "incremental" option.
I wanted to migrate from Google Photos to iCloud. Turns out there is no easy way how to import the photos to iCloud without loosing metadata. I gave up and just bought more storage on Google.
I'm a bit surprised that you had trouble importing photos, though. Isn't most of the metadata kept in standard EXIF tags in each file?
However, I don't agree with "remember all the different places you need to download content from". Google does this with Takeout, so I can have 1 backup of most of my things. When using different services, I need to have various backups.
Reason is: I don't depend on services giving me 30 days. I assume they can block access on the spot.
Protip: you can easily sync obsidian by sharing the top-level vault directory with syncthing. Its entirely transparent, you just start obsidian and open the vault, and changes you make on one system automatically appear on others.
As for protonmail, its better than google -- but you're right in the data ownership. In the case of protonmail, they have a much better track record than Google, but if you are really paranoid choose a service that supports SMTP/SNMP. You can then just have a mail client store the mail as an archive or connect it to any other mail system.
I have mentioned my preferences before, but I'll refrain from turning this comment into an unpaid ad. Drew Devault's recommendations are pretty good though: https://drewdevault.com/2020/06/19/Mail-service-provider-rec...
SNMP is something entirely unrelated, afaik.
Your backup note is on point; I highly recommend everyone to do a Google Takeout every few months (or at least years!!). If you've never done one, like most Google users, you're playing with fire.
“GoDaddy has two major problems.
First, their customer service (…).
Second, if there are accusations made against you, they will shut you down and side with your accuser more often than not.“ https://www.warriorforum.com/main-internet-marketing-discuss...
Maybe? I would hope that you could raise the issue with the dowmain registry or ultimately ICANN if the registrar does not let you move the domain elsewhere after banning you. Registrars do not have the same platform ownership over domains that Google has over gmail accounts, they are just middlemen.
why not?
Currently I'm syncing to a s3 bucket with e2e encryption but of course you could sync to a server you setup yourself including a basic windows box.
I've been using it for a little over 3 years and it serves all my note-taking/storage needs, especially with the relatively recent addition of extensions/add-ons. I have had no issues syncing through either dropbox or Nextcloud.
Not really, big players have the advantage that nobody is going to block them. Most of them spam regularly by thousands of letters before some automation of theirs triggers (or the spammer stops).
That said, the rep failed to provide any definitive guidance on issue or resolution.
In a way, this is sort of a digital-era generalization of "freedom of the press belongs to those who own one."
For my corporate accounts there is NO WAY i'd use GCP. I have the privilege of MSAs with all three major cloud providers and we're doing most things with AWS. So on the corporate front, I didn't leave because I just didn't enter in the first place.
I'm currently thinking of migrating from Google for productivity to Office 365. Wondering if I'm just re-branding the risk of my counterparty.
With AWS/Azure, you typically wouldnt have extensive personal data with them, so you dont have the risk of work and personal accounts colliding. I dont know anyone with personal emails/accounts/photos on the Microsoft ecosystem. With Amazon, whats the worst that can happen? You lose your connected Amazon purchasing account, doesnt seem terrible.
With Google you often have email/documents/photos with them. If you have an Android phone, you have almost everything with them.
A lot of folks are offended by $100 / year developer fees. If Apple et al charged $10,000 to get going as a developer, they would probably be better positioned to deal with all this less automatically. In fact, game dev historically might have followed a bit of this model (xbox etc).
Anyways, my own thought, there should be a pathway to a $5,000 fee where you get a higher level of human interaction.
I really dislike this explanation because there are so many obvious things they can do. Example:
1. Force uploads of Passport/ID for identity confirmation. If you have 100 accounts with the same passport...ok...issue, but if not, is it worth human review at least?
2. Force credit card payment with address verification, ideally match to passport. Same credit card used across 1000 accounts...ok...issue, but if not, perhaps worth a review at least?
3. Still an issue? Force user to pay $100 for verification and run credit check routine.
The idea that blanket account terminations are the only way to handle issues seem lazy.
Op wants to be able to hire somebody with a history of abuse without google enforcing them
That sounds like extortion...
"We're going to ban your account because we want to, unless of course you pay us $5,000 so you can talk to a human to resolve this issue."
Would you rather have a neighbourhood mafioso who is amenable to financial incentives or a local random psychopath?
If you want to talk to a tech company engineer for bug fixes, you pay for that level of service.
There is something a bit almost scammy about all these "businesses" demanding white glove custom treatment, but complaining loudly about even being asked to pay a one time $25 fee to get on platform.
It used to be to deploy to a platform / get SDKs for the platform the costs were FAR higher.
There are something like 5M+ android developers. If you want to support this developer pool with 2-3 hours of work per developer per year, you are looking at 15M hours of work per year. And these people also become a risk - they can be socially engineered, they can be paid off etc. We've seen this over and over again.
If you look at phone co employees who are supposed to protect you from sim swap attacks etc, they have a large number of employees, so service is "good", but security? Not so much.
What you are proposing is that google should offer a human service in a very adversarial and tricky area (ie, your own staff may be working against you) and that asking to get paid for that is "extortion" that would result in jail time. This is perhaps why they don't even offer a way to pay (a lot) for a very careful high level review. Folks like you would demand jail time for them. Instead we are stuck with automation.
"Bid more than your competitor on AdWords for the literal name of your business or else they'll get the customers who intended to do business with you."
You would think something like this would increase competition between businesses (competitors surfaced immediately for users). Instead I guess this is seen by a bad thing - though it's not been clear to me recently that the FTC is looking out for users, they seem to have gone BIG into protecting businesses for some reason.
And that's pretending they don't already make obscenely high profits per developer, and can absolutely afford to provide the necessary support for these situations, which again, are largely their mistakes to begin with.
I don't know what universe android app developers are living in, this is basically "free" for most significant businesses.
For that $25, you are NOT going to get white glove support / treatment. Not happening.
> The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
> In the cases referred to in points (a) and (c) of paragraph 2, the data controller shall implement suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.
As if that will ever happen. We don't live in a world of rules and logic until things play out as simply as above.
„ personal data’ means any information relating to an identified or identifiable natural person (‘data subject’)“.
This is a business, not a natural person.
Give access to as few employees as possible, and have all access to Google Play go through a designated, trusted release manager or "play account manager"? And don't log in to Google Play from random browsers and IP addresses which could create an association with other Google accounts?
Use company e-mail addresses to register for everything. Enforce it for your employees. This is in the interest of both the company and the employee. Yes, the summer intern gets a corp email too, which at minimum gets access to internal resources beyond the OT chatroom revoked when they are out.
(Your advise is not bad though: grant granular access as it's needed)
But yes, my point of not mixing accounts does go that far - if you don't have separate hardware, at least use separate browsers or browser profiles.
Don't put the cookies in the same jar.
Easier said than done, in my experience. Years ago I had to log into my Company's Play account on my computer for some specific reason, one time, and more than a year after that, my daughter purchased a game on my android phone and the CEO sent me a message saying "FYI, we just paid $3 for a princess coloring book app, please enjoy it with our compliments but please delete the Play Store login info from your devices." I still have zero idea how that could possibly have happened. That company will be shutting down and now I'm worried that my google account is somehow "linked" to it.
As mentioned in a sibling comment: Utilize browser profiles (Chromium-based/Firefox) or Multi-Account Containers (Firefox).
This is probably "best" practice, but Google has randomly closed accounts for our mobile test devices. They're only used to run our (non-shady) apps on a single device that is never used with other accounts.
FWIW: there's some reason to suspect that the "later" bit is being spun here. Per the timeline in the article, there were only 5-6 weeks between the employee being fired and Google taking action against the employer[1].
That's pretty tight, and from an enforcement perspective is going to make it extremely difficult to distinguish which entity is doing the bad things. And, frankly, given the spin elsewhere in the story, I'm inclined to suspect more ambiguity here and not less.
What's the ask here, that Google (which correctly detected the association between the accounts) audit the IT permissions logs of accounts that commit bannable offenses before taking action? That just doesn't seem feasible.
[1] They further spin this by trying to claim that the employee left in 2019, but have to admit that he was still present as a consultant.
Mar 2019 - H. Left the company, all permissions removed except on one game which we were still using H.'s consultation on - The app was unpublished later on
04 Dec 2021 - Termination of H. (Former Employee) account because of multiple policy violations
26 Jan 2022 - Termination of our company account (Raya Games Ltd - AKA TOD Studio) without prior notices and warnings
I think the 04 Dec 2021 is Google's termination of the "H" account.
But Google has its own reputation (and users) to protect. It's taking a risk whenever it allows a developer on its platform. If a developer with low name recognition uploads malicious software, it's not the developer's name that makes the headline.
Crucially, there's no information on what the employee (and later contractor) 'H.' did to get themselves banned. Or fired. From the OP's own timeline, the ban came less than two months after they severed their relationship with 'H.' Google isn't swinging around the ban hammer years after the OP separated with 'H.'
The OP's games could still include code contributed by 'H.' And 'H.' is apparently untrustworthy. Is that a risk Google should be forced to take as the curator of the Google Play store? I don't think so.
If 'H.' is a malicious developer, then all apps that were extant while 'H.' was associated with Raya should be considered suspect. Google (and its user base) have no idea what apps 'H.' touched. The very least Google should do is ban all apps uploaded and/or updated during 'H.'s employment.
And even then Google has no way to know whether 'H.' still works at the company, or will work again there in the future. Google doesn't (and can't reasonably) have any insight into personnel decisions at Raya Games.
Is Google throwing the baby out with the bathwater? Yeah, probably. But Google can't differentiate between baby and bathwater when it comes to malicious developers. Google has an affirmative responsibility to protect its userbase. It doesn't have an affirmative responsibility to let any individual publisher sell apps on the Google Play store.
The problem lies in the people who implement these anti-fraud measures forgetting that not every account their system flags is actually a scammer. The goal should always be to fuck over the scammer as hard as possible. However you must always make sure the real humans that get caught in the net can always get out of jail.
Assuming that the 1% of real humans that get flagged in your system don’t matter is how you piss people off. Always provide ways to get real people out of jail! Those people are honest people doing the right things. They are the ones you are trying to protect!
I can't help but notice the "they're a private company, so they can do whatever they want" folks that pop up whenever somebody's account gets banned for political views are strangely silent right now...
My favorite was when they were licking their lips and reaching ecstasy over Parler getting deplatformed but then throwing a tantrum like a week later when Terraria dev got banned by Google.
Terraria guy and this guy simply need to build their own Google, Gmail, Play Store, and Android, easy! ;)
Also celebrating that Google was ‘on their side’. Until they are not.
> My favorite was when they were licking their lips and reaching ecstasy over Parler getting deplatformed but then throwing a tantrum like a week later when Terraria dev got banned by Google.
That was my favorite one. Basically the chickens cheering on the wolves eating the other chickens that disagreed with them. Now the wolves are eating them as well and they are complaining why they are ‘not on their side’ anymore.
They thought it could never happen to them. Just use the same ‘private platform’ logic towards them for everyone else that is getting banned after Parler and now they are all crying in the comments here.
These companies are not on anyone’s side and these bans can happen to anyone on their platform. They won’t change.
Tired of seeing people equate war crimes to Google screwing over some company.
Really, it's a monopoly problem. You shouldn't be affected by whether google wants to work with you or not
The problem isn't that you don't have options with regard to hosting, email, etc (with the notable exception of google play store), the problem is that once you've picked your option it's hard to migrate out, and as a customer you have a right IMO, whether in the terms or not, to a good faith effort on the part of the service vendor to sort our any problems you encounter with the service. If a robot just shuts you down no notice and there's nobody to reach to sort it out that's a negligent business practice and I believe any vendor of any service that operates this way is liable.
If they want to offer migration tooling, notice and access to your data I can see it being alright. A pain in the ass, but at least not the end of your business one morning while making coffee.
As far as google play goes, I think there's the monopoly aspect to work on and hopefully legislation brings a resolution to this problem, like offering independent repositories as a default option or something like that, til that time though, do not rely on it entirely. If you have to open source it and put it on f-droid, maintain an aptoide repo, apk download on your site and market that heavier than your google play account, whatever you have to do, just do not rely primarily on the play store because you're basically giving google the keys to your kingdom.
Just clarifying that the concept of a limited liability company has nothing to do with this. It is about not having company liabilities (e.g. debt) reaching stockholders (e.g. banks seizing your personal car and house to pay for your business defaulted debt).
What we are seeing is a monopolist abusing its power by directly harming somebody and the civil society refusing to acknowledge any harm. And it's doing so by the most visible power demonstration it can.
I have such little trust in Google's automation for banning accounts that I don't even bother commenting on Youtube or uploading videos anymore. Who know when some innocuous footage that I have will trigger a cascade of copyright strikes and ban my personal GMail? It's like walking around glass.
Theoretically no but practically yes. Even if they know they are in the wrong and would loose a court case, they still "win" by just dragging it out and making you go broke on legal fees.
1.8T is an unimaginable amount of money.
You are paying hundreds of dollars per hour to someone who is discovering your issue.
It's possible,sure. But how do you think that's going to play out?
Unless you lost kin, or a 5 million dollar inheritence due to your issue with Google, you're going to find a way to live with it.
The whole idea is that you get a lawyer to be taken seriously instead of been dismissed.
It costs them money to have their lawyers look over a letter from your lawyer. It costs them nothing to ignore your emails. It also separates you from most scammers, that would not get a lawyer because their position is bullshit but will 100% send a bunch of emails to googles support.
One of the most interesting ones was Free Range Content v Google[1] where a number of Adsense publishers had their accounts closed after Google detected invalid click activity on their websites. The publishers sued alleging Google breached the Adsense terms of service.
Incredibly the Court denied Google’s motion to dismiss and allowed the breach of contract claim to continue. Google settled shortly thereafter but the takeaway is that these terms of service contracts are not as ironclad as Google would like you to believe.
[1]https://law.justia.com/cases/federal/district-courts/califor...
In other words you need [transitive] "Google priviledge".
The easier and more effective solution is to simply force them to allow alternative app stores (without suppressing competition, like Google currently does). A free market tends to correct itself in the long term, so that should solve the majority of problems plaguing the mobile software industry today.
Anything has to be better than what we have today…
Sunlight (and competition) is the best disinfectant!
I don't think it's hard or unrealistic to force companies to provide realistic support. Entire industries have had this established for decades.
Imagine you're renting office space and the landlord decides you've done something wrong, clears your things out and changes the locks -- refusing to tell you what you've done or allow your business to continue to operate. This sounds extremely unrealistic because it is, in the real world you'd take them to court and sue them for losses. And there is plenty of legislation behind it to support you.
Similarly, having companies like Google become accountable like this isn't actually that hard. There just isn't any will to do so at the moment and livelihoods will continue to be destroyed in the interim.
But how do you design a law that corrects the bad behavior of 2 monopolists, while at the same time not adding a burden to any potential competitors (and thereby strengthening the existing monopolies)?
Forcing competition makes more sense to me. No need to get into endless debates about the risks to innovation, or government being too big, etc. Just open the gates to competition and call it a day.
If the mobile app store market goes to shit in the future, then we can start getting into the weeds of it. But for now, there’s no need for that; the answer is obvious.
Expecting some level of support being provided, especially in a paid B2B engagement, doesn't stifle competition. If a competitor can't provide basic support, especially when they're just starting up, then it's best that that business fails.
They're essentially modelling their business plan based on Google's worst attributes. That's not competition I'd like to see develop a foothold, or the type of competition we should be encouraging, let alone structure our laws to support.
Only if enough consumers are affected.
Situations like the OP happen, but they're exceptionally rare. They just make a lot of noise.
A noisy post like OPs would actually make Google shit themselves if they didn’t have an app store monopoly. Even if it’s a single dev out of millions, the bad press would be much more costly than making things right.
* developers continue to develop apps for the respective app store (they could often create a web app, but they don't)
* there is no outcry among users for competition (instead of monopoly) in the provides app store(s)
nothing will change.
NewPipe does this for F-Droid in order to deploy the updates faster. Otherwise, F-Droid needs to very, compile and deploy themselves and it usually takes a few days.
F-Droid's rules exist specifically to ensure that an app's source code corresponds with it's binaries. This reduces the risk of using F-Droid because all source code is available and auditable. There is no guarantee that said source code has been audited, and FOSS malware does exist[0], but it makes it harder to hide such code.
I would personally prefer if Google Play had similar requirements, but the entire industry would be up in arms if Google started mandating source code escrow.
[0] Notably, the ironically-named `peacenotwar` package on npm, which is a cyberwarfare tool that attempts to wipe files on Russian and Belarusian machines.
They assumed, but don't know, it was because the developer who had his personal account suspended as well once worked for a company who was kinda scummy and went fully scummy a few years after that developer left. Somehow that was associated with him personally and then the chain of guilt made its way to them.
This seems to re-enforce that this kind of chain of guilt is a thing.
6 degrees of termination.
I died.
This should be the term.
https://en.m.wikipedia.org/wiki/Nine_familial_exterminations
Maybe Google's algorithm is more concerned with being a tyrannical emperor than we think ...
They had this developer associated with their accounts still.
This developer did bad things.
Google banned this developer and businesses using this developer?
What more is needed to understand what happened?
I think the problem is the only solid connection google has are developer accounts / that's the only club they have to swing. So bad actors may jump from account to account and Google's method of whack a mole is to just associate accounts.
Way back in the day I worked on an old forum where we used to try to do that for spammers and such. But we didn't automate it. We just had a checking mechanism that would indicate if some accounts might be from the same person ... maybe.
But beyond anecdotes and the above story I've no idea how widespread this is.
Looks like it's 100% a valid tactic.
Looks like you need to make sure your employees all leave on good terms, and stay on good terms in the coming years. Otherwise, you too might find your Google accounts terminated with no recourse.
As I understand it, this may not be sufficient, since Google also looks at things like "logged in from the same browser" or "logged in via the same IP" to find associated accounts.
> mark a developer's account as "fired for cause"
Which, practically (and maybe legally) speaking is not something Google needs to know. Then again, in a world where Google can shut your company down arbitrarily, perhaps it is something Google needs to know...
To absolutely prevent any and all association.
I've ever seen anyone successfully pull off this kind of secrecy in anything larger than a 10 person team, and the cost was insane.
The simple way to "enforce" it is to literally just use AWS/Azure instead. I agree with you, totally unenforceable.
I do agree that it's a sensible thing to do and it _should_ be enough to mitigate issues like this.
It is valid and I’m sure quite effective but it isn’t perfect. You need to provide escape hatches for real people in all anti-fraud systems you create. Even if those escape hatches sometimes let fraudsters through as well.
I’m not Google and I don’t know the kinds of fraud they attract (note: probably all kinds of fraud imaginable) nor do I know the level of effort those fraudsters are willing to put in (note: probably unimaginable amounts of effort)… but I do know that all anti-fraud work needs to allow ways for real people to escape. Your job in this space is to protect real users… and sometimes those real users inadvertently behave like fraudsters and get flagged. There has to be ways out.
It seems like there is: appeal your case in a public forum (HN, Reddit) and hope you catch the attention of a sympathetic Googler with the political clout to get the case reviewed.
But I can't imagine this will work forever. It certainly doesn't scale.
But who knows… what aspect of your users do you know about that Apple refuses to understand?
Fanboy logic.
I'd be interested in hearing more details.
Not long ago, someone here raised similar concerns with Microsoft 's ecosystem
It stemmed from their current underway process to force all Minecraft accounts to Microsoft accounts, and the current Microsoft account process, if you don't add a phone number during account creation, locks and bans the account automatically after a week with they only recovery option being to then give a phone number, and most voip ones are auto detected and not accepted.
If you set up the account with an alternate email, that has no effect. Setting up TOTP has had scattered reports over sometimes allowing the account to not auto ban you, but recent reports are that this too often won't stop it. There are reports that using Microsoft s own authenticator app, does stop the account from auto banning you unironically, that I have not confirmed
Of course this means they can then tie it to potentially your computer pending how you set up Windows, or Xbox live, etc. Which is a risk if you've been formerly banned from something like xbox- everything is now linked, and therefore subject to action automatically with no human team to talk to about the process.
Also, if you then go and give it to them then afterwards try to remove it, the system will not let you without extreme effort, and more details.
I worry greatly about this situation where our personal accounts are all tied together through hardware ids, mandatory phone numbers,IP addresses, and different accounts across systems, only to all get banned or locked out at once with no recourse - or demanding more data(like Minecraft indirectly giving Microsoft every single phone number for the biggest player base in the world, as mandatory(with specific exceptions for like one or two countries who's laws they are working around now, with Korea appears to be one)
Also, so many companies use Amazon, Google, Microsoft company emails and systems- your full name is there, so there is a increasing risk that if something happens to your company account, the systems knows your personal accounts and by name, bans or affects them too.
Privacy advocates are being proven right about the need to be able to not give info that ties everything together
I can't imagine how bad it is at a less regulated institution.
Can you play at all once banned?
I suspect burner phones are the only way to not give one's phone number, or to gamble with the microsoft authentication app, which theoretically ever since recent versions of android should not be able to pull your phone number from the hardware - theoretically. I have not tested that out yet.
There's quite a bit about this out there Here's one such thread where a lot are trying to figure out why they are being forced to give up their number https://github.com/MultiMC/Launcher/issues/4093
to my understanding, since they fully linked it- once your MS account auto locks- you can't do anything, since it's linked to Minecraft- as well as other stuff. You'd think they'd allow one to still play Minecraft- but i guess if you can't log into the account, you're out of luck
It's simply not economical for many companies to deal with the long tail of false positives, so they don't. Google has billions of users, and if their algorithms are 99.999% right about bans, their metrics look great but that's still tens of thousands users wrongfully banned.
I'm not usually a fan of government intervention but this is such a no-brainer for regulation.
With how much our modern lives are dependent on services like Google's, they effectively become utilities and should be regulated as such.
But that's only part of it. A business account might not fall within these rules, and Google can enforce them anyway (after human review) with very little recourse available.
Breaking the App store duopoly is the solution.
Not really. We a comparable situation in a lot of different industries; if a large companies serves tens of thousands of customers and get hundreds of thousands of malicious requests, they're going to do some filtering and it will lead to some people getting stuck in the cracks, even if it's just 0.01%. More app stores won't solve this; if enough developers would be burned, the problem would solve itself on its own.
That's not to say that I like the current situation, but from what I see it's likely that the actual number of incidents is low (compared to the number of Google's customers) and a third or fourth store won't change this.
I think that forcing human recourse _is_ the solution. This problem is much bigger than just the “App store duopoly” axe. A law that required the ability to perform all account actions/appeals/etc realtime with another human (phone, chat, etc) would’ve also minimized the need for the recent unsubscription laws as well since the hassle would’ve been much less in the first place. These are the kind of foundational human-centric business laws we need instead of the reactionary hyper-focused ones that don’t address root problems and usually just wind up further cementing incumbents.
Imagine I’m a trillionaire real estate mogul. I have 1,000,000 properties under my domain across the world. Some will, inevitably, not get the upkeep they need and a situation like the apartment building in Miami occurs. Let’s say even that no one dies, to be generous. Another building the electrical is jacked up and held together by paper clips, regularly leaving residents without power. Another one has grey water coming out of every faucet.
The government comes in and goes “hey, a bunch of stuff isn’t up to code. You can’t have buildings like this.” I then proceed to go, “well, it’s unreasonable to expect me to address every problem. I’m just too large of a company with too many assets. I’d need to hire a small army to manage it all.” The government goes, “huh, that’s reasonable. Well I guess just automate what you can and do your best!”
That’s absolutely ridiculous, right?
Google is never going to improve the situation out of the goodness of their corporate heart (if such a thing were even to exist).
[1] https://www.commoncause.org/find-your-representative/
[2] https://nypost.com/2022/03/29/biden-doj-backs-senate-antitru...
Pretty much, the amount of effort you put into your communication is a reflection of how important the issue is, and how important it is to you.
Which kind of goes hand-in-hand with lobbyists. Companies don't pay them millions of dollars to send emails or rant on web forums.
Order of importance was (at least in 2011):
1. In person meeting 2. Physical letter 3. Phone call
Then go to district events that your rep will be at, get the district manager to introduce you to the rep.
That's way better than calling the same phone line all the wackos call
I don't think this is enforceable nor I think it's even possible to have such legislature.
At the end of the day Google has every right to decide what they put and what they don't put on their store, with whom they do business and with whom they don't.
> With how much our modern lives are dependent on services like Google's, they effectively become utilities and should be regulated as such.
Calling an online application store an utility seems quite a stretch.
De-googling and de-duopoling is the answer to these situations. At the end of the day you can't force Google or Apple to have your products on their shop.
So perhaps the real solution is to split up these giants..?
A couple of years ago, the New York Times ran an interesting article where someone tried to live an ordinary day without interacting in any way with Google. The result was that it simply wasn't possible.
The fact Apple, Google, Microsoft, Amazon, Disney, Verizon, and others [1], etc are even allowed to exist in their current forms is absolutely bonkers to me. The outsized roles and influence they have on the economy and their individual markets just highlights that the government is incompetent or willfully corrupt.
[1]: Just a random selection of giants I can think of in a split second. But there are tons of other companies that dominate other less-sexy markets that should absolutely broken up.
Yes.
Refusing to have say, Telegram, on your app store is similar to not allowing a telco to operate. Also as much as I dislike Meta, if Apple/Google decided to remove WhatsApp/Instagram/Facebook, that would disrupt a lot of lives. Many businesses heavily rely on WhatsApp, more than they'd rely on landlines in the past.
In the US at least, where these companies are headquartered, every example you gave has an alternative that doesn't require an app.
There might be an argument for more regulation, but calling apps utilities most definitely is not one.
There are countless U.S. examples where an app (native and/or web) is the only practical interface you have to a company or service.
For example: What's the phone number to YouTube customer service if someone needs to discuss a misunderstanding about a copyright strike?
Eh, just de-googling is probably enough. This isn't really a walled garden problem, this is mostly a Google problem. Apple can do stupid things, for sure, but you can reach a human there. And they definitely don't have the same Google algorithmic "scorched earth" account banning style.
The sentiment is basically correct. Enforcing a ban on stores being able to control who they do business with is a radical break with all precedent and violates freedom of association. All stores have always had the ability to kick out any buyer or seller for any reason whatsoever short of systematic discrimination against specific protected minorities. Whether or not any particular seller thinks this is a morally optimal situation or bad for their personal business isn't going to change the centuries of history behind this.
The actual problem here isn't the arbitrariness with which Google bans sellers or the false positive rate of their decision-making process. The problem is the device vendor, OS vendor, and app store vendor are all the same company, and there are, practically speaking, only two options for the entire mobile market. Solving this is basic antitrust enforcement. Force competition for app distribution platforms. At least Android allows you to sideload and has F-Droid, but the situation is still anticompetitive and bad for both consumers and sellers.
And yes, with all respect to mobile app developers, access to a selling platform is not a utility. You don't need to be an Android developer to meet the basic necessities of life. It doesn't mean we can't or shouldn't do anything to make the situation better, but this drive to call everything a utility is not helping.
So now do we say that companies have the innate right to make profit without any regard for the public good? That profits are more important than what voters in a democracy want?
Correct. AdSense worked the exact same way on YouTube. They are just doing the same thing with apps on their platform so really nothing has changed here.
These companies can do business with whoever they want to. You can criticise them, scream at them, protest, etc but they will never change, unless you split them all up.
The problem in account termination cases would also be that:
1) they can claim they've reviewed the ban, that it's legitimate and they're refusing to disclose the reasons behind it to avoid helping people circumvent the ban, while in reality they didn't do any investigation at all. Proper enforcement should be able to pierce through this veil (by forcing them to disclose the reasons and data behind the bank to the regulator, a neutral third-party), but it's missing and nothing suggests it's going to get any better.
2) given that businesses are still allowed to essentially "fire" customers at will, and changing that is impossible due to wide-ranging repercussions, nothing prevents them from "firing" you anyway. Proper antitrust enforcement is needed here (so that you're not allowed to "fire" customers this way) but that's missing as well.
All it would take is to reestablish that you are the sole owner of your information that is your property, as has been established by the courts, and it cannot be sold without a formal contract, e.g., the way real estate is transferred; and that any tracking is illegal stalking and wire fraud (because it is) just like tapping someone’s phone would be since it is using the public internet. Alternately, these companies can stop relying on the public internet for illegal criminal actions and fraud, and build their own internet if they want to track and stalk people.
The law exists, it doesn’t matter what other laws you make when none, even the fundamental Constitutional law, is not enforced and simply ignored. We have too many people who have these narcissistic perceptions that the real problem is that their pet legislation hasn’t been added to the mountain of legislation; when the real problem is people trying to control others, some in business, some through legislation.
If the general public does not recognize this soon, the clutter of legalization will become a prison, if it isn’t already.
I would imagine any broad-based regulation around recourse for account locks is likely to start with the individual B2C user due to how many more of them there are (essentially everyone, even if you only count Apple and Google - legislation would of course cover every provider).
The bigger issue is that I don't even know where or how you would start with this. Ironically, there's a certain amount of comfort in knowing that your data is behind an unresponsive brick wall these days as it makes it harder/impossible for someone to socially engineer their way in. The downsides to that are many and varied, and what the post references.
This happens everywhere, not just Big Tech. Even as humans, we try to handle the 99% and ignore the 1%.
I still don’t understand what anyone is proposing - force companies to provide support against their will?
That's what laws are: forcing people to do things they would otherwise not do.
What I worry about most is that human support requirements will apply to smaller companies and essentially guarantee supremacy of big tech since no startup would ever be able to disrupt them.
Yes. This happens all the time in all sortes of industries. But people on HN think that tech companies are somehow different and shouldn't be held to the normal rules that other companies have adhered to for decades, generations, and centuries.
Like we force telecom companies to serve rural areas against their will.
Like we force construction companies to use safety gear and have insurance for injuries against their will.
Like we force credit companies to provide mandatory disclosures.
Like we force airlines to do what the people in the control tower tell them to do.
And so on. The entire concept of a corporation is a legal fiction, a privilege granted by the state that enables them to pretend they even have something analogous to free will. Without the consent of the state companies wouldn’t exist at all. Maybe we should do a better job of reminding them of that.
What you want is human judgement, but it will be hard to legislate that. What can easily happen is the human parroting back the underlying reasons for the decision. In this case "We have reviewed your case, and according to our records the account is associated with the problematic account"
I have had this happen to me in bureaucratic situations with no computers involved.
What we want isn't review of automated decisions, what we want is openness, transperancy and clarity in the process. The problem people have isn't so much the appeals process it is the opaqueness and seeming arbitrary nature of the whole thing.
But that's what a public court gets you.
If the signals used are made public, fraudsters will win every time. It’s the same with search engines- if they publish how a score is calculated, people will game it immediately.
Maybe the signals should be required to go through a review with authorities? Idk.
That isn’t to say there shouldn’t be some kind of way to escalate an appeal to a real human.
Of course keeping the fraudsters from DDOSing the crap out the appeals process will be a challenge! Because I could see them doing that…
There have been a few occasions where I would gladly have paid Google/Twitter/Apple to answer my questions.
It's also a big part of many people's social lives these days (like it or not).
We want to switch now to professional and can’t despite fulfilling all the criteria they tell you need.
I would like to see legislation forcing detailed explanations of bans though.
It's more head scratching to me that people think it's going to be easier to pass legislation than to go through the existing legal channels when a company's policies are causing damages. You sue them.
Every business needs some kind of legal advice, they don't have to be on retainer. You probably did have one or more lawyers that your leadership was in contact with for particulars. Every business I've worked at has dealt with legal bullshit at some point (even the 3-4 person startups!).
The worst part was the complete and absolute silence from Twitter. I tried opening a support ticket and got no response. DAYS later, I got an automated email about what I needed to do, but the instructions didn't even work. Eventually I was able to get my account back about a week after that by going through some cumbersome verification process.
All for sharing a dumb space meme.
In that moment, if I could pay $10 to talk to an actual human being who could resolve my problem or at least tell me what I needed to do, even if it was via web-chat, I would gladly have done so.
Living in a liberal democracy has made me so used to the system working mostly fairly that these interactions with a ‘fiefdom’ introduce some sort of cognitive dissonance.
It's not hard to argue that all algorithmic decisions impact people's lives though, Facebook for example, prioritizes certain friends' posts over others... it doesn't seem like a stretch to say this could actually impact who you're close to.
If there were more competition, there would also be alternatives that companies like in the subject case could choose from and which would deter companies from making mistakes in order to prevent loss of market share.
A good measure should be that anything should have more than 3 equal competitors, is 4+ search engine companies of equal scale, 4+ App marketplaces for 4+ phone OS/hardware makers, that can operate on 4+ telecom services, etc.
And that transfer of data and services between each must be effortless.
We don’t need new legislation that will not be enforced or is flawed because it is too specific and myopic, we need enforcement of basic and fundamental law and concepts that expand freedom and choice and our fundamental human rights.
Submit to our every tech company dictate whim or we will destroy everything you have worked for and not be able to work in your industry ever again or feed yourself is not freedom and is a crime against humanity.
And prohibition against slavery? It's both laughable and deeply offensive to consider this situation even remotely similar to chattel slavery.
No, I'm sorry, this is a horrible, horrible idea. As long as these companies are targeted by automated spambots, they need automated systems to counteract and remove spam accounts. That's just the reality of the internet arms race in the last 20 years. If you make them manually review everything, you hand a victory over to the spammers and degrade service quality for everyone.
>and have a proper appeals process.
This is a much better idea. Do this and require them to have a functioning customer service department.
Edited the comment to reflect this - thanks!
I worked on an abuse prevention system in the past and know the challenges very well, except my company actually put in the effort to respond to every appeal and compensate affected customers for their troubles.
Yes, humans are expensive, and spammers will try to game the appeals process, too - but it's simply a cost of doing business.
> Yes, humans are expensive, and spammers will try to game the appeals process, too - but it's simply a cost of doing business.
Another Hacker News commentator¹ had a good suggestion for this problem:
> Microsoft have a better solution, or at least one of their departments does. You pay for support questions and if it turns out it’s actually Microsoft’s fault they refund you the fee.
If users paid some up-front fee for the appeal, similar to the above, regular users would have the opportunity to appeal an automated ban (if the appeal was done properly). On the other hand, spammers and other malicious actors would have to pay money for the opportunity to attempt to game the system.
[1]https://www.brookings.edu/blog/techtank/2021/12/20/why-new-y...
This appeal is required to be real, actually reviewing the content or conduct in question to determine if it violates the law or terms and conditions. If there is enough information to conclude that no violation occur, the company is required to reinstate the account.
If after the appeal, the user is still not satisfied they can appeal to one of a set of government approved arbitrators, who will listen to the dispute and decide the case. It is the user who gets to decide which of the arbitrators will be used (among those certified for the relevant category of platform). The company always handles its own expenses associated with this process, and if the company loses, they must reimburse reasonable fees and expenses incurred by the user.
These appeal processes also apply to removed content, not just account suspension/termination.
There is an exception for "small and micro enterprises" though.
The main downside of this law is that its primary purpose is to create a DCMA++ framework over in Europe, but it still looks to have a much better balance of concerns that the laws here in the US have.
I think there's probably a connection between the "bloat" and complexity of the modern web that the Gemini crowd rails against, and the draconian and wildly inconsistent gatekeeping that is applied to native apps for mobile platforms. It puts the Web platform in tight competition with native apps, because it is the only viable alternative; this causes developers to exert pressure to add more and more capabilities to browsers so that they can match native experiences without having to pass review or pay commissions. I wonder if browsers would have evolved in the same way if mobile devices were more open platforms.
Lesson is, don't hire scam artists, ask your employees not to scam while they work for you or are linked to your account.
I'm going to be tweeting this story out as soon as I get to my computer.
Otherwise you still have the same problem wherever you go.
Google has a history of excluding humans from their processes, with no recourse for when their automation breaks except to complain online and hope someone important enough hears you. That's not something people can trust.
(Although more focus on the mobile web rather than apps might be a good thing)
Too bad developer greed prevents an effective boycott of their ecosystem. If enough people stopped giving them money, they would change.
In some ways I'm lucky it happened when it did, as it kept me from relying on Google services since then. Google is horrible when it comes to customer service- always has been, always will be- and it's why I'll never understand people who advocate for GCP or other Google services.
I really found this video to be enlightening on our current techno-dystopian state: https://yewtu.be/watch?v=GWvFZ99s558
But as a sibling to you say, maybe I therefore self-select away from those kind of companies, and those not thinking or caring about those things end up taking those jobs.
The people running a company have a legal responsibility to act in the interests of their shareholders. Even if making a morals>economics decision doesn’t get them into legal trouble, it can get them into trouble with shareholders, and they may be fired and replaced with someone who doesn’t have a moral compass.
So if the infrastructure doesn’t have room for morally correct decisions, no amount of martyrdom from executives is going to eliminate bad behavior in the long run.
There is also a lot of internal corporate training and team-building designed to redefine "ethics" to make this sort of stuff acceptable.
It was more likely years worth of minor changes that got it into this state. Teams adding different algorithmic checks for various things, where the output is just setting a flag on the account. And other teams adding account termination logic for certain flags or a certain number/combination of flags, not knowing exactly how the flags are set. Though maybe that would be the bad task. I'm just spitballing.
There is a balance, of course, but if you haven't seen how much automated abuse there is on the Internet, be careful of what you wish for. Even the tiniest of the tiny services suffer from massive amount of automated abuse. At that tiny scale, it was nearly impossible for me to keep up with the abuse without the help of automation, very broad bans, and deleting related accounts by walking a reputation graph (like Google is being criticized for doing here). At Google's scale, I don't think there are enough humans on Earth to deal with the abuse. As a result, there are going to be some innocent casualties.
I don't think it's an ethics thing, it's simply not possible to run a business without some sort of process like this. There are laws, rules, and processes that could cut all this down to levels that could be managed by humans, but the cure might be worse than the disease. (For example, it would be great if there was a 1:1 mapping between your national ID card and your IP address. All of these stolen-credit-card users could then be imprisoned. But, you know that that's a terrible thing, because it will also be used against anyone criticizing governments or large corporations.)
Perhaps they've scaled too large then. I don't think "we're too big to be held accountable for screwing innocent people" is a valid excuse.
Shit is hard. If it was easy to tell fraudsters from real people we’d never be discussing this. The fraudsters are willing to invest unimaginable amounts of time and effort to get into your systems and do their dirty work. Every fix you make will eventually be routed around. Always.
I disagree.
Some time ago, a person (on HN, although it may have been somewhere else) did an estimate of what it would take for Google to review all 500 hrs of video uploaded to YouTube every minute.
The result was that Google could more than afford it.
Based on that I don't see any reason Google couldn't add more humans to deal with these ban appeals.
I’m not saying it would be easy. Doing so would require insane amounts of coordinated with basically every country on the planet. But damn would it be nice if fraudsters couldn’t easily hide behind internet anonymity.
All software giants hold too much power in their hands and nobody can touch them. What can you do? They have at least 50% of the market.
https://puri.sm/products/librem-5 and https://pine64.org/pinephone.
If it needs to be more expensive to publish and buy apps, so be it. This is unsustainable.
On the other hand- at every company I’ve worked at, this is why there’s clear onboarding and off boarding policies. Yes- if you have someone on your developer account violating terms of service, they’ll shut down the account. No, it doesn’t matter that it wasn’t you personally.
To put this differently: if you had a bank account shared between your developers, and someone who left the company started using it for money laundering, the entire account would be shut down and you would not be getting that money back. In fact, you might even be investigated by authorities for money laundering since it ran through your account.
As someone who works in FinTech, we deal with tons of people just trying to steal / defraud others on a daily basis, and we’re required but governments across the world to be on the lookout for people doing “fraudy” things and terminate their accounts ASAP. If we just said “oh, it’s fine, you’re not in trouble because your (insert X relative here) was the bad person, not you,” then social engineering fraud would be rampant everywhere.
To me, the Google situation is identical to the bank situation. There’s not a good way to prove the bad account shouldn’t be associated with your Play store account. This is why you have to be diligent about who has access to these things.
To use your example, that would be like an employee getting their bank account frozen for something they'd done in their personal life, and then the company having their bank frozen too for depositing money into the employee's account.
I see your point, though.
No, having had a company credit card account 3 years ago. Unless I’m misunderstanding something, the employee had no more relationship to the company for some time.
For Google, good luck if you get in contact with a person.
Fraud is hard. If you don’t crack down enough, you get in trouble with the government, many legitimate account users, and companies working with you. If you crack down too hard, you might mess up people’s lives who did nothing wrong. Even with an appeals process- its rare to get everything right. I think the reason we had about it with big tech so much is because their userbase is so large, so even with a low false positive rate, you’ll see high numbers of people getting flagged.
I'm not against government regulation of these sorts of decisions, but to pretend that the regulations we currently have are consumer-focused in every aspect is just completely burying your head in the sand. Read https://bam.kalzumeus.com/archive/moving-money-international..., and especially the "Tiniest bit of personal opinion" section for a clearer explanation of the problems with the way banking regulation currently works.
I don't see how that analogy applies here. It would be more like if someone who had access to the shared bank account was using their own personal bank account for money laundering.
The developer wasn't breaking ToS on the company account, it was their own personal developer account. Quote from the reddit post:
> Our company used to have several employees with access to the business's Play Console, and one of them recently had done something wrong with "his own personal" Google Play Developer account.
If that’s wrong, and they were removed, then you’re completely right and everything I said is very wrong.
If you have an employee doing stupid things on their own personal account on their own personal time, should your company’s Google Play developer account also be terminated?
This is one of the many reasons I personally stay as far as possible from anything to do with Google.
What’s next? Loosing access to all our company’s emails and personal photos because someone former employee’s twice-removed cousin decided to try their hands at phishing?
Sounds like a joke, but if even Google employees' families can permanently lose access to their Google account without any recourse[^1], who’s safe?
Risk bans or bans for suspicious / illegal activity? Totally different story (see the stories of Stripe / PayPal / etc shutting down accounts). The government (at least in the US) will punish banks pretty hard if they don’t crack down on fraud hard, so banks tend to lean more towards over enforcement.
In addition, it hardly seems relevant that a ToS violation from an employee's personal account should result in effectively destroying a business.
Something really has to change with how Google handles this kind of thing. At the very least they need to have a working appeals process handled by people.
There’s a couple of ways (that are best practices for any company) to avoid this problem: - Have separate Google accounts for work / personal use - Remove old employees from the developer account when terminated
Having separate google accounts for work and personal use does not actually solve this, since google has an algorithm to figure out if the accounts are used by the same person.[0][1]
Major difference
And that is the difference. Google is not the Govmnt and there is no legislation supporting them (except their probably murky and possibly ilegal TOS -ilegal because of lack of human oversight).
This is more like giving someone a credit card associated with your business account, them leaving, and three years later your business account is closed because they committed a fraud using their personal bank account.
Google goes out of their way to associate people's accounts and identities. Even if you have work and personal Google Accounts, you should assume that Google knows they're the same person. For example, Google wants you to login to their Youtube App on Roku. If you choose not to but have it open at the same time someone opens Youtube on their phone, the two communicate and you'll get prompted to login. Even if you choose not to login, the two apps share information and cross pollinate watch histories and suggestions.
Google also makes it difficult/costly to properly lock down their development tools. You can't for example lock down your developer console or cloud account to accounts with specific domains. You also can't take ownership of your domain outside of a Workplaces Subscription in the same way you can with Apple's ABM tool.
At the same time Google requires you to consolidate all of your company assets into one basket. You can't have different developer consoles so an employee or contractor working on Project X might have access to aspects of Project Y because the console permissions aren't granular enough. So there's no plausible deniability for Project Y when a Bad Actor working on Project X is identified.
You can't even insulate projects on Google's tools as there is a 1:1 relationship between their Play Console, Cloud Console, and a singular Cloud Project. So again absolutely no plausible deniability.
What you end up with is a situation where if a user does something Google doesn't like, Google decides how large of a net to cast over that user's network graph when bringing down the ban hammer.
Side note: I absolutely won’t use my Gmail account for any other Google service. It’s just too great a risk and it’s ridiculous that a developer ToS violation can also kill your Gmail access.
I see a fundamental mistake these companies make with automation: optimizing for the wrong metric.
The metric they seem to use is the number of cases handled by automated systems. What they should use is the number of cases their workers can deal with.
The difference is that the second one doesn’t reward false positives. There are some cases that need human review. You should even be able to pay for expedited review (ideally refunding you if the decision is made in error).
A good example of this is Tiktok’s reporting system. Like many such systems it’s clear that it just takes actions based on the number of reports. There is no penalty for fake reports. So people brigade creators they don’t like (typically politics and science) and those affected have to go appeals processes. It’s ridiculous.
Put another way: automation shouldn’t replace people. It should augment their effectiveness.
I'm curious about this and not completely sure I understand what it would look like in an example. Would you be willing to expand on the point?
Given the automation that worked might process 5000 cases a day.
If the automation can resolve more cases that figure might go up to 8000.
But if there’s an appeal that takes manual review and resolution that might wear up a lot of time stick that the rate drops to 3000.
This means two things:
1. There is an impact on the metric from false positives; and
2. Having human review is still part of the system ultimately. It rather it can always be escalated to such.
Now you might say the worker might be motivated to take the least time consuming action possible even if wrong but an appeal might be escalated above then and further time spent rectifying their mistake still counts against them.
Omelas aside, I think of this every time I read about someone's work or life or memories or whatever just getting zapped by Google, for a reason that is probably contained in a 500kb EULA, but one you will never find. It's free! You can do all of this stuff! It's great! Except for when your stuff gets randomly eaten.
[0] https://tvtropes.org/pmwiki/pmwiki.php/Main/InsectoidAliens
[1] https://tvtropes.org/pmwiki/pmwiki.php/GiantSpider/Literatur...
If you fall out of favour with them you're screwed. They know they have a monopoly on their platform and it's their house their rules.
Remember this when making any business decisions about using their products
I was banned from AdSense for a never disclosed reason. I guess I still am - never tried again, in part because the alternative I used after that paid better.
> Develop for iOS. Apple has humans who answer phones and create support tickets and escalate issues and follow up and respond.
Is this true? Because if it is, my next phone will be an iPhone and I will completely move into the Apple ecosystem and develop for publishing in the App Store instead of Google Play Store.
Even though I don't do anything bad, these kind of news do have me absolutely scared that it's simply not worth it. It's beyond ridiculous how Google is treating developers. At least be precise in the cause of the termination, explain exactly what has happened.
They're not quite as bad as Google in this respect, but tying Apple chain over your neck for slightly less abusive system is a pretty Stockholm syndrome thing to do as well.
You can't fix this by paying corporations more money.
If you’re having trouble with Apple, it’s probably you.
This experience is also available with Google - "you just need to know someone" or be a company they care about right now.
We see few posts about Apple banning people with zero recourse and never reversing or reviewing the decision. Given how many people here are critical of Apple, the low volume of posts is extremely telling.
Google is on the front page regularly for this behavior.
Apple is nowhere close to perfect, though. They probably have even more problems with control over the app store and what you can put on it. To make it worse, unlike android, sideloading is not only not supported, it can be a violation of terms.
I saw the comments about developing for iOS instead and shook my head, to be honest. It's just as difficult to deal with, possibly even more frustrating when you make a simple app update and it gets rejected because something that was already in the app now violates app store policies, or you do something with your app that <big company> does, but you're not allowed to. And their explanations can be just as useless.
But, at least you can get support. Which is why I switched to Apple for many of my devices and services. Probably the main exception is I don't use macOS devices (macbooks, etc).
When we get the full story it's usually less black and white. Quick skim over the thread and it sounds like they let an ex-employee have access to one of their accounts and he committed multiple violations? Was he spamming? Was he uploading malicious content to the store?
Also, don't build on others platforms if you want to control your destiny. You can't have it both ways.
Our company account is assumed to be "associated" with wrongdoing of my former employee. This is the black side.
In the future, fully control the accounts yourself or don't build in someones walled garden and then complain when they ask you to leave.
It's a warning that if your livelihood or something is really important to you, you should not build it inside google or apples walled garden. Or if you do, know that for any reason they choose they can kick you off. Unfair as that is.
Welcome to capitalism. Go host your own stuff if you don't like their rules.
https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32...
Specifically, article 4 covers termination of service, and the rules around this.
It seems Google and other platform providers have no interest in following these rules though.
The reason? None. The same as this one: [0]. Robots at Google once again de-platforming apps because they can and for no reason.
Like YouTube, Google will not change and it will only get worse. [0]
This is pretty horrific!
One "bad" Youtube comment can ban your Gmail account.
"...Youtube Account Suspended" - "...All i do is watch videos and subscribe to my favorite youtube channels while sitting on the toilet!... I have no idea what to do."
https://support.google.com/youtube/thread/21108892/youtube-a...
"I am not a Google or YouTube employee - Product Experts are volunteers"
wow, i must live under a rock, but is this how google does "support"... by volunteers?- make applications/repositories discoverable without running a service,
- allow developers to handle billing for paid apps themselves, again, no service,
- have client side malware protection without playing a cat and mouse game,
- prevent discoverability of pirate repositories without running a service?
If these problems can be solved (or others I didn't think of, maybe you did?) you can basically get rid of monopoly curation of available applications on android (or anywhere for that matter).
I think that Google has done enough damage. Government has to step in and smack hard in a teeth with a heavy fine and a requirement to introduce notices before doing any action (especially where money are involved) and mandatory appeal process with the human involved and obligation to answer direct questions (like giving detailed reason).
Good luck fighting this as a small company.
We can't have app distribution in these people's hands (both Apple and Google) unless they change fundamentally.
So the only safe way is for companies to say you have to have a separate browser for @company.com?
Isn’t that kind of the trade off of small entities doing business with a tech conglomerate? There’s not much government authorization with developing smart phone apps.
Reddit is cancer.
(BTW, I'm talking about the email Google sent the dev's)
Moreover, you likely supported this when it manifested a bit differently. Most of HN seems to firmly believe in guilt-by-association as a way to control behavior, speech and thought. You get all preachy and act horrified when it goes "too far" (i.e. when it looks like something that might happen to you personally), but in general it's a concept endorsed or at least tolerated by the majority here. Well, you know what they say about Karma.
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
https://support.google.com/googleplay/android-developer/answ...
Hard to judge without having all the data in hand
The screenshotted notice indicates it may be due to actions by the individual developer on their own account, for which the company would not necessarily have been notified.
I think Google handles these situations terribly from a PR perspective, because the moment someone posts negative publicity would be the perfect time to Google PR to show their hand and say no they are misleading the public.
There is probably a good reason they don't do that though. I could see how a company isn't really responsible for what another developer did that they may have not known about, but I don't think we are getting the full story here.
Things like this don't ruin a company though. The company should immediately file an injunction and claim against both the developer and Google. They should have done that immediately. I think they have no clue or simply don't have the money to pay an attorney so there isn't much they can do. Heck an employee could steal all their money and unless they are willing to file a lawsuit there isn't much that anyone can do.