This is beyond the pale. Google should not have the power to decide who you are and are not allowed to hire. It both goes against the basic concept of a limited-liability corporation, and harms worker rights.
This is beyond the pale. Google should not have the power to decide who you are and are not allowed to hire. It both goes against the basic concept of a limited-liability corporation, and harms worker rights.
Ultimately it did not disappear in 30 days. Was it because I upload passport photos? Not sure. Because I spoke to customer service? Not sure. Because the original shutdown notice was a mistake? Not sure. The lack of clarity made it worse.
I've heard stories about people losing personal accounts like this due to GCloud usage. At work, where I'm CTO, I have open access +MSAs to the three major cloud providers -- BUT I am very hesitant to use anything but AWS/Azure. The risk of something going wrong with GCloud and that metastasizing to my (or anyone's on the team) personal Google account (or vice versa) is huge and just not worth the risk.
I'm still forced to use Google stuff here and there but I'm no longer dependant on them, and coincidentally I've been sleeping much better recently.
I use various google services, and do a monthly backup of everything. I guess that's a sane thing to do with any service, even self hosted ones.
It's a questions of eggs per basket. Google wants you to keep everything in their one basket, and the result is that if they arbitrarily terminate your account, you lose everything. If they give you 30 days like OP, you have to remember all the different places you need to download content from.
If you split your services up, a sudden termination only affects a few things rather than everything, and a forewarned termination has a much smaller surface area you need to consider.
Google Takeout (takeout.google.com) should give you almost everything in one place. It's a good idea to do this periodically in case you don't get the 30-day notice. Be prepared to download a few dozen GB, though. And there is no "incremental" option.
I wanted to migrate from Google Photos to iCloud. Turns out there is no easy way how to import the photos to iCloud without loosing metadata. I gave up and just bought more storage on Google.
I'm a bit surprised that you had trouble importing photos, though. Isn't most of the metadata kept in standard EXIF tags in each file?
However, I don't agree with "remember all the different places you need to download content from". Google does this with Takeout, so I can have 1 backup of most of my things. When using different services, I need to have various backups.
Reason is: I don't depend on services giving me 30 days. I assume they can block access on the spot.
Protip: you can easily sync obsidian by sharing the top-level vault directory with syncthing. Its entirely transparent, you just start obsidian and open the vault, and changes you make on one system automatically appear on others.
As for protonmail, its better than google -- but you're right in the data ownership. In the case of protonmail, they have a much better track record than Google, but if you are really paranoid choose a service that supports SMTP/SNMP. You can then just have a mail client store the mail as an archive or connect it to any other mail system.
I have mentioned my preferences before, but I'll refrain from turning this comment into an unpaid ad. Drew Devault's recommendations are pretty good though: https://drewdevault.com/2020/06/19/Mail-service-provider-rec...
SNMP is something entirely unrelated, afaik.
Your backup note is on point; I highly recommend everyone to do a Google Takeout every few months (or at least years!!). If you've never done one, like most Google users, you're playing with fire.
“GoDaddy has two major problems.
First, their customer service (…).
Second, if there are accusations made against you, they will shut you down and side with your accuser more often than not.“ https://www.warriorforum.com/main-internet-marketing-discuss...
Maybe? I would hope that you could raise the issue with the dowmain registry or ultimately ICANN if the registrar does not let you move the domain elsewhere after banning you. Registrars do not have the same platform ownership over domains that Google has over gmail accounts, they are just middlemen.
why not?
Gmail is worst-in-class at this point. It's slow, it's bloated, it's bad at spam filtering compared to the alternatives. They've been riding on people remembering email before Gmail, but not really actually stayed competitive with any modern alternative offering.
The difference is night and day. I can look in the spam folder for my work email now and there are hundreds of spam messages there for the last 30 days, and absolutely zero false positives. I have seen a handful of spam messages come through, but it's in the single digits over the last two years.
That's often the case with one of my friends who has a Gmail email address: anything that I send him (once or twice a year) doesn't even show up in his spam list without first making him start an email exchange to me => in my opinion that kind of filtering is just too easy to do (come on Google, at least put it into the spam folder and/or show it as a colored/blinking line and/or put some warnings whatever - don't just delete it), and of course it poses questions about oligopoly etc. How Gmail works is just not fair (in my opinion) :(((
Spam filtering on Fastmail has been the same/better than Gmail was - including possibly fewer false-positives on the Fastmail side. Gmail was getting worse about those, both with mailing lists and individuals' emails.
Like many on HN, I'm diversifying my data/access risk across more providers. Too many wake-up calls recently about Google locking people out. There are still some services Google is compellingly better enough that I still use them (Android, Maps, YouTube, Google Sheets), but Email was too precious to tie up with them. I also wanted to finally kick myself into stoping using the `gmail.com` address at all anymore (maybe 20% of my emails before the migration).
One important point here, and I don't know how long you used Fastmail when you tried it, is that Fastmail uses a personalized spam filter. It probably took me six to eight months to receive enough spam on Fastmail to actually train it. (In the interim, they use a non-personalized filter, which as I said, still worked!) Gmail doesn't seem to be able to make personal spam decisions: When I was regularly using Gmail, some types of regular messages would spam-bin no matter how many times I marked them not spam or classified them as a particular category of mail.
Anybody that knows better, will avoid Gmail like the plague or use it for only the minimum.
EDIT: Verified. Not yet for iOS.
While I have a work iPhone 12 so I use both iOS and Android daily, I do actually prefer the Android ecosystem, plus iOS being locked down in terms of installing third party apps is a disqualifier for my personal device. Also bugbears like the headphone jack, though I might be out of luck there in Android in another device rotation.
The up-front cost and setup time is a stiff investment, but I’m much easier in mind now.
The other side of the coin is my wife’s gmail, which is going to be deleted come May. So... we gotta figure that out.
Yes, NextCloud and Owncloud both integrate with OnlyOffice Community Edition[0][1] which supports collaborative editing of text documents, spreadsheets, and presentations.
My collab needs are pretty light, I only work with a few family and friends, but I haven’t run into anything I wanted to do in Synology that I couldn’t.
Not really, big players have the advantage that nobody is going to block them. Most of them spam regularly by thousands of letters before some automation of theirs triggers (or the spammer stops).
Currently I'm syncing to a s3 bucket with e2e encryption but of course you could sync to a server you setup yourself including a basic windows box.
I've been using it for a little over 3 years and it serves all my note-taking/storage needs, especially with the relatively recent addition of extensions/add-ons. I have had no issues syncing through either dropbox or Nextcloud.
For my corporate accounts there is NO WAY i'd use GCP. I have the privilege of MSAs with all three major cloud providers and we're doing most things with AWS. So on the corporate front, I didn't leave because I just didn't enter in the first place.
That said, the rep failed to provide any definitive guidance on issue or resolution.
I'm currently thinking of migrating from Google for productivity to Office 365. Wondering if I'm just re-branding the risk of my counterparty.
With AWS/Azure, you typically wouldnt have extensive personal data with them, so you dont have the risk of work and personal accounts colliding. I dont know anyone with personal emails/accounts/photos on the Microsoft ecosystem. With Amazon, whats the worst that can happen? You lose your connected Amazon purchasing account, doesnt seem terrible.
With Google you often have email/documents/photos with them. If you have an Android phone, you have almost everything with them.
In a way, this is sort of a digital-era generalization of "freedom of the press belongs to those who own one."
It's both. When you work with tech companies this kind of overautomation is rife. When you work with any other type of business they give you an account manager and you manage these issues openly together with a relationship. If there was a human at Google who picked up the phone and worked out the problem with the developers before this ban was imposed, this could have all been nipped-in-the-bud before an account was terminated.
My current account doesn't have much money in it, but my bank would call me if there is an issue which would terminate my account, and I'm confident that they would work with me to offer up solutions rather than instantly terminate it. Google should provide developers more respect than my bank offers average consumers.
There is no excuse for them not picking up the phone and just talking these things through before they implement the bans (unless there is active malicious behaviour in an app, in which case I would expect a suspension to happen and be followed up with a phone call straight away).
The only way to fix this is to legally require it, because nobody's going to stop the profit train by themselves.
Or they've simply removed those tasks under the rubric of automation.
That's not correct. Google is more profitable because it is a monopoly and routinely engages in illegal anti-competitive behavior.
It's precisely because this is the case that it's able to have nonexistent customer service and stay in business.
[1] e.g.: https://www.bbc.com/news/business-36737666
[2] among others: https://www.forbes.com/sites/enriquedans/2021/01/19/jedi-blu...
Which is why both need aggressive regulation.
I don't know what Google's rates of customer service failures actually are, but even a minuscule of rate of horror stories seems to hurt brand, judging from HN comments.
I wonder whether fixing half of, say, 0.00000001% of cases that would otherwise be PR horror stories, could translate into measurable boost to brand value.
Maybe all the math has already been done, and all possible wins for creative automation motivated by business payoff (and promo bids) have already been achieved, or maybe not.
I doubt it. Brand value is a notoriously fuzzy concept, and corporate decision-making features a heavy measurement bias. A toxic brand might be measurable by the time it's influencing enough purchaser decisions to show up on "would you consider?" surveys, but that's an advanced stage of the problem.
I've never worked with or for Google, but having worked for software companies my whole life, I suspect that it's overautomation, combined with "silo-ing". Even if somebody identifies the problem from the user's perspective, it becomes a rats nest of responsibilities to untangle to figure out who or what group(s) can address it and how. The people who actually understand how a particular component works and can change it are limited to their particular component and the people who are nominally in charge of "everything" have no detailed visibility into anything at all.
Especially not retroactively.
"Your former employee broke the rules at their next job, so you're banned" is just bizarre.
A lot of folks are offended by $100 / year developer fees. If Apple et al charged $10,000 to get going as a developer, they would probably be better positioned to deal with all this less automatically. In fact, game dev historically might have followed a bit of this model (xbox etc).
Anyways, my own thought, there should be a pathway to a $5,000 fee where you get a higher level of human interaction.
I really dislike this explanation because there are so many obvious things they can do. Example:
1. Force uploads of Passport/ID for identity confirmation. If you have 100 accounts with the same passport...ok...issue, but if not, is it worth human review at least?
2. Force credit card payment with address verification, ideally match to passport. Same credit card used across 1000 accounts...ok...issue, but if not, perhaps worth a review at least?
3. Still an issue? Force user to pay $100 for verification and run credit check routine.
The idea that blanket account terminations are the only way to handle issues seem lazy.
Op wants to be able to hire somebody with a history of abuse without google enforcing them
And that's pretending they don't already make obscenely high profits per developer, and can absolutely afford to provide the necessary support for these situations, which again, are largely their mistakes to begin with.
I don't know what universe android app developers are living in, this is basically "free" for most significant businesses.
For that $25, you are NOT going to get white glove support / treatment. Not happening.
That sounds like extortion...
"We're going to ban your account because we want to, unless of course you pay us $5,000 so you can talk to a human to resolve this issue."
If you want to talk to a tech company engineer for bug fixes, you pay for that level of service.
There is something a bit almost scammy about all these "businesses" demanding white glove custom treatment, but complaining loudly about even being asked to pay a one time $25 fee to get on platform.
It used to be to deploy to a platform / get SDKs for the platform the costs were FAR higher.
There are something like 5M+ android developers. If you want to support this developer pool with 2-3 hours of work per developer per year, you are looking at 15M hours of work per year. And these people also become a risk - they can be socially engineered, they can be paid off etc. We've seen this over and over again.
If you look at phone co employees who are supposed to protect you from sim swap attacks etc, they have a large number of employees, so service is "good", but security? Not so much.
What you are proposing is that google should offer a human service in a very adversarial and tricky area (ie, your own staff may be working against you) and that asking to get paid for that is "extortion" that would result in jail time. This is perhaps why they don't even offer a way to pay (a lot) for a very careful high level review. Folks like you would demand jail time for them. Instead we are stuck with automation.
"Bid more than your competitor on AdWords for the literal name of your business or else they'll get the customers who intended to do business with you."
You would think something like this would increase competition between businesses (competitors surfaced immediately for users). Instead I guess this is seen by a bad thing - though it's not been clear to me recently that the FTC is looking out for users, they seem to have gone BIG into protecting businesses for some reason.
Would you rather have a neighbourhood mafioso who is amenable to financial incentives or a local random psychopath?
I can't help but notice the "they're a private company, so they can do whatever they want" folks that pop up whenever somebody's account gets banned for political views are strangely silent right now...
My favorite was when they were licking their lips and reaching ecstasy over Parler getting deplatformed but then throwing a tantrum like a week later when Terraria dev got banned by Google.
Terraria guy and this guy simply need to build their own Google, Gmail, Play Store, and Android, easy! ;)
Also celebrating that Google was ‘on their side’. Until they are not.
> My favorite was when they were licking their lips and reaching ecstasy over Parler getting deplatformed but then throwing a tantrum like a week later when Terraria dev got banned by Google.
That was my favorite one. Basically the chickens cheering on the wolves eating the other chickens that disagreed with them. Now the wolves are eating them as well and they are complaining why they are ‘not on their side’ anymore.
They thought it could never happen to them. Just use the same ‘private platform’ logic towards them for everyone else that is getting banned after Parler and now they are all crying in the comments here.
These companies are not on anyone’s side and these bans can happen to anyone on their platform. They won’t change.
Tired of seeing people equate war crimes to Google screwing over some company.
The secondary sanctions exist because it's near-trivial to automatically create dozens of proxy accounts for a bad actor to launder reputation through. So in addition to direct fraud detection, Google has had to automate secondary "Is this account probably the same bad actor" detection.
That system, like any such system (including human review), has false-positivies where two accounts are believed to be the same owner when they are not. But the automation-with-insufficient-human-review problem is specifically Google's mistake, and there's room for improvement.
Anti-fraud is a tough space because you can never be 100% sure which actors are legit and which are scammers… after all if you knew who the scammers actually were you’d have blocked them all ready.
I always make sure there is some kind of escape hatch for legit users who get caught in our system. These escape hatches might not be super awesome for real users, especially if they fell into a bucket that strongly labels them as scammers, but at least they have an out.
Give access to as few employees as possible, and have all access to Google Play go through a designated, trusted release manager or "play account manager"? And don't log in to Google Play from random browsers and IP addresses which could create an association with other Google accounts?
Use company e-mail addresses to register for everything. Enforce it for your employees. This is in the interest of both the company and the employee. Yes, the summer intern gets a corp email too, which at minimum gets access to internal resources beyond the OT chatroom revoked when they are out.
(Your advise is not bad though: grant granular access as it's needed)
But yes, my point of not mixing accounts does go that far - if you don't have separate hardware, at least use separate browsers or browser profiles.
Don't put the cookies in the same jar.
Easier said than done, in my experience. Years ago I had to log into my Company's Play account on my computer for some specific reason, one time, and more than a year after that, my daughter purchased a game on my android phone and the CEO sent me a message saying "FYI, we just paid $3 for a princess coloring book app, please enjoy it with our compliments but please delete the Play Store login info from your devices." I still have zero idea how that could possibly have happened. That company will be shutting down and now I'm worried that my google account is somehow "linked" to it.
As mentioned in a sibling comment: Utilize browser profiles (Chromium-based/Firefox) or Multi-Account Containers (Firefox).
This is probably "best" practice, but Google has randomly closed accounts for our mobile test devices. They're only used to run our (non-shady) apps on a single device that is never used with other accounts.
FWIW: there's some reason to suspect that the "later" bit is being spun here. Per the timeline in the article, there were only 5-6 weeks between the employee being fired and Google taking action against the employer[1].
That's pretty tight, and from an enforcement perspective is going to make it extremely difficult to distinguish which entity is doing the bad things. And, frankly, given the spin elsewhere in the story, I'm inclined to suspect more ambiguity here and not less.
What's the ask here, that Google (which correctly detected the association between the accounts) audit the IT permissions logs of accounts that commit bannable offenses before taking action? That just doesn't seem feasible.
[1] They further spin this by trying to claim that the employee left in 2019, but have to admit that he was still present as a consultant.
Mar 2019 - H. Left the company, all permissions removed except on one game which we were still using H.'s consultation on - The app was unpublished later on
04 Dec 2021 - Termination of H. (Former Employee) account because of multiple policy violations
26 Jan 2022 - Termination of our company account (Raya Games Ltd - AKA TOD Studio) without prior notices and warnings
I think the 04 Dec 2021 is Google's termination of the "H" account.
What we are seeing is a monopolist abusing its power by directly harming somebody and the civil society refusing to acknowledge any harm. And it's doing so by the most visible power demonstration it can.
Really, it's a monopoly problem. You shouldn't be affected by whether google wants to work with you or not
The problem isn't that you don't have options with regard to hosting, email, etc (with the notable exception of google play store), the problem is that once you've picked your option it's hard to migrate out, and as a customer you have a right IMO, whether in the terms or not, to a good faith effort on the part of the service vendor to sort our any problems you encounter with the service. If a robot just shuts you down no notice and there's nobody to reach to sort it out that's a negligent business practice and I believe any vendor of any service that operates this way is liable.
If they want to offer migration tooling, notice and access to your data I can see it being alright. A pain in the ass, but at least not the end of your business one morning while making coffee.
As far as google play goes, I think there's the monopoly aspect to work on and hopefully legislation brings a resolution to this problem, like offering independent repositories as a default option or something like that, til that time though, do not rely on it entirely. If you have to open source it and put it on f-droid, maintain an aptoide repo, apk download on your site and market that heavier than your google play account, whatever you have to do, just do not rely primarily on the play store because you're basically giving google the keys to your kingdom.
> The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
> In the cases referred to in points (a) and (c) of paragraph 2, the data controller shall implement suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to contest the decision.
„ personal data’ means any information relating to an identified or identifiable natural person (‘data subject’)“.
This is a business, not a natural person.
As if that will ever happen. We don't live in a world of rules and logic until things play out as simply as above.
Just clarifying that the concept of a limited liability company has nothing to do with this. It is about not having company liabilities (e.g. debt) reaching stockholders (e.g. banks seizing your personal car and house to pay for your business defaulted debt).
But Google has its own reputation (and users) to protect. It's taking a risk whenever it allows a developer on its platform. If a developer with low name recognition uploads malicious software, it's not the developer's name that makes the headline.
Crucially, there's no information on what the employee (and later contractor) 'H.' did to get themselves banned. Or fired. From the OP's own timeline, the ban came less than two months after they severed their relationship with 'H.' Google isn't swinging around the ban hammer years after the OP separated with 'H.'
The OP's games could still include code contributed by 'H.' And 'H.' is apparently untrustworthy. Is that a risk Google should be forced to take as the curator of the Google Play store? I don't think so.
The problem lies in the people who implement these anti-fraud measures forgetting that not every account their system flags is actually a scammer. The goal should always be to fuck over the scammer as hard as possible. However you must always make sure the real humans that get caught in the net can always get out of jail.
Assuming that the 1% of real humans that get flagged in your system don’t matter is how you piss people off. Always provide ways to get real people out of jail! Those people are honest people doing the right things. They are the ones you are trying to protect!
If 'H.' is a malicious developer, then all apps that were extant while 'H.' was associated with Raya should be considered suspect. Google (and its user base) have no idea what apps 'H.' touched. The very least Google should do is ban all apps uploaded and/or updated during 'H.'s employment.
And even then Google has no way to know whether 'H.' still works at the company, or will work again there in the future. Google doesn't (and can't reasonably) have any insight into personnel decisions at Raya Games.
Is Google throwing the baby out with the bathwater? Yeah, probably. But Google can't differentiate between baby and bathwater when it comes to malicious developers. Google has an affirmative responsibility to protect its userbase. It doesn't have an affirmative responsibility to let any individual publisher sell apps on the Google Play store.