Google has removed Conversations_im from the Play Store
gultsch.social
gultsch.social
Recently Google Play decided to display a permanent notification prompting me to uninstall that "dangerous" app because it could "damage" my device. It's impossible to disable this notification.
This app hasn't been updated in years. It has no ads. The only network request it makes is a GET to update the local DB.
My theory is that Google has decided to take into account generated revenue in their risk assessment algorithm. That would explain why FOSS apps are getting the axe while the dodgy commercial call blockers that upload your call history to their servers are still up.
Both companies response to the press has been to blame the apps again and again hoping that it would be enough to continue what they are doing.
Occasionally they even blame the users directly, the play store page on install displays "Safety starts with understanding how developers collect and share your data"
I started using it after Google refused to let me install watch faces, because the apps hadn't been updated for foldable phones.
Edit: the trick I found was to search on google.com in the browser, then click on the link until it gives you the option to open in aurora v/s play store.
Google even allows this for banking apps.
If an app has been removed from the “Play Store”, that means it's been removed from the repo, and a different front-end to that repo won't include it.
Mischievous and dishonest use of "security" as an cover by policy bullies, profiteers and other gangsters is as much a threat as worms, viruses, zero-days, phishing scams, data leaks all other kinds of actual security problem.
Not least because it weakens rational expectations and evaluations of security and substitutes blind trust in (obviously untrustworthy) entities.
Sadly, It's a powerful lever because the average person knows so little about computer security and is easily bamboozled by scare-mongers. Indeed, many phishing and malware scams start with a pop-up saying; "Security Risk! You must update now!"
It is a form of extremely dangerous disinformation. For companies like Google to engage in it for profit is treacherous and reckless.
It's a sure sign of an underlying toxic and abusive relationship.
[0] https://techrights.org/o/2021/11/29/teaching-cybersecurity/
No, they don't. They are protecting against malicous actors or at the most buggy software doing bad things on accident.
>most of the locking down of devices isn't to make it harder for attackers who want your data
Advances in this area definitely has been happening. The move to apps getting their own sandbox and having to be explicitly granted permission to access files outside the sandbox definitely helps against this. No longer can malware just read and upload all of one's browser history and malware. Even if an attacker got physical access to the device they would not be able to just dump what's stored either due to encryption.
>to keep things like DRM keys from you
This should be pretty self explanatory, but of the security of DRM keys is bad then attackers can dump unprotected versions of the content which is against what creators that have elected for DRM want to have happen with their works.
On the third point, we are in agreement. They want to make sure that when content right hoarders want to remove the content from the service you've paid for and move it to another service you now have to pay for all over again, you can't just keep a copy of what you already paid for. That's what I meant, keeping the device secure against you, who paid for it.
I didn't do this. Can you explain your thinking?
By sending all my data to Microsoft or Google so they can sell it on the open market ?
They are not "protecting against malicous actors". They fix bugs when they are openly exploited in the wild (hello Apple).
BTW, what happened to ProjectZero ? Never heard from them for a while.
Mine was mid-last year. It was a huge pain, since my apps are really a PWA with a wrapper around it and is updated through the web. This means that I hadn't update the apps in the app store in a few years, as it wasn't necessary.
And of course, the wrapper I was using (cordova) didn't support some things from the new SDK, so I had to upgrade to a new major version. Anyway, it was a huge pain to upgrade all that for no functional changes for the end user, for the 10-ish open source apps I built and maintain.
Slightly off-topic, but Android does now support a much better method for submitting PWAs[1] that I'll move to the next time Android requires me to update the target SDK of every app. Hopefully, they'll continue supporting that and it won't require new submissions after that.
I have an app in the Play store and starting in June I have to get a D-U-N-S number, have a phone & email for users to contact me, a phone & email for Google to contact me and documents to verify my identity and my business.
Another topic is how aggressively anti-freedom Android has gotten with the standard practice of root detection. It feels like more tech overall is becoming a walled garden as of late.
Suddenly, they started doing this? I don't rely on Google Play in any capacity, but it is terrifying. Anyone not determined enough to sideload a third party app store or apps in general will find themselves unable to use a substantial amount of projects that relied on outdated SDK or just couldn't keep the pace, even if the code is out there and can be audited.
Also, if the app hasn't been updated for years, chances are that it targets and outdated version of Android, which works, but is considered suspicions by Google as it is also a way to bypass some security checks in recent Android versions.
There are probably many other criteria but I think these are the most likely.
Not saying it is a good thing, but it explains the reasoning. I wish Google did human reviews and not rely that much on their bots, but then that's what Apple does, and it is even more locked down. Maybe try F-Droid, it is an alternative app store dedicated to open source.
And yet the only reason Google won't add internet access as a revocable permission is their ad business.
Chrome constantly scans your harddrive in a way you can't easily turn off, and it's not for your safety: it's for the safety of their ad business to try to catch malware that engages in click fraud. If you have media or backup drives it just constantly adds wear to them.
Is this true? Chrome is open source so someone should be able to point out the code that is doing that. What is the source of this info if not the code?
Can't they (at least in principle) apply whatever patches they want before build and release?
https://www.google.com/chrome/privacy/whitepaper.html#unwant...
> Chrome periodically scans your device to detect potentially unwanted software. In addition, if you have opted in to automatically report details of possible security incidents to Google, Chrome will report information about unwanted software, including relevant file metadata and system settings linked to the unwanted software found on your computer.
> System information includes metadata about programs installed or running on your system that could be associated with harmful software, such as: services and processes, scheduled tasks, system registry values commonly used by malicious software, command-line arguments of Chrome shortcuts, Windows proxy settings, and software modules loaded into Chrome or the network stack.
Even spinning rust wears out eventually. Not knowing any details about how often Chrome did this, it is hard to say just how significant this wear would be compared to other normal uses of the media. But it is clear that wear would occur to some degree.
Only write cycles cause wear, read cycles don't cause any meaningful wear.
https://security.googleblog.com/2023/03/thank-you-and-goodby...
Though, Google banning unlocked devices from using Google Pay was a really user-hostile decision.
Settings>security and privacy>app security>play protect security
The worst part is the lack of communication from Google about what they think the problem is. There are plenty of apps that do actually upload contact lists to servers (hi WhatsApp, etc.), and they are still listed on the store.
Many XMPP apps do request the contacts permission, but this is to (on the client side only) allow storing XMPP addresses in your phone's address book and reusing your existing contact pictures, etc. This is explained within the app, and granting the permission is entirely optional.
Really really creepy when you just exchanged numbers with someone and you can see all their 50 tiktoks. Happened to me with a girl I matched online - funny for me to see her videos, for her it was super creepy.
† Or a hash but that's barely pseudonymous. The social graph alone could constitute PII as it could easily identify me unequivocally, but here's no way for me nor anyone outside foostter to know what happens internally, let alone request erasure.
You send links to friends, and they immediately pop up as contact suggestions, too. TikTok is really keen on tracking those relationships down
Facebook (and others im sure) absolutely do the same thing. It's just that on facebook there is no attribution to how they generated the suggestion when the person appears on the 'people you might know' feed
See, that's probably where you're going wrong: I doubt a human looked at any of these apps and thought "this is suspicious".
Instead, I think Google is using some kind of AI for determining this stuff. The only human component I expect to be present would be people working to prevent large apps that do upload your contacts to the cloud (WhatsApp and friends) from getting flagged automatically.
Claimed we were uploading contacts and removed our app; we definitely don't upload contacts, that's a fact; the infra is also self-hosted so where would we be uploading them to?
They only way we got them to allow it back was to add a privacy-policy notice to say that we upload contacts and why, despite the fact we actually don't...
Google and Apple are well positioned to help everyone do better here, but the game-theory doesn't make being transparent any easier.
I can't be more specific, as I'm not authorised to speak on behalf of, or represent my employer; my words/opinions are my own etc.
We know, because we have to know.
At most places the most serious bit is some sort of compliance checks with vendors. And while that might carry legal consequences it's technically a pinky-promise. Nothing in the system enforces it in any way.
Unless one does some technical analysis on every version of every deps one uses, a dep (maybe via one of its deps) can get compromised and how/when will anyone notice it?
It is a technical challenge, and almost impossible for small devs. If you have a process in place to tackle this I'd love to learn about it, even if it has to stay in general terms.
Google and Apple's role is to defend users. This nanny state solution is not the only way to accomplish that, and in fact, they only do this to extract as much value as possible from the marketplace.
An alternative app store gripping the mass-market is unlikely; a new entrant into the Android-iOS duopoly is unlikely, Google/Apple actually giving a shit about the apps and developers making the software to rake in cash for them is _unlikely_.
Having been in the mobile-app-development space since the beginning of Android and iOS, I've given up. I don't use my personal developer accounts any more, and I don't do "mobile" at work any more.
I'm just too jaded to care how wrong it all now.
...? How does self-hosted make a difference in this scenario? Uploading means it's leaving the phone, regardless of the destination. It could be going to your server or AWS or anywhere else, and I would consider it being "uploaded".
"Google has just removed #Conversations_im from the Play Store because they think we are uploading the user’s contact list. We don’t."
and
"To be clear: They didn’t just reject an update. They outright removed the app entirely. Otherwise my plan B would have been to remove the contacts permission which is used to display the name and profile picture locally if the XMPP address matches an entry in the users address book."
/s *
*) For that one person that thinks this is not a sarcasm.
I never heard of anyone who was able to talk to anyone at Google. HN is full of folks getting apps suspended, locked out of their Google account and so on... Not being able to talk to someone is sometimes actually the only problem (though we all know the app store has much more issues than just that)
But: Often it does help to simply write them! Yesterday at 16:56 our update got rejected, at 17:51 I submitted an appeal and at 18:33 they accepted the appeal and the update got approved.
The only way to sometimes get stuff like this resolved is to make the front page of HN, Twitter, etc.
Feels like a slap in the face every time.
It builds a database of users’ contacts. Probably in violation of GDPR but they have a constitutional exception for that in Sweden (“utgivningsbevis”).
I.e. they checked 1. uses contact permission 2. doesn't have in their privacy policy that they process/upload/store the contacts => must be malicious so kick it.
probably they don't want to bother to have to consider if contacts are actually uploaded or not and just blindly assume they are
problem with that is a lot of privacy friendly apps do exactly that, access contacts for convenience features but not upload it
Article 6.12 states: "The gatekeeper shall apply fair, reasonable, and non-discriminatory general conditions of access for business users to its software application stores", whereas nothing about their decision is fair & reasonable.
Furthermore: "For that purpose, the gatekeeper shall publish general conditions of access, including an alternative dispute settlement mechanism.", while it sounds like no serious appeals procedure was offered.
Now, how to actually enforce this in a procedure that won't take years to complete is a different question..
Yes, I understand this limits the reach to those who know about F-Droid (et al) but given the way XMPP has been pushed out by the aforementioned corporate entities it is likely that those who use XMPP already know about and use F-Droid.
So a reminder that F-Droid features donation links on app listings that support it (including Conversations), allowing you to discover how to donate directly to the developer (no percentage fee is taken by Google that way, too).
Maybe someone else remembers better?
There is a an extensive comparison of power consumption by messaging apps out there somewhere on the 'net but I can not find it at the moment. In that test Conversations ended up as the 'best' (using the least amount of power) while Skype and Facebook Messenger ended up worst if I'm not mistaken.
"I understand that most of my audience here on Mastodon is more ideology aligned with F-Droid but the app sales on Google Play store have contributed significantly to me working (almost) full time on #Conversations_im.
Without the revenue from Google Play I can’t afford this." -- https://gultsch.social/@daniel/111929678072451151
I hope he can work it out with Google. Conversations is the best Android XMPP client I know of.
I was using XMPP only for some notifications (through a small bot) and it was nice while on Android. But when I moved to iOS I just stopped using XMPP because I didn't want to use any of the available clients.
Recently, I have encountered problems with Tasker, because Google has removed another set of abilities from Android for the sake of "security". Which for means there is less and less reason to use Android, which kinda sucks..
They should totally remove WhatsApp as well then. Last time I tried to install it it did not even work without access to the contact list.
And for other individuals just wanting to talk with their parents it's just a chat app, they don't care if it's XMPP or not, Conversations is just really nice to use.
Without standardization, there can be no interoperability and without agility any IM protocol will soon be outdated. I think XMPP is a success story because it realized this, but it's a success story that isn't told very often.
All those platforms only can make so much money because AI makes critical decisions and they can even claim not to be liable. If they make so much money with you it would at least seem reasonable that you get a human contact.
Fellow humans, there are alternatives to Google and Apple! Your neck need not be under anyone's boot! You don't even need to give up any functionality:
Data service:
The simplest thing is to buy a prepaid SIM and top it off with cash. The lovely people over at /r/nocontract maintain a big spreadsheet so you can filter by various properties of the available contracts.
Another way to go is to pay for a postpaid plan with a virtual credit card (VCC) like at privacy.com. It won't be linked to your name at the telco, but of course privacy.com knows who you are. There is also Abine Blur, and some others.
Yet a third way to go, which is nascent, is buy an eSIM with crypto. You can also buy prepaid VCCs with crypto.
An interesting new choice is PGPP https://invisv.com/pgpp/ who rotate your IMSI and do some other cool stuff. It works by e-sims.
All these methods make you /pseudo/nymous, but obviously you're still identifiable by subscriber number and possibly IMEI, to put aside correlational things like your traffic profile. You can help this problem by routing everything through a VPN. Then you're pseudonymous but the cell carrier knows nothing about you other than that you use a VPN. Pay for the VPN with crypto. Of course now the VPN provider knows your traffic, but you're much more anonymous to them than you are to a telco. You make your choices. Defense in depth. Etc.
OS:
GrapheneOS: https://grapheneos.org/ Very much like Calyx, but extra-hardened and with no MicroG. No involvement with Google at all by default. You can make a secondary profile in which you install Google Play Services to set up an environment where you can run unprivileged Play services + whatever crapware you need that requires them. Unprivileged here means it's like any other app: if you don't give it access to your location, it won't know where you are. If you end the profile session when you leave, Play Services stops running and stops talking to Google.
CalyxOS: https://calyxos.org/ Privacy-respecting Android distribution that replaces Google spyware with MicroG, so you can have your cake and eat it too. Most everything will work as you're used to, but it does still talk to Google to make that happen.
LineageOS: https://lineageos.org/ The successor to CyanogenMod, will work with many different phones. More privacy and control than stock Android.
There are also many others: Sailfish, Replicant, e
Hardware:
CalyxOS and GrapheneOS run best on Pixels. The path of least resistance is to get one of these phones and run GrapheneOS with Google Services installed in one profile or other.
You could also buy a Librem 5 https://puri.sm/products/librem-5/ If privacy and security and hacking are really important to you.
Or a pinephone: https://www.pine64.org/pinephone/
Neither work very well by regular standards, but they're cool :-)
I've been so full of missing and delayed notifications I just bought an iPhone, which has zero issues with it, with zero configuration.
Still, as I made a few really small android apps in the past, this has been a sticking point for me for years.
Is it possible to write an app that can notify at ANY time? Let's say I want to monitor my self-hosted infrastructure. On an iPhone I get e-mail alerts right away. On Android, some ring exactly at the time I pick up the cursed phone.
I checked for every possible consumer facing configuration option (deep sleep exclusion, background service allowed, etc.) and I found zero reliable options.
Once you leave AOSP-land it can be more tricky, https://dontkillmyapp.com/ has more info if you're interested.
This actually looks very relevant [1]:
> Even disabling the system battery restrictions does not save the app from being killed. Let's find out, if it is a bug or a feature... Here you can read more details
I have Samsung s21; after years of fighting it (3 samsungs) I'm welcome to a bug explanation
- [1] https://dontkillmyapp.com/samsung#:~:text=Even%20disabling%2...
- iPhone rings, Samsung nothing
- I wait few minutes just to be sure and pick up Samsung - immediately after picking it up the notification shows up, with the exact timestamp of the moment I picked it up
That's why I called it a tangent to XMPP
So the iphone version of any xmpp app has to use apples notification service, but the android version of the same app might try to use a direct connection (saving the app developer a lot of server costs), even though on many models of phone it only works when the device is charging for example.
I'll phrase my issue differently: Is there any way to have reliable notification delivery that are time critical? Is actually calling the only 100% reliable option, as the PagerDuty does?
Note that you can only have one push notification reliably per user interaction. So once you have sent a notification, further ones won't be reliably delivered until the user interacts with your app in some way.
It's been a standard feature of XMPP mobile apps for as long as it's been necessary.
In any case, this is the choice of a specific implementation, and not something inherent to XMPP. Your original comment said that integration with Firebase was needed, and I wanted to point out that it is already integrated.
More on the app-killing ROMs can be found at https://dontkillmyapp.com
What you're describing also has been true for iOS for a while. Apps cannot do long-polling and require a push notification server (usually provided by the app maker, e.g: siskin, snikket, chatsecure), and that adds another point of failure.